Vulnerability Assessment of Multi Biometric Systems
نویسندگان
چکیده
The objective of this study was to provide vulnerability analysis for multi biometric systems and their performance against the known attacks. The report helps in identifying and analyzing risks that may have detrimental outcomes on the security provided by multi biometric systems. The risk assessment process was based on the standards of Risk Management (ISO 31000). Investigation of various research papers, experiments and whitepapers on risk analysis of biometric systems provided major insights in determining the overall risk associated with biometric systems in general, and the performance and security gains obtained from implementing multi biometric systems, in particular. Multi biometric systems provide performance gains in terms of increased reliability, accuracy and security. These gains come at the cost of increased constraints on operating environments, cost of operation, comparatively high computational costs (as compared to unimodal systems) and user convenience and these need to be taken into consideration while developing the systems. The report provides an introduction to the various biometric modalities and fusion rules available for the system designers, which can be implemented in order to obtain best performance in terms of reliability and accuracy for that particular implementation scenario. The functional, operational and technical requirements of the proposed biometric systems can be used for assessment of whether the intended security level can be obtained by implementing multiple sensors or comparing the signals from various samples; if additional computational power can be used by implementing multiple algorithms to obtain a reliable decision or to implement multiple modalities in order to make the system more robust. After further analysis of the risks and detailed study of previously carried research, it was concluded that more rigid, robust controls and better fusion rules were required to increase the security of the system. Various interoperability standards and testing frameworks for multi biometric systems need to be developed to make the process of integration of various systems more streamlined and to help remove the vulnerabilities present in loosely coupled biometric systems. As the technology changes rapidly and new techniques keep emerging to subvert the biometric systems, effort should be made, on the part of system designers and system developers, to keep an eye for emerging vulnerabilities along with keeping a check on existing ones in order to develop more secure and robust biometric authentication systems in the future. Table of
منابع مشابه
Robustness of Multi Biometric Authentication Systems against Spoofing
Nowadays biometric authentication systems have been more developed, especially in secure and financial systems; so cracking a biometric authentication system is now a growing concern. But their security has not received enough attention. Imitating a biometric trait of a genuine user to deceive a system, spoofing, is the most important attacking method. Multi biometric systems have been develope...
متن کاملRisk Analysis of Biometric Systems
This paper, presents a risk analysis knowledgebase, which aims to enhance existing risk analysis methodologies and tools, by adding the capability of analyzing the risk of the biometric component of an information system. The knowledgebase was created by applying the Multi-Criteria Analysis methodology to the results of research in the security aspect of biometric technologies. The result is a ...
متن کاملTowards the Security Evaluation of Biometric Authentication Systems
Despite the obvious advantages of biometric authentication systems over traditional security ones (based on tokens or passwords), they are vulnerable to attacks which may considerably decrease their security. In order to contribute in resolving such problematic, we propose a modality-independent evaluation methodology for the security evaluation of biometric systems. It is based on the use of a...
متن کاملVulnerabilities in Biometric Encryption Systems
Biometric encryption systems embed a secret code within a biometric image in a way that it can be decrypted with an image from the enrolled individual. We describe a potential vulnerability in biometric encryption systems that allows a less than brute force regeneration of both the secret code and an estimate of the enrolled image. This vulnerability requires the biometric comparison to “leak” ...
متن کاملUser-Centric Key Entropy: Study of Biometric Key Derivation Subject to Spoofing Attacks
Biometric data can be used as input for PKI key pair generation. The concept of not saving the private key is very appealing, but the implementation of such a system shouldn’t be rushed because it might prove less secure then current PKI infrastructure. One biometric characteristic can be easily spoofed, so it was believed that multi-modal biometrics would offer more security, because spoofing ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
دوره شماره
صفحات -
تاریخ انتشار 2015