Wednesday, July 18, 2012

Iris Biometrics: Come on Down!

It's not a real biometric modality until someone hacks it (yes, I'm talking to you foot, ear and butt). So cheer up, iris. You're in good company.

Black Hat: Hacking iris recognition systems (Bank Info Security) UPDATE: Link was wrong before, fixed now.

The article is short on detail about how and how successfully iris systems have been hacked but more information will certainly follow Black Hat's presentation on July 25 summarized as follows:
FROM THE IRISCODE TO THE IRIS: A NEW VULNERABILITY OF IRIS RECOGNITION SYSTEMS

A binary iriscode is a very compact representation of an iris image, and, for a long time, it has been assumed that it did not contain enough information to allow the reconstruction of the original iris. The present work proposes a novel probabilistic approach to reconstruct iris images from binary templates and analyzes to what extent the reconstructed samples are similar to the original ones (that is, those from which the templates were extracted). The performance of the reconstruction technique is assessed by estimating the success chances of an attack carried out with the synthetic iris patterns against a commercial iris recognition system. The experimental results show that the reconstructed images are very realistic and that, even though a human expert would not be easily deceived by them, there is a high chance that they can break into an iris recognition system.
Stay tuned.