Skip to main content
QUICK REVIEW

[论文解读] On the Reliability of Cancelable Biometrics: Revisit the Irreversibility

Xingbo Dong, Zhe Jin|arXiv (Cornell University)|Oct 17, 2019
Biometric Identification and Security参考文献 22被引用 5
一句话总结

本文研究了可撤销生物识别系统的不可逆性,揭示了在 Kerckhoffs 假设下,变换模板中的距离相关性使得基于相似性的攻击成为可能。本文提出了一种通过互信息衡量信息泄露的框架,表明在人脸、虹膜和指纹系统中,完全不可逆性在理论上无法实现,因此必须在安全性和性能之间进行权衡。

ABSTRACT

Over the years, many biometric template protection schemes, primarily based on the notion of have been proposed. A cancelable biometric algorithm needs to satisfy four biometric template protection criteria, i.e., irreversibility, revocability, unlinkability, and performance preservation. However, a systematic analysis of irreversibility has been often neglected. In this paper, the common distance correlation characteristic of cancelable biometrics is analyzed. Next, a similarity-based attack is formulated to break the irreversibility of cancelable biometric under the Kerckhoffs's assumption where the cancelable biometrics algorithm and parameter are known to the attackers. The irreversibility based on the mutual information is also redefined, and a framework to measure the information leakage from the distance correlation characteristic is proposed. The results achieved on face, iris, and fingerprint prove that it is theoretically hard to meet full irreversibility. To have a good biometric system, a balance has to be achieved between accuracy and security.

研究动机与目标

  • 为解决可撤销生物识别模板保护方案中不可逆性缺乏系统性分析的问题。
  • 研究在 Kerckhoffs 假设下,已知的可撤销生物识别算法是否可通过基于相似性的攻击实现逆向还原。
  • 利用互信息重新定义不可逆性,并量化由距离相关性引起的信息泄露。
  • 评估在不同生物识别模态(人脸、虹膜、指纹)中实现完全不可逆性的理论可行性。

提出的方法

  • 分析可撤销生物识别模板中普遍存在的距离相关性特征,以识别可被利用的模式。
  • 构建一种基于相似性的攻击方法,利用已知的算法和参数来重建原始生物识别特征。
  • 利用互信息重新定义不可逆性,以量化由距离相关性引起的信息泄露。
  • 提出一种测量框架,以评估可撤销生物识别系统中信息泄露的程度。
  • 在真实世界的人脸、虹膜和指纹生物识别数据集上评估该框架,以验证理论发现。

实验结果

研究问题

  • RQ1当算法和参数公开时,基于相似性的攻击是否能够破坏可撤销生物识别系统的不可逆性?
  • RQ2变换后的生物识别模板中的距离相关性在多大程度上泄露了原始生物识别数据的信息?
  • RQ3如何利用互信息重新定义不可逆性,以更好地反映实际的安全保障?
  • RQ4在不同生物识别模态中,可撤销生物识别系统的不可逆性理论极限是什么?

主要发现

  • 可撤销生物识别模板中的距离相关性特征使得在 Kerckhoffs 假设下基于相似性的攻击具有有效性。
  • 由于通过距离相关性残留的信息泄露,可撤销生物识别系统中的完全不可逆性在理论上无法实现。
  • 所提出的基于互信息的框架成功量化了信息泄露,表明存在可测量的安全风险。
  • 在人脸、虹膜和指纹数据集上的实证结果证实,若不牺牲系统性能,则无法完全实现不可逆性。
  • 系统准确率与安全性之间存在根本性权衡,因此在生物识别模板保护设计中必须谨慎权衡选择。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。