On Security of Fuzzy Commitment Scheme for Biometric Authentication

被引:1
|
作者
Chang, Donghoon [1 ,2 ]
Garg, Surabhi [1 ,3 ]
Hasan, Munawar [1 ,2 ,5 ]
Mishra, Sweta [4 ]
机构
[1] IIIT Delhi, New Delhi, India
[2] NIST, Gaithersburg, MD 20899 USA
[3] TCS Res, Chennai, Tamil Nadu, India
[4] Shiv Nadar Univ, Kalavakkam, India
[5] Irisys Co Ltd, Seoul, South Korea
关键词
Fuzzy commitment; Error correcting codes; Bit padding; Biometric security; Authentication; BCH Codes; CRYPTOSYSTEM; PRIVACY;
D O I
10.1007/978-3-031-22301-3_20
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Biometric security is a prominent research area with growing privacy and security concerns related to biometric data, generally known as biometric templates. Among the recently proposed biometric template protection schemes, fuzzy commitment is the most popular and reliable. It uses error correcting codes to deal with the significant number of bit errors present in the biometric templates. The high error correcting capability of the underlying error correcting codes is crucial to achieving the desired recognition performance in the biometric system. In general, it is satisfied by padding the input biometric template with some additional bits. The fixed padding approaches proposed in the literature have security vulnerabilities that could disclose the user's biometric data to the attacker, leading to an impersonation attack. We propose a user-specific, random padding scheme that preserves the recognition performance of the system while it prevents the impersonation attack. The empirical results show that the proposed scheme provides 3 times better recognition performance on the IIT Delhi iris database than the baseline, unprotected systems. Through security analysis, we show that the attack complexity of our proposed work is 2(k), where k is the length of the secret message used to generate codeword, with k >= 128 bits.
引用
收藏
页码:399 / 419
页数:21
相关论文
共 50 条
  • [1] Biometric Cryptosystems based Fuzzy Commitment Scheme: A Security Evaluation
    Lafkih, Maryam
    Mikram, Mounia
    Ghouzali, Sanaa
    El Haziti, Mohamed
    Aboutajdine, Driss
    [J]. INTERNATIONAL ARAB JOURNAL OF INFORMATION TECHNOLOGY, 2016, 13 (04) : 443 - 449
  • [2] Gait authentication on mobile phone using biometric cryptosystem and fuzzy commitment scheme
    Thang Hoang
    Deokjai Choi
    Thuc Nguyen
    [J]. International Journal of Information Security, 2015, 14 : 549 - 560
  • [3] Gait authentication on mobile phone using biometric cryptosystem and fuzzy commitment scheme
    Hoang, Thang
    Choi, Deokjai
    Thuc Nguyen
    [J]. INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2015, 14 (06) : 549 - 560
  • [4] Euclidean-Distance Based Fuzzy Commitment Scheme for Biometric Template Security
    Gilkalaye, Babak Poorebrahim
    Rattani, Ajita
    Derakhshani, Reza
    [J]. 2019 7TH INTERNATIONAL WORKSHOP ON BIOMETRICS AND FORENSICS (IWBF), 2019,
  • [5] Security Authentication Method of Speech Perceptual Hashing Based on Fuzzy Commitment Scheme
    Zhang Qiu-yu
    Ren Zhan-wei
    Huang Yi-bo
    Yu Shuang
    Hu Wen-jin
    [J]. INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2016, 10 (01): : 229 - 240
  • [6] Security Improvement on Biometric Based Authentication Scheme for Wireless Sensor Networks Using Fuzzy Extraction
    Choi, Younsung
    Lee, Youngsook
    Won, Dongho
    [J]. INTERNATIONAL JOURNAL OF DISTRIBUTED SENSOR NETWORKS, 2016,
  • [7] Secure biometric template protection in fuzzy commitment scheme
    Teoh, Andrew Beng Jin
    Kim, Jaihie
    [J]. IEICE ELECTRONICS EXPRESS, 2007, 4 (23): : 724 - 730
  • [8] Biometric Based Signature Authentication Scheme for Cloud Healthcare Data Security
    Thangarasu, Gunasekar
    Dominic, P. D. D.
    Subramanian, Kayalvizhi
    Smiley, Sajitha
    [J]. RECENT TRENDS IN DATA SCIENCE AND SOFT COMPUTING, IRICT 2018, 2019, 843 : 557 - 565
  • [9] Security analysis and enhancements of a multi-factor biometric authentication scheme
    Wu, Min
    Chen, Jianhua
    Zhu, Wenxia
    Yuan, Zhenyang
    [J]. INTERNATIONAL JOURNAL OF ELECTRONIC SECURITY AND DIGITAL FORENSICS, 2016, 8 (04) : 352 - 365
  • [10] On the Security of Biometrics and Fuzzy Commitment Cryptosystems: A Study on Gait Authentication
    Van Hamme, Tim
    Rua, Enrique Argones
    Preuveneers, Davy
    Joosen, Wouter
    [J]. IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 5211 - 5224