Biometric recognition and authentication systems
Pages
Page 3 of 13
General principles
These principles address the most fundamental issues relating to the development and use of biometrics. They should be kept in mind throughout the lifecycle of any biometric access control system.
The importance of enrolment
Enrolment is fundamental - while it should be secure and protect biometric data, its importance goes far beyond that.
In order for a system to work effectively and as expected, it is important that the enrolment data is as good as possible - poor quality enrolments will lead to significant worsening in performance, in terms of both the ability to recognise an individual who has enrolled in the system, and also to avoid mistaking one individual for another.
On-device versus server-based processing
Biometric data collected by a device can either be used in-situ or shipped out to an external processor.
On Device
Most modern devices (laptops, mobile phones, tablets) will have at least one dedicated sensor for capturing biometric data - usually this will be a fingerprint scanner, but it could be face or iris based.
The security of such sensors is relatively strong. Without being exposed at any point, sensitive biometric data is encrypted on the device and stored using secure hardware-backed storage. This approach makes the data non-recoverable.
Once stored, no other processes or applications running on the device are allowed to access the biometric data. Typically, the API to the biometric functionality within the device only takes an input sample and returns a Yes/No decision. This enables a strong association with an individual enrolled to the particular device, which can be used to authenticate a specific transaction or session.
The pros and cons of on-device processing are:
On device
Secure storage and processing - biometric data is never visible externally
Typically, consent is explicit, as required by GDPR
No centralised biometric store as honey pot
You have no control over processing of biometric data or decision making
It is very difficult to get any idea of how the biometric mechanism functions. This makes it hard to know, or manage, your security and performance levels
Loss or replacement of the device requires re-enrollment
Lower powered devices may be limited in their use of the feature
Off Device
Biometric data captured by the device can be processed remotely, typically on a server controlled by the service performing the analysis. Choosing to process data off-device makes it possible to retain greater control over the processing of biometric data, allowing the management of desired performance, ease of use, exception handling, and so on. It is also easier to update the algorithm, meaning that emerging vulnerabilities can be addressed.
Central processing can also give the user a smoother experience because it's possible to use a single enrolled biometric across a range of devices. So, if a device is replaced or lost, it is not necessary to re-enrol the biometric.
There are some limitations on which biometric data can be captured, largely because built-in sensors are designed to operate within a closed system. Part of their security is that the data is never exposed and is therefore not available for external processing. However, it's still possible to capture a range of biometric modalities without using dedicated sensors.
The pros and cons of remote processing are:
Off device
Whoever performs the remote processing has direct control over the biometric functionality
Security and risk posture can be managed
Updates to algorithms are easy, allowing quick response to emerging threats and vulnerabilities
Device resources do not have to be devoted to biometric functionality
Users can use as single enrolled biometric on multiple devices
Vulnerability to attacks targeting outbound data
Biometric data at risk to large-scale data breaches if the processing servers are compromised
Increased complexity of system architecture and application security required to ensure the integrity of biometric data
Use a second factor in high security applications
Although discrimination within a population for a particular biometric modality can be very good (that is, there is a strong probability it will be able to uniquely identify an individual within the population) there are a number of factors which make it inadvisable to use a biometric on its own. These include the probabilistic nature of the processes and the fact that for any biometric there will be a percentage of the population for whom they just don't work.
The advantages to using a biometric as part of a two factor solution include:
- All biometrics make false match errors, using a second factor can reduce this error by orders of magnitude
- The addition of a second factor makes it significantly more difficult for an attacker to defeat the system without requiring a noticeably greater effort on the part of a genuine data subject
- The need to physically present a biometric characteristic at the biometric sensor limits the number of attacks in a period of time
- The weaknesses of one factor are likely to be very different to that of the other
- The use of a biometric gives confidence to the physical presence of the individual
The need for a secure fallback process
An exception handling process will be needed to manage the failure to capture a biometric sample, or a failure of recognition.
This should be of an equivalent level of security to the biometric itself. This will avoid the introduction of a simple attack where deliberately forcing a failure when presenting a biometric sample allows an attacker to use a less secure fallback process.


