Fake Fingerprints - Liveness Detection Solutions

By: Brian Rhodes, Published on Oct 19, 2015

One of the biggest concerns with fingerprint readers is how easy they can be fooled. While biometrics are typically more difficult to steal or fake, headlines still break news of fake fingers or stolen prints being used to fool sensors.

For this reason, many access control fingerprint readers include live finger or liveness detection that checks the finger being scanned is authentic.

In this note, we examine the four common methods (tissue reflection, heartbeat detection, dermal electric resistance, unnaturalness analysis), what HID, Morpho and Suprema use and why you need to beware of ambiguous claims.

*** ** *** ******* concerns **** *********** ******* is *** **** **** can ** ******. ***** biometrics *** ********* **** difficult ** ***** ** fake, ********* ***** ***** news ** **** ******* or ****** ****** ***** used ** **** *******.

*** **** ******, **** access ******* *********** ******* include **** ****** ** liveness ********* **** ****** the ****** ***** ******* is *********.

** **** ****, ** examine *** **** ****** ******* (tissue **********, ********* *********, dermal ******** **********, ************* analysis), **** ***, ****** *** Suprema *** *** *** you **** ** ****** of ********* ******.

[***************]

Stealing ************ ** ***** **********

*** **** ***** ** the ******* ** **** while ************ *** ******, they *** ** ****** or **** ******* **********. Throughout *** *****, ******* methods ** ******** ******, by ***************** ******** ** ****** tips, ********** **** ***** *********, *****-**** ******* ** latent ****** [**** ** longer *********], ** **** using ******* ******* **** been ********.

***** *** ****** ** producing ******* ****'* ***** takes **** ****** **** stealing * ****, ***, or ***, *** **** is *** **** - unauthorized ****** **** **** access ** ********* ***** they ** *** ******.  

Four Common *******

***** *********** ****** ************* frequently *** ******** ********* methods, **** ** *** always ******* **** **** are ** *** **** work. ** *******, *** number *** **** ** methods * ************ ******* vary *** ********* **** into **** ********* **********:

  • ****** **********:*** **** ****** ****** (sometimes ****** ************* *******) typically **** ** ***** to ******* *** ********* contrast ** * ******'* skin. **** ****** ****** on *** **** **** normal, ****** **** ******** IR ***** ** * consistent *** **** ***** different ** **** ** covered ** ********* ********. Especially *** ******* ***** sensors, **** ***** ** done ** *** **** time ** *** *********** is '****', ** ***** is ** ***** ****** the ****. 
  • ********* *********: *** ** *** strongest ******* **** * high ******* ******** **** to ****** *** *********, rhythmic ******** ** *********** coursing **** *****. **** impulse *********** ** * beating *****, *** ******* it ******* *** ******** attempt ** *******.  ***** both ******* ** ******** and ******** ***** **** particular ****** *** ** the **** ********* ******* for ************* ** ***.
  • ****** ******** **********:*** ********** **** ** sensors, ******* ***** **** carries * ***** *** consistent ********** **********. ** a ****** ** ********* and *** ****** ** unable ** ******* ******* skin **********, ** ** invalidated. **** ** *** cost ********** ***** ******, this ******** ***** ** common, *** ** *** not ** ******** ** wet ** **** ************ that ****** *** ******* of **** *** ***** in ******.
  • ************* ********: **** ****** ***** ** the *******, ** ** relies ** ******** ****** alone ** ********* ************. This ****** ******** * print ******* ******* *************** of ***** ** ******* *******. ***** ** ****** checks **** *******, ****** or ***** *****, ***** print *****, ** ******** clarity ** *** *****, if *** ******* ** the **** ***** ******* a ******* '*********' *****, the ***** ** *********** as ****.

***** *** **** ****** of ******* ** *** market, * **** ******* Liveness ********* ******* $***, ***** * **** **** layers ******* ******* *** cost *** ****.  *** addition ** ******** ********* is **** *** ****** of ***** ***** **** drive ***** ******, ***** with ****** ****, *********** support, *** ************* *********** of *** ******.

Liveness ******* ****

** ****** *** **** of **** ** ******* prints, **** ********** *********** scanners *** ******* *** checks ** ******* **** are real.  ***** ** * list ** '******** *********' or '**** ****** *********' on ****** *********** ******* specsheets:

  • ********/*** ******: **** ********* ********* and ****** ********** ** validate ******* *** ****.
  • ******: ********* ** *** reader, ****** **** ****** reflection, ****** **********, ******* up **** ************* ********.
  • *******: **** * ****** of ************* ********** ** determine ** ****** *** faked ** *********** ** they *** ******.

** *******, ***** ********* implement **** **** * single ****** ** **** on *******- * *** point ** ******** *** wide ***** ** ********* fake/spoofed ***** ********.  

Beware ******** ******

*** *** '******** *********' methods *** ******* *********. For ******* *****'* ***** ** *** ****** *********** ****** (**** release) ** * ****** fingeprint *****. ***** ******* the ****** **** '******** detection ******** *** **********' (unnaturalness ********) ** ********** models. *******, ******* ***** ****** ****** effective *****, **** ***** ***** updates. ** *** **** of *****'* *********** ******, spoofed ** ***** ****** are ***** * **** with ******** ******* *****.

** *******, ********* ******* that *** ******** *** software **** *** ****** performing (**: *********, ****** Resistance, *** ****** **********). Take **** ** ***** methods ************* **** **** use, *** ** ********-**** (like ************* ********) ** unclear, ** ****.

Comments (7)

Thanks, Brian, for a really informative article.

It would be interesting to hear about hyperspectral's robustness to skin color variations. It seems reasonable that natural variation has been considered and accommodated, without substantially reducing ability to discriminate false presentations. In fact, it would be interesting (and probably more secure) if hyperspectral skin tones added another dimension to the fingerprint signature.

There must be a reasonably wide variation in acceptable conductivity to accommodate routinely varying conditions. Knowing that skin conductivity is relevant, how hard could it be to replicate a static resistance within a dummy finger, or even on a dummy image? Naively, considering that many laserjet inks are conductive, could you print a target resistance by varying print darkness? Who knows what is possible?

For heartbeat, one could print onto a flexible substrate (something like acetate), then glue it onto a bladder such as a balloon. While presenting that image to the reader, one could gently squeeze the bladder slightly more frequently than once per second.

If hyperspectral IR has a reasonable resolution, it seems as if it could be the most difficult to faithfully replicate, and that fingerprint augmentation with hyperspectral signature could even enhance security.

IMHO, one could obtain, at the expense of authorization delay, a higher level of confidence by using a challenge and response mechanism.

Something where the reader would display randomly changing "challenge", like a gesture, that would one mimic in response.

Of course, this is easier said than done, but could be useful since all static biometrics are, if someone is willing to spend enough $, vulnerable to the attack vector of 'fool the sensor'.

IMHO, it is too expensive (and usually affects accuracy) and can be solved by employing other methods. For instance, a couple of possible options:

  • enroll all fingers and request a different one each time or a combination
  • in the same price range it is more efficient (accurate, robust) to use palm vein or iris verification
  • the easiest (and probably the best) way is to use multi-factor authentication (PIN / Card / Fingerprint / Voice / Face)

[Request for Update (Suprema)]

Hi John / Brian,

Check this out: https://www.supremainc.com/en/AccessControl-TimeandAttendance/Biometric/BioStation-A2

Not all fingeprint devices from Suprema are using that advanced feature thought:

BioStation A2 is implementing advanced Live Finger Detection based on:

- Dynamic Pattern Analysis

- Unnaturalness Analysis

- Dual Source Light Imaging

BioStation A2 was tested and compared to nop notch fingerprint vendors as below:

#pushingthelimits

Best regards,

baud

Who would dig up grandma just to look at a bunch of military floppy discs?

Some people just need a hobby...

once again it seems like it comes down to adding layers to decrease risk. all about the how much the customer is willing to spend to protect their assets. 

I guess I should have read the next article before I asked the previous question.

Login to read this IPVM report.
Why do I need to log in?
IPVM conducts unique testing and research funded by member's payments enabling us to offer the most independent, accurate and in-depth information.

Related Reports

Proxy Access Control Tested on May 09, 2019
Silicon Valley Access Startup Proxy raised $13.6 Million in May 2019, focusing on mobile physical access control. Beyond the fund raising, Proxy...
Farpointe Data Conekt Mobile Access Reader Tested on Jun 13, 2019
California based Farpointe Data has been a significant OEM supplier of conventional access readers for years to companies including DMP, RS2, DSX,...
HID Mobile Tested on Jun 21, 2019
HID Global is one of the largest access brands, but their mobile access has had challenges. Indeed, the company has already restructured their...
Nortek Blue Pass Mobile Access Reader Tested on Jul 11, 2019
Nortek claims BluePass mobile readers are a 'more secure and easy to use approach to access', but our testing uncovered security problems and...
How To Troubleshoot Wiegand Reader Problems - Inverted Wiring on Jul 16, 2019
Wiegand is the dominant method of connecting access readers, but problems can arise for installers. In fact, one of the most difficult reader...
Mobile Access Control Shootout - Farpointe, HID, Openpath, Nortek, Proxy on Jul 29, 2019
One of the biggest rising trends in access control is using phones as credentials but which offering is best? IPVM has tested five of the...
Mobile Access Control Guide on Aug 28, 2019
One of the biggest trends in access for the last few years has been the marriage of mobile phones and access cards. But how does this...
Fingerprints for Access Control Guide on Sep 09, 2019
Users can lose badges, but they never misplace a finger, right? The most common biometric used in access are fingerprints, and it has become one...
HID Fingerprint Reader Tested on Oct 09, 2019
HID has released their first access reader to use Lumidigm optical sensors, that touts it 'works with anyone, anytime, anywhere'. We bought and...
Directory of Access Reader Manufacturers on Nov 27, 2019
Credential Readers are one of the most visible and noticeable parts of access systems, but installers often stick with only the brand they always...

Most Recent Industry Reports

Hazardous & Explosion Proof Access Control Tutorial on Feb 27, 2020
Controlling access to hazardous environments requires equipment meeting specific ratings that certify they will not start fires or will not...
Motorola / Avigilon Drops ISC West on Feb 26, 2020
Motorola Solutions has pulled out of ISC West 2020 effective immediately, because of coronavirus concerns, IPVM has learned. This is done amidst...
Cancel or Not? Industry Split Over ISC West on Feb 26, 2020
The industry is split, polarized, over whether ISC West 2020 should run or be canceled. New IPVM survey results of 400+ respondents show heated...
Coronavirus Hits Sony, Bosch Says Switch on Feb 26, 2020
Sony's fall in video surveillance has been severe over the past decade. Now, they may be done. In this note, we examine Bosch's new...
Video Surveillance Cameras 101 on Feb 25, 2020
Cameras come in many shapes, sizes and specifications. This 101 examines the basics of cameras and features used in 2020. In this report, we...
Favorite Video Analytic Manufacturers 2020 on Feb 25, 2020
Video analytics is now as hot as ever, driven by the excitement of advancing deep learning offers. But what are actually integrator's...
Latest London Police Facial Recognition Suffers Serious Issues on Feb 24, 2020
On February 20, IPVM visited another live face rec deployment by London police, but this time the system was thwarted by technical problems and...
Masks Cause Major Facial Recognition Problems on Feb 24, 2020
Coronavirus is spurring an increase in the use of medical masks, which new IPVM test results show cause major problems for facial recognition...
Every VMS Will Become a VSaaS on Feb 21, 2020
VMS is ending. Soon every VMS will be a VSaaS. Competitive dynamics will be redrawn. What does this mean? VMS Historically...
Video Surveillance 101 Course - Last Chance on Feb 20, 2020
This is the last chance to join IPVM's first Video Surveillance 101 course, designed to help those new to the industry to quickly understand the...