What if biometric systems were not quite so infallible? Five American researchers presented an artificial intelligence capable of generating forged fingerprints at a security conference in Los Angeles.
Ergonomic identification, but not so secure
Over the past few years, the speculation surrounding big data has set in motion an increasingly sophisticated drive to protect data. Authentication systems are therefore aiming to be more effective — but are they really safe and reliable? There have been many hacking attempts, but to date none had managed to fool the human eye, which is still a benchmark. In order to outwit fingerprint scanners, the American scientists describe in their paper how they took advantage of two characteristics common to biometric systems, namely:
- authentication from image fragments
- the similarity of the components of a fingerprint
A partitioned fingerprint
You have probably noticed that when you register a fingerprint, you have to repeat the same movement several times. Why? Firstly, so that the gesture you use to scan your biometric data is as natural as possible. Secondly, because for the sake of usability most scanners do not read all the parts of a fingerprint at the same time. That means these authentication devices represent your fingerprint as a series of different extracts. And it is these partial fragments that allow you to unlock your device, even if you do not always place your finger in exactly the same spot.
A unique fingerprint, many similar features
Although it is unique, this biometric data is made up of various characteristics, some of which are more common than others. As a result, even if a fingerprint is forged, if it contains a lot of common elements it will more easily be able to “match” the original.
It was on the basis of these two observations that the researchers built an artificial neural system capable of generating DeepMasterPrints (fake fingerprints). This type of artificial intelligence comprises several algorithms which, like the human brain, are able to recognise patterns.
The artificial intelligence is in fact able to learn automatically by comparing several partial image fragments. Once that first step is complete, it can then generate a new image from the most common characteristics. Much like a password cracker, the algorithm can then generically offer up images and succeed in unlocking access. And it works around one time in five, according to the American researchers!
A hacking feat that is not quite so promising
These claims do need to be put into perspective, though! To begin with, 6,000 real fingerprints were fed into a database in order to get this neural system working. Is that enough to successfully reproduce the immense diversity of fingerprints, which — let us remember — are all unique?
Unique personal data cross-referenced for better authentication
According to 2017 figures, fingerprint scanners were admittedly present on more than 70% of smartphones. However, their variety and the way they work are evolving. As far as fingerprint recognition is concerned, more and more manufacturers are incorporating more comprehensive authentication systems based on detecting the whole finger. An ultrasound detection technology lies behind these new sensors, making it possible to create a 3D image of your fingerprints. That makes forging fingerprints considerably more difficult, if only in terms of the resources needed (running an artificial intelligence with 3D rendering engines) and data cross-referencing.
What is more, there are other formats of biometric scanner based on other data to be analysed. That is the case with facial scanners, which even manage to cross-reference very fine-grained, relevant data without leaving any opportunity to be fooled by a photograph. Some even manage to recognise a person despite changing factors such as:
- wearing glasses, a hood or a hat
- varying make-up
- a different haircut
- low lighting
- and so on
In addition, other biometric identification solutions could be a more complete alternative to fingerprint scanners, which for the sake of user experience tend to be less strict. Among the possible technologies, iris scanners are already mature but remain in the minority. Their price and their usability may deter their adoption; however, they remain one of the most reliable means of identification. For more articles on the same theme, head over to our blog.