Fuzzy Extractors: How to Generate Strong Keys from Biometrics and Other Noisy Data
arXiv:cs/0602007 · doi:10.1137/060651380
Abstract
We provide formal definitions and efficient secure techniques for - turning noisy information into keys usable for any cryptographic application, and, in particular, - reliably and securely authenticating biometric data. Our techniques apply not just to biometric information, but to any keying material that, unlike traditional cryptographic keys, is (1) not reproducible precisely and (2) not distributed uniformly. We propose two primitives: a "fuzzy extractor" reliably extracts nearly uniform randomness R from its input; the extraction is error-tolerant in the sense that R will be the same even if the input changes, as long as it remains reasonably close to the original. Thus, R can be used as a key in a cryptographic application. A "secure sketch" produces public information about its input w that does not reveal w, and yet allows exact recovery of w given another value that is close to w. Thus, it can be used to reliably reproduce error-prone biometric inputs without incurring the security risk inherent in storing them. We define the primitives to be both formally secure and versatile, generalizing much prior work. In addition, we provide nearly optimal constructions of both primitives for various measures of ``closeness'' of input data, such as Hamming distance, edit distance, and set difference.
47 pp., 3 figures. Prelim. version in Eurocrypt 2004, Springer LNCS 3027, pp. 523-540. Differences from version 3: minor edits for grammar, clarity, and typos
Cited by in corpus (45)
- Leftover Hashing Against Quantum Side Information
- Maximization of Extractable Randomness in a Quantum Random-Number Generator
- Securing Wireless Communications of the Internet of Things from the Physical Layer, An Overview
- The Fuzzy Vault for fingerprints is Vulnerable to Brute Force Attack
- Strong experimental guarantees in ultrafast quantum random number generation
- Secure and Reliable Key Agreement with Physical Unclonable Functions
- On Error Correction for Physical Unclonable Functions
- Practical security analysis of a continuous-variable quantum random number generator with a noisy local oscillator
- Secret Key Agreement with Physical Unclonable Functions: An Optimality Summary
- A Modular End-to-End Framework for Secure Firmware Updates on Embedded Systems
- Error Correction for Physical Unclonable Functions Using Generalized Concatenated Codes
- PUF for the Commons: Enhancing Embedded Security on the OS Level
- Practical Rateless Set Reconciliation
- Attacks and Countermeasures in Fingerprint Based Biometric Cryptosystems
- Authentication Protocols for Internet of Things: A Comprehensive Survey
- Application of single-electron effects to fingerprints of chips using image recognition algorithms
- Key Generation for Internet of Things: A Contemporary Survey
- The Wiretap Channel for Capacitive PUF-Based Security Enclosures
- Secure authentication via Quantum Physical Unclonable Functions: a review
- Converses for Secret Key Agreement and Secure Computing
- Fuzzy Commitments Offer Insufficient Protection to Biometric Templates Produced by Deep Learning
- HoneyFaces: Increasing the Security and Privacy of Authentication Using Synthetic Facial Images
- Comparative Analysis of SRAM PUF Temperature Susceptibility on Embedded Systems
- Efficiently decoding strings from their shingles
- A Near-Optimal Algorithm for L1-Difference
- Building Secure SRAM PUF Key Generators on Resource Constrained Devices
- Identification with Encrypted Biometric Data
- Non-Malleable Condensers for Arbitrary Min-Entropy, and Almost Optimal Protocols for Privacy Amplification
- IronMask: Modular Architecture for Protecting Deep Face Template
- Secure Biometric-based Remote Authentication Protocol using Chebyshev Polynomials and Fuzzy Extractor
- Inaccessible Entropy I: Inaccessible Entropy Generators and Statistically Hiding Commitments from One-Way Functions
- A New Biometric Template Protection using Random Orthonormal Projection and Fuzzy Commitment
- Entropies and their Asymptotic Theory in the discrete case
- Adversarial Wiretap Channel with Public Discussion
- Information-theoretically Secret Key Generation for Fading Wireless Channels
- Information-theoretic Key Encapsulation and its Applications
- Security and Privacy Enhanced Gait Authentication with Random Representation Learning and Digital Lockers
- Design and Analysis of a Secure Three Factor User Authentication Scheme Using Biometric and Smart Card
- Space- and Computationally-Efficient Set Reconciliation via Parity Bitmap Sketch (PBS)
- Nearly-Linear Time Seeded Extractors with Short Seeds
- Symbolic Execution + Model Counting + Entropy Maximization = Automatic Search Synthesis
- On the Oblivious Transfer Capacity of Generalized Erasure Channels against Malicious Adversaries
- An Improved Robust Fuzzy Extractor
- Discrete Logarithmic Fuzzy Vault Scheme
- Minutia-pair spectral representations for fingerprint template protection