Uncoupling Biometrics from Templates for Secure and Privacy-Preserving Authentication

被引:2
|
作者
Abidin, Aysajan [1 ]
Rua, Enrique Argones [1 ]
Peeters, Roel [1 ]
机构
[1] Katholieke Univ Leuven, IMEC, COSIC, Leuven, Belgium
来源
PROCEEDINGS OF THE 22ND ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES (SACMAT'17) | 2017年
关键词
Biometrics; multi-factor authentication; template protection; unlinkability; irreversibility; PROTECTION; SCHEME;
D O I
10.1145/3078861.3078863
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Biometrics are widely used for authentication in several domains, services and applications. However, only very few systems succeed in effectively combining highly secure user authentication with an adequate privacy protection of the biometric templates, due to the difficulty associated with jointly providing good authentication performance, unlinkability and irreversibility to biometric templates. This thwarts the use of biometrics in remote authentication scenarios, despite the advantages that this kind of architectures provides. We propose a user-specific approach for decoupling the biometrics from their binary representation before using biometric protection schemes based on fuzzy extractors. This allows for more reliable, flexible, irreversible and unlinkable protected biometric templates. With the proposed biometrics decoupling procedures, biometric metadata, that does not allow to recover the original biometric template, is generated. However, different biometric metadata that are generated starting from the same biometric template remain statistically linkable, therefore we propose to additionally protect these using a second authentication factor (e.g., knowledge or possession based). We demonstrate the potential of this approach within a two-factor authentication protocol for remote biometric authentication in mobile scenarios.
引用
收藏
页码:21 / 29
页数:9
相关论文
共 50 条
  • [31] A novel ECC-based provably secure and privacy-preserving multi-factor authentication protocol for cloud computing
    Shivangi Shukla
    Sankita J. Patel
    Computing, 2022, 104 : 1173 - 1202
  • [32] Privacy-Preserving Universal Authentication Protocol for Wireless Communications
    He, Daojing
    Bu, Jiajun
    Chan, Sammy
    Chen, Chun
    Yin, Mingjian
    IEEE TRANSACTIONS ON WIRELESS COMMUNICATIONS, 2011, 10 (02) : 431 - 436
  • [33] Privacy-Preserving Authentication Based on Group Signature for VANETs
    Zhu, Xiaoyan
    Jiang, Shunrong
    Wang, Liangmin
    Li, Hui
    Zhang, Weidong
    Li, Zan
    2013 IEEE GLOBAL COMMUNICATIONS CONFERENCE (GLOBECOM), 2013, : 4609 - 4614
  • [34] Efficient Privacy-Preserving Authentication in Wireless Mobile Networks
    Jo, Hyo Jin
    Paik, Jung Ha
    Lee, Dong Hoon
    IEEE TRANSACTIONS ON MOBILE COMPUTING, 2014, 13 (07) : 1469 - 1481
  • [35] Information-theoretic privacy-preserving user authentication
    Kazempour, Narges
    Mirmohseni, Mahtab
    Aref, Mohammad Reza
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2025, 24 (01)
  • [36] Attacks and Countermeasures on Privacy-Preserving Biometric Authentication Schemes
    Wu, Yongdong
    Weng, Jian
    Wang, Zhengxia
    Wei, Kaimin
    Wen, Jinming
    Lai, Junzuo
    Li, Xin
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (02) : 1744 - 1755
  • [37] A novel ECC-based provably secure and privacy-preserving multi-factor authentication protocol for cloud computing
    Shukla, Shivangi
    Patel, Sankita J.
    COMPUTING, 2022, 104 (05) : 1173 - 1202
  • [38] Physically Secure and Privacy-Preserving Charging Authentication Framework With Data Aggregation in Vehicle-to-Grid Networks
    Liang, Yangfan
    Liu, Yining
    Zhang, Xianchao
    Liu, Gao
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2024, 25 (11) : 18831 - 18846
  • [39] XAuth: Secure and Privacy-Preserving Cross-Domain Handover Authentication for 5G HetNets
    Wang, Mingjun
    Zhao, Dongsheng
    Yan, Zheng
    Wang, Haiguang
    Li, Tieyan
    IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (07) : 5962 - 5976
  • [40] Privacy Preserving Biometrics-Based and User Centric Authentication Protocol
    Gunasinghe, Hasini
    Bertino, Elisa
    NETWORK AND SYSTEM SECURITY, 2014, 8792 : 389 - 408