Biometrics - Vein Patterns

Super short presentation on a type of Biometrics covering Vein Patterns as a means of personal identification and authorisation. Presentation was made for a module "Topics in Privacy and Security" at the University of York in January 2015.

Aleksandrs Cudars

January 21, 2015

  1. about vein patterns • veins and arteries absorb more light,

    thus can be scanned • unique patterns • palms, fingers “a vein pattern exists on the skin surface between the roots of the five fingers and the wrist of the palm- dorsum. This pattern offers stable, unique and repeatable features for personal identification purposes”
  2. about vein patterns • Method ◦ infra red light •

    Security and Accuracy ◦ high • Cost ◦ low • Speed ◦ fast patterns matching • Size ◦ small “it takes around 0.5s to match your vein patterns to those previously digitised, compressed and captured (...) there’s only a 0.0001% chance of someone passing off their vein patterns as yours
  3. likely major attacks • fake physical and digital biometric input

    ◦ identity theft • false match • decision override / false accept
  4. countermeasures • activity logging (time-stamping) • encryptions and digital signatures

    • multi-factor identification • use of multiple biometrics • hardware and template integrity
  5. threats • system and database compromised • interception (social engineering)

    • false data injection • override feature extraction
  6. analysis of choice • pros ◦ unique, repeatable ◦ practically

    immune from forgery ◦ non-invasive ◦ successful identification of dark-skinned subjects ◦ accurate and reliable ◦ ease of use - quick, discreet and clean ◦ systems already exist (low cost on installation and equipment) • cons ◦ not mainstream
  7. alternatives Other Biometric Scans: • Fingerprint Scanners, e.g., Apple Touch

    ID • Visual Recognition: ◦ Eye Recognition (Retina and Iris), Ear Recognition, Whole Face Recognition • Other Recognition ◦ Olfactory (Odour) Recognition, Voice Recognition • DNA Matching • etc. Other Authentication Methods • Password • Object Possession, e.g., Google Authenticator • 2-factor authentication, combination of multiple methods
