May the Force Not Be With You: Brute-Force Resistant Biometric Authentication and Key Reconstruction
Alexandra Boldyreva, Deep Inder Mohan, Tianxin Tang
Abstract
The use of biometric-based security protocols is on the steep rise. As biometrics become more popular, we witness more attacks. For example, recent BrutePrint/InfinityGauntlet attacks showed how to brute-force fingerprints stored on an Android phone in about 40 minutes. The attacks are possible because biometrics, like passwords, do not have high entropy. But unlike passwords, brute-force attacks are much more damaging for biometrics, because one cannot easily change biometrics in case of compromise. In this work, we propose a novel provably secure Brute-Force Resistant Biometrics (BFRB) protocol for biometric-based authentication and key reconstruction that protects against brute-force attacks even when the server storing biometric-related data is compromised. Our protocol utilizes a verifiable partially oblivious pseudorandom function, an authenticated encryption scheme, a pseudorandom function, and a hash. We formally define security for a BFRB protocol and reduce the security of our protocol to the security of the building blocks. We implement the protocol and study its performance for the ND-0405 iris dataset.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 56fdb498-305b-4fc1-ab47-aec8a70d6c1eCited by top-tier papers1
Ask how each one uses itBuilds on7
- Security Analysis of the WhatsApp End-to-End Encrypted Backup ProtocolGareth T. Davies, Sebastian H. Faller, Kai Gellert, Tobias Handirk et al.CRYPTO 2023 · 29 citations
- A Fast and Simple Partially Oblivious PRF, with ApplicationsNirvan Tyagi, Sofía Celi, Thomas Ristenpart, Nick Sullivan et al.EUROCRYPT 2022 · 28 citations
- Biometrics-Authenticated Key Exchange for Secure MessagingMei Wang, Kun He, Jing Chen, Zengpeng Li et al.CCS 2021 · 20 citations
- Game-Set-MATCH: Using Mobile Devices for Seamless External-Facing Biometric MatchingShashank Agrawal, Saikrishna Badrinarayanan, Pratyay Mukherjee, Peter RindalCCS 2020 · 17 citations
- A Formal Treatment of End-to-End Encrypted Cloud StorageMatilda Backendal, Hannah Davis, Felix Günther, Miro Haller et al.CRYPTO 2024 · 15 citations
Related papers
- Voice In Ear: Spoofing-Resistant and Passphrase-Independent Body Sound AuthenticationYang Gao, Yincheng Jin, Jagmohan Chauhan, Seokmin Choi et al.UbiComp 2021 · 45 citations
- InfinityGauntlet: Expose Smartphone Fingerprint Authentication to Brute-force AttackYu Chen, Yang Yu, Lidong ZhaiUSENIX Security 2023
- Revisiting Fuzzy Signatures: Towards a More Risk-Free Cryptographic Authentication System based on BiometricsShuichi Katsumata, Takahiro Matsuda, Wataru Nakamura, Kazuma Ohara et al.CCS 2021 · 19 citations
- On the Resilience of Biometric Authentication Systems against Random InputsBenjamin Zi Hao Zhao, Hassan Jameel Asghar, Mohamed Ali KâafarNDSS 2020
- Fuzzy Extractors are Practical: Cryptographic Strength Key Derivation from the IrisAmey Shukla, Luke Demarest, Benjamin Fuller, Sohaib Ahmad et al.CCS 2025
