[论文解读] Secure and Reliable Biometric Access Control for Resource-Constrained Systems and IoT
该论文提出BLOcKeR,一种基于PUF和硬件混淆的高效安全生物识别访问控制框架,适用于物联网和资源受限设备,通过消除持久的生物特征模板存储实现安全防护。通过集成噪声感知位分配(NA-IOMBA)用于心电图(ECG)密钥生成,该方法在压力/运动条件下实现密钥长度缩短56%、可靠性提升25%,同时将去噪和纠错开销降低62%,并保持高熵值及对物理攻击的强抵抗力。
With the emergence of the Internet-of-Things (IoT), there is a growing need for access control and data protection on low-power, pervasive devices. Biometric-based authentication is promising for IoT due to its convenient nature and lower susceptibility to attacks. However, the costs associated with biometric processing and template protection are nontrivial for smart cards, key fobs, and so forth. In this paper, we discuss the security, cost, and utility of biometric systems and develop two major frameworks for improving them. First, we introduce a new framework for implementing biometric systems based on physical unclonable functions (PUFs) and hardware obfuscation that, unlike traditional software approaches, does not require nonvolatile storage of a biometric template/key. Aside from reducing the risk of compromising the biometric, the nature of obfuscation also provides protection against access control circumvention via malware and fault injection. The PUF provides non-invertibility and non-linkability. Second, a major requirement of the proposed PUF/obfuscation approach is that a reliable (robust) key be generated from the users input biometric. We propose a noiseaware biometric quantization framework capable of generating unique, reliable keys with reduced enrollment time and denoising costs. Finally, we conduct several case studies. In the first, the proposed noise-aware approach is compared to our previous approach for multiple biometric modalities, including popular ones (fingerprint and iris) and emerging cardiovascular ones (ECG and PPG). The results show that ECG provides the best tradeoff between reliability, key length, entropy, and cost. In the second and third case studies, we demonstrate how reliability, denoising costs, and enrollment times can be simultaneously improved by modeling subject intra-variations for ECG.
研究动机与目标
- 解决资源受限物联网设备中生物识别认证的安全与效率挑战,特别是生物特征模板泄露风险和高处理成本。
- 通过基于硬件的不可克隆函数(PUFs)消除传统‘服务器端匹配’和‘卡片端匹配’系统中对生物特征模板的持久存储,克服其局限性。
- 开发一种低开销、高可靠的生物识别密钥生成方法,可适应用户内部变化(如压力、运动),尤其适用于ECG系统。
- 通过硬件混淆和基于PUF的不可逆密钥派生机制,提升系统对物理攻击(如故障注入、恶意软件)和侧信道攻击的抵抗能力。
- 在实际部署于低功耗设备时,优化生物识别系统中密钥可靠性、熵值、长度与计算成本之间的权衡。
提出的方法
- 提出BLOcKeR,一种新型框架,结合PUF、比特流混淆与可重构硬件,实现无需存储模板的不可逆、不可链接生物识别密钥生成。
- 利用物理不可克隆函数(PUFs)从生物特征输入派生密码学强密钥,确保不可逆性,并抵抗克隆或模板重建攻击。
- 提出噪声感知区间优化映射位分配(NA-IOMBA),一种动态位分配方案,用于建模由压力、运动和生理变化引起的心电信号变化。
- 通过引入动态模型,以缩放参数α、b和θ表示心电图形态变化(如振幅、间期、心率变化),实现在NA-IOMBA中自适应的容差优化。
- 通过利用可重构性,实现按用户动态调整预处理、特征提取与纠错开销,从而降低系统整体功耗与延迟。
- 在低功耗物联网设备中集成ECC(纠错编码),通过NA-IOMBA降低的开销支持密钥重建,实现39 mW的功耗。
实验结果
研究问题
- RQ1能否为物联网设备设计一种生物识别系统,实现持久生物特征模板存储的消除,同时保持强安全性和低资源消耗?
- RQ2如何对心电信号中的噪声和用户内变化(如压力、运动)进行建模与补偿,以提升密钥可靠性并降低去噪与纠错成本?
- RQ3动态心电图波形变化(如P波、QRS波、T波偏移)对生物识别密钥生成可靠性有何影响?能否通过自适应位分配加以缓解?
- RQ4噪声感知位分配(NA-IOMBA)在不牺牲密钥长度或熵值的前提下,能在多大程度上降低系统开销(去噪、纠错)?
- RQ5在‘设备端匹配’系统中,PUF与硬件混淆的集成如何增强对物理攻击(如故障注入、模板提取)的抵抗能力?
主要发现
- 采用NA-IOMBA的心电图生物识别系统在可靠性、密钥长度、熵值与成本之间的权衡上优于指纹、虹膜和PPG等模态。
- 与传统方法相比,NA-IOMBA将去噪与纠错开销降低了62%,且无需额外的注册测量。
- 在压力/运动条件下,NA-IOMBA相比标准IOMBA将密钥可靠性提升25%,T波最小可靠性为71.61%,P波为72.37%,QRS波为73.96%(在0.5缩放系数下)。
- 为实现此可靠性提升,NA-IOMBA将密钥长度缩短56%(平均降至420位),但仍足以满足大多数密码学应用需求。
- BLOcKeR框架功耗仅为39 mW,证明其在低功耗物联网设备中的可行性,并支持按用户粒度进行硬件级处理开销自适应。
- PUF与混淆机制的使用确保了密钥的不可逆性与不可链接性,使系统具备抵御模板重建、恶意软件与故障注入攻击的能力。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。