ACM Home Page
Please provide us with feedback. Feedback
Privacy preserving multi-factor authentication with biometrics
Full text PdfPdf (228 KB)
Source Conference on Computer and Communications Security archive
Proceedings of the second ACM workshop on Digital identity management table of contents
Alexandria, Virginia, USA
SESSION: Security, privacy and anonymity table of contents
Pages: 63 - 72  
Year of Publication: 2006
ISBN:1-59593-547-9
Authors
Abhilasha Bhargav-Spantzel  Purdue University, West Lafayette, IN
Anna Squicciarini  Purdue University, West Lafayette, IN
Elisa Bertino  Purdue University, West Lafayette, IN
Sponsors
ACM: Association for Computing Machinery
SIGSAC: ACM Special Interest Group on Security, Audit, and Control
Publisher
ACM  New York, NY, USA
Bibliometrics
Downloads (6 Weeks): 31,   Downloads (12 Months): 687,   Citation Count: 0
Additional Information:

abstract   references   index terms   collaborative colleagues  

Tools and Actions: Review this Article  
Save this Article to a Binder    Display Formats: BibTex  EndNote ACM Ref   
DOI Bookmark: Use this link to bookmark this Article: http://doi.acm.org/10.1145/1179529.1179540
What is a DOI?

ABSTRACT

An emerging approach to the problem of reducing the identity theft is represented by the adoption of biometric authentication systems. Such systems however present however several challenges, related to privacy, reliability, security of the biometric data. Inter-operability is also required among the devices used for the authentication. Moreover, very often biometric authentication in itself is not sufficient as a conclusive proof of identity and has to be complemented with multiple other proofs of identity like passwords, SSN, or other user identifiers. Multi-factor authentication mechanisms are thus required to enforce strong authentication based on the biometric and identifiers of other nature.In this paper we provide a two-phase authentication mechanism for federated identity management systems. The first phase consists of a two-factor biometric authentication based on zero knowledge proofs. We employ techniques from vector-space model to generate cryptographic biometric keys. These keys are kept secret, thus preserving the confidentiality of the biometric data, and at the same time exploit the advantages of a biometric authentication. The second authentication combines several authentication factors in conjunction with the biometric to provide a strong authentication. A key advantage of our approach is that any unanticipated combination of factors can be used. Such authentication system leverages the information of the user that are available from the federated identity management system.


REFERENCES

Note: OCR errors may be found in this Reference List extracted from the full text article. ACM has opted to expose the complete List rather than only correct and linked references.

1
 
2
A. Bhargav-Spantzel, A. Squicciarini, and E. Bertino. Establishing and protecting digital identity in federation systems. Journal of Computer Security, 13(3): 269--300, 2006.
 
3
 
4
 
5
 
6
 
7
C. R. Costanzo. Biometric cryptography: Key generation using feature and parametric aggregation. Online Technical Report, 2004.
 
8
I. Damgård and E. Fujisaki. An integer commitment scheme based on groups with hidden order. In Advances in Cryptology -- ASIACRYPT 2002, volume 2501. Springer, 2002.
 
9
G. Davida, Y. Frankel, and B. Matt. The relation of error correction and cryptography to an offine biometric based identication scheme, 1999.
 
10
Y. Dodis, R. Ostrovsky, L. Reyzin, and A. Smith. Fuzzy extractors: How to generate strong keys from biometrics and other noisy data. In Eurocrypt 2004, 2006.
 
11
Identity-Management. Liberty alliance project. http://www.projectliberty.org.
12
 
13
Internet2. Shibboleth. http://shibboleth.internet2.edu.
 
14
A. Jain, S. Prabhakar, L. Hong, and S. Pankanti. Filterbank-based fingerprint matching, 2000.
15
 
16
A. Juels and M. Wattenberg. A fuzzy vault scheme. In Proceedings of IEEE International Symposium on Information Theory, 2002., 2002.
 
17
C. Mills. Biometrics: Back to security basics, rsa security, 2002.
 
18
F. Monrose, M. Reiter, Q. Li, and S. Wetzel. Using voice to generate cryptographic keys. 2001.
 
19
20
21
 
22
U. Uludag, S. Pankanti, S. Prabhakar, and A. Jain. Biometric cryptosystems: Issues and challenges, 2004.
 
23
I. M. R. VeriSign. Web Services Federation Language (WS-Federation). version 1.0. July 8 2003. http://www-128.ibm.com/developerworks/library/specification/ws-fed/.
24
25
 
26
W. Zhang, Y.-J. Chang, and T. Chen. Optimal thresholding for key generation based on biometrics. In ICIP, pages 3451--3454, 2004.

Collaborative Colleagues:
Abhilasha Bhargav-Spantzel: colleagues
Anna Squicciarini: colleagues
Elisa Bertino: colleagues