Analysis of the attack potential in low cost spoofing of fingerprints

Ines Goicoechea-Telleria, Judith Liu‐Jimenez, Helga C. Quiros-Sandoval, Raúl Sánchez-Reillo · 2017

The use of biometrics in smartphones keeps growing. Every day, we use our phones to store sensitive data (such as photos, bank accounts and documents), so we rely on the security manufacturers offer when protecting our private life. It is well known that it is possible to hack into a smartphone using fake fingers made of Play-Doh and other easy-to-obtain materials but, to what extent? Is this true for all users or only for specialists with deep knowledge on biometrics? To test this, we performed an evaluation: 15 simulated attackers with no background in biometrics were asked to create fake fingers of several materials out of a silicon mold, and they had one week to attack the fingerprint sensors of 5 very well-known smartphones. Each had to, at least, use 3 bona-fide capture subjects, summing a total of 5,841 attempts. Their starting point was a short video of a researcher performing the attack and apart from that, they were on their own. This paper will provide the results achieved, as well as an analysis on the attack potential of this kind of biometric implementations. All results are given following the metrics of the standard ISO/IEC 30107-3.

Read the paper · More papers on PaperTik