Guidance
Biometric recognition and authentication systems
Understanding biometric recognition technologies, and how to build secure authentication systems.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
Page 13 of 13
Biometrics: general principles - contains some high level considerations of the whys and whens of biometric-based authentication. Biometrics: understanding biometrics gives you some insight on the technology and terminology in use.
Biometrics: choosing biometrics - discusses the relative strengths and weaknesses of commonly-encountered biometric modalities.
A solution which works well enough is the desired outcome of this guidance and much of the content is geared to providing the reader with enough information to answer this question. Start with Biometrics: choosing biometrics.
Biometrics: How biometrics are attacked is a good starting point for understanding attacks on biometrics. Biometrics: choosing biometrics provides specific information about particular biometric modalities.
A healthy skepticism is to be recommended regarding any claims made for biometrics. Claims, particularly around very high performance, or very good security, need to be considered carefully and should not be taken at face value. Biometrics: measuring performance will give you more detail on this problem.
No. Biometrics are fundamentally different from passwords. The way security is gained is very different in each case. Biometrics: understanding biometrics is a good starting point if you're trying to get to grips with the potential benefits of biometrics.
Stealing biometric data, whether a source image or specific biometric template, does not automatically mean that the biometric is no longer viable for authenticating the owner of the compromised data.
It takes some effort and skill to implement an attack using such data, so there is a threat, but that threat needs to be kept in perspective: the degree of difficulty in successfully implementing an attack will be set against any perceived benefit by the attacker. It is a question of who the attacker is, what the biometric information relates to and what use may be made of the stolen data.
As a general rule, you should control who is given access to biometric data. Privacy legislation should be followed by the biometric service provider to minimise the amount of information that is taken, and its use should be proportionate.
We do not propose single factor verification, therefore it follows that there will be additional information used in any authentication. The presence of additional factors limits the value of a compromised biometric template.


