Biometric Security Strength Analysis via Feature Domain Volume
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric security systems (BSS) face challenges in accurately measuring security strength against spoofing attacks, as current methods fail to consider the adversary's knowledge and are dependent on data distribution estimation, bin size selection, and simulation configurations, leading to inconsistent and costly evaluations.
Innovation Solution
A novel analytical framework that calculates the feature domain volume to estimate the probability of guessing a feature point, considering the adversary's knowledge and processing algorithms, to evaluate the security strength of BSS, specifically using geometrical methods to calculate the average number of guesses required to break the system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If entropy measures are used to evaluate security strength, then the evaluation is simple and based on data uniqueness, but the measurement is inconsistent and does not consider the adversary's knowledge
Solution Approach 1:
The patent transforms the security strength evaluation from static entropy measures to dynamic parameter-based evaluation. It introduces multiple parameters including feature domain volume, class boundary characteristics, and adversary knowledge levels. The security strength is recalculated based on these changed parameters, providing a more accurate and context-dependent measurement that accounts for the adversary's information about the system.
Solution Approach 2:
The patent segments the security evaluation into distinct components: feature extraction stage, classification stage, and adversary knowledge stages. Each segment is evaluated separately with appropriate metrics, allowing for more precise measurement of security strength at different system levels rather than using a single entropy measure for the entire system.
2Reliability
If simulation methods are used to evaluate security strength, then the evaluation considers system dynamics, but the process is costly and time-consuming
Solution Approach 1:
The patent performs preliminary analytical calculations of feature domain volume and class boundary characteristics before actual security evaluation. By pre-computing geometric properties and statistical parameters of the feature space, the system establishes a foundation for rapid security assessment without requiring extensive simulations during the evaluation phase.
Solution Approach 2:
The patent replaces mechanical simulation approaches with analytical mathematical methods. Instead of running time-consuming simulations to evaluate security strength, the system uses closed-form mathematical calculations based on feature domain geometry, probability distributions, and information theory to directly compute security metrics.
3Manufacturing precision
If feature extraction is performed to improve system performance, then authentication accuracy increases, but the security strength decreases due to entropy reduction
Solution Approach 1:
The patent applies local quality by evaluating security strength at different stages of the authentication process. Instead of treating the entire system uniformly, it separately analyzes the feature extraction stage and classification stage, allowing feature extraction to optimize local authentication accuracy while the classification stage maintains overall security strength through proper boundary design.
Solution Approach 2:
The patent addresses the security-accuracy tradeoff by introducing additional evaluation dimensions. It measures not only authentication accuracy but also feature domain volume, class boundary complexity, and adversary guessing effort in multiple dimensional spaces. This multi-dimensional evaluation allows optimization of both accuracy and security simultaneously by considering factors beyond simple entropy.
Data Source
AI summary
A framework for measuring the security strength of bio-metric security systems against spoofing attacks considering the adversary's knowledge about the system is disclosed.


