Ablaufschema der biometrischen Authentifizierung: links die Registrierung mit Sensoraufnahme, Merkmalsberechnung und gespeichertem Template im geschützten Chipbereich; rechts die Anmeldung mit neuer Aufnahme, Vergleich der Merkmalslisten, Ähnlichkeitswert und Entscheidung anhand eines Schwellenwerts, ergänzt um den Zwischenschritt Lebenderkennung.

Biometric Authentication

Biometric authentication verifies a person's identity using physical characteristics such as fingerprint, face, or voice. Instead of entering a password, you show yourself — which is convenient, but carries its own risks.

Anyone who unlocks their phone must prove that they are its rightful owner. Classically, this is done with something you know: a numeric code or a password. Biometric authentication instead uses something you are. The device compares a physical characteristic — the fingerprint, the face, the iris of the eye, or the voice — with a stored template. If the two match closely enough, access is granted. The term is composed of the Greek words for life and measure: so it is a measurement taken on the body.

Convenient, but not revocable

The practical advantage is obvious. A fingerprint cannot be forgotten, cannot be written on a piece of paper, and cannot be accidentally passed on. This is precisely why biometrics has displaced the password in many everyday situations. Companies also favor this method, since insecure passwords like “123456” are one of the most common causes of account breaches.

Yet this is offset by a fundamental problem. A stolen password can be changed; a stolen face cannot. Once someone has copied a person’s stored characteristics, they can in theory misuse them permanently. Experts therefore call biometrics a non-revocable secret. For this reason, biometric data is classified as especially sensitive under the European General Data Protection Regulation and may only be processed under strict conditions.

A second point of contention is fairness. In tests, facial recognition long performed measurably worse for women and people with darker skin than for white men. The reason usually lay in the training data, in which these groups were underrepresented. A system that works more reliably for some people than for others is more than just a technical shortcoming.

From template to threshold value

In the first step, enrollment, a sensor captures the characteristic. From the image, the software calculates a kind of numerical list that describes characteristic points: for a face, for example, the distances between eyes, nose, and chin. This list is called a template. The original photo is usually discarded, and the face cannot simply be reconstructed from the template.

At every subsequent login, a new numerical list is generated and compared with the stored one. Unlike with a password, there is never an exact match here. Light, angle, a beard, or damp fingers alter the measurement slightly each time. The system therefore calculates a similarity score and accepts it once it reaches a defined threshold value.

This threshold value is a trade-off. Set it strictly, and legitimate users are rejected more often. Set it loosely, and strangers get through more easily. Added to this is liveness detection: it is meant to recognize whether a real person is standing in front of the camera or just a printed photo. Modern sensors measure, for example, the depth of the face using infrared dots. Also security-relevant is where the template is stored — on modern smartphones it remains in a shielded chip area within the device and does not travel to a server.

From phone login to border control

Most commonly, one encounters biometrics when unlocking a smartphone or laptop, as well as when confirming payments in banking apps. The electronic passport also contains fingerprints and a facial image; at many airports, automated gates therefore replace inspection by officials. In companies, biometric readers open doors to server rooms.

In the news, the term often comes up in debates over surveillance. Facial recognition in public spaces searches camera footage for specific individuals. This is technically related but legally something different: here, no one is voluntarily proving their identity. The EU’s AI Act therefore significantly restricts such systems.

Finally, a common misconception is that biometrics is automatically more secure than a password. Above all, it replaces the need to remember something, not the need for care. Experts therefore recommend multi-factor methods: the physical characteristic is combined with a second form of verification, such as possession of a particular device. For fake voices and videos that AI can now generate, this is often the only effective safeguard.

Subscribe free. Unsubscribe the second it sucks.

High-signal news across AI, business, UX, and tech. Every morning.