Privacy Preserving Biometric Authentication on the blockchain for smart healthcare

被引:6
|
作者
Sarier, Neyire Deniz [1 ]
机构
[1] Cose, B It, Friedrich Hirzebruch Alle 6, D-53115 Bonn, Germany
关键词
Privacy Preserving Biometric; Authentication (PPBA); Smart healthcare; Blockchain; Monero; Hill climbing attacks; Low-entropy; Identity privacy; Public Key Cryptography (PKC); Zero Knowledge Proofs (ZKP); GDPR; IPFS;
D O I
10.1016/j.pmcj.2022.101683
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Privacy Preserving Biometric Authentication (PPBA) schemes are designed for anonymous authentication of patients to protect patient's privacy in accessing healthcare services. Recently, blockchain technology in healthcare has emerged as a new research area to provide tamper-resistance and non-repudiation in e-health systems. One aspect of this research could lead to blockchain-based secure biometric identification for smart healthcare, which may face the paradox of anonymous biometric authentication on public blockchains. In this paper, we describe an efficient, fully anonymous and GDPR-compliant PPBA protocol built into the blockchain of any privacy coin such as Monero. The new protocol provides encrypted offline storage and processing in the encrypted domain. The infrastructure necessary for the online authentication is outsourced to the public blockchain that provides integrity of its data. In addition to auditing capabilities for misbehaving entities, the new system reduces the number of transactions necessary for authentication and enables revocation of biometric identities. We provide new PPBA schemes both for set difference/overlap and Euclidean distance metrics without using bilinear pairings, where the former leads to an efficient solution to the compatibility for organ transplant. We limit the generation of encrypted templates for public testing even if biometric/health data is of low min-entropy. Due to the anonymity of the cryptocurrency, we break the link between the stealth address of an authenticating user and its biometrics. We describe the user and identity privacy notions independent of the underlying privacy coin and guarantee the security of our proposal in the framework of those generic notions. Finally, we simulate the new proposal on Monero blockchain and analyze the transaction fees required for hill climbing attacks. The results show that our design leads to a natural hindrance against these attacks that could be successful even if the templates are stored as encrypted. To the best of our knowledge, this is the first efficient blockchain-based PPBA scheme that exhibits a punishment against hill climbing attacks through transaction fees. (C) 2022 Elsevier B.V. All rights reserved.
引用
收藏
页数:19
相关论文
共 50 条
  • [1] Identity Privacy Preserving Biometric Based Authentication Scheme for Naked Healthcare Environment
    Kumar, Tanesh
    Braeken, An
    Liyanage, Madhusanka
    Ylianttila, Mika
    [J]. 2017 IEEE INTERNATIONAL CONFERENCE ON COMMUNICATIONS (ICC), 2017,
  • [2] A Novel Biometric Authentication Scheme with Privacy Preserving
    Yang, Dexin
    Xu, Baolin
    Yang, Bo
    Wang, Jianping
    [J]. PROCEEDINGS OF THE 2012 EIGHTH INTERNATIONAL CONFERENCE ON COMPUTATIONAL INTELLIGENCE AND SECURITY (CIS 2012), 2012, : 452 - 456
  • [3] Privacy Preserving Multimodal Biometric Authentication in the Cloud
    Sarier, Neyire Deniz
    [J]. GREEN, PERVASIVE, AND CLOUD COMPUTING (GPC 2017), 2017, 10232 : 90 - 104
  • [4] Privacy Preserving Biometric Authentication for Fingerprints and Beyond
    Blanton, Marina
    Murphy, Dennis
    [J]. PROCEEDINGS OF THE FOURTEENTH ACM CONFERENCE ON DATA AND APPLICATION SECURITY AND PRIVACY, CODASPY 2024, 2024, : 367 - 378
  • [5] Privacy-Preserving Blockchain-Based Authentication in Smart Energy Systems
    Vangala, Anusha
    Das, Ashok Kumar
    [J]. PROCEEDINGS OF THE TWENTIETH ACM CONFERENCE ON EMBEDDED NETWORKED SENSOR SYSTEMS, SENSYS 2022, 2022, : 1208 - 1214
  • [6] RETRACTED: Biometric Authentication for Intelligent and Privacy-Preserving Healthcare Systems (Retracted Article)
    Nigam, Dhananjay
    Patel, Shilp Nirajbhai
    Vincent, P. M. Durai Raj
    Srinivasan, Kathiravan
    Arunmozhi, Sinouvassane
    [J]. JOURNAL OF HEALTHCARE ENGINEERING, 2022, 2022
  • [7] Privacy Preserving Biometric-based User Authentication Protocol using Smart Cards
    Park, Minsu
    Kim, Hyunsung
    Lee, Sung-Woon
    [J]. 2014 IEEE 17TH INTERNATIONAL CONFERENCE ON COMPUTATIONAL SCIENCE AND ENGINEERING (CSE), 2014, : 1541 - 1544
  • [8] Towards A Transparent and Privacy-preserving Healthcare Platform with Blockchain for Smart Cities
    Al Omar, Abdullah
    Jamil, Abu Kaisar
    Nur, Md Shakhawath Hossain
    Hasan, Md Mahamudul
    Bosri, Rabeya
    Bhuiyan, Md Zakirul Alam
    Rahman, Mohammad Shahriar
    [J]. 2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1292 - 1297
  • [9] Efficient privacy-preserving authentication protocol using PUFs with blockchain smart contracts
    Patil, Akash Suresh
    Hamza, Rafik
    Hassan, Alzubair
    Jiang, Nan
    Yan, Hongyang
    Li, Jin
    [J]. COMPUTERS & SECURITY, 2020, 97 (97)
  • [10] Cryptanalysis of Two Privacy-Preserving Authentication Schemes for Smart Healthcare Applications
    Xu, Feihong
    Luo, Junwei
    Ziaur, Rahman
    [J]. MATHEMATICS, 2023, 11 (15)