首页> 外文期刊>Computers & Security >Comments on biometric-based non-transferable credentials and their application in blockchain-based identity management
【24h】

Comments on biometric-based non-transferable credentials and their application in blockchain-based identity management

机译:评论基于生物识别的不可转让凭据及其在基于区块链的身份管理中的应用程序

获取原文
获取原文并翻译 | 示例
           

摘要

In IT-ecosystems, access to unauthorized parties is prevented with credential-based access control techniques (locks, RFID cards, biometrics, etc.). Some of these methods are ineffective against malicious users who lend their credentials to other users. To obtain non-transferability, Adams proposed a combination of biometrics encapsulated in Pedersen commitment with Brands digital credential. However, Adams' work does not consider the Zero Knowledge Proof-of Knowledge (ZKPoK) system for Double Discrete Logarithm Representation of the credential. Besides, biometrics is used directly, without employing any biometric cryptosystem to guarantee biometric privacy, thus Adams' work cannot be GDPR-compliant. In this paper, we construct the missing ZKPoK protocol for Adam's work and show its inefficiency. To overcome this limitation, we present a new biometric-based non-transferable credential scheme that maintains the efficiency of the underlying Brands credential. Secondly, we show the insecurity of the first biometric-based anonymous credential scheme designed by Blanton et al.. In this context, we present a brute-force attack against Blanton's biometric key generation algorithm implemented for fuzzy vault. Next, we integrate an Oblivious PRF (OPRF) protocol to solve the open problem in Blanton's work and improve its efficiency by replacing the underlying signature scheme with PS-signatures. Finally, we evaluate application scenarios for non-transferable digital/anonymous credentials in the context of Blockchain-based Identity Management (BBIM). We show that our modified constructions preserve biometric privacy and efficiency, and can easily be integrated into current BBIM systems built upon efficient Brands and PS-credentials.
机译:在IT-ECOSYSTEMS中,通过基于凭据的访问控制技术(锁,RFID卡,生物识别技术等)防止访问未经授权的各方。这些方法中的一些对恶意用户对其他用户归还凭证的恶意用户来说无效。为了获得不可转换性,亚当斯提出了封装在Pedersen与品牌数字凭证的承诺中的生物识别性的组合。但是,亚当斯的工作不考虑凭证的双离散对数表示的零知识知识(ZKPOK)系统。此外,Biometrics直接使用,无需使用任何生物识别密码系统来保证生物识别隐私,因此亚当斯的工作不能符合GDPR。在本文中,我们构建了亚当的工作缺失的ZKPOK协议,并效率低下。为了克服这一限制,我们提出了一种新的基于生物识别的不可转让凭证方案,可以维持底层品牌凭证的效率。其次,我们展示了Blanton等人设计的第一个基于生物识别的匿名凭证方案的不安全性。在这种情况下,我们为Blanton的生物识别密钥生成算法提出了一个蛮力攻击,用于为模糊拱顶实现。接下来,我们整合了一项令人沮丧的PRF(OPRF)协议,以解决布兰顿工作中的开放问题,并通过用PS-Signatores替换潜在的签名方案来提高其效率。最后,我们在基于区块链的身份管理(BBIM)的上下文中评估不可转让的数字/匿名凭证的应用方案。我们表明,我们的修改结构保留了生物识别隐私和效率,并且可以轻松集成到现有的BBIM系统,建立在高效的品牌和PS凭据上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号