Log in
Talk about my operation
Technology

Biometrics and the Digitization of Identity

por Daniel Silva
Biometrics and the Digitization of Identity

The number of records needed to build a database that is both reliable and complete is astronomical. Depending on the records previously collected, it's possible to alter physical features to the point of concealing the person's real identity, or at least making recognition harder. No entanto, isso depende do método de verificação implementado, que pode abranger desde testes fisiológicos à comportamentais e anatômicos.

Leia também: Digital Identities: the History of Biometrics

Below we list some of the methods used, and the reliability of each one according to the difficulty involved in how easy it is to falsify each one's results:

Typing

This is the simplest verification method, based on the subconscious and behavioral characteristics of the user in question. Each person's typing style varies, especially in terms of (1) the force with which the key is pressed; (2) speed, and; (3) typing rhythm. Even though these are intuitive characteristics – that is, unrehearsed -, this verification method is one of the easiest to falsify. Através da observação minuciosa, pareada à desenvoltura corporal do malfeitor em questão, a confiabilidade, como também os custos dessa biometria, são baixos. 

These days there's a plurality of courses and workshops for bodily practice and awareness. Even though they weren't created for these purposes, there's a possibility of technically appropriating these courses for nefarious goals. However, it takes superior skill, both analytical and technical, plus proximity to the target in question, for these techniques to be used for such ends.

Retina Identification

Retina identification collects information from the ocular membrane through infrared rays, analyzing the formation of the blood vessels that supply the back of the eye. The pattern in question is collected by a high-resolution machine that, alongside the structural recording, emits a low-intensity white light to enhance the internal contrasts of the ocular membrane.

The image is translated into algorithms produced by the analysis system itself, associating a unique pattern with that image for later recognition, should it be needed. Normally, the retina pattern is defined by two algorithms that, together, turn that mathematical data into a unique code. Machines capable of performing retina recognition cost around R$ 8,000, and are capable of analyzing up to 10 million records in just two seconds during the identity verification process.

According to an article published by the Escola Politécnica UFRJ, “Among all the characteristics of the human body, the retina is the one with the most stable vascular pattern over time and the greatest guarantee of uniqueness, since no two people have identical retinas.” There has never been a recorded case of retina forgery to date, and due to the low number of algorithms and analysis required to identify a unique pattern, analysis and identification through the retina tends to be reliable as well as fast and effective.

The problem with this identification, however, lies in collecting the necessary data. Many believe the light emitted by the machine, especially given its proximity to the eyeball, can result in vision damage. That, combined with the distress of staying still while a tool approaches your eye, makes the collection process harder — an essential step in encoding the unique pattern.

Iris Pattern

Similar to retina identification, iris recognition goes through a comparable process of collecting and analyzing the unique patterns revealed by examining the colored rings and dots around the pupil. Even though it is more complex (iris recognition uses 5 algorithms, compared to the retina's 2), the biometric analysis of this organ is less reliable than the other, since it depends on patterns found on the surface and, therefore, ones that could potentially be faked with high-resolution photos.

O collection method for these patterns is similar to the retina's, but it differs when it comes to the type of light used and the time needed to identify and encode the unique patterns. An infrared light is shone into the eyeball for 3 seconds, to account for pupil dilation, making it easier to capture the necessary details. The device tends to cost around R$ 4,000. 

Because the verification is based on analyzing patterns found on the surface of the eye, the system can be fooled without much effort. According to Jan Krissler, a researcher at the Technical University of Berlin and a professional who has worked at Deutsche Telekom for over 10 years, “In the case of facial or iris recognition systems, generally all it takes is getting a high-resolution photo of a person and printing it. That's it: you have the material needed to fool the systems. It's quite easy. Anyone can do it at home.”

Facial recognition

This process collects three-dimensional images and analyzes the metrics of its components, based on measurement points on the face, algorithmically linking features and sizes, among other details, processing and comparing them with the registered images. There are two options for this type of biometrics: either the system itself handles the recognition and the authorization; or a technician analyzes the consistency between the image on file and the face of the person in question.

The reliability of this system depends entirely on how well established the program itself is, and on the algorithms used. The greater the number of features and metrics analyzed, the more reliable the system will be. However, while extra metrics help when it comes to the reliability of the security processes it contains, they also make the system slower and less responsive. That's because the algorithm has to analyze every image using the same metrics that were used to register them.

In Brazil, this system was implemented to combat fraud in the public transportation system, and was tested late last year in Campinas. According to official data, 20% of the 155,000 individuals hold some kind of improper benefit (usually this comes down to parents or grandparents lending their free-pass cards to friends and children), meaning more than 30,000 people use the system without paying the proper fares.

Voice Pattern

Voice recognition is used extensively in bank call centers, credit card call centers, and companies with remote customer service. That's because, even with a personal authentication process that requires information considered private (whether the RG number, CPF, date of birth, among other security measures) to prove the requester's identity, this information isn't impossible for hackers and IT technicians to get hold of. Convincing a phone assistant to believe you is possible, which is why voice recognition is necessary. Even with all the required information in hand, the algorithm prevents these security lapses caused by human error from being exploited. In the United Kingdom alone, an annual loss of R$ 18.5 billion is estimated as a result of this fraud. 

To gather enough data to build the database, the system uses recordings to analyze and compare details of the catalogued voices. This way, customer identification is carried out reliably and verifiably. The analysis consists of recognizing patterns of resonance, low tones, and high-pitched signals in a voice, as well as the rhythmic eloquence used when speaking. However, the technology isn't the most reliable, since it's subject to fluctuations caused by ambient noise, as well as changes due to common illnesses, such as the flu, for example. The cost of installing this validation process is low, given the difficulties when it comes to reliability, and the enrollment process and reading are time-consuming. 

Fingerprint

Biometric fingerprint reading is one of the most recommended technologies when it comes to biometrics. Every person has a unique fingerprint, with several distinctive characteristics and lines, easily translated into algorithms for digital assessment. Besides having a relatively low cost, security, for these reasons, is guaranteed, with an extremely low rate of false positives or even reading errors.

However, as we said in this post, every day that goes by, more and more innovative ways of identity fraud are created. Just as scientists in Japan were able to “lift” a fingerprint using photo editing programs, there are older ways to appropriate someone's print. As shown in the movie “Ant-Man”, having access to the place where the victim lives or spends time means you can get access to countless prints scattered around. With creativity and basic tools, it's possible to recreate someone's fingerprint, if the wrongdoer wants to.

Learn more: Biometrics in the Real World

Conclusion

Getting serious now, even though there are a million reasons and ways to steal someone's identity, whether through malware granting access to the confidential data of the individual in question or something as crazy as appropriating their fingerprint, this is still far from truly widespread. Like it or not, for someone to intentionally go after the characteristics and data that would give them access to your accounts, among other things, it takes study, dedication, and free time.

In any case, biometrics is still widely used (and grows more each year) for operational identification at companies and establishments. Whether it's biometric time clocking, or even identifying the staff member, this process makes it easier and faster for the professionals employed there to move around these places, as well as speeding up service. The less time spent validating an individual password, or “clocking in”, the more time will be set aside for serving customers and getting the necessary work done

In other words, if you're not hiding a piece of the melted-down Jules Rimet trophy (or the trophy itself) in your safe, or even the alleged videos made by the Kremlin of President Trump, you probably won't need to install all these identity authentication steps on your phone. At your company, however, it would be worth discussing how this technology could speed up and optimize the applicable processes within it.

Talk to a specialist

Your operation has grown. Is your technology ready?

How many locations, what stack is already running, what needs to be integrated, and what the rollout would look like.