Hitoshi Kokumai

3年前 · 2 分の読書時間 · ~10 ·

ブログ作成
>
ブログ Hitoshi
>
Biometrics - Spoofing and Liveness Detection

Biometrics - Spoofing and Liveness Detection

 

Last November I examined the issue of spoofing and liveness detection from the view point of the trade-off between False Acceptance/False Match (FA/FM) and False Rejection/False Non-Match (FR/FNM). I bring it back in view of the yet bigger noises around fruitless arguments.

Below is the conclusion.

Spoofing is another factor to raise FA/FM rates and Liveness Detection is another factor to raise FR/FNM rates; the presence of FR/FNM forcing the users to rely on a fallback measure, a default password/pincode in most cases, which brings down the overall security to the level lower than the authentication by a default password/pincode alone.

That’s all.


Spoofing raises FA/FM rates

Counter-spoofing raises FR/FNM rates

Spoofing and Liveness-Detection of Biometrics


Summary: 'Spoofing' of body features is an additional factor that raises false acceptance/match rates, while a 'counter-spoofing' measure is an additional factor that raises the false rejection/non-match rates. 

 You are perhaps aware of this news - http://www.forbes.com/sites/daveywinder/2019/11/02/smartphone-security-alert-as-hackers-claim-any-fingerprint-lock-broken-in-20-minutes/

In view of such big incidents, ‘Liveness-Detection’ as a counter-spoofing measure is reportedly a hot topic now among certain biometrics people. It's not worth it. 

 We are focusing on the problems arising from the trade-off relation between false match/acceptance (FM/FA) and false non-match/rejection (FNM/FR) inherent in the measurement of body features.

* The relation between FM/FA and FNM/FR is closely examined with graphs in this article - http://www.valuewalk.com/2018/02/biometrics-aadhaar-danger/

FRR (Fal Reyection Rages)

 

 

False Acceptance Rates and False Rejection Rates|

 

FA (Poise Acceptance] v3 FR (False Rejection) & Threshold |

 

§

10°

    
 

RR (Equator Rates)

00 wt
a]

10°From this perspective, the counter-spoofing measures like liveness detection could be a factor to increase the FNM/FR rates while possibly contributing to the reduction of FM/FA rates. A gain grasped in the right hand could possibly be dropping from the left hand, although it is not possible to quantitatively examine this effect until the specific liveness detection is put to the empirical tests in both indoor and outdoor environments.

 You may recall that we had already heard of liveness detection 15 years ago. It was a built-in thermometer and an infra-red sensing to measure the warm temperature of genuine or spoofed hands, fingers and faces. We were not surprised to hear that those measures were fooled within hours by curious students who started to warm the spoofed objects. Sensing the presence of heartbeats was also defeated very quickly by smart students. Motion-detection beaten by video as well. We could be watching what will happen between the ‘advanced liveness detection’ and the ever more inquisitive students.

 We should not forget that, even if someone comes up with a perfect liveness detection technology, it would solve just one aspect of the spoofing problem. There would still be the spoofing for which liveness detection may not be relevant. And, even if someone miraculously comes up with a perfect solution to eliminate the spoofing altogether, biometrics still has the fundamental problem of having the trade-off relation between FM/FA and FNM/FR due to the nature of body features inherent in living animals.


Worry about a backdoor?


 The trade-off relation of FM/FA and FNM/FR inevitably brings this security problem - Early models of smartphones were safer than newer models - How come? – https://www.linkedin.com/pulse/early-models-smartphones-were-safer-than-newer-how-come-kokumai



By the way, liveness-detection is sometimes discussed as if it were a second layer of security. It is not the case. Body features of living animals are variable. What would the user be expected to do if they got wrongly rejected by the liveness detection? Give up the login altogether? 

If something gets brought in as a fallback measure, it means that the liveness detection works as a second entrance, not a second layer. Liveness detection is not outside the scope of FM/FA and FNM/FR.


< Related Articles and Video >

Summary and Brief History - Expanded Password System

External Body Features Viewed as ‘What We Are’

Negative Security Effect of Biometrics Deployed in Cyberspace

Removal of Passwords and Its Security Effect

Video Biometrics in Cyber Space - "below-one" factor authentication



コメント

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

Biometrics is 'probabilistic' by nature since it measures unpredictably variable body features of li ...

2年前 · 3 分の読書時間

I today take up this The Register report - “Client-side content scanning as an unworkable, insecure ...

2年前 · 3 分の読書時間

Today's topic is “Microsoft Exchange Autodiscover protocol found leaking hundreds of thousands of cr ...

この職種に興味がある方はこちら

  • AEON Hokkaido Co.,Ltd

    衣料品関連商品スタッフ/スーパー/パート

    次の場所にあります: Talent JP C2 - 3日前


    AEON Hokkaido Co.,Ltd 岩見沢市, 日本

    仕事情報 · 仕事内容 衣料品グループオペレーションのお仕事は、 · 婦人、紳士、靴鞄服飾、子供服の売場全体に渡り · 商品陳列や商品整理、表示物交換等の作業です。 · 催事・催し物を実施する際は、レジ助手も行います。 · 特定売場に固定せず、衣料品に関わる売場でお仕事が出来ます。 社員登用制度あり 年に一度、社員登用試験があり、パートから社員を目指すことが · できます。これまで多くの方が自ら手を挙げてステップアップし · てきました。社員になることで、大事なポジションを任されたり · 、より手厚い待遇・福利厚生のもとで長期活躍が可能です。イオ ...

  • 公開範囲1.等を含む求人情報を公開する

    コンビニエンスストアスタッフ

    次の場所にあります: Talent JP C2 - 2日前


    公開範囲1.等を含む求人情報を公開する Goshogawara, 日本 パート

    仕事内容 · ○レジ・接客・清掃等のコンビニエンスストア運営に係わる業務 · *採用後は親切丁寧に先輩スタッフが教えますので、未経験からの · スタートでも安心です。 · *ユニフォームを貸与します。 雇用形態 パート労働者 正社員登用の有無 なし 派遣・請負等 就業形態 派遣・請負ではない 雇用期間 雇用期間の定めなし 就業場所 就業場所 事業所所在地と同じ 〒 青森県五所川原市大字唐笠柳字藤巻730-1 最寄り駅 五所川原駅 最寄り駅から就業場所までの交通手段 車 所要時間 ...


  • セカンドサイトアナリティカ(株) 東京都, 日本

    金融/通信/EC・小売/不動産など幅広い業界の課題(リスク管理/収益モデル構築)をAIなどの最新技術を用いて分析し、コンサルティングを実施します。ハイクラス案件(高額受注)が中心です。 · ■PM・分析・コンサルティングの3つが求められる業務です · ■PMとしてクライアントとの対話を通じ分析・モデル構築からツール実装まで様々な案件に対応し、データを活用した新規事業企画、事業推進 · 【プロジェクト詳細】一人当たり3?4件ほどのプロジェクトに参加して頂きます。期間は3か月単位のものが基本となります。 ...