Biometric authentication
Also known as: Biometrics · Face authentication · Biometric login · Biometric re-authentication
Confirming that the person accessing an account is the same holder who enrolled, by comparing a physical trait — typically the face — against the biometric captured at onboarding.
Legal basis
NIST SP 800-63B — Authentication and Lifecycle Management
Verifying identity at enrollment is 1:1 against the document; authenticating afterward is 1:1 against what was stored. It is the step that replaces the password on return — to pay, approve a transaction, recover access — proving the "something you are" factor. NIST SP 800-63B treats a biometric as an authentication factor that must always accompany another, because a biometric cannot be reset like a password once it leaks.
Biometric authentication is only as strong as its liveness detection: without it, a photo, a video or a deepfake of the holder passes the face match. That is why authenticating and checking liveness travel together, and the quality of the algorithm — measured in tests like ISO/IEC 19795 — sets the false-accept rate. In the US, collecting face geometry for authentication also brings state biometric-privacy duties, such as Illinois's notice-and-consent requirements.
Frequently asked questions
What is the difference between biometric verification and authentication?
Verification, at enrollment, compares the face to the document to prove who the person is. Authentication, on later logins, compares the face to the biometric already on file to prove it is the same holder returning — replacing or reinforcing the password.