?
Parametric study of hand dorsal vein biometric recognition vulnerability to spoofing attacks
Biometric vein recognition systems are vulnerable to presentation attacks. Traditionally, researchers have used a near-infrared (NIR) drawing of the user’s vascular bed to create a presentation attack instrument (PAI). This paper investigates the feasibility of using free software to capture a venous pattern of the hand without NIR under normal lighting conditions and to create a PAI on biometric systems based on the obtained data. The authors compare the effectiveness of presentation attacks conducted using “classical” PAI – a printed image of the user’s vascular bed obtained in the NIR range, a cropped version of the “classical” PAI pasted on the attacker’s hand, and a PAI generated from data obtained from a smartphone. The study showed that it is not only possible to covertly acquire the venous pattern of the dorsal part of the hand in vivo with available equipment but also to create artifacts based on this data that can traverse the biometric system, with a successful attack possible in 65.5% of attempts.