Biometric recognition and authentication systems
Pages
Page 1 of 13

bjdlzx via Getty Images
Introduction
This guidance will help you understand the security profiles of biometric recognition technologies, and how to build secure authentication systems which incorporate them.
Although biometrics have a variety of unusual and interesting applications, this document will be concerned with biometric systems for the verification of individuals. For example, as part of an access control system. The example use cases will help clarify the type of system we are considering here.
We will not be considering the assignment of identities to individuals.
There are numerous experimental biometrics which measure such things as gait, heartbeat, and skin reflectance. But in this guidance we are only interested in those modalities which are commercially available, and appropriate to the field of cyber security. These are: fingerprint, face, iris, vein pattern, and speaker recognition.
Biometric decision making
Biometrics work in a slightly different way to something like a PIN or password. In these cases, an access control system will compare a stored password with the one entered by an individual. If they are identical, access will be granted.
However, no two captures of biometric data will produce truly 'identical' results. So, a biometric system must make an estimation as to whether two biometric samples come from the same individual.
In other words, the decision is not based on a simple comparison, it is rather, 'this sample is so similar to the one I have on record that it is judged to be from the same person'.
Since the decisions of a biometric system are probabilistic in this way, their function can be varied to give different performance. For example, if we want comparisons to happen faster then we must accept that more comparisons will be incorrect. This can't happen with a password, where the input either matches or it does not.
Much of the job in choosing and deploying biometrics in access control systems depends on first understanding these problems and then determining whether there is a combination of settings which will work for you in your particular scenario. This guidance aims to give you the tools to do just that.
Who is this guidance for?
This document is aimed at providing a framework for understanding automated human recognition technologies for the following audience:
- Organisations looking to implement identity management and access control systems
- Decision makers seeking NCSC advice on biometric verification systems
- Biometrics producers seeking to understand the NCSC’s position on biometric technology
How to use this guidance
When using this guidance to help you assess the suitability of biometric systems, we suggest the following methodology:
- Understanding biometrics
Obtain a basic grasp of the pros, cons and costs of biometrics. This will help you determine whether your system would benefit from such an input. - General principles
Things to keep in mind when considering the use of biometrics. - How biometrics are attacked
A more in-depth analysis of the ways in which biometrics can be attacked. You will need to weigh this analysis against the capacity of your expected adversaries. In other words, do the people you expect to attempt an attack against your systems have the capacity to carry one out successfully? - Choosing biometrics
How to frame the questions which underlie this decision. If you ask the right questions, the field of possible solutions will become considerably more manageable. - Measuring performance
Having a list of potential biometric systems in mind, you need the ability to assess their performance, either claimed by manufacturers or tested in-house. - Example use cases
A series of examples intended to help you develop a clear picture of the real-world uses to which biometrics can be put. - Frequently Asked Questions
Answers to some of the most common biometric-related questions received by the NCSC


