Biometrics

Authentication by a measured physical or behavioural characteristic, such as a fingerprint, face, iris or typing rhythm: something you are, matched against a threshold rather than exactly.

Biometrics authenticate a person by measuring a characteristic of the body or of behaviour and comparing it with a template recorded at enrolment. Examples include fingerprint, face and iris, and behavioural traits such as typing rhythm. Both are “something you are” as an authentication factor. Because two readings of the same person rarely match exactly, the system accepts a comparison that clears a set threshold, which produces two errors: a false rejection of a genuine user and a false acceptance of an impostor. The crossover error rate is where the two rates are equal.

NIST SP 800-63B-4 treats a biometric as a factor but not as a secret, and permits it only as part of multi-factor authentication together with a physical authenticator. It also treats presentation attacks, such as a spoofed fingerprint or a photograph of a face, as a risk separate from matching error. Biometric data also raises privacy concerns, and a compromised fingerprint cannot be changed the way a password can.

Exam relevance: questions in this area tend to turn on the error trade-off and on the limits of the factor. Candidates are expected to know that tightening the threshold lowers false acceptance at the cost of more false rejections, and that a biometric is best treated as one factor among several rather than as an unstealable password.