Privacy Protection in Distributed Fingerprint-based Authentication

11/01/2019
by   Swe Geng, et al.
0

Biometric authentication is getting increasingly popular due to the convenience of using unique individual traits, such as fingerprints, palm veins, irises. Especially fingerprints are widely used nowadays due to the availability and low cost of fingerprint scanners. To avoid identity theft or impersonation, fingerprint data is typically stored locally, e.g., in a trusted hardware module, in a single device that is used for user enrollment and authentication. Local storage, however, limits the ability to implement distributed applications, in which users can enroll their fingerprint once and use it to access multiple physical locations and mobile applications afterwards. In this paper, we present a distributed authentication system that stores fingerprint data in a server or cloud infrastructure in a privacy-preserving way. Multiple devices can be connected and perform user enrollment or verification. To secure the privacy and integrity of sensitive data, we employ a cryptographic construct called fuzzy vault. We highlight challenges in implementing fuzzy vault-based authentication, for which we propose and compare alternative solutions. We conduct a security analysis of our biometric cryptosystem, and as a proof of concept, we build an authentication system for access control using resource-constrained devices (Raspberry Pis) connected to fingerprint scanners and the Microsoft Azure cloud environment. Furthermore, we evaluate the fingerprint matching algorithm against the well-known FVC2006 database and show that it can achieve comparable accuracy to widely-used matching techniques that are not designed for privacy, while remaining efficient with an authentication time of few seconds.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/18/2018

Security Vulnerabilities Against Fingerprint Biometric System

The biometric system is an automatic identification and authentication s...
research
06/12/2017

Portable Trust: biometric-based authentication and blockchain storage for self-sovereign identity systems

We devised a mobile biometric-based authentication system only relying o...
research
05/27/2022

Locally Authenticated Privacy-preserving Voice Input

Increasing use of our biometrics (e.g., fingerprints, faces, or voices) ...
research
04/26/2018

In-field Remote Fingerprint Authentication using Human Body Communication and On-Hub Analytics

In this emerging data-driven world, secure and ubiquitous authentication...
research
11/25/2020

Stay Connected, Leave no Trace: Enhancing Security and Privacy in WiFi via Obfuscating Radiometric Fingerprints

The intrinsic hardware imperfection of WiFi chipsets manifests itself in...
research
02/14/2020

MAGNETO: Fingerprinting USB Flash Drives via Unintentional Magnetic Emissions

Universal Serial Bus (USB) Flash Drives are nowadays one of the most con...
research
12/21/2022

Secure and Privacy Preserving Proxy Biometrics Identities

With large-scale adaption to biometric based applications, security and ...

Please sign up or login with your details

Forgot password? Click here to reset