A comprehensive security analysis of match-in-database fingerprint biometric system

Abstract The match-in-database fingerprint biometric system has emerged as the most widely used human identification and authentication method in public and private sectors due to its high efficiency, low-cost, and ease of use. This paper provides an exhaustive insight into the security aspect of such systems. We propose a comprehensive threat model depicting sixteen vulnerable attack points, which can act as a reference model while designing a new biometric application. We provide a comparison between the existing and proposed threat model. This article pinpoints all probable attacks at each vulnerable location and suggests possible mitigation techniques to thwart such attack attempts. We investigate the attacks on such systems, present a threat model, and categorize them into eight classes while specifying the risk factor associated with each class. This facilitates any new attack on such a system to be classified into one of these eight classes.

Paper

Full text

PDF

A comprehensive security analysis of match-in-database fingerprint biometric system

Semantic Scholar · Computer Science · 2020

Abstract

Abstract The match-in-database fingerprint biometric system has emerged as the most widely used human identification and authentication method in public and private sectors due to its high efficiency, low-cost, and ease of use. This paper provides an exhaustive insight into the security aspect of such systems. We propose a comprehensive threat model depicting sixteen vulnerable attack points, which can act as a reference model while designing a new biometric application. We provide a comparison between the existing and proposed threat model. This article pinpoints all probable attacks at each vulnerable location and suggests possible mitigation techniques to thwart such attack attempts. We investigate the attacks on such systems, present a threat model, and categorize them into eight classes while specifying the risk factor associated with each class. This facilitates any new attack on such a system to be classified into one of these eight classes.

Similar papers

© 2026 NYSGPT2525 LLC