Revisiting Fuzzy Signatures: Towards a More Risk-Free Cryptographic Authentication System based on Biometrics

12/16/2021
by   Shuichi Katsumata, et al.
0

Biometric authentication is one of the promising alternatives to standard password-based authentication offering better usability and security. In this work, we revisit the biometric authentication based on "fuzzy signatures" introduced by Takahashi et al. (ACNS'15, IJIS'19). These are special types of digital signatures where the secret signing key can be a "fuzzy" data such as user's biometrics. Compared to other cryptographically secure biometric authentications as those relying on fuzzy extractors, the fuzzy signature-based scheme provides a more attractive security guarantee. However, despite their potential values, fuzzy signatures have not attracted much attention owing to their theory-oriented presentations in all prior works. For instance, the discussion on the practical feasibility of the assumptions (such as the entropy of user biometrics), which the security of fuzzy signatures hinges on, is completely missing. In this work, we revisit fuzzy signatures and show that we can indeed efficiently and securely implement them in practice. At a high level, our contribution is threefold: (i) we provide a much simpler, more efficient, and direct construction of fuzzy signature compared to prior works; (ii) we establish novel statistical techniques to experimentally evaluate the conditions on biometrics that are required to securely instantiate fuzzy signatures; and (iii) we provide experimental results using a real-world finger-vein dataset to show that finger-veins from a single hand are sufficient to construct efficient and secure fuzzy signatures. Our performance analysis shows that in a practical scenario with 112-bits of security, the size of the signature is 1256 bytes, and the running time for signing/verification is only a few milliseconds.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
01/17/2023

Multi-Biometric Fuzzy Vault based on Face and Fingerprints

The fuzzy vault scheme has been established as cryptographic primitive s...
research
08/18/2014

Offline Signature-Based Fuzzy Vault (OSFV: Review and New Results

An offline signature-based fuzzy vault (OSFV) is a bio-cryptographic imp...
research
08/22/2007

The Fuzzy Vault for fingerprints is Vulnerable to Brute Force Attack

The fuzzy vault approach is one of the best studied and well accepted id...
research
01/26/2019

A Linear-complexity Multi-biometric Forensic Document Analysis System, by Fusing the Stylome and Signature Modalities

Forensic Document Analysis (FDA) addresses the problem of finding the au...
research
08/10/2010

Biometric Authentication using Nonparametric Methods

The physiological and behavioral trait is employed to develop biometric ...
research
04/14/2020

Topology-Aware Hashing for Effective Control Flow Graph Similarity Analysis

Control Flow Graph (CFG) similarity analysis is an essential technique f...
research
09/04/2017

Lattice Operations on Terms over Similar Signatures

Unification and generalization are operations on two terms computing res...

Please sign up or login with your details

Forgot password? Click here to reset