0% found this document useful (0 votes)
12 views40 pages

Biometric Privacy Risks and Framework

Uploaded by

low07140
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views40 pages

Biometric Privacy Risks and Framework

Uploaded by

low07140
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

Housekeeping

Notice
Please mute your handphone during
class
TPB 6323
Password Authentication and
Biometrics

Chapter 10
Practical Issues of Using
Biometrics
Objectives

DISCUSS ON SOME UNDERSTAND VARIOUS UNDERSTAND THE


PRACTICAL ISSUES OF BIOMETRIC BIOPRIVACY IMPACT
USING BIOMETRICS, DEPLOYMENTS ON A FRAMEWORK.
ESPECIALLY ON THE PRIVACY CONTINUUM.
PRIVACY RISKS.
• Information security means
protecting information and
information systems from:

• unauthorized access
Informat
• use
ion
• disclosure
Security
• disruption
Basics
• modification
• destruction
Biometric Systems Security
and Privacy
• Biometric identifiers are
becoming widely used by
organizations to identify users
• Devices using biometric
identifiers attempt to
automate this process by
comparing the information
scanned in real time against a
template stored digitally in a
database
Major Areas of
Concern
• Storage: How is the data stored,
centrally or dispersed? How should
scanned data be retained?
• Vulnerability: How vulnerable is the
data to theft or abuse?
• Confidence: How much of an error
factor in the technology's authentication
process is acceptable? What are the
implications of false positives and false
negatives created by a machine?
Major Areas of
Concern
• Authenticity: What constitutes
authentic information? Can that
information be tampered with?
• Linking: Will the data gained from
scanning be linked with other
information about spending habits, etc.?
What limits should be placed on the
private use (as contrasted to
government use) of such technology?
Major Areas of
Concern
• Ubiquity: What are the implications of
having an electronic trail of every
human movement if cameras and other
devices become common place, used on
every street corner and every means of
transportation?
• Public is concerned
about giving their
personal information
away
Assessi • Biometrics is even more
ng the sensitive data
Privacy (information taken from
the body parts)
Risks of
Biometr • Biometric system design
and deployment must not
ics undermine or threaten
personal or informational
privacy
Biometric
Deployments on a
Privacy Continuum
• Relationships between biometrics
privacy
Negative Relationship Positive Relationship

Privacy Privacy Privacy Privacy


Invasive Neutral Sympathetic Protective

o Worst case
o Biometrics used without individual knowledge or consent
o Biometrics used to track movement, associate with illegal
data, or eliminate a person’s ability to act anonymously
Biometric
Deployments on a
Privacy Continuum
• Relationships between biometrics
privacy
Negative Relationship Positive Relationship

Privacy Privacy Privacy Privacy


Invasive Neutral Sympathetic Protective

o Lacking special precautions or design elements to ensure


privacy but also incapable of being used in a privacy
invasion fashion
o Cannot be used to protect individual information and
cannot be used to undermine privacy
Biometric
Deployments on a
Privacy Continuum
• Relationships between biometrics
privacy
Negative Relationship Positive Relationship

Privacy Privacy Privacy Privacy


Invasive Neutral Sympathetic Protective

o Incorporate special design elements and controls to


ensure privacy of biometric data
o Example: encrypt biometric data, multiple admin to access
biometric data, store biometric data independently from
personal data
o Ensure enough active protections to prevent misuse of
biometrics
Biometric
Deployments on a
Privacy Continuum
• Relationships between biometrics
privacy
Negative Relationship Positive Relationship

Privacy Privacy Privacy Privacy


Invasive Neutral Sympathetic Protective

o Use biometric to protect other personal information


o Example: access bank accounts, medical data, or other
personal files through biometric authentication
Privacy Concerns
Associated with
Biometric
Deployments
• Two types of privacy concerns
associated with biometrics:
• Informational privacy
• Personal privacy
Informational Privacy

• Relates to unauthorized collection,


storage, and usage of biometric
information
• Biometrics may expose to potential
linkage, aggregation, and misuse of
personal information
• Biometrics is an unchangeable identifier
that could be used to track information
about individual across database, from
workplace to private life
• Privacy-sympathetic biometric system
Personal Privacy

• Relates to an inherent discomfort in the


individual when using biometrics
• Biometrics perceived as offensive,
invasive, or disturbing
• Relate to cultural, religious, or personal
beliefs
• Example: the implementation of
biometrics in workplace is an expression
of mistrust of employees which is an
implicit insult
Personal Privacy

• Objection based on informational


privacy can be mitigated by using
various security measures; however,
objection based on personal privacy is
more difficult to solved, as it is simply –
personal
• Therefore, deployers must make clear
why biometrics are used, where they
have been used, and how the systems
work
Bioprivacy Impact
Framework
• Certain types of biometric deployments
are more prone to privacy-invasive uses,
while others have little or no bearing on
privacy
• Biometrics, in themselves, are neither a
protector nor an enemy of privacy.
• Instead, the type of deployment
determines the relation between
biometrics and privacy
Bioprivacy Impact
Framework
• The BioPrivacy Impact Framework was
developed in mid-2001 to help deployers
define the potential privacy impact of a
biometric deployment and take
appropriate precautions to ensure that
deployments are privacy sympathetic
• The BioPrivacy Impact Framework
allows deployers to implement the
proper controls on biometric data and
system design
Bioprivacy Impact
Framework
Lower Risk of Privacy Greater Risk of Privacy
Invasiveness Invasiveness

Overt 1. Are users aware of the system? Covert

Opt-in 2. Is the system optional or mandatory? Mandatory

Verification 3. Is the system used for iden or veri? Identification

Fixed duration 4. Is the system used for fixed period? Indefinite duration

Private sector 5. Is the system used in public/private sector? Public sector

Individual/ Employee/
6. In what capacity is the user interacting
Customer with the system? Citizen
Bioprivacy Impact
Framework
Lower Risk of Privacy Greater Risk of Privacy
Invasiveness Invasiveness

User 7. Who owns the biometric info?


Institution

Personal Template
8. Where is the biometric data stored?
Storage Database
Behavioral Physiological
9. What type of biometric is used?

Template Identifiable
10. Does the system store templates or
identifiable biometric data? Data
Bioprivacy Technology
Risk Ratings
• Each biometric technology bears
different relation to privacy
• Some technologies have almost no
privacy impact and would be difficult to
use in any privacy-invasive fashion
• Other technologies are much more likely
to be associated with privacy-invasive
usage, either because of their basic
operations or due to extrinsic factors
Bioprivacy Technology
Risk Ratings
• Each technology is given a Risk Rating
of Low, Medium, or High in each of
the categories:
• Verification/Identification –
technology only capable of verification
are rated lower technologies capable of
robust identification are rated higher
• Overt/Covert – Technologies requiring
individuals be aware of biometric
system are rated lower; technologies
capable of operating without user
Bioprivacy Technology
Risk Ratings
• Behavioral/Physiological –
Technologies based on variable
behavioral characteristics are rated
lower; technologies based on
unchanging physiological
characteristics are rated higher
• Give/Grab – Technologies in which user
gives biometric data are rated lower;
technologies which the system grabs
user data without the user initiating a
sequence are rated higher
Bioprivacy Technology Risk
Ratings
TECHNOLOG POSITIVE NEGATIVE PRIVACY BIOPRIVACY RISK
Y PRIVACY RATING

Fingerprint  Large variety of  Use in forensic  Verification/


vendors with applications Identification (H)
different templates  Storage of images  Overt/Covert (M)
and algorithm in public-sector  Behavioral/
 Can provide applications Physiological (H)
different fingers  Strong  Give/Grab (M)
for different identification  Risk Rating (H)
systems capabilities

Face  Changes in  Easily captured  Verification/


hairstyle, facial, without consent or Identification (H)
position, lighting knowledge  Overt/Covert (H)
reduce accuracy  Existing face image  Behavioral/
database can be Physiological (M)
used for compare  Give/Grab (H)
 Risk Rating (H)
Bioprivacy Technology Risk
TECHNOLOG
Ratings POSITIVE NEGATIVE PRIVACY BIOPRIVACY RISK
Y PRIVACY RATING

Iris  Requires high  Very strong  Verification/


degree of user identification Identification (H)
cooperation  Development of  Overt/Covert (L)
 Requires technology may  Behavioral/
proprietary device lead to covert Physiological (H)
 Iris images not acquisition  Give/Grab (M)
used in forensic  No vendor  Risk Rating (M)
applications heterogeneity

Retina  Requires high  Very strong  Verification/


degree of user identification Identification (H)
cooperation  Can indicate certain  Overt/Covert (L)
 Require proprietary eye diseases  Behavioral/
device Physiological (H)
 Give/Grab (L)
 Risk Rating (M)
Bioprivacy Technology Risk
Ratings
TECHNOLOG POSITIVE NEGATIVE PRIVACY BIOPRIVACY RISK
Y PRIVACY RATING

Voice  Text-dependent  Biometric data can  Verification/


 Not capable of be captured without Identification (L)
identification consent or  Overt/Covert (H)
knowledge  Behavioral/
Physiological (L)
 Give/Grab (M)
 Risk Rating (M)

Signature  Signing is largely  Signature images  Verification/


behavioral – can can be used to Identification (L)
be modified at will commit fraud  Overt/Covert (L)
 Behavioral/
Physiological (L)
 Give/Grab (L)
 Risk Rating (L)
Bioprivacy Technology Risk
Ratings
TECHNOLOG POSITIVE NEGATIVE BIOPRIVACY RISK
Y PRIVACY PRIVACY RATING

Keystroke  Highly behavioral –  Can be captured  Verification/


subject to without Identification (L)
significant day-to- knowledge/consent  Overt/Covert (M)
day changes  Behavioral/
Physiological (L)
 Give/Grab (L)
 Risk Rating (L)

Hand  Measures of hand  None  Verification/


structure Identification (L)
 Requires  Overt/Covert (L)
proprietary device  Behavioral/
Physiological (M)
 Give/Grab (L)
 Risk Rating (L)
Designing Privacy-
Sympathetic Biometric
Systems
• Scope and Capabilities
• Limit system scope – the scope of
biometric system can be limited by
legislation, by internal or third-party
oversight, and by the type of data
collected
• Do not use biometrics as unique
identifier – make sure the enrollment
cannot be exported to other systems and
do not store identifiable biometric data
Designing Privacy-
Sympathetic Biometric
Systems
• Limit retention of biometrics – biometric
data must only be stored for the specific
purpose of usage and should not be
stored any longer than necessary
• Evaluate system’s potential capabilities
– the system’s potential capabilities
must be assessed in addition to the risks
involved in its intended usage
• Limit storage of identifiable biometric
data – after template generation, the
identifiable data should be deleted to
Designing Privacy-
Sympathetic Biometric
Systems
• Data Protection
• Use security tools and access policies to
protect biometric information
• Protect postmatch decisions – data
transmission resulting from biometric
matching should be protected to prevent
replay attacks or compromise of
personal information
Designing Privacy-
Sympathetic Biometric
Systems
• Limit system access – access to
biometric system functions and data
must be limited to authorized operators
and specific, controlled functions
• Implement logical and physical
separations between biometric and non-
biometric data – biometric data must be
stored separately from personal
information such as name, address, and
medical or financial data
Designing Privacy-
Sympathetic Biometric
Systems
• User Control and Personal Data
• Make system usage voluntary and allow
for unenrollment – allow individual to
have the right to control usage of their
biometric information and can have it
deleted or rendered unusable upon
request
• Enable anonymous enrollment and
verification – biometric system can be
designed such that individuals can
enroll and verify with varying degrees of
Designing Privacy-
Sympathetic Biometric
Systems
• Provide means of correcting and
accessing biometric-related information
– system operators should provide a
method for individuals to correct,
update, and view stored information
that is associated with biometrically
enabled account
Designing Privacy-
Sympathetic Biometric
Systems
• Disclosure, Auditing, and
Accountability
• Make provisions for third-party auditing
and oversight – trusted independent
parties with authority to penalize
breaches and enforce rules are required
to ensure institutions manage their
biometric data in accordance with
privacy principles
Designing Privacy-
Sympathetic Biometric
Systems
• Hold operators accountable for system
use and misuse – the operators of
biometric systems must be held
accountable for system misuse, whether
by internal or by external sources
• Fully disclose audit findings –
individuals should have access to
findings gathered through third-party
audits of biometric systems in order to
facilitate public discussion on the
system’s privacy impact
Designing Privacy-
Sympathetic Biometric
Systems
• Disclose the system purpose and
objectives – the purposes for which a
biometric system is being deployed must
be fully disclosed
• Disclose when individuals may be
enrolled in a biometric system –
individuals must be aware that
biometric enrollments are being
generated in a given area or through a
recording device
• Disclose when individuals may be
Designing Privacy-
Sympathetic Biometric
Systems
• Disclose whether enrollment is optional
or mandatory
• Disclose enrollment, verification, and
identification processes – individuals
should be informed of the basic process
flow of enrollment, verification, and
identification, in order to provide them
with a general understanding of how the
system works
• Disclose policies and protections in
place to ensure privacy of biometric
Summary

The BioPrivacy Impact Framework provides a


mean of assessing the privacy risks involved in
biometric deployments.

Biometrics are not inherently privacy invasive,


although biometric systems can be deployed in
privacy invasive fashions
Summary

• Adherence to good practices limits the


harm that biometric systems can do to
privacy, increases awareness of valid
privacy concerns, and allows biometric
systems to provide the benefits for which
they are known – including increased
security and convenience – without
reducing privacy

You might also like