Marina Blanton, Mehrdad Aliasgari
2011.7.18Proceedings of the International Conference on Security and Cryptography
tlooto Summary
This work proposes for each user to store one short secret string for all possible uses of her biometric, and shows that simple constructions in the computational setting have numerous security and usability advantages under standard hardness assumptions.
Abstract
Secure sketches and fuzzy extractors enable the use of biometric data in cryptographic applications by correcting errors in noisy biometric readings and producing cryptographic materials suitable for many applications. Such constructions work by producing a public sketch, which is later used to reproduce the original biometric and all derived information exactly from a noisy biometric reading. It has been previously shown that release of multiple sketches associated with a single biometric presents security problems for certain constructions. Through novel analysis we demonstrate that all other constructions in the literature are also prone to similar problems, which hinders their adoption in practice. To mitigate the problem, we propose for each user to store one short secret string for all possible uses of her biometric, and show that simple constructions in the computational setting have numerous security and usability advantages under standard hardness assumptions. Our constructions are generic in that they can be used with any existing secure sketch as a black box.
Citation format
BLANTON, Marina; ALIASGARI, Mehrdad. On the (non-)reusability of fuzzy sketches and extractors and security in the computational setting. Proceedings of the International Conference on Security and Cryptography, 2011: 68–77.