Biometric recognition and authentication systems
Pages
Page 5 of 13
Choosing biometrics
How to identify and choose the correct biometrics for the function you wish to use it for.
Are biometrics suited to your needs?
Biometrics are frequently used to control access to all sorts of things. Buildings and computers are two common examples.
When first thinking about the possibility of incorporating biometrics into an access control project, it's quite common to hear questions such as: "Is biometric X any good and can I use it for my application?". This is the wrong type of question to ask first.
Your primary concern should be: "what method should I use to determine that a subject is authorised to access a system?" If, having weighed up the pros, cons and costs, the answer is a system which includes a biometric, then you can move on to think about specifics. That is what this page is about.
Knowing the right questions to ask, and how they should be answered, will help you to better understand where biometrics can be of use. These questions can be asked at an early stage in your development process, and will quickly whittle down your options to a small selection of suitable technologies. These can then be assessed further.
This section provides information that will help you to phrase your own questions in a way which will lead you towards the right biometric for your project.
Some useful considerations
The nature of the security requirements
'Security' means protecting an asset that is at risk. This being so, your security requirements will depend on the asset at risk and who has responsibility for protecting it.
Biometrics make it possible to address risks taken by the asset holder, and the trust between asset holder and credential holder, in a way that's different to PINs, passwords and tokens.
For example, a banking system may assume a high level of trust in the person holding a bank card plus PIN because the cardholder has a significant investment in the security of their own bank account. A theme park, on the other hand, may assume its user population has no qualms about sharing a season pass and therefore place low trust in them.
The bank may consider the PIN provides adequate security for their risk, while the theme park may require the use of biometrics to make the pass non-transferable.
Biometrics can also be used to ensure that a single individual only has a single authorisation. For example, it is important that an individual should only have a single record on a immigration visa system. Biometrics can enable a 'one person - one record' policy.
Security requirements favouring the use of biometrics
Biometrics can be used to avoid some common security problems, including:
- forgetting PINs, passwords or access cards
- sharing of PINs, passwords or access cards
- theft of PINs, passwords or access cards
- a person enrolling under a second identity
- a person denying that they participated in a transaction
Legal and policy constraints
Biometric characteristics are by definition Personally Identifiable Information (PII). There are many regulations in the UK and elsewhere, governing the collection, use, storage, protection and destruction of PII. Prior to deployment of a biometric system it is important that you fully consider any relevant PII legislation. Any use of biometrics should be appropriate and proportional to the application. It is important to understand how this may limit your use of biometrics.
Exception handling
For any biometric system, there will be a proportion of the population who are unable to use it. The exception handling system required to deal with these cases must be as secure as the biometric system, but may be of a very different nature.
Choosing a biometric modality
This section provides a list of questions and answers which you should run through when attempting to decide which modality is right for your project.
What are the locations and environments where biometric devices will be used?
Environmental factors, such as illumination, acoustic noise, and humidity, have consequences for each of the modalities. For example, face recognition is known to be more challenging in outdoor lighting conditions. Fingerprint systems struggle in high humidity or very dry conditions.
You will need to take into account any possible environmental factors which your proposed use will have to overcome.
Required throughput rate
Throughput can mean a number of different things - data collection speeds (e.g. the speed at which individuals can be processed at the data collection point), data processing speed or enrolment time.
For example, an access control system through a single portal taking 20 seconds to process each person would take nearly 2 hours to process a population of 300, most likely making the system unusable. Some modalities are inherently faster than others.
What is your target population?
Sensors will need to accommodate the range of people within a population, taking account of age, height, physical ability, ethnicity and other variations. The ergonomics of the biometric system must be designed with the target population in mind. Some biometric characteristics are harder to capture for some parts of a population. For example, fingerprint doesn't work as well with young children and older people as it does with those within the middle age ranges. The problem cases might not be obvious prior to deployment.
Do you already collect biometric samples for other applications, which could be leveraged?
Enrolment is one of the most expensive and time consuming aspects of any biometric system. If possible, avoid bespoke collection by leveraging existing biometric databases. For example, if you already have a database of facial images, as in the case of passports and driving licences, face recognition would not require a special enrolment campaign.
What is the cost of acquiring samples?
Cost can be measured in terms of the financial cost of capturing biometric samples, for example in the need for any special equipment. It can also refer to the effort required to acquire the samples, in terms of time, training and hours taken from day to day business.
It may be that a less accurate modality is actually preferable for practical reasons. For example, there is a very strong argument in favour of face recognition at border control as ePassports all hold a face image which the passport holder's face can be compared against.
So, even though other biometric modalities may be “more accurate”, facial recognition wins out on a purely practical basis, because there are no added costs involved in acquiring the reference images.
Do your systems already use devices with biometric capabilities?
Changing processes to accommodate a new biometric function is inherently expensive. Exploiting existing biometric capabilities and modes of behaviour may be a way to minimise cost. If you're implementing a biometric application on a smart phone, there will likely be an opportunity to use the phone's existing biometric capability. Many smartphone users are comfortable with the biometric capability of their phone.
Are there any commercial issues?
It is possible that issues such as whether a competitive market of suppliers exists will feature heavily in any design decisions.
Is the system resilient to presentation attacks?
The most obvious type of attack against any biometric system will involve an impostor presenting an artefact designed to replicate the biometric characteristic of an enrolled individual. It therefore makes sense to ensure that your choice of implementation should be able to withstand such challenges.
Does the biometric reflect how your organisation manages likely risks and threats?
Before choosing a biometric you should be aware of the likely threats and risks associated with its use and determine how this fits with your organisation's management of risk. Below we give in-depth consideration to each modality in turn.
Is the modality easy to use?
The more convenient a modality is for end users (aka data subjects) and system operators, the more likely it is to be adopted.
- Fingerprint recognition Introducing fingerprint system biometrics.
- Speaker recognition Introducing speaker recognition biometrics.
- Iris recognition Introducing Iris recognition biometrics.
- Vein pattern recognition Introducing vein pattern biometrics.
- Face recognition Introducing face recognition biometrics.