Privacy-Preserving Biometric Authentication: Cryptanalysis and Countermeasures

被引:10
作者
Zhang, Hui [1 ]
Li, Xuejun [1 ]
Tan, Syh-Yuan [3 ]
Lee, Ming Jie [4 ]
Jin, Zhe [2 ]
机构
[1] Anhui Univ, Sch Comp Sci & Technol, Hefei 230093, Peoples R China
[2] Anhui Univ, Sch Artificial Intelligence, Hefei 230093, Peoples R China
[3] Newcastle Univ, Sch Comp, Newcastle Upon Tyne NE1 7RU, England
[4] Univ Tunku Abdul Rahman, Lee Kong Chian Fac Engn & Sci, Dept Internet Engn & Comp Sci, Kajang 43000, Malaysia
关键词
Biometrics (access control); Authentication; Protocols; Security; Physical unclonable function; Encryption; Resists; Privacy-preserving biometric authentication; cancelable biometrics; threshold predicate encryption; physical unclonable functions; CANCELABLE BIOMETRICS; USER AUTHENTICATION; PROTOCOL; SCHEME; PUF;
D O I
10.1109/TDSC.2023.3239611
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
In this article, we cryptanalyzed a Verifiable Threshold Predicate Encryption (VTPE) enabled Privacy-Preserving Biometric Authentication (PPBA) protocol reported in IEEE-TDSC and revealed discrepancies between its security claims and our security analysis. To be precise, the underlying authentication and key agreement scheme which is based on a challenge-response mechanism and watermark signal unsatisfactorily meets the following security scenario: (a) resistance to man-in-the-middle attacks, (b) biometric template protection, and (c) user anonymity and untraceability. To address these issues, we utilize Physical Unclonable Functions (PUF) to design a PUF driven Verifiable Threshold Predicate Encryption (PUF-VTPE) scheme and a secure PPBA protocol. The PUF-VTPE-based PPBA protocol equips with dual authentication using biometric and mobile device, which offers strong authenticity before establishing the session key. Simultaneously, the non-invertible property of PUF protects the biometric templates in the physical layer. The proposed storage-free mechanism that hides the challenge of device PUF in biometric template alleviates data leakage caused by storage challenges in PUF-based authentication protocols. Moreover, the experimental analysis suggests that the proposed PPBA protocol possesses ISO/IEC 24745 criteria of non-invertibility, unlinkability, and revocability. Additionally, the proposed PPBA protocol reduces the computational cost by about 50% compared to that of the cryptanalyzed scheme.
引用
收藏
页码:5056 / 5069
页数:14
相关论文
共 34 条
[1]  
Abdalla M, 2005, LECT NOTES COMPUT SC, V3386, P65
[2]   GREYC-Hashing: Combining biometrics and secret for enhancing the security of protected templates [J].
Atighehchi, Kevin ;
Ghammam, Loubna ;
Barbier, Morgan ;
Rosenberger, Christophe .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2019, 101 :819-830
[3]   Biometric Template Protection for Dynamic Touch Gestures Based on Fuzzy Commitment Scheme and Deep Learning [J].
Bajaber, Asrar ;
Elrefaei, Lamiaa .
MATHEMATICS, 2022, 10 (03)
[4]   Bio-AKA: An efficient fingerprint based two factor user authentication and key agreement scheme [J].
Bian, Weixin ;
Gope, Prosanta ;
Cheng, Yongqiang ;
Li, Qingde .
FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 109 :45-55
[5]   3PAA: A Private PUF Protocol for Anonymous Authentication [J].
Chaterjee, Urbi ;
Mukhopadhyay, Debdeep ;
Chakraborty, Rajat Subhra .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 (16) :756-769
[6]  
Dong XB, 2020, Arxiv, DOI arXiv:1910.07770
[7]   Open-set face identification with index-of-max hashing by learning [J].
Dong, Xingbo ;
Kim, Soohyung ;
Jin, Zhe ;
Hwang, Jung Yeon ;
Cho, Sangrae ;
Teoh, Andrew Beng Jin .
PATTERN RECOGNITION, 2020, 103
[8]   A Genetic Algorithm Enabled Similarity-Based Attack on Cancellable Biometrics [J].
Dong, Xingbo ;
Jin, Zhe ;
Jin, Andrew Teoh Beng .
2019 IEEE 10TH INTERNATIONAL CONFERENCE ON BIOMETRICS THEORY, APPLICATIONS AND SYSTEMS (BTAS), 2019,
[9]   A Cryptanalysis of Two Cancelable Biometric Schemes Based on Index-of-Max Hashing [J].
Ghammam, Loubna ;
Karabina, Koray ;
Lacharme, Patrick ;
Thiry-Atighehchi, Kevin .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 :2869-2880
[10]   General Framework to Evaluate Unlinkability in Biometric Template Protection Systems [J].
Gomez-Barrero, Marta ;
Galbally, Javier ;
Rathgeb, Christian ;
Busch, Christoph .
IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2018, 13 (06) :1406-1420