Spoofing and Liveness-Detection of Biometrics
Right hand grasp something and let hand drops something

Spoofing and Liveness-Detection of Biometrics

Summary: 'Spoofing' of body features is an additional factor that raises false acceptance/match rates, while a 'counter-spoofing' measure is an additional factor that raises the false rejection/non-match rates. 

 You are perhaps aware of this news - https://www.forbes.com/sites/daveywinder/2019/11/02/smartphone-security-alert-as-hackers-claim-any-fingerprint-lock-broken-in-20-minutes/

In view of such big incidents, ‘Liveness-Detection’ as a counter-spoofing measure is reportedly a hot topic now among certain biometrics people. It's not worth it. 

 We are focusing on the problems arising from the trade-off relation between false match/acceptance (FM/FA) and false non-match/rejection (FNM/FR) inherent in the measurement of body features.

* The relation between FM/FA and FNM/FR is closely examined with graphs in this article - https://www.valuewalk.com/2018/02/biometrics-aadhaar-danger/

No alt text provided for this image

 From this perspective, the counter-spoofing measures like liveness detection could be a factor to increase the FNM/FR rates while possibly contributing to the reduction of FM/FA rates. A gain grasped in the right hand could possibly be dropping from the left hand, although it is not possible to quantitatively examine this effect until the specific liveness detection is put to the empirical tests in both indoor and outdoor environments.

 You may recall that we had already heard of liveness detection 15 years ago. It was a built-in thermometer and an infra-red sensing to measure the warm temperature of genuine or spoofed hands, fingers and faces. We were not surprised to hear that those measures were fooled within hours by curious students who started to warm the spoofed objects. Sensing the presence of heartbeats was also defeated very quickly by smart students. Motion-detection beaten by video as well. We could be watching what will happen between the ‘advanced liveness detection’ and the ever more inquisitive students.

 We should not forget that, even if someone comes up with a perfect liveness detection technology, it would solve just one aspect of the spoofing problem. There would still be the spoofing for which liveness detection may not be relevant. And, even if someone miraculously comes up with a perfect solution to eliminate the spoofing altogether, biometrics still has the fundamental problem of having the trade-off relation between FM/FA and FNM/FR due to the nature of body features inherent in living animals.

No alt text provided for this image

 The trade-off relation of FM/FA and FNM/FR inevitably brings this security problem - Early models of smartphones were safer than newer models - How come? – https://www.dhirubhai.net/pulse/early-models-smartphones-were-safer-than-newer-how-come-kokumai

By the way, liveness-detection is sometimes discussed as if it were a second layer of security. It is not the case. Body features of living animals are variable. What would the user be expected to do if they got wrongly rejected by the liveness detection? Give up the login altogether? 

If something gets brought in as a fallback measure, it means that the liveness detection works as a second entrance, not a second layer. Liveness detection is not outside the scope of FM/FA and FNM/FR.


< Related Articles and Video >

Summary and Brief History - Expanded Password System

External Body Features Viewed as ‘What We Are’

Negative Security Effect of Biometrics Deployed in Cyberspace

Removal of Passwords and Its Security Effect

Video Biometrics in Cyber Space - "below-one" factor authentication


#identity #authentication #password #security #safety #biometrics #ethic #privacy #civilrights #democracy

Debesh Choudhury, PhD

Information Security Researcher, Academician, Entrepreneur | Password & Cybersecurity, Digital Identity, Biometrics Limit, 3D Education | Linux Trainer | Writer | Podcast Host

5 å¹´

Insightful article Hitoshi Kokumai?.. It is a real question how much liveness detection can help rejecting biometrics spoofing attacks.

赞
回复

要查看或添加评论,请登录

Hitoshi Kokumai的更多文章

  • Join Our Endeavour

    Join Our Endeavour

    You could start with£100 to join our endeavour. We announced the progress with crowdfunding along with the release of…

    1 条评论
  • Join Our Endeavour

    Join Our Endeavour

    You could start with£100 to join our endeavour. We announced the progress with crowdfunding along with the release of…

  • Announcement on Release of Beta Mnemonic Gateways

    Announcement on Release of Beta Mnemonic Gateways

    As you may have heard from us, we were planning the release of Beta Mnemonic Gateways, which we now have formally…

    7 条评论
  • Dissection of Passwordless MFA

    Dissection of Passwordless MFA

    I found this report to be very inviting - “What are passkeys? A cybersecurity researcher explains how you can use your…

    1 条评论
  • Mnemonic Gateways as Leading Digital Identity App (updated 16/Nov/2023)

    Mnemonic Gateways as Leading Digital Identity App (updated 16/Nov/2023)

    We aim to grasp a quarter of the global demand for digital identity apps in 2027 with Mnemonic Gateways, our new-breed…

    1 条评论
  • When, why and how Expanded Password System was developed

    When, why and how Expanded Password System was developed

    Here is what we wish to emphasize as to the development of Expanded Password System invented in the first quarter of…

  • How to not see our weak digital identity further weakened (updated 31May2023)

    How to not see our weak digital identity further weakened (updated 31May2023)

    A. Introduction - From ‘Password Fatigue’ to ‘Fatigue-free Password’ We often hear ‘xxxx-fatigue’ these days.

  • Power of Citizens’ Episodic Memory

    Power of Citizens’ Episodic Memory

    Collected here are our digital identity posts since 24/February/2022 on the power and merit of citizens’ episodic…

    11 条评论
  • Probabilistic Biometrics Unravelled : How it brings down identity security

    Probabilistic Biometrics Unravelled : How it brings down identity security

    Collected here are our digital identity posts since 24/February/2022 on the security-destructive effects of biometrics…

    2 条评论
  • LOSS of Security Taken for GAIN of Security

    LOSS of Security Taken for GAIN of Security

    Collected here are our digital identity posts since 24/February/2022 on the security-destructive effects of…

    2 条评论

社区洞察

其他会员也浏览了