首页> 外文OA文献 >Secure and private fingerprint-based authentication
【2h】

Secure and private fingerprint-based authentication

机译:安全和专用的基于指纹的身份验证

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

This thesis studies the requirements and processes involved in building an authentication system using the fingerprint biometric, where the fingerprint template is protected during storage and during comparison. The principles developed in this thesis can be easily extended to authentication systems using other biometric modalities. Most existing biometric authentication systems store their template securely using an encryption function. However, in order to perform matching, the enrolled template must be decrypted. It is at this point that the authentication system is most vulnerable as the entire enrolled template is exposed. A biometric is irreplaceable if compromised and can also reveal sensitive information about an individual. If biometric systems are taken up widely, the template could also be used as an individual's digital identifier. Compromise in that case, violates an individual's right to privacy as their transactions in all systems where they used that compromised biometric can be tracked. Therefore securing a biometric template during comparison as well as storage in an authentication system is imperative. Eight different fingerprint template representation techniques, where templates were treated as a set of elements derived from the locations and orientations of fingerprint minutiae, were studied. Four main steps to build any biometric based authentication system were identified and each of the eight fingerprint template representations was inducted through the four steps. Two distinct Error Tolerant Cryptographic Constructs based on the set difference metric, were studied for their ability to securely store and compare each of the template types in an authentication system. The first construct was found to be unsuitable for a fundamental reason that would apply to all the template types considered in the research. The second construct did not have the limitation of the first and three algorithms to build authentication systems using the second construct were proposed. It was determined that minutiae-based templates had significant intra sample variation as a result of which a very relaxed matching threshold had to be set in the authentication system. The relaxed threshold caused the authentication systems built using the first two algorithms to reveal enough information about the stored templates to render them insecure. It was found that in cases of such large intra-sample variation, a commonality based match decision was more appropriate. One solution to building a secure authentication system using minutiae-based templates was demonstrated by the third algorithm which used a two stage matching process involving the second cryptographic construct and a commonality based similarity measure in the two stages respectively. This implementation was successful in securing the fingerprint template during comparison as well as storage, with minimal reduction in accuracy when compared to the matching performance without the cryptographic construct. Another solution is to use an efficient commonality based error tolerant cryptographic construct. This thesis lists the desirable characteristics of such a construct as existence of any is unknown to date. This thesis concludes by presenting good guidelines to evaluate the suitability of different cryptographic constructs to protect biometric templates of other modalities in an authentication system.
机译:本文研究了使用指纹生物识别技术构建身份验证系统的要求和过程,其中指纹模板在存储和比较期间受到保护。本文提出的原理可以很容易地扩展到使用其他生物识别方式的身份验证系统。大多数现有的生物特征认证系统都使用加密功能安全地存储其模板。但是,为了执行匹配,必须对注册的模板进行解密。此时,随着整个注册模板的公开,身份验证系统最容易受到攻击。如果受到威胁,生物特征是不可替代的,并且还可以揭示有关个人的敏感信息。如果生物识别系统被广泛采用,则该模板也可以用作个人的数字标识符。在那种情况下,妥协侵犯了个人的隐私权,因为可以追踪他们使用受损生物特征的所有系统中的交易。因此,在比较期间以及在认证系统中存储时确保生物特征模板是必不可少的。研究了八种不同的指纹模板表示技术,其中将模板视为一组源自指纹细节位置和方向的元素。确定了构建任何基于生物特征的身份验证系统的四个主要步骤,并且通过这四个步骤分别引入了八个指纹模板表示形式。研究了两种基于集合差异度量的不同的容错密码构造,​​它们在身份验证系统中安全地存储和比较每种模板类型的能力。发现第一个构建体由于适用于研究中考虑的所有模板类型的根本原因而不合适。第二种结构不受第一种结构的限制,提出了三种使用第二种结构构建认证系统的算法。确定基于细节的模板具有显着的样本内变异,因此必须在身份验证系统中设置非常宽松的匹配阈值。宽松的阈值使使用前两种算法构建的身份验证系统揭示了有关已存储模板的足够信息,从而使它们变得不安全。发现在如此大的样本内变化的情况下,基于共同性的匹配决策更为合适。第三种算法演示了一种使用基于细节的模板构建安全身份验证系统的解决方案,该算法分别使用了涉及第二个密码结构的两阶段匹配过程和两个阶段中基于通用性的相似性度量。与没有密码结构的匹配性能相比,此实现成功地在比较和存储过程中确保了指纹模板的安全,并且准确性降低得最少。另一解决方案是使用基于有效通用性的容错密码构造。本文列出了这种结构的理想特性,因为迄今为止尚不存在任何结构。本文的结论是通过提出好的指南来评估不同密码结构在保护身份验证系统中其他方式的生物特征模板的适用性。

著录项

  • 作者

    Arakala A;

  • 作者单位
  • 年度 2008
  • 总页数
  • 原文格式 PDF
  • 正文语种
  • 中图分类

相似文献

  • 外文文献
  • 中文文献
  • 专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号