[论文解读] Decodability Attack against the Fuzzy Commitment Scheme with Public Feature Transforms
本文表明,Kelkboom 等人提出的公开置换对策在防止模糊承诺方案中二值特征向量的可解码攻击方面无效,且当受保护模板的汉明距离较低时,甚至可能引发广义可解码攻击。作者证明,在基于线性码的二值方案中,任何保持距离的变换都无法完全防止此类攻击,并提出在非二值情况下使用改进的模糊保险箱方案结合域置换,以实现不可链接性。
The fuzzy commitment scheme is a cryptographic primitive that can be used to store biometric templates being encoded as fixed-length feature vectors protected. If multiple related records generated from the same biometric instance can be intercepted, their correspondence can be determined using the decodability attack. In 2011, Kelkboom et al. proposed to pass the feature vectors through a record-specific but public permutation process in order to prevent this attack. In this paper, it is shown that this countermeasure enables another attack also analyzed by Simoens et al. in 2009 which can even ease an adversary to fully break two related records. The attack may only be feasible if the protected feature vectors have a reasonably small Hamming distance; yet, implementations and security analyses must account for this risk. This paper furthermore discusses that by means of a public transformation, the attack cannot be prevented in a binary fuzzy commitment scheme based on linear codes. Fortunately, such transformations can be generated for the non-binary case. In order to still be able to protect binary feature vectors, one may consider to use the improved fuzzy vault scheme by Dodis et al. which may be secured against linkability attacks using observations made by Merkle and Tams.
研究动机与目标
- 分析在受保护的生物特征模板遭受记录多重性攻击时,模糊承诺方案的安全性。
- 研究 Kelkboom 等人提出的公开置换对策在防止基于可解码的跨匹配攻击方面的有效性。
- 确定保持距离的公开变换是否能防止基于线性码的二值模糊承诺方案中的可解码攻击。
- 提出一种使用改进的模糊保险箱方案结合记录特定域置换来保护二值生物特征模板的安全替代方法。
- 评估在不依赖密钥的情况下实现生物特征模板保护不可链接性的可行性。
提出的方法
- 分析 S. Simoens 等人描述的可解码攻击及其广义变体在模糊承诺方案背景下的应用。
- 评估 Kelkboom 等人提出的对策,即对生物特征向量应用公开的、记录特定的位置换。
- 证明当相关模板之间的汉明距离较低时,该对策无法防止通过广义可解码攻击恢复模板。
- 证明基于线性码的二值模糊承诺方案中,任何保持距离的变换类都无法防止可解码攻击。
- 提出一种使用非二值模糊承诺方案中公开域置换的改进对策,以抵御广义可解码攻击。
- 建议采用 Dodis 等人提出的改进模糊保险箱方案,并结合记录特定的域置换,作为二值特征向量的可行且不可链接的替代方案。
实验结果
研究问题
- RQ1Kelkboom 等人提出的公开置换对策是否能有效防止模糊承诺方案中的可解码攻击?
- RQ2在使用公开特征变换的情况下,广义可解码攻击在何种条件下仍具可行性?
- RQ3是否可以设计一种保持汉明距离的公开变换,同时防止二值模糊承诺方案中的链接攻击?
- RQ4结合公开域置换的改进模糊保险箱方案能否为二值生物特征模板提供不可链接性?
- RQ5在记录多重性攻击下,使用线性码保护二值生物特征模板在理论和实践上的局限性是什么?
主要发现
- 当受保护的特征向量汉明距离较小时,Kelkboom 等人提出的公开置换对策无法防止广义可解码攻击。
- 如果两个相关记录的汉明距离足够低,广义可解码攻击可完全恢复生物特征模板。
- 在基于线性码的二值模糊承诺方案中,任何保持距离的公开变换类都无法防止可解码攻击。
- 在非二值模糊承诺方案中,公开域置换可有效用于防止广义可解码攻击。
- 当结合记录特定的域置换时,Dodis 等人提出的改进模糊保险箱方案为保护二值生物特征模板提供了一种可行且不可链接的替代方案。
- 除非对模板相似性做出强假设,否则基于线性码的二值模糊承诺方案在链接攻击下仍存在根本性安全漏洞。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。