Feeds

Japanese researchers check IDs with eyeball twitch

'Spoof-proof' biometrics

Choosing a cloud hosting partner with confidence

Biometric identity scanners are attracting more attention as safe way to handle user authentication and security. But a team of Japanese researchers claim current methods are bunk if approached by a sufficiently sophisticated intruder.

Iris scans, electronic fingerprinting and signature recognition – they're certainly better than jotting a password down on a post-it note.

"However, biometric information can easily be leaked or copied," the researchers claim. "It is therefore desirable to devise biometric authentication that does not require biometric information to be kept secret."

Writing for the International Journal of Biometrics, researchers lead by Masakatsu Nishigaki and Daisuke Arai of Shizuoka University say they've turned to a superior alternative that can't be spoofed: the unique reflex response of a person's eyeball.

Nishigaki and Arai use the eye's involuntary twitchy movement combined with the position of its blind spot as a biometric. Every vertebrate has a blind spot, or scotoma, where the optic nerve exits the retina. This visual gap is not perceived normally because the visual field of each eye overlaps the blind spot of the other.

The researchers use the blind spot position to trigger eye movement. A visual cue is displayed within and outside a person's blind spot, and the reflex time taken until the eye moves is measured. The team has also published different versions of reflex-based authentication, such as using blind spot position and pupil contraction.

Nishigaki points out that if the blind spot position alone was used, an imposter could conceivably use contact lenses or even surgery to fool the system – making it no safer than an iris scan. All that's needed is for the biometric information to fall into the wrong hands.

That's certainly not inconceivable. Just last month, medical firm The Wellcome Trust accidentally emailed dozens of fingerprints and iris scans to the wrong people. While an impostor getting massive reconstruction surgery in order to access secure data is presently a bit far-fetched, eliminating at least one weak link in the chain sounds like a good idea if we're going to be forced to go along with this whole biometrics thing. ®

Beginner's guide to SSL certificates

More from The Register

next story
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
FYI: OS X Yosemite's Spotlight tells Apple EVERYTHING you're looking for
It's on by default – didn't you read the small print?
Microsoft pulls another dodgy patch
Redmond makes a hash of hashing add-on
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.