Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, January 27, 2009

Image Recognition: Facial and license plate recognition news items

There are two on-line news articles related to image recognition that I would like to bring to your attention.

The first news article is about law enforcement in Tacoma, Washington, USA using a facial recognition package to match 16 years worth of prisoner mug shots with pictures taken by ATM (Automated Teller Machines) in a forgery and theft investigation to generate the lead needed to solve the case.

The second news article is from New Orleans, Louisiana, USA where local law enforcement used a license-plate recognition system to make 20 arrests and recover 23 stolen vehicles and license plates in a 25 day period.

The common thread here is, of course, automatic image recognition. These software algorithms have come a long way in the last decade. However, one should understand that the conditions are partially or completely controlled in both of these applications - i.e. distance, lighting, exposure, aspect (turned toward the camera), and (possibly) compression all fall within acceptable boundaries. In addition, with the license plate recognition problem, the character set and fonts were known in advance. The controlled conditions and a priori knowledge significantly increase the accuracy of the results tremendously and the chances of a successful investigation and prosecution.

(Hat-tip to JUSTNETNews, USA - I highly recommend this free service of the National Law Enforcement and Corrections Technology Center, or NLECTC, which is part of the National Institute of Justice, USA)

Tuesday, October 28, 2008

Image Recognition: Military requirements push technology forward

The Strategy Page has an article about how the proliferation of video on the battlefield (e.g. from surveillance cameras and even night vision goggles) is driving technology development. Initially, it was the UK (United Kingdom) that drove image recognition technology with its massive deployment of CCTV in public spaces (e.g. train stations, airports, city centers, and shopping malls). Now, it is the military.

The benefit from computer-assistance in analyzing video comes from the following:

  1. Volume (i.e. the sheer number of cameras and, hence, images to be monitored and/or analyzed)
  2. Concentration (i.e. the human visual system loses the ability to concentrate effectively on images after about 20 minutes of continuous viewing)
  3. Memory (i.e. computers can track and, possibly, predict more things simultaneously than a human can because, generally speaking, computers are not nearly as attention and working-memory limited in the short-term as humans and far outstrip us in their ability to recall video sequences over the long term - they can just play back the video recording off of their hard disks)

The article claims that the abilities of computer systems to recognize patterns is rapidly improving and approaching that of humans - that is no small feat as humans are simply amazing in their ability to perform real-time pattern analysis.

One intriguing point made in the article is that the current conflicts are generating a lot of real-world recordings of "bad behavior" that can be used to train and test new pattern analysis and prediction algorithms - training data like this is like gold to us signal processing types!

Enjoy!

Sunday, February 03, 2008

Biometrics: Finger vein scanners being deployed

The use of various biometric technologies to identify individuals as a routine matter of daily life has been slow to catch on, thus far at least. Perhaps it is because there is insufficient demand, perhaps it costs too much (relative to the perceived benefits), or perhaps there are drawbacks with the technologies that have been fielded to implement it to this point.

As far as industry addressing possible technology drawbacks of the equipment, the Guardian (UK, left-wing newspaper) reports that Hitachi has started fielding a new type of biometric technology - finger vein scanners. Finger vein scanners differ from finger print scanners in that they are reportedly more difficult to fool. The principle of operation in similar to the blood oxygenation sensors commonly used in medical settings - i.e. shining a light onto (into) the skin of the finger which is absorbed by the hemoglobin in the capillaries, thereby allowing the imaging sensor to "take a picture" of the capillary pattern. These patterns are reportedly unique to an individual, just like finger prints. Of course, it all depends in how you implement the matching algorithm, but that is another issue - for more, see the Journal of Forensic Identification paper on errors in fingerprint examination.

Whether the scanners address the cost issue I mentioned above remains to be seen. For more details, including one disturbinging case of how a gang got around a finger print scanner to steal an automobile, you can check out the Guardian article.

Saturday, July 07, 2007

Surveillance: Stop sign cameras

It is time to add a new type of "safety camera" to the list - a stop sign camera. The interesting thing about this system is that it detects if the car comes to a complete stop or not. Here is a brief news article about a deployment in California, USA.

Wednesday, June 13, 2007

Biometrics: Implications of Pay by Voice commercial service

MIT's Technology Review has an article about the new Pay by Voice commercial service by a company called, surprisingly enough, Voice Pay. Now, I can imagine at least a couple of different general responses you, the reader, might have to this news. The first would be the semi-jaded, popular science devotee's reaction of "gee, that makes sense". The other would be the security-minded skeptic's reaction of "that's got to be so full of holes it will look like Swiss cheese."

Both responses are probably right in some sense, BUT, the devil is in the details, as they say. I'll point out the ones that seem the most obvious to me, without getting too technical.
  1. The system is based around mobile (or cell, for the US readers) phones, which implies more environmental noise than fixed line, compression effects (from coding the voice to use less bandwidth over the air), and possible hands-free use (which means even more noise and a different "sound" to the voice, which could confuse the voice recognition algorithm).
  2. Verifying someone's identity is easier than other recognition tasks (like picking someone out of a crowd). The system has been pre-trained on the person's characteristics and the system architecture is usually better controlled, for starters.
  3. This implementation of identity verification uses voice biometrics as well as call-back to the previously registered mobile number. This allows the fusion of two different types of data, although it is over the same "channel." If the shopping is done on-line, then there is not only multiple types of data, but also multiple channels that the data is passing over, which increases security.
  4. Fooling the system with a voice synthesizer might indeed be possible, but access to the potential victim's mobile phone would be required - as well as log-in details in some cases and 100% spoof rate could not be guaranteed.
  5. The company obviously didn't want to get into the issues surrounding false positive/negative rates and credit card security, but the truth of the matter is that the existing credit card system is not very secure in itself, but the losses to the credit card industry due to fraud are small enough compared to the profits that it isn't worth the effort to them to make it significantly more secure. (Note: Before anyone emails me about credit cards with chip and PIN, please consider just how big the credit card market is and how many traditional chipless cards are out there and will be for many years to come.) The company seems to be assuming that the same rules will apply here - if they succeed in getting into the market in a big way, their losses due to fraud will be easily written off.
There is much more that I could say here, but in the interest of not turning this into a paper by itself, I'll cut it off here. Feel free to email me or post a comment, though.

Sunday, April 22, 2007

Security: The weakest link

Q.- What high tech hacker tools are needed to steal $25 million of diamonds from behind all the layers of a bank's security system?

A. - Chocolates and charm.

The hacker community calls this "social engineering."

Friday, March 09, 2007

Biometrics: Biometric passport with RFID is hacked remotely

A regular reader pointed me to the Daily Mail (a UK tabloid) article describing how they had a security expert "hack" one of the new biometric passports with an electronic Radio Frequency IDentification (RFID) microchip to extract all of the digital data. They arranged to simulate intercepting the passport being mailed from the government to the citizen. Because the passport had this RFID chip, it could be remotely interrogated, they were able to do this without even opening the postal envelope containing the passport. Of course, the data was encrypted, so then the security expert had to break that (and he succeeded). The only apriori information he needed was the citizen's date of birth, which he obtained through searching the Internet. The entire process took four days, but in the end, he was able to recover all of the passport's digital data, which even included the citizen's digital picture.

It seems pretty obvious that they either didn't bother to do a proper independent security analysis before they developed and deployed the system or the managers discounted the results of any one that was done. Because of that lapse, now it seems that they need to rethink their encryption scheme at the very least. When they do, it might make sense to add some type of limit to the number of times a passport can be interrogated with an incorrect password, either in a certain time window or an accumulated number over the life cycle of the passport.

Sunday, February 11, 2007

Security holograms relatively easy to copy

The Daily Irrelevant has a post on the rise in counterfeiting of security holograms, which are found on everything from credit cards to whiskey bottles these days. Reportedly, the cost of the equipment to make a copy is in the range of only $2,500 USD, which, given the illegal profits to be made, is insignificant. Interesting reading.

Monday, January 15, 2007

Beyond Nielsen ratings - now with audio

Imagine getting a free cell phone, but instead of being forced to listen to advertising in exchange for your free-ride, it listens to you instead. That's right. Every so often, it records the activity going on around you and then uses a computer algorithm to create a "signature" from those sounds passes that signature back to a processing center, where another algorithm compares that signature to its master database to recognize what media type and "program" you are listening to - be it a music CD, TV/radio program, Muzak, rock concert, or whatever. Your data is then compiled with many others' to create media ratings. By only passing a signature and not the raw audio itself, no actual conversations get eavesdropped on - which would be illegal in many places.

In this age of TiVO, iPod, and other time- and/or location-shifting devices to allow viewers and listeners to consume media when and where it is convenient, traditional ways of measuring and estimating ratings are not as effective - hence the market's experimentation with this type of technology.

If you are interested in reading more, one company that is selling such a service is IMMI (Integrated Media Measurement Inc). There is a link on their home page to a Wall Street Journal review of several companies doing similar things.

(Hat Tip: Bruce Schneier's CRYPTO-GRAM email newsletter, January 17, 2007 edition)