Hitoshi Kokumai

1年前 · 2 分の読書時間 · visibility 0 ·

chat 著者への問い合わせ

thumb_up 関連性 message コメント

Spoofing and Liveness-Detection of Biometrics

Spoofing and Liveness-Detection of BiometricsSpoofing raises FA/FM rates<br />
<br />
Counter-spoofing raises FR/FNM ratesSummary: 'Spoofing' of body features is an additional factor that raises false acceptance/match rates, while a 'counter-spoofing' measure is an additional factor that raises the false rejection/non-match rates.

You may well be aware of this news - http://www.forbes.com/sites/daveywinder/2019/11/02/smartphone-security-alert-as-hackers-claim-any-fingerprint-lock-broken-in-20-minutes/

In view of such big incidents, ‘Liveness-Detection’ as a counter-spoofing measure is reportedly a hot topic now among certain biometrics people. It is not worth it.

We are focusing on the problems arising from the trade-off relation between false match/acceptance (FM/FA) and false non-match/rejection (FNM/FR) inherent in the measurement of body features (The relation between FM/FA and FNM/FR is closely examined with graphs in this article) - http://www.valuewalk.com/2018/02/biometrics-aadhaar-danger/

FRR (Fal Reyection Rages)<br />
<br />
 <br />
<br />
 <br />
<br />
False Acceptance Rates and False Rejection Rates|<br />
<br />
 <br />
<br />
FA (Poise Acceptance] v3 FR (False Rejection) & Threshold |<br />
<br />
 <br />
<br />
§<br />
<br />
10°<br />
<br />
    <br />
 <br />
<br />
RR (Equator Rates)<br />
<br />
00 wt<br />
a]<br />
<br />
10°

From this perspective, the counter-spoofing measures like liveness detection could be a factor to increase the FNM/FR rates while possibly contributing to the reduction of FM/FA rates. A gain grasped in the right hand could possibly be dropping from the left hand, although it is not possible to quantitatively examine this effect until the specific liveness detection is put to the empirical tests in both indoor and outdoor environments.

You may recall that we had already heard of liveness detection 15 years ago. It was a built-in thermometer and an infra-red sensing to measure the warm temperature of genuine or spoofed hands, fingers and faces. We were not surprised to hear that those were fooled within hours by curious students who started to warm the spoofed objects. Sensing the presence of heartbeats was also fooled very quickly by smart students. Motion-detection fooled by video as well. We could be watching what will happen between the ‘advanced liveness detection’ and the inquisitive students.

We should not forget that, even if someone comes with a perfect liveness detection technology, it would solve just one aspect of the spoofing problem. There would still be the spoofing for which liveness detection may not be relevant. And, even if someone comes up with a perfect solution to eliminate the spoofing altogether, biometrics still has the fundamental problem of having the trade-off relation between FM/FA and FNM/FR due to the nature of body features inherent in living animals.

The trade-off relation of FM/FA and FNM/FR inevitably brings this security problem - Early models of smartphones were safer than newer models - How come? – https://www.linkedin.com/pulse/early-models-smartphones-were-safer-than-newer-how-come-kokumai

By the way, liveness-detection is sometimes discussed as if it were a second layer of security. It is not the case. Body features of living animals are variable. What would the user be expected to do if they got wrongly rejected by the liveness detection? Give up the login altogether?

If something gets brought in as a fallback measure, it means that the liveness detection works as a second entrance, not a second layer. Liveness detection is not outside the scope of FM/FA and FNM/FR.


< Related Articles and Video >

Biometrics and Me

 Publication on EDPACS of Taylor & Francis

Video Biometrics in Cyber Space - "below-one" factor authentication


#identity #authentication #password #security #safety #biometrics #ethic #privacy #civilrights #democracy




thumb_up 関連性 message コメント
コメント
Hitoshi Kokumai

Hitoshi Kokumai

1年前 #2

#1
A bad guy who gets rejected by the liveness detection would be usually given the chance to attack another entrance provided as a fallback measure. Do you mean this, Debesh?

Debesh Choudhury

Debesh Choudhury

1年前 #1

Agree Hitoshi Kokumai Liveness detection is a second entry to the authentication system.

その他の記事 Hitoshi Kokumai

ブログを見る