Skip to main content
Guidance

Biometric recognition and authentication systems

Understanding biometric recognition technologies, and how to build secure authentication systems.

Page 3 of 13

General principles

Addressing the fundamental issues related to the use of biometrics.

These principles address the most fundamental issues relating to the development and use of biometrics. They should be kept in mind throughout the lifecycle of any biometric access control system. 



Off Device

Biometric data captured by the device can be processed remotely, typically on a server controlled by the service performing the analysis. Choosing to process data off-device makes it possible to retain greater control over the processing of biometric data, allowing the management of desired performance, ease of use, exception handling, and so on. It is also easier to update the algorithm, meaning that emerging vulnerabilities can be addressed.

Central processing can also give the user a smoother experience because it's possible to use a single enrolled biometric across a range of devices. So, if a device is replaced or lost, it is not necessary to re-enrol the biometric.

There are some limitations on which biometric data can be captured, largely because built-in sensors are designed to operate within a closed system. Part of their security is that the data is never exposed and is therefore not available for external processing. However, it's still possible to capture a range of biometric modalities without using dedicated sensors.

The pros and cons of remote processing are: 

Off device

  • Whoever performs the remote processing has direct control over the biometric functionality

  • Security and risk posture can be managed

  • Updates to algorithms are easy, allowing quick response to emerging threats and vulnerabilities

  • Device resources do not have to be devoted to biometric functionality

  • Users can use as single enrolled biometric on multiple devices

  • Vulnerability to attacks targeting outbound data

  • Biometric data at risk to large-scale data breaches if the processing servers are compromised

  • Increased complexity of system architecture and application security required to ensure the integrity of biometric data



Published

Reviewed

Version

1.0