Fingerprint Scan

A fingerprint scan captures the ridge pattern of a finger and converts it into a mathematical template that can be compared against a stored reference. It is a one-to-one or one-to-many comparison against something enrolled earlier, which makes it an excellent authentication method and a poor way to establish who a stranger is for the first time.

What is measured Ridge endings, bifurcations and other minutiae — not a picture of the finger
Sensor types Optical, capacitive, ultrasonic, thermal
Stored artifact A template derived from the image; well-designed systems do not retain the image itself
Template standard ISO/IEC 19794-2 for minutiae data interchange
Spoof-resistance standard ISO/IEC 30107-3 for presentation attack detection testing
Accuracy measures False acceptance rate, false rejection rate, and the trade-off between them
Requires prior enrollment Yes — a scan is meaningless without a reference to compare against
Common use Device sign-in, physical access control, criminal and civil identification systems

How it works

The sensor produces an image, and the image is immediately discarded in favor of a template. Feature extraction locates minutiae — the points where a ridge ends or splits — and records their positions and orientations relative to each other. A typical finger yields dozens of usable minutiae, and matching compares the relative geometry of those points rather than overlaying two pictures.

Sensor technology determines what can be spoofed. Optical sensors photograph the ridge pattern and are the easiest to defeat with a printed or molded replica. Capacitive sensors measure electrical differences between ridges and valleys, which rules out flat images but not conductive molds. Ultrasonic sensors image below the surface of the skin, reaching subdermal structure that a surface replica does not reproduce. Each step up costs more and buys resistance to a specific class of attack rather than to attacks generally.

Every fingerprint system sits somewhere on a curve between false acceptance and false rejection. Tightening the match threshold rejects more impostors and also more legitimate users; loosening it does the reverse. There is no setting that reduces both, only a choice about which error is more costly in context. A phone unlock and a border control system land in very different places on that curve.

Why fingerprint matters for identity verification — and where it doesn’t apply

The distinction worth being precise about: a fingerprint scan authenticates, it does not identify. Comparing a live finger against a template proves the same finger that enrolled is present now. It says nothing about whose finger enrolled. If the enrollment was fraudulent, every subsequent authentication faithfully confirms the fraud.

This is why remote onboarding rarely uses fingerprint. There is no trusted reference to compare against, no way to verify the sensor is real rather than a replayed template, and no widely-held credential carrying a fingerprint that a consumer device can read. The modality that works at first contact is the face, because government identity documents carry a facial image that can be compared against a live selfie — the reference already exists and is issued by an authority.

That comparison is what biometrics does in an identity document verification workflow, and it is why liveness detection carries so much weight. A fingerprint sensor is physical hardware an attacker must be present to defeat. A camera accepts whatever the software feeds it, which moves the entire problem from replica-making to stream manipulation.

Fingerprint compared with facial biometrics

Fingerprint Face
Reference source Must be enrolled beforehand Available from a government-issued identity document
Works at first contact No Yes
Hardware required A dedicated sensor Any camera
Primary attack Physical replica presented to the sensor Presentation attacks and injected media
Best suited to Repeat authentication on a known device Establishing identity remotely

What a fingerprint scan can’t do

It cannot identify an unknown person. Without a prior enrollment or access to an authoritative database, a fingerprint matches nothing.

It cannot be reissued. A compromised template is a permanent problem in a way a password is not, which is the argument for storing templates rather than images and for binding them to a device.

It does not work for everyone. Worn ridges from manual work, age, certain medical conditions, and simple moisture or dryness produce failures to enroll and failures to acquire. Any system depending on it needs a fallback path.

Presentation attack detection is not universal. Many deployed sensors have no liveness capability at all, and testing against ISO/IEC 30107-3 is the difference between a claim and a measurement.

Frequently asked questions

Is a fingerprint image stored when I enroll?

In a well-designed system, no. Feature extraction produces a mathematical template describing the position and orientation of minutiae, and the original image is discarded. The template is not reversible into a usable reproduction of the fingerprint, though it should still be protected as biometric personal data.

Can a fingerprint scanner be fooled?

Yes, with effort that varies sharply by sensor type. Optical sensors are the most vulnerable to printed or molded replicas. Capacitive sensors require a conductive material. Ultrasonic sensors image subdermal structure and are harder to defeat with a surface replica. Presentation attack detection tested against ISO/IEC 30107-3 is the meaningful measure.

Why is face used for remote identity verification instead of fingerprint?

Because a reference already exists. Government identity documents carry a facial image that can be compared against a live capture, so identity can be established at first contact. Fingerprint requires a prior enrollment, and consumer devices cannot read a fingerprint from an identity document.

What are FAR and FRR?

False acceptance rate is the proportion of impostor attempts wrongly accepted; false rejection rate is the proportion of genuine attempts wrongly refused. They move in opposite directions as the match threshold changes, so a system is tuned to whichever error is more costly in its context rather than minimizing both.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data