Skip to Content

Changeable Fingerprint

If someone steals your fingerprint, “cancelable biometrics” software from IBM can issue a new one.
December 1, 2005

Your fingerprints are yours and yours alone, and that makes them a useful tool for confirming the identity of people doing things like conducting secure banking transactions or passing through corporate security checkpoints.

Trouble is, it’s theoretically possible for a hacker to break into the software of, say, an employer, steal a copy of your stored fingerprint, and later use it to gain entrance.

So researchers at IBM have come up with “cancelable biometrics”: if someone steals your fingerprint, you’re just issued a new one, like a replacement credit card number.

The IBM algorithm takes biometric data and runs it through one of an infinite number of “transform” programs. The features of a fingerprint, for example, might get squeezed or twisted. A bank could take a fingerprint scan when it enrolls a customer, run the print through the algorithm, and then use only the transformed biometric data for future verification.

If that data is stolen, the bank simply cancels the transformed biometric and issues a new transformation. And since different transformations can be used in different contexts – one at a bank, one at an employer – cross-matching becomes nearly impossible, protecting the privacy of the user.

Finally, the software makes sure that the original image can’t be reconstituted from the transformed versions. IBM hopes to offer the software package as a commercial product within three years.

Keep Reading

Most Popular

Large language models can do jaw-dropping things. But nobody knows exactly why.

And that's a problem. Figuring it out is one of the biggest scientific puzzles of our time and a crucial step towards controlling more powerful future models.

How scientists traced a mysterious covid case back to six toilets

When wastewater surveillance turns into a hunt for a single infected individual, the ethics get tricky.

The problem with plug-in hybrids? Their drivers.

Plug-in hybrids are often sold as a transition to EVs, but new data from Europe shows we’re still underestimating the emissions they produce.

It’s time to retire the term “user”

The proliferation of AI means we need a new word.

Stay connected

Illustration by Rose Wong

Get the latest updates from
MIT Technology Review

Discover special offers, top stories, upcoming events, and more.

Thank you for submitting your email!

Explore more newsletters

It looks like something went wrong.

We’re having trouble saving your preferences. Try refreshing this page and updating them one more time. If you continue to get this message, reach out to us at customer-service@technologyreview.com with a list of newsletters you’d like to receive.