Biometrics for enterprise security

Mark Crosbie · Network Security · 2005

‘You can't leave your finger behind,’ as biometrics fans never tire of telling us. In fact biometrics have been promoted as a ‘foolproof’ way to authenticate an individual's identity. But how much should we trust those claims? Industry vendors even suggest error rates of less than one in a million, which appear far too broad (and too good) to be true. A brave new world of reliable and trustworthy authentication is promised, but how applicable are biometrics really in the enterprise today? Few decisions facing security professionals are straightforward – for instance, whether to use a central database to store all biometrics for users, or to issue them with a smartcard that will hold their biometric samples; whether to use the good old finger, or retina, vein patterns, perhaps – or even the way you walk. This article aims to dispel some of the common myths around biometrics, to give a deeper grasp of today's biometric technology and what it implies. Biometrics have been touted as a ‘foolproof’ way to authenticate an individual's identity – and industry vendors claim accuracy ratings of more than a million to one. A brave new world of reliable and trustworthy authentication is promised, but just how much can you trust those claims, and how applicable are biometrics in the enterprise today?

Read the paper · More papers on PaperTik