0PricingLogin
Security+ Academy · Lesson

Biometrics and Token-Based Authentication

Explore fingerprint, retina, and behavioral biometrics alongside hardware tokens (TOTP, FIDO2/WebAuthn) and their strengths and weaknesses.

Biometrics: Authentication You Are

Biometric authentication verifies identity based on unique physical or behavioral characteristics — 'something you are.' Unlike passwords, biometrics cannot be forgotten, shared easily, or lost. However, they also cannot be changed if compromised: you cannot get a new fingerprint. Biometric systems measure and compare a biological or behavioral trait against an enrolled template stored during setup. The quality of a biometric system is measured by its error rates and the security of how templates are stored. Biometrics are most powerful when combined with another factor (e.g., fingerprint + PIN).

Physiological Biometrics

Physiological biometrics are based on physical characteristics of the body. Key types include: Fingerprint: most widely deployed due to low cost and acceptance; used in phones, access control, and border security. Retinal scan: scans blood vessel patterns on the back of the eye — very accurate and hard to spoof, but requires close contact with the reader. Iris scan: scans patterns in the colored part of the eye — can be done from greater distance, used in airports. Facial recognition: analyzes facial geometry from a camera; increasingly accurate but can be affected by lighting, aging, and disguises. Hand geometry: measures hand shape and finger length.

All lessons in this course

  1. Password Policies and Multi-Factor Authentication
  2. Biometrics and Token-Based Authentication
  3. Authorization Models: RBAC, MAC, and DAC
  4. Federated Identity: SAML, OAuth, and OpenID Connect
← Back to Security+ Academy