Multisketches: Practical Secure Sketches Using Off-the-Shelf Biometric Matching Algorithms
Rahul Chatterjee, M. Sadegh Riazi, Tanmoy Chowdhury, Emanuela Marasco, Farinaz Koushanfar, Ari Juels
Abstract
Biometric authentication is increasingly being used for large scale human authentication and identification, creating the risk of leaking the biometric secrets of millions of users in the case of database compromise. Powerful "fuzzy" cryptographic techniques for biometric template protection, such as secure sketches, could help in principle, but go unused in practice. This is because they would require new biometric matching algorithms with potentially much diminished accuracy. We introduce a new primitive called a multisketch that generalizes secure sketches. Multisketches can work with existing biometric matching algorithms to generate strong cryptographic keys from biometric data reliably. A multisketch works on a biometric database containing multiple biometrics --- e.g., multiple fingerprints --- of a moderately large population of users (say, thousands). It conceals the correspondence between users and their biometric templates, preventing an attacker from learning the biometric data of a user in the advent of a breach, but enabling derivation of user-specific secret keys upon successful user authentication. We design a multisketch over tenprints --- fingerprints of ten fingers --- called TenSketch. We report on a prototype implementation of TenSketch, showing its feasibility in practice. We explore several possible attacks against TenSketch database and show, via simulations with real tenprint datasets, that an attacker must perform a large amount of computation to learn any meaningful information from a stolen TenSketch database.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 5428d325-6ff2-426e-b6eb-219086d756cdCited by top-tier papers2
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- Game-Set-MATCH: Using Mobile Devices for Seamless External-Facing Biometric MatchingShashank Agrawal, Saikrishna Badrinarayanan, Pratyay Mukherjee, Peter RindalCCS 2020 · 17 citations
Related papers
- Revisiting Fuzzy Signatures: Towards a More Risk-Free Cryptographic Authentication System based on BiometricsShuichi Katsumata, Takahiro Matsuda, Wataru Nakamura, Kazuma Ohara et al.CCS 2021 · 19 citations
- Biometrics-Authenticated Key Exchange for Secure MessagingMei Wang, Kun He, Jing Chen, Zengpeng Li et al.CCS 2021 · 20 citations
- Fuzzy Extractors are Practical: Cryptographic Strength Key Derivation from the IrisAmey Shukla, Luke Demarest, Benjamin Fuller, Sohaib Ahmad et al.CCS 2025
- Fuzzy Labeled Private Set Intersection with Applications to Private Real-Time Biometric SearchErkam Uzun, Simon P. Chung, Vladimir Kolesnikov, Alexandra Boldyreva et al.USENIX Security 2021 · 49 citations
- MaskPrint: Take the Initiative in Fingerprint Protection to Mitigate the Harm of Data BreachYihui Yan, Zhice YangCCS 2024 · 1 citation
