Skip to content
CY-503 (A) · Biometric Techniques for Security/Quick Revision Short Notes

Biometric Techniques for Security (CY-503 (A)) - Unit 3 Short Notes

1.0 Introduction to Biometric Authentication

Biometric Authentication is the automatic recognition of individuals based on their distinctive physiological or behavioral characteristics.

1.1 Core Principle

  • Uses inherent human traits (e.g., fingerprint, iris pattern, voice) as credentials.

  • Replaces or supplements traditional methods (passwords, tokens).

  • Based on the premise that these traits are unique to each individual and stable over time.

1.2 Fundamental Properties (The "7 Pillars")

A viable biometric trait must satisfy:

  1. Uniqueness: Distinguishes one individual from another (e.g., iris patterns are highly unique).

  2. Permanence: Remains stable over a person's lifetime (e.g., hand geometry is stable; weight is not).

  3. Collectability: Can be measured quantitatively with a suitable sensor.

  4. Performance: Accuracy, speed, and resource requirements (FAR/FRR).

  5. Acceptability: User willingness to use the system (cultural/social factors).

  6. Circumvention: Resistance to being faked or spoofed.

  7. Reliability: Consistency under varying environmental conditions.

1.3 Biometric vs. Traditional Authentication

Feature Biometrics Knowledge-Based (Password/PIN) Token-Based (Smart Card/Key)
Basis Inherent trait Something you know Something you have
Revocability Difficult (cannot "reset" a fingerprint) Easy (change password) Easy (revoke/issue new card)
Loss/Theft Not applicable Can be stolen/guessed Can be lost/stolen/copied
Convenience High (no memorization) Low (memory burden) Medium (carry physical item)
Spoofability High risk (presentation attacks) Medium (phishing, keyloggers) High (cloning, theft)

1.4 General System Architecture

A biometric system has two primary phases:

  1. Enrollment (Registration):

    • Sensor captures raw biometric sample.

    • Feature extraction creates a template (mathematical representation).

    • Template is stored in a database (with user ID).

  2. Authentication (Verification/Identification):

    • New sample captured.

    • Features extracted to create a probe template.

    • Probe template is matched against stored template(s).

    • Decision module outputs accept or reject.

1.5 Operational Modes

Mode Verification (1:1) Identification (1:N)
Query "Is this person X?" "Who is this person?"
Process Compare probe to single, claimed template. Compare probe to all templates in database.
Output Yes/No (or match score). Identity (ID) or "Unknown".
Complexity O(1) - Constant time. O(N) - Linear search (N = database size).
Use Case Accessing a laptop, ATM. Finding a criminal in a watchlist, attendance.

DiagramCANVAS: A flowchart showing two parallel paths: ENROLLMENT (Sensor -> Feature Extraction -> Template Storage) and AUTHENTICATION (Sensor -> Feature Extraction -> Matching -> Decision). The Matching block for Verification has one arrow from Storage, for Identification has multiple arrows from Storage.


2.0 Biometric Modalities and Technologies

2.1 Physiological Biometrics

  • 2.1.1 Fingerprint Recognition:

    • Feature: Ridge patterns (minutiae: ridge endings, bifurcations).

    • Extraction: Minutiae-based algorithms (most common). Template is set of (x,y,θ) coordinates.

    • Pros: Mature, low cost, high uniqueness.

    • Cons: Latent prints, worn ridges, user cooperation.

  • 2.1.2 Iris Recognition:

    • Feature: Complex, random texture patterns in the iris (pupil, sclera boundaries).

    • Extraction: Gabor filters or wavelet transforms to encode phase information into iris code (binary template).

    • Pros: Extremely high accuracy, stable, non-contact.

    • Cons: User cooperation (glasses, lighting), camera cost.

  • 2.1.3 Face Recognition:

    • Approaches:

      1. Geometric: Distances between facial landmarks (eyes, nose).

      2. Photometric: Pixel intensity patterns (Eigenfaces, Fisherfaces).

      3. Deep Learning: Convolutional Neural Networks (CNNs) - state-of-the-art.

    • Pros: Non-intrusive, passive.

    • Cons: Sensitive to pose, lighting, expression, aging.

  • 2.1.4 Others:

    • DNA: Ultimate uniqueness, but slow, expensive, invasive. Used for forensics.

    • Retinal: Vascular pattern in retina. Very high accuracy but highly intrusive (user must look into scanner).

    • Hand Geometry: Measures finger length, palm width. Moderate accuracy, robust.

    • Ear Shape: Unique, stable, but occluded by hair/glasses.

2.2 Behavioral Biometrics

  • 2.2.1 Voice Recognition:

    • Feature: Spectral features (MFCCs - Mel-Frequency Cepstral Coefficients).

    • Types:

      • Text-Dependent: User says fixed phrase ("My voice is my passport").

      • Text-Independent: Analyzes speech patterns regardless of content.

    • Pros: Remote-friendly, natural.

    • Cons: Sensitive to noise, health (cold), emotion.

  • 2.2.2 Signature Dynamics:

    • Static: Image of signature (like a picture).

    • Dynamic: Pen-tip movement (speed, pressure, stroke order). More secure.

  • 2.2.3 Others:

    • Keystroke Dynamics: Timing between key presses (dwell time, flight time).

    • Gait Recognition: Walking pattern from video or wearable sensors.

    • Typing Rhythms: Similar to keystroke dynamics.

2.3 Comparative Analysis Summary

Modality Accuracy (EER) Cost User Acceptance Environmental Robustness
Fingerprint Low-Medium Very Low High Medium (dirty/wet fingers)
Iris Very Low High Medium High (needs good lighting)
Face Medium Medium Very High Low (pose, light, occlusion)
Voice Medium Low High Very Low (noise)
Signature Medium Low High Medium

DiagramSEARCH: fingerprint minutiae diagram, iris texture close-up, face landmark points, voice spectrogram, signature dynamic plot (x,y vs time)


3.0 Biometric System Components and Workflow

3.1 Sensor/Input Device

  • Captures raw biometric sample (optical, capacitive, ultrasonic for fingerprints; CMOS camera for iris/face).

  • Critical Function: Quality Assessment (rejects blurry, low-contrast samples).

  • Live Detection (Liveness Detection): Prevents spoofing with artifacts (fake finger, photo). Techniques: challenge-response, pulse detection, skin conductivity.

3.2 Feature Extraction & Template Creation

  • Transforms raw sensor data into a compact, discriminative, and non-invertible template.

  • Algorithm Examples:

    • Fingerprint: Minutiae extraction (crossing number algorithm).

    • Iris: 2D Gabor wavelet phase quantization → binary iris code.

    • Face: CNN-based embedding (e.g., FaceNet: 128-D vector).

  • Template Size: Varies (Fingerprint: ~300 bytes; Iris: ~256-512 bytes; Face: ~1-2KB).

3.3 Template Storage & Security

  • Centralized Database: Single repository. Pros: Easy management. Cons: Single point of failure, privacy risk.

  • Distributed (On-card): Template stored on personal smart card/device. Pros: User control, no central breach. Cons: Limited storage/computation on card.

  • Security: Templates must be encrypted (AES) at rest and in transit. Never store raw biometric image.

3.4 Matching Algorithm

  • Compares probe template ($$\displaystyle T_p $$) with stored template ($$\displaystyle T_s $$).

  • Computes a similarity score ($S$) or dissimilarity distance ($D$).

    • Minutiae: Graph matching algorithms (Hausdorff distance).

    • Iris/Face (binary): Hamming Distance (HD). HD = (Number of disagreeing bits) / (Total bits). HD=0 = perfect match.

    • Face (real-valued): Euclidean distance or cosine similarity.

  • Threshold ($\theta$): Pre-defined value. If $$\displaystyle S > \theta $$ (or $$\displaystyle D < \theta $$), it's a match.

3.5 Decision Module

  • Simple rule: IF (Score >= Threshold) THEN Accept ELSE Reject.

  • Threshold tuning is a critical trade-off between security (low FAR) and convenience (low FRR).

3.6 Detailed Workflow Diagram

DiagramCANVAS: A two-column diagram. LEFT COLUMN: ENROLLMENT. Steps: 1. Sensor Capture (raw image), 2. Quality Check (Pass/Fail), 3. Feature Extraction (algorithm), 4. Template Creation, 5. Template Encryption, 6. Secure Storage (DB/Card) with User ID. RIGHT COLUMN: AUTHENTICATION. Steps: 1. Sensor Capture (raw probe), 2. Quality Check, 3. Feature Extraction (probe template), 4. Template Retrieval (by claimed ID for verification, or all for identification), 5. Matching (compute score/distance), 6. Score vs Threshold Comparison, 7. Decision (Accept/Reject).


4.0 Performance Metrics and Evaluation

4.1 Key Metrics

Assume a test with $N$ genuine attempts and $M$ impostor attempts.

Metric Definition Formula
False Acceptance Rate (FAR) Probability an impostor is incorrectly accepted. $$\displaystyle \text{FAR} = \frac{\text{False Positives (FP)}}{M} $$
False Rejection Rate (FRR) Probability a genuine user is incorrectly rejected. $$\displaystyle \text{FRR} = \frac{\text{False Negatives (FN)}}{N} $$
Failure to Capture (FTC) Rate at which sensor fails to acquire a usable sample. $$\displaystyle \text{FTC} = \frac{\text{Failed Acquisitions}}{\text{Total Attempts}} $$
Genuine Acceptance Rate (GAR) Probability a genuine user is correctly accepted. $$\displaystyle \text{GAR} = 1 - \text{FRR} $$

4.2 ROC Curve & EER

  • ROC (Receiver Operating Characteristic) Curve: Plots FAR (x-axis) vs GAR (y-axis) as the decision threshold $\theta$ is varied.

    • Lower threshold → Higher GAR, Higher FAR.

    • Higher threshold → Lower GAR, Lower FAR.

  • Equal Error Rate (EER): The point on the ROC curve where FAR = FRR. It's a single-number summary of system accuracy. Lower EER = Better system.

$$\text{EER} = \text{FAR} = \text{FRR} \text{ at the threshold where they intersect.}$$

\boxed{\text{EER is the operating point where FAR = FRR.}}

4.3 Factors Influencing Performance

  • Sensor Quality & Resolution.

  • Environmental Conditions: Lighting, noise, temperature.

  • User Cooperation & Presentation: Pose, expression, pressure on sensor.

  • Template Quality & Algorithm Robustness.

  • Population Diversity: Age, ethnicity, disability.

4.4 Benchmarking & Standards

  • NIST (National Institute of Standards and Technology): Conducts major evaluations (e.g., FRVT - Face Recognition Vendor Test, IREX - Iris Exchange).

  • ISO/IEC 19794 series: Standards for biometric data interchange formats.

  • Protocols: Use large, diverse, and labeled datasets for fair comparison.


5.0 Security and Privacy Considerations

5.1 Threats to Biometric Systems

  1. Presentation Attack (Spoofing): Submitting a fake biometric artifact (gummy finger, printed iris, voice recording).

  2. Replay Attack: Re-transmitting a previously intercepted digital sample.

  3. Trojan Horse Attacks: Malware that intercepts/steals templates from the sensor or database.

  4. Database Attack: Direct theft of the central template database.

  5. Bypass/Override: Tampering with the matching module's decision.

5.2 Liveness Detection Techniques

  • Challenge-Response: "Blink twice," "Turn head." Detects life.

  • Physiological Signals: Detect blood flow (pulse) from face video, skin conductivity.

  • Texture Analysis: Analyze skin texture, specular reflection (for fingerprints/iris) to distinguish live skin from silicone/paper.

  • 3D Structure: Use 3D sensors (structured light, time-of-flight) to reject flat photos.

5.3 Template Protection Schemes

The goal: protect stored templates so that even if stolen, the original biometric cannot be reconstructed and the template can be revoked/reissued.

  • 5.3.1 Cancelable Biometrics:

    • Apply a non-invertible transformation $f$ to the original template $T$: $$\displaystyle T' = f(T) $$.

    • $f$ is one-way; $T$ cannot be recovered from $T'$.

    • If $T'$ is compromised, a new transformation $f'$ is applied to the same biometric to issue a new template $$\displaystyle T'' = f'(T) $$.

    • Example: BioHashing, Cartesian transforms.

  • 5.3.2 Biometric Cryptosystems:

    • Fuzzy Vault: Locks a secret key $K$ using biometric features. Only the correct biometric can unlock (reveal) $K$. Tolerates small variations.

    • Fuzzy Commitment: Similar; binds a key to a noisy biometric feature vector using error-correcting codes.

  • 5.3.3 Advanced Crypto:

    • Homomorphic Encryption: Perform matching directly on encrypted templates without decryption.

    • Secure Multi-Party Computation (MPC): Multiple parties jointly compute a match without revealing their private templates.

5.4 Privacy Concerns

  • Biometric data is Personally Identifiable Information (PII) and often sensitive under laws like GDPR (EU) and CCPA (California).

  • Key Issues:

    • Function Creep: Data used for purposes beyond original consent.

    • Secondary Use: Sharing with law enforcement or third parties.

    • Surveillance: Covert collection and tracking.

    • Bias: Algorithmic discrimination based on race, gender, age.

5.5 Revocability & Reissuance

  • Major Challenge: Unlike passwords, biometrics are fixed. If a fingerprint template is stolen, you cannot "change" your fingerprint.

  • Solution: Cancelable Biometrics (see 5.3.1) provides a way to issue a new "version" of the template for the same finger.


6.0 Smart Cards and Comparative Analysis with Biometrics

6.1 Smart Card Authentication Fundamentals

  • A smart card is a plastic card with an embedded microprocessor and/or memory chip.

  • Capabilities: Secure storage of cryptographic keys, execution of cryptographic algorithms, PIN verification.

  • Operation: Challenge-Response protocol.

    1. Reader sends a random challenge to card.

    2. Card uses its stored private key to compute a response (e.g., sign the challenge).

    3. Reader verifies response using the corresponding public key.

    4. Often combined with PIN (something you know) for two-factor.

6.2 Comparative Analysis: Biometrics vs. Smart Cards

Aspect Biometrics Smart Cards
Security Basis Inherent, non-transferable. Tied to the person. Token-based, transferable. Can be lost/stolen/copied.
Primary Threat Presentation attacks (spoofing), template theft. Physical loss/theft, cloning, PIN guessing.
Convenience High - No token to carry, no PIN to remember. Medium - Must carry card, remember PIN.
Revocability Very Low - Cannot change biometric. High - Easy to revoke lost card and issue new one.
Cost & Infra High initial (sensors, DB), low per-user. Medium initial (readers), medium per-user (card issuance).
Scalability Excellent for large populations (1:N search). Poor for 1:N (requires each card to have unique key; verification is 1:1).
User Acceptance Privacy concerns, hygiene (contact sensors). Widely accepted, familiar (credit cards).

6.3 Two-Factor/Multi-Factor Authentication

  • Combining both provides stronger security than either alone.

  • Example: Access to a secure lab.

    1. Something you have: Swipe smart card (proves possession).

    2. Something you are: Scan fingerprint (proves identity).

  • The system requires both to succeed. Compromise of one factor (lost card or spoofed fingerprint) is insufficient.

6.4 Use Case Preference

Prefer Biometrics Prefer Smart Cards
High-throughput physical access (turnstiles). Environments requiring strong non-repudiation and key management (digital signatures).
When user convenience is paramount (mobile device unlock). When revocability is critical (employee turnover).
1:N identification scenarios (finding a person in a crowd). 1:1 verification with a pre-issued token (bank transactions).
Environments where carrying tokens is impractical (hospitals, factories). Systems already built on PKI infrastructure.

7.0 Applications and Deployment Challenges

7.1 Physical Access Control

  • Buildings, data centers, server rooms, vehicles.

  • Challenge: Speed (throughput), hygiene (contact sensors), tailgating.

7.2 Logical Access Control

  • Computer login (Windows Hello), network authentication, mobile device unlock.

  • Challenge: Integration with OS, remote attacks.

7.3 National ID & Border Control

  • e-Passports (ICAO Doc 9303): Store digital face image and optionally fingerprints/iris in a chip.

  • US-VISIT, IOM: Biometric watchlists (1:N identification) at borders.

  • Challenge: Interoperability between countries, database size (1:N search at scale).

7.4 Financial Sector

  • ATM transactions (fingerprint/iris), high-value payment authorization.

  • Challenge: Regulatory compliance (KYC), fraud prevention, user trust.

7.5 Healthcare

  • Patient identification (prevent mix-ups), medical records access.

  • Challenge: HIPAA compliance, hygiene in clinical settings, accommodating elderly/ill patients.

7.6 Deployment Challenges

  • User Acceptance: Privacy fears ("big brother"), cultural/religious objections.

  • Disability Accommodation: Users with no fingerprints (manual laborers), blindness (face/iris).

  • Hygiene: Contact-based sensors in public/hospital settings.

  • Environmental Factors: Outdoor lighting, rain, gloves.

  • Cost-Benefit Analysis: Justifying high cost for low-risk applications.


8.0 Advanced Topics and Future Directions

8.1 Multimodal Biometric Systems

  • Use multiple biometrics (e.g., fingerprint + face) or multiple instances (two fingers, both eyes).

  • Fusion Strategies:

    • Feature-Level: Concatenate feature vectors from different modalities. (Most information, but complex).

    • Score-Level: Combine matching scores (e.g., sum, weighted average, logistic regression). Most common.

    • Decision-Level: Combine final accept/reject decisions (majority vote).

  • Goal: Improve accuracy (lower EER), increase robustness (if one modality fails), enhance security (harder to spoof all).

8.2 Continuous & Implicit Authentication

  • Concept: Authenticate user continuously during a session without explicit action.

  • Methods: Behavioral biometrics (keystroke dynamics, gait, touchscreen gestures) monitored in the background.

  • Use Case: Mobile devices, workstations. Detects session hijacking.

8.3 Standardization Efforts

  • ISO/IEC 19794 series: Defines data formats for different biometrics (e.g., Part 2: Finger minutiae, Part 5: Face image data).

  • ANSI/INCITS 358: Biometric data interchange formats (US standard).

  • Purpose: Ensure interoperability between systems from different vendors.

8.4 Ethical & Legal Frameworks

  • Consent: Must be informed, specific, and freely given.

  • Data Ownership: Who owns the biometric data? Individual or collector?

  • Bias & Fairness: Algorithms can have disparate error rates across demographics (e.g., higher FRR for darker skin faces). Requires diverse training data and auditing.

  • Regulation: GDPR (Biometric data as "special category" requiring explicit consent), BIPA (Illinois Biometric Information Privacy Act).

8.5 Emerging Trends

  • Behavioral Biometrics for IoT: Authenticating devices/users based on usage patterns.

  • Blockchain for Template Management: Decentralized, immutable audit trail of template access and use.

  • Privacy-Preserving Recognition: Using Secure Enclaves (e.g., Apple's Secure Element) or Federated Learning to process biometrics locally without sharing raw data.

  • Contactless & Remote: Accelerated by COVID-19 (e.g., contactless fingerprint, remote face/voice verification).

DiagramSEARCH: multimodal fusion diagram (face+iris), continuous authentication on smartphone, blockchain biometric template ledger


UNIT 3 EXAM QUICK RECAP:

  1. Know the 7 properties of a good biometric trait.

  2. Be able to draw & explain the complete biometric system workflow (enrollment vs. auth).

  3. Memorize definitions & formulas: FAR, FRR, GAR, EER, ROC curve.

  4. Contrast Biometrics vs. Smart Cards in a table format (security, revocability, cost).

  5. List 3 spoofing attacks and 2 liveness detection techniques.

  6. Explain Cancelable Biometrics vs. Biometric Cryptosystems (Fuzzy Vault).

  7. Name 2 real-world applications and 1 key challenge for each.

  8. Define multimodal fusion levels (feature, score, decision).

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in