5.8: Biometric (Doshi) Flashcards
What is biometric?
Biometrics refers to metrics related to a human characteristic
Biometric verification
Any means by which a person can be uniquely identified by evaluating one or more distinguishing biological features.
Unique identifiers of biometric
palm, hand geometry, fingerprints, retina and iris patterns, voice waves and DNA
What is false ACCEPTANCE with biometric
A rate of acceptance of unauthorized person i.e. biometric will allow a unauthorzied person to access the system.
Example of a false acceptance:
Mr. A is the only authorized person to access the system. However, if biometric allows access to Mr. B, then the same is false acceptance
What is false REJECTION with biometric?
A rate of rejection of authorized person(s) i.e. biometric will reject even though the person is authorized to access the system.
Example of false rejection:
Mr. A is the only authorized person to access the system. However, if biometric DOES NOT allow access to Mr. A, then the same is false REJECTION
Cross Error Rate (CER) or Equal Error Rate (ERR):
It’s a rate at which FAR and FRR are equal.
Characteristic of the MOST effective biometric system
It will have the lowest CER or ERR
Characteristic of the MOST ineffective biometric system
It will have the highest CER or ERR.
What is a Replay attack?
A biometric attack in which a residual biometric characteristic such as fingerprint left on a device is used by an attacker to gain unauthorized access.
Brute force attack:
Involves sending the numerous different biometric samples to a biometric device
Cryptographic attach:
Targets the algorithm or the encrypted data transmitted between the biometric device and access control system.
What happens when Fale Acceptance Rate Decreases
False Rejection Rate Increases and vise- versa
The MOST important PERFORMANCE indicator for biometric system:
False acceptance rate (FAR
The most important OVERALL quantitative performance indicator for biometric system
Cross error rate CER or Equal error rate EER
Which biometric method has the highest relibility and lowest FAR?
Retina Scan
BEST performance indicator of biometrics
False Acceptance Rate FAR
OVERALL BEST performance indicator of biometrics
Cross Error Rate CER or Equal Error Rate EER
Mimic Attack?
attacker attempts to fake the biometric characteristics
What are the 4 attacks on biometrics?
Mimic
Brute Force
Crypto
Replay
In any given scenario, which biometric technology has the highest reliability and lowest false acceptance rate FAR?
Retina Scan
The three MAIN accuracy measures for biometric technologies are:
(1) False Acceptance Rate (FAR)
(2) False Rejection Rate (FRR)
(3) Cross Error Rate (CER) or Equal Error Rate (EER)
Data transfer of biometric data should be
encrypted
Biometric life cycle is:
(1) enrollment
(2) transmission and storage
(3) verification
(4) identification
(5) termination of processes
Biometric controls are more reliable than
forms of Access Control