Jump to content
Nytro

Concerns regarding the security of biometric authentication

Recommended Posts

Concerns regarding the security of biometric authentication

February 2, 2015

Daniel Tomescu

biometrics-154660_1280.png?w=220&h=139

More and more gadgets that we use these days (smart phones, smart watches, etc) try to make a personal connection with the owner via his biometric characteristics.Using biometric measures for authentication purposes is a fast growing trend in the IT world, but there are genuine security concerns regarding the maturity level of these methods and their security faults. How safe is it to use biometrics for authentication? Can they be bypassed? Let’s find out!

How to find a good biometric characteristic?

At this moment, we have 3 main possibilities for verifying a user’s identity: something that the user knows (like a code or a passphrase), something that the user has (a smart card or a token) or something that the user is (a biometric characteristic).For a biometric characteristic to be considered a valid authentication method, it should have the following properties:

  • Universality, meaning that the feature must be present on all individuals;
  • Measurability, meaning that the feature can be measured and the individuals are willing to share it for measurement purposes;
  • High accuracy, meaning that the feature can be measured with an acceptable error rate;
  • Uniqueness, meaning that the feature should be different for every individual;
  • Robustness, meaning that the feature should not vary in time for the same individual;
  • Circumvention, meaning that the feature should not be easily altered, imitated or replicated by third parties.

Although the standards might seem too restrictive, there are a big number of biometric characteristics that meet the requirements above (or at least most of them) and can be used in user recognition.

Articol complet: Concerns regarding the security of biometric authentication – Security Café

Link to comment
Share on other sites

Am o prezentare diseara la Talks #60 pe aceeasi tema. Voi aminti si de recunoastrea venelor, dar tot nu mi se pare o metoda viabila pentru autentificare. Din cate stiu, inca nu a fost sparta si este destul de greu sa imiti structura venelor dintr-un deget sau o mana.

Totusi, tehnologia este noua si ma astept sa apara ceva probleme. Mai sunt si senzorii destul de scumpi, comparativ cu un token ce genereaza "one time passwords", deci nu va fi adoptata la scara larga prea curand. Totusi, are timp sa se dezvolte.

  • Upvote 1
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...