GCSE · Computer Science · AQA · Spec 8525

Biometric measures

Your phone opens for you and stays shut for your little cousin, with no password typed. How does it know it's you?

Computer Science · Biometric authentication

Stand at the scanner

First pick who is at the scanner. Then pick what the comparison finds. Every route ends somewhere different.

Who is at the scanner? → Is the new scan close enough to the stored template?

  • Whoever it is, the system asks the same single question: is this scan close enough to the template?

4 possible login outcomes.

On A finger is placed on the fingerprint scanner. 2 branches to choose from.

The enrolled user's fingerprint is already stored as a template. Walk both people up to the scanner and see where each ends up.

Exam line: The system never asks 'is this identical?'. It asks 'is this close enough?', and that one question produces both kinds of wrong result.
Watch out: A scan is not an exact, infallible match. Two of the four routes end in a mistake.

Computer Science · How it works

Put the login story in order

the order the stages happen in, from the very first scan onwards

1 · First stage5 · Last stage
  1. Compare the new scan with the stored template

  2. Scan the user's characteristic when they enrol

  3. Grant access, or refuse it

  4. Scan the characteristic again at login

  5. Store that first scan as the user's template

Computer Science · Biometrics vs passwords

Rebuild the comparison grid

Tick every cell where the property is true for that method. Then check the grid.

Password
PIN
Fingerprint
Face recognition
Iris or retina scan
Voice

Exam line: Compared with passwords, biometrics win on forgetting and guessing or sharing. They lose on special hardware and on being impossible to change if stolen.

Predict, then check

A phone needs your fingerprint and your PIN. A thief has watched you type the PIN.

The thief now knows the PIN but has a different fingerprint. What happens when they try to unlock it?

WHAT YOU'VE LEARNED

A quick recap of today's lesson.

That one question is why biometrics work, and why they sometimes get it wrong.

What you need to know

  • A biometric measure checks who you are using a physical or behavioural characteristic that is unique to you.
  • Fingerprints, face recognition, the iris or retina of the eye, and voice are all examples.
  • Have a goYour mate swears their gran's PIN is a biometric measure because it's 'unique to her'. Which part of the definition does a PIN fail?

    A PIN is not a physical or behavioural characteristic of the person.

    Biometrics authenticate you from a characteristic of you, such as a fingerprint or your voice. A PIN is just a code someone chose.

  • At enrolment, your characteristic is scanned once and stored as a template.
  • At every later login it is scanned again and compared with that stored template.
  • Access is granted only when the new scan matches the template closely enough.
  • Have a goA user's login scan is very close to their template but not identical. Granted or refused?

    Granted, because the scan matches closely enough.

    The check is for a close match, not a perfect copy, so 'not identical' on its own does not cause a refusal.

  • Because it is a closeness check, it can wrongly reject an authorised user or wrongly accept an unauthorised one.
  • Compared with passwords, a characteristic cannot be forgotten, is difficult to guess, share or copy, and is always with you.
  • The costs: special hardware such as a scanner or camera, and sensitive data that cannot be changed if stolen.
  • Have a goMaya's password leaks, and separately Sam's fingerprint data leaks. Who has the bigger long-term problem, and why?

    Sam, because he cannot change his fingerprint.

    Maya can replace a leaked password, but biometric data cannot be changed if it is stolen.

  • Because of this, biometrics are often used with a password or PIN, so more than one factor is needed.

The big picture

Biometric authentication scans a characteristic of the person, stores it as a template at enrolment, and later asks one question: is today's scan close enough to that template? That closeness check is why it beats passwords on forgetting, guessing and sharing, why it can still get things wrong, and why it is often paired with a password or PIN.

Key points

1Enrol once: the characteristic is scanned and stored as a template.
2Each login: scan again and compare with the template. Access needs a close enough match, not a perfect copy.
3A close-enough check can wrongly reject an authorised user and wrongly accept an unauthorised one.
4Over passwords: nothing to forget, difficult to guess, share or copy, always with the user.
5Against: special hardware needed, and sensitive data that cannot be changed if stolen.
6Often combined with a password or PIN so that more than one factor is needed.

Worked example

Problem

A school wants pupils to log in to its computers with a fingerprint scanner instead of a password. Give one advantage and one limitation of this, each with a reason.

⚠ Watch out

Thinking a fingerprint or face scan is an exact, infallible match. The new scan is compared with a stored template and accepted if it matches closely enough, so an authorised user can be wrongly rejected and an unauthorised one wrongly accepted.

🧠

Memory hook

Enrol once, compare every time, and ask 'close enough?'. A fingerprint can't be forgotten or guessed, but if it's stolen you can never change it.

✓

Check yourself

Without looking back, tell the whole story in order: what happens at enrolment, what happens at each login, and at which point each of the two wrong results can happen.

Flashcards

(9)
What is a biometric measure?
A way of authenticating a user from a physical or behavioural characteristic that is unique to that person.
Name four characteristics used for biometric authentication.
Fingerprints, facial features (face recognition), the iris or retina of the eye, and voice.
What happens at enrolment?
The user's characteristic is scanned and stored as a template.
What happens at each later login?
The characteristic is scanned again and compared with the stored template.
When does a biometric system grant access?
Only if the new scan matches the stored template closely enough.
What are the two ways a biometric scan can get it wrong?
It can wrongly reject an authorised user, or wrongly accept an unauthorised one.
Why is a biometric characteristic harder to attack than a password?
It cannot be forgotten, it is difficult to guess, share or copy, and it is always carried by the user.
Three limitations of biometric measures?
They need special hardware, scans can wrongly reject or accept, and the data is sensitive and cannot be changed if stolen.
Why are biometrics often used together with a password or PIN?
So that more than one factor is needed to authenticate, which makes unauthorised access harder.

Tap any card to flip it, or use Study as deck to go through them one at a time. In the full lesson these run as a spaced-repetition deck — you rate each card Hard, Good or Easy and the tricky ones keep coming back until they stick.

Learning with Lightbulb is opening soon

You can use this lesson now. Join the waitlist and we'll let you know when the full Lightbulb experience is ready.

Keep me posted

More AQA GCSE Computer Science topics

See the full AQA Computer Science curriculum →

How this lesson was checked. This AQA GCSE Computer Science (specification 8525)lesson was published through Lightbulb Learning's human-designed editorial process — the educational standards, accuracy rules and publication checks it must pass were authored and approved by Philip Halpin. It passed subject-specific assessment, automated educational checks and technical publication verification before going live (publication checks completed 9 October 2026). Published pages are monitored, human spot-checking is ongoing across the lesson library, and anything found wrong is corrected or withdrawn. How our lessons are made and checked. Spotted a mistake? Email hello@lightbulblearning.co and we'll review it.