Fujisawa City Office, Kanagawa Prefecture

Quickly introduced biometric authentication and thin client as a municipality
System has been switched smoothly at the time of introduction of a new system, and burden on users and administrators has been mitigated.

In the Fujisawa City Office, one PC has been supplied to each official in around 2001, and then the necessity to identify the individual user had increased in comparison with the time when PCs were shared by group members. Furthermore, with the progress of digitalization of regional information and administrative information, it has been recognized as a top priority issue to ensure the security in order to gain the trust of residents. Along with our digitalization movement, we decided to study the introduction of biometric authentication and thin clients that cannot be spoofed from the viewpoint of (1) human measures, (2) physical measures and (3) technical measures with the highest priority on the security issue.

Introduction of “biometric authentication” as the only key to identify a person

We introduced DDS’s system in 2006. Before that, authentication was with IDs/passwords. Since Fujisawa City set the security to the most important issue in the digitalization promotion, we studied measures having higher security level.
In the previous ID/password authentication, there is a possibility that the ID/password can be told to the person or stolen. In case of IC card authentication, there is a risk that the card is lost or stolen, and then third parties who get it can impersonate users. Furthermore, IDs/passwords must be changed regularly in order to improve safety, while it is indispensable to change the registered data at the time of personnel changes. If we choose either, the burden increased on both the user and the administrator.
Therefore, we introduced biometric authentication as the only solution that identifies the person without the headache of a regular update of passwords and avoids the risk of impersonation.

Frequency analysis method of DSS reduces the reluctance to fingerprint authentication.

At the time of introduction of biometric authentication, we were concerned about the reluctance of officials for fingerprint authentication. In 2006 when we introduced the system, biometric authentication was not common yet, many people did not have a very good image of fingerprints since it made people reminisce the police investigation. While the protection of personal information became more important, many officials were reluctant to register their physical features into a PC. Among various technologies including ones of other companies, it has been highly appreciated the fact that the system of DDS analyzes fingerprints by converting irregularities of fingerprints into waveform information. We certainly explained to the officials that fingerprint images were not recorded at all and it was impossible to restore the image of fingerprint from the recognized waveform information, and then they were convinced. Furthermore, a key factor was that the surface of input units was the sweep type to authenticate by sliding the finger instead of a glass surface. While fingerprints will remain on the glass surface as a residual mark, there is no residual mark of fingerprints in the sweep type, so that it is a reason why the officials can use it without resistance.

We struggled at the time of introduction since there was a few example.

At that time, we had a hard time, since there are few cases of introducing biometric authentication among the local governments of nationwide and we had also introduced the thin client at the same time.
At that time, there were only a few products supporting the thin client among the security products for companies. For biometric authentication in particular, the cost of the hardware was expensive since the system itself was not generally widespread.
In the circumstance, the system of DDS could be introduced at relatively inexpensive costs and could support thin clients as well. The decisive factor was that there was sufficient operation management software, such as interworking with Active Directory of Microsoft.
At the time of introduction, it was unavoidable work to register fingerprints of all ersonnel, so we formed a caravan to register fingerprints of all officials of about 2700 persons. It is a memory now, but it was great difficulty at that time.

The authentication ratio improved more after switching to the new system

While security has been secured by introducing biometric authentication, there were several issues for fingerprint authentication, such as the fact that it took time or needed to try many times to read fingerprints if the features of fingerprint was thin. Therefore, from 2010 we started studying new systems to be introduced at the time of the equipment update in 2012.
As a result, we employed “MA” of DDS to continue the new biometric authentication system. The reason for our choice was the fact that the system supported multiple devices. Since we thought that it would be difficult to solve the problem fundamentally with fingerprint authentication only, we considered adopting other biometric authentication methods. In that regard, the new system is capable of not only authenticating smoothly by improving its accuracy of fingerprint authentication but also supporting other authentication methods, such as the vein authentication with the same management system as fingerprint authentication. Consequently there was no increase in the administrative burden and the system was easier to use.
Furthermore, another reason for the selection was that it could be switched to the new system smoothly by inheriting fingerprint data from the past. Since it was not necessary to register fingerprints of all officials unlike the previous introduction, the system transfer could take place smoothly.

We expect to the system that supports the evolving OS and can be used for many years.

Since the security products operate in a deep part of the OS, such as starting a PC or recognizing an individual profile, they may conflict with other security products. As evolving the OS rapidly, it is very inconvenient that the hardware does not support the latest OS. We want DDS to follow the evolution of OS so that we can use the DDS products for a long time.
Furthermore, enhancement of tools for registering fingerprints and their management software and management tools is important for introducing such a system. While usability of the hardware is important for the user using the system, easy management where the individual management information and fingerprint registration tool function to integrate with Active Directory smoothly is important for the administrator. We expect that these functions are interlink seamlessly and the system is a tool that can be controlled easily with few burdens on the administrator side.


