Title: PrivacyByDesign: Private Use of Biometrics EBF Research Seminar October 2
1Privacy-By-Design Private Use of
BiometricsEBF Research SeminarOctober 2 3,
2007, BrusselsMichiel van der Veen
2Agenda
- (Biometric) Identity Theft
- Privacy-by-Design
- privID for Private Speaker Identification
- Conclusion
3Identity TheftA problem that affects everyone
and becomes more serious in the networked
environment
- Homeland security
- Fake IDs
- Terrorist threat
- Healthcare
- Insurance fraud
- Medical casualties
- Financial
- Credit card fraud, bank account transfer fraud
- 15 M victims (US only)
- Average loss per individual (US only)
2005
1,408 3,257
2006
source Gartner 2007
4The ChallengeDoes biometric open up
possibilities for the ultimate identity theft ?
- Current biometric systems depend on perimeter
based security solutions that are not guaranteed
in a broad on-line deployment - Biometric identity theft
- Unchangeable biometric over a persons
- lifetime (once compromised, compromised
- forever)
5Agenda
- (Biometric) Identity Theft
- Privacy-by-Design
- privID for Private Speaker Identification
- Conclusion
6Privacy-by-DesignCombating biometric identity
theft
- Fear for Identity Theft in Biometric Systems
leading to a preference for local storage (11)
versus centralized storage (1N), however - The world is on-line and networked
- Limitations on application functionality and
efficient data management - Privacy-by-Design Guidelines
- Data minimization only store the necessary
information - Limited use principles
- Build in privacy up front, into the design
specifications
A technology should reveal no more information
than is necessaryit should be built to be the
least revealing system possible. Lawrence
Lessig, 1999
7Pseudo Biometric IdentitiesIntrinsically secured
biometric ID information
PrivID Template Protection
- Pseudo Biometric Identities
- Intrinsic security
- renewable and revocable
- Multi-biometric input
- Face, Finger, Iris, Voice
8Privacy-by-Design in BiometricsKeeping the noise
down to generate unique and independent
identifiers
PrivID Template Protection
A-D Conversion
Error Correction
Hash/ Encrypt
Diversify
(i) Reduced Template Size
(ii) Exact Matching
(iii) Multiple Templates
(iv) Secured Templates
93-Stage Privacy Platform
10Unlimited Applications and Uses of Template
Protection
- Biometric ticketing for events
- Biometric boarding cards for air travel
- Identification, credit and loyalty card systems
- Anonymous (untraceable) labeling of sensitive
records (medical, financial) - Consumer biometric payment systems
- Access control to personal computing devices
- Personal encryption products
- Local or remote authentication to access files
held by government and other various
organizations
Source Ann Cavoukian, Sept 17, 2007
11Agenda
- (Biometric) Identity Theft
- Privacy-by-Design
- privID for Private Speaker Identification
- Conclusion
12Private Speaker IdentificationWorlds first
pilot for biometric privacy-by-design solution
- Bell Canada is deploying voluntary voice identity
verification service for its customers using
PerSays world leading Voice Biometric technology
- Sept 2007 325,000 voluntary enrollments - Successful integration of privID with PerSays
voice technology offering superior matching
performance while including privacy - Opportunity for worlds first pilot on privacy
protected speaker identification
13Agenda
- (Biometric) Identity Theft
- Privacy-by-Design
- privID for Private Speaker Identification
- Conclusion
14SummaryPrivacy-by-Design solutions for
biometrics are pivotal for public acceptance of
biometrics
- Biometric is crucial to verify identities, at the
risk of the perfect (biometric) identity theft - Although at an early phase, Privacy-by-Design
solutions promise intrinsic security - Pseudo Biometric Identities
- Renewable and Revocable
- Additional benefits may drive down the cost of
todays biometric systems - Universal and Small Footprint
- Fast Search
- Universal Back-end for Multimodal
- European Initiatives
- 3D Face (FP6), Sagem, Philips. L1, Cognitec, FhG
IGD - New Opportunities
- Template protection for minutiae fingerprint for
generating pseudo biometric identities
15www.research.philips.com/password