FB pixel

Researchers warn biometric template protection still not adopted by industry

Idiap, MSU, CODE researchers publish comprehensive overview of BTP field
Categories Biometric R&D  |  Biometrics News  |  Trade Notes
Researchers warn biometric template protection still not adopted by industry
 

As facial recognition and fingerprint scanning become ubiquitous – from unlocking smartphones to airport security – biometric data privacy and security is becoming an increasing concern. Unlike a stolen password, fingerprints and facial templates cannot be reset, which makes biometric information uniquely sensitive.

These dangers are putting the spotlight on the field of biometric template protection (BTP), which, despite two decades of academic innovation, still lags behind in practical adoption. To address this, a group of researchers from the Swiss Idiap Research Institute, the University of the Bundeswehr Munich, and Michigan State University has written a new book focused on mitigating the risks associated with storing and using biometric templates.

The “Handbook of Biometric Template Protection: Motivation, Methods and Metrics” was published by Springer earlier this week, offering an overview of the technical and regulatory landscape of biometric template protection.

“This is the first book to present a comprehensive overview of the increasingly relevant biometric template protection (BTP) field, including: why it matters (motivation), what types of techniques have been proposed for protecting our irreplaceable biometric data (methods), and the approaches used to evaluate these methods (metrics),” writes Vedrana Krivokuća Hahn, the book’s co-editor and a researcher in Idiap’s Biometrics Security and Privacy Group.

The other editors are Marta Gomez-Barrero from Research Institute CODE at the University of the Bundeswehr Munich, Arun Ross from the Department of Computer Science and Engineering, Michigan State University and Sébastien Marcel, also with Idiap’s Biometrics Security and Privacy Group.

The handbook identifies three main culprits behind the slow adoption of BTP in the real world: Many system deployers do not recognize the importance of protecting biometric data or have no incentive to do so. Other researchers prefer sticking with traditional encryption methods despite their limitations, while some cite uncertainty over robustness and the proper evaluation of newer BTP techniques.

Privacy regulations such as the EU’s GDPR are beginning to change this calculus, fueling renewed interest in BTP research. The EAB examined the GDPR compliance challenge of biometric template protection in a 2023 workshop. The book offers a brief introduction on how to approach the evaluation of BTP methods from the point of view of existing technical standards.

Researchers argue that the methods used for generic data protection are usually unsuitable for protecting biometric templates. This includes traditional techniques like hashing, conventional encryption, distributed databases and smart cards and the more recent trusted execution environments.

“This is due, in large part, to factors such as the intrinsic noisiness of biometric measurements versus the exactness requirements of mechanisms like cryptographic hashing and encryption,” the book notes.

The handbook explores methods such as handcrafted BTP algorithms designed by humans, including feature transformations and biometric cryptosystems. It also delves into BTP methods learned using neural networks.

Other chapters explore how BTP could be achieved with the help of homomorphic encryption, which does not traditionally fall into the BTP domain. In Norway, for instance, the banking industry is testing homomorphic encryption from Mobai for protecting biometric templates.

Related Posts

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

authID adds post-quantum cryptography to biometric signature platform

The threat of quantum computing is prompting many companies to boost their defenses. Identity verification company AuthID is the latest,…

 

Dutch gov’t extends DigiD contract despite security concerns over US takeover bid

The debate around a government contract that raised national security concerns in the Netherlands has reached a conclusive stage, if…

 

Eurail breach exposes passport data, fuels dark web identity trade

The fallout from a data breach at Eurail is raising fresh concerns about identity fraud, after stolen personal data from…

 

EES faces scrutiny over border delays, proportionality

After Greece announced last week that it will no longer apply biometric registration for British passport holders, questions are arising…

 

Trinidad and Tobago launches digital credentials platform in DPI push

Trinidad and Tobago has launched VerifyTT, a digital credentials platform under its digital public infrastructure (DPI) push, enabling institutions to…

 

Australia plans biometric liveness detection refresh for national digital ID

Australia plans to contract a biometric liveness detection capability to support the country’s national digital ID and protect it against…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events