Biometric recognition and authentication systems
Pages
Page 2 of 13
Understanding biometrics
Introduction
In this section, we first address some of the terminology used when talking about biometrics. After this, we look at the benefits and limitations which need to be taken into account when considering the use of biometrics.
Biometrics may be used to improve the security, convenience or the efficiency of interactions with a verification system. However, these benefits are unlikely to be obtained if careful consideration is not given to the design and deployment of a system. As a result, this guidance will be most useful during the initial phases of designing an authentication system.
Terminology
Basic terms
The ISO and IEC standards bodies have defined biometrics as, “The automated recognition of individuals based on their biological and behavioural characteristics.”
To be recognised, an individual must have been previously seen and their biometric data recorded. This process is known as enrolment. Samples of biometric data, captured from an individual, are stored to allow comparison with samples captured during subsequent encounters.
The individual is often referred to as a data subject because we are interested in the data captured from them, at enrolment and subsequently.
The choice of which data is recorded - fingerprint, iris etc. - is known as the modality.
A fallback process will be needed to handle cases when the biometric system fails to recognise an individual.
Terms from access control
The process of determining which data record, if any, belongs to a specific individual. Biometrics are not considered reliable enough to perform this function.
Do we have a record in our database tied to fingerprints matching those taken from the individual before us? This will require a search through the entire database.
The process of confirming that a data record refers to a specific individual
Is the person standing before you, holding a passport, really the person to whom the passport was issued? This will require comparison of the face of the holder to the face image on the passport.
Establishing an individual as the owner of a set of identifying characteristics.
This is the process of collecting and verifying information about a person and assigning the records collected to that individual. For example, from witnesses when applying for a passport, fingerprints at a police station or a photograph of the head for facial recognition.
The process of verification used to determine whether a claimed characteristic, such as a fingerprint, identifies an individual as being who they claim to be.
Matching a fingerprint to a template stored in a mobile phone.
Terms relating to biometric errors
When the data subject presents him or herself to be recognised, the two main types of error are:
A false match occurs when an individual presents themselves to the biometric system for recognition and is matched with someone else's record.
For example, a facial recognition system may incorrectly match an image of a data subject with an image of their sibling.
A measure of the propensity of the system to make this error.
A false non-match occurs when an enrolled individual presents themselves to the biometric system, but is not matched to their own record.
For example a fingerprint system might fail to match two fingerprint images from the same finger, due to damage or wear between enrolment and subsequent recognition attempt. This could be due to something as simple as manual labour.
A measure of the propensity of the system to make this error.
The merits of using a biometric
Below, we outline the potential benefits which can be obtained from a biometric verification system, before moving on to look at the challenges of implementation and the costs of such a system.
Deciding whether to employ biometrics will require a careful consideration of these factors, as they apply to your particular situation.
There is a strong link between the biometric data and the subject/source of that data
As a means of access, it is less easily lost, stolen or loaned to someone else
Biometric systems have the ability to check against and consolidate multiple records referring to the same individual
This can help with database de-duplication and in the elimination of fraudulent registrations
For some applications, biometrics can be faster and more convenient than passwords or tokens
Biometrics can avoid the need to remember and enter a secure password, or to carry a token or other credential
Additional security
Obtained by using a source of information which is complementary to, but also independent of, tokens or passwords
As with other security technologies, biometrics may be defeated by determined attackers
For systems requiring the highest levels of security, biometrics should be augmented by additional factors.
For any modality, there will be some people who cannot use it successfully
This becomes relevant when choosing a modality. For example, fingerprint recognition will not achieve optimal levels of performance for a target population of young children, older people, or those who do manual labour. There's a higher percentage of individuals in these groups who have prints which are hard to read.
As with any technology, introducing biometrics may entail a certain amount of change management
Adopting a new process may require training, with some people having trouble adapting
Variability between images captured at different times can lead to false match or false non-match errors
Because no two captures of biometric data will produce truly 'identical' images, a biometric system must make an estimation as to whether two biometric samples come from the same individual. The level of similarity which a system requires for a match may be adjustable to better suit your purposes.
Compromised biometric characteristics cannot be replaced
Due to the link with physical characteristics, unlike tokens and passwords, it's not possible to assign users a new biometric characteristic, if compromised. For example, issuing a new set of fingerprints presents obvious difficulties.
Some technologies are proprietary and non-interoperable
Some biometrics have been in use for many years and are not limited to proprietary solutions. Other modalities are new and limited to a single vendor. The field has yet to be properly standardised.
Some people are not comfortable with the potentially intimate nature of biometric imaging
The acceptability of capturing a biometric sample may depend on culture, religion, age, environment, gender as well as the particular biometric modality.
Costs
- Additional processes compared to other authentication methods
An enrolment process will normally require the bodily presence of the individual.
A fallback process will be needed to handle cases when the biometric system fails to recognise an individual
- Re-enrolment may be required if there is a change in biometric characteristics
The natural ageing process may necessitate the periodic updating of an individual's reference. - Costs of processing and protecting biometric data, including compliance with legal requirements
Biometric data is always considered Personally Identifiable Information (PII). Legal requirements must, therefore, be taken into account in the overall design of a biometric system. You will need to identify the privacy implications of your intended system and ensure the data is appropriately managed.


