首页> 外文会议>ACM multimedia and security workshop >Multi-Factor Biometrics for Authentication: A False Sense of Security
【24h】

Multi-Factor Biometrics for Authentication: A False Sense of Security

机译:用于认证的多因素生物识别方法:虚假的安全感

获取原文

摘要

Multi-factor biometric authentications have been proposed recently to strengthen security and/or privacy of biometric systems in addition to enhancing authentication accuracy. An important approach to multi-factor biometric authentication is to apply User-Based Transformations (UBTs) on biometric features. Typically, UBTs rely on generating user-based transformation keys from a password/PIN or retrieved from a token. One significant advantage of employing UBTs is its ability to achieve zero or near zero Equal Error Rate (EER) i.e. a clear separation of genuine and imposter distributions. However, the effect of compromised transformation keys on authentication accuracy has not been tested rigorously. In this paper, we challenge the myth that has been reported in the literature that in the case of stolen transformation key(s), accuracy drops but remains close to the accuracy of biometric only system. Moreover, we shall show that a multi-factor authentication system setup to operate at a zero EER has a serious security lapse in the event of stolen or compromised keys. In such a scenario, the False Acceptance Rate (FAR) of the system reaches unacceptable levels. We shall demonstrate this by experiments conducted on face and fingerprint biometrics, and show that an imposter with a stolen key needs no more than two attempts on average to be falsely accepted by the biometric system.
机译:最近已经提出了多因素生物识别认证,以加强生物识别系统的安全性和/或隐私,以及提高认证准确性。多因素生物认证的重要方法是在生物识别特征上应用基于用户的转换(UBT)。通常,UBT依赖于从密码/引脚生成基于用户的转换键,或者从令牌中检索。使用UBT的一个显着优点是它能够实现零或接近零的零错误率(eer)即正品和冒砂分布的清晰分离。然而,损害的转化键对认证精度的影响尚未经过严格测试。在本文中,我们挑战了在文献中报告的神话,即在被盗的转换密钥的情况下,精度下降但仍然靠近生物识别的精度。此外,我们将表明,在零EER处运行的多因素身份验证系统设置在被盗或受损的键时具有严重的安全流逝。在这种情况下,系统的错误接受率(远)达到不可接受的水平。我们将通过在面部和指纹生物识别性上进行的实验来证明这一点,并表明具有被盗钥匙的冒险件不超过两次尝试,平均被生物识别系统被错误地接受。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号