Tech Talk: Knowing How Biometrics Can Be Beaten Helps You Win

Biometrics is one of the most fascinating areas of electronic security, representing both the epitome of high tech and the nadir of false authentication and vulnerability to compromise. But improvements continue to emerge, and so long as security professionals remain aware of potential issues biometrics can have a place in your access control mix.

What Spoofing Testing Tells Us

In 2002, biometric spoofing experiments were conducted at Yokohama National University. Not only were fingerprint sensors spoofed with simple silicone rubber fingers, but iris recognition systems were defeated with high resolution camera images.

For some time now West Virginia University has had spoofing workshops and events to challenge liveness characteristics of biometric manufacturers. They have recently been awarded a $100,000 grant from the National Institute of Standards and Technology (NIST) to do further testing.

LivDet 2009, The First International Fingerprint Liveness Detection Competition, took place at Clarkson University, Potsdam, N.Y. LivDet II (2011) competition is being conducted right now. It is good to see various biometric technologies being challenged for liveness side by side.

While much of the data from research such as this is not for everyday field usage, there is one big lesson for installing security contractors to learn here. Remember, sensor vendors will typically not be comfortable discussing their products’ vulnerabilities. That being said, it is important for us, the security trade, to understand the weaknesses of these systems.

You now have a few more questions for biometric sensor vendors when looking at products: How well do you defeat spoofing of liveness? What is your FRR, FAR, CER? What liveness competitions have you participated in and how did you fare?

Additionally, don’t forget that high security applications can collectively use several technologies. This could be proximity cards, passwords, randomly changing keypads and several forms of biometrics (facial, finger, voice, hand geometry). In the future you may also see evasive interactive strategies like intelligent facial recognition giving on-spot commands such as wink left eye twice and then right eye once.

Breakthroughs Continue

Keep an eye on future technology developments. A recent case comes from researchers at Dermalog Identification Systems in Hamburg, Germany.

The company has developed a method for a fingerprint scanner to differentiate between dead and live tissue. The detection process involves detecting the way tissue changes in color when blood is compressed through the capillaries as you press your fingertip against the surface. This is also known as “blanches.” In trying to spoof with dead or artificial digits, the spectra for light with strong contact pressure did not respond the same, thereby giving hope to further liveness detection methodology.

Bob Dolph has served in various technical management and advisory positions in the security industry for 30+ years. To share tips and installation questions, E-mail Bob at [email protected]. Check out his Tech Shack.

 [IMAGE]12263[/IMAGE]Tech Talk Tool Tip

 The next best thing to a tool that can save installers time and frustration is a manufacturer with a product that makes life easier for all us installers. Since we are talking about access control this month, I thought I would feature the “Easy Mount” 5 Series from Rutherford Controls Int’l Corp. (RCI).

As we all know, trying to cut and fit an electri
c strike can take extra time and patience. RCI has addressed this with a strike series that is designed to easily fit into a standard ANSI frame prep. The company boasts that NO frame cutting is required. Thanks, Rutherford!

About the Author


Bob is currently a Security Sales & Integration "Tech Talk" columnist and a contributing technical writer. Bob installed his first DIY home intercom system at the age of 13, and formally started his technology career as a Navy communication electronics technician during the Vietnam War. He then attended the Milwaukee School of Engineering and went on to complete a Security Management program at Milwaukee Area Technical College. Since 1976, Bob has served in a variety of technical, training and project management positions with organizations such ADT, Rollins, National Guardian, Lockheed Martin, American Alarm Supply, Sonitrol and Ingersoll Rand. Early in his career, Bob started and operated his own alarm dealership. He has also served as treasurer of the Wisconsin Burglar and Fire Alarm Association and on Security Industry Association (SIA) standards committees. Bob also provides media and training consulting to the security industry.

Security Is Our Business, Too

For professionals who recommend, buy and install all types of electronic security equipment, a free subscription to Security Sales & Integration is like having a consultant on call. You’ll find an ideal balance of technology and business coverage, with installation tips and techniques for products and updates on how to add sales to your bottom line.

A free subscription to the #1 resource for the residential and commercial security industry will prove to be invaluable. Subscribe today!

Get Our Newsletters