| Privacy preserving multi-factor authentication with biometrics |
| Full text |
Pdf
(228 KB)
|
| Source
|
Conference on Computer and Communications Security
archive
Proceedings of the second ACM workshop on Digital identity management
table of contents
Alexandria, Virginia, USA
SESSION: Security, privacy and anonymity
table of contents
Pages: 63 - 72
Year of Publication: 2006
ISBN:1-59593-547-9
|
|
Authors
|
|
| Sponsors |
|
| Publisher |
|
| Bibliometrics |
Downloads (6 Weeks): 49, Downloads (12 Months): 357, Citation Count: 1
|
|
|
ABSTRACT
An emerging approach to the problem of reducing the identity theft is represented by the adoption of biometric authentication systems. Such systems however present however several challenges, related to privacy, reliability, security of the biometric data. Inter-operability is also required among the devices used for the authentication. Moreover, very often biometric authentication in itself is not sufficient as a conclusive proof of identity and has to be complemented with multiple other proofs of identity like passwords, SSN, or other user identifiers. Multi-factor authentication mechanisms are thus required to enforce strong authentication based on the biometric and identifiers of other nature.In this paper we provide a two-phase authentication mechanism for federated identity management systems. The first phase consists of a two-factor biometric authentication based on zero knowledge proofs. We employ techniques from vector-space model to generate cryptographic biometric keys. These keys are kept secret, thus preserving the confidentiality of the biometric data, and at the same time exploit the advantages of a biometric authentication. The second authentication combines several authentication factors in conjunction with the biometric to provide a strong authentication. A key advantage of our approach is that any unanticipated combination of factors can be used. Such authentication system leverages the information of the user that are available from the federated identity management system.
REFERENCES
Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.
 |
1
|
|
| |
2
|
A. Bhargav-Spantzel, A. Squicciarini, and E. Bertino. Establishing and protecting digital identity in federation systems. Journal of Computer Security, 13(3): 269--300, 2006.
|
| |
3
|
|
| |
4
|
|
| |
5
|
|
| |
6
|
|
| |
7
|
C. R. Costanzo. Biometric cryptography: Key generation using feature and parametric aggregation. Online Technical Report, 2004.
|
| |
8
|
I. Damgård and E. Fujisaki. An integer commitment scheme based on groups with hidden order. In Advances in Cryptology -- ASIACRYPT 2002, volume 2501. Springer, 2002.
|
| |
9
|
G. Davida, Y. Frankel, and B. Matt. The relation of error correction and cryptography to an offine biometric based identication scheme, 1999.
|
| |
10
|
Y. Dodis, R. Ostrovsky, L. Reyzin, and A. Smith. Fuzzy extractors: How to generate strong keys from biometrics and other noisy data. In Eurocrypt 2004, 2006.
|
| |
11
|
Identity-Management. Liberty alliance project. http://www.projectliberty.org.
|
 |
12
|
|
| |
13
|
Internet2. Shibboleth. http://shibboleth.internet2.edu.
|
| |
14
|
A. Jain, S. Prabhakar, L. Hong, and S. Pankanti. Filterbank-based fingerprint matching, 2000.
|
 |
15
|
|
| |
16
|
A. Juels and M. Wattenberg. A fuzzy vault scheme. In Proceedings of IEEE International Symposium on Information Theory, 2002., 2002.
|
| |
17
|
C. Mills. Biometrics: Back to security basics, rsa security, 2002.
|
| |
18
|
F. Monrose, M. Reiter, Q. Li, and S. Wetzel. Using voice to generate cryptographic keys. 2001.
|
| |
19
|
|
 |
20
|
|
 |
21
|
|
| |
22
|
U. Uludag, S. Pankanti, S. Prabhakar, and A. Jain. Biometric cryptosystems: Issues and challenges, 2004.
|
| |
23
|
I. M. R. VeriSign. Web Services Federation Language (WS-Federation). version 1.0. July 8 2003. http://www-128.ibm.com/developerworks/library/specification/ws-fed/.
|
 |
24
|
|
 |
25
|
|
| |
26
|
W. Zhang, Y.-J. Chang, and T. Chen. Optimal thresholding for key generation based on biometrics. In ICIP, pages 3451--3454, 2004.
|
|