A Privacy Preserving Two-Factor Authentication Protocol for Secure Access Control
Christina-Angeliki Toli, Enrique Argones Rúa, Aysajan Abidin, Roel Peeters, Bart Preneel
Abstract
Christina-Angeliki Toli, Enrique Argones Rúa, Aysajan Abidin, Roel Peeters, Bart Preneel
Abstract
The use of biometrics in several domains, services\nand applications has never been a timelier endeavor. Researchers\nare expected to design and maintain systems considering the data\nprotection standards, security, usability and user’s privacy. In\nthe last decade, there are numerous proposals for enforcing the\nprivacy of biometric data. However, few concrete works exist for\narchitectures to support highly secure access control, qualitative\ntechnical assurances, convenient implementation and privacy\nmethodologies complying with frameworks for these sensitive information.\nIn this paper a three-party, two-factor authentication\nprotocol is presented, establishing a bridge between biometrics,\nknowledge-based authentication factors (passwords/tokens) and\ntraditional template protection schemes. To handle the security\nchallenges, instead of using homomorphic encryption techniques,\nsuch other single factor authentication protocols do, a novel userspecific\napproach for the binarization of biometrics combined\nwith fuzzy extractors is suggested. For providing a feasible protection\nmechanism, symmetric encryption is used to bind together\nthe binarization parameters with the produced password-derived\nkey. Precise security, privacy targets and adversaries are defined,\nespecially for those scenarios where impersonation, biometric\ndisclosure and user tracking among services are possible. Finally,\nthe design can be used for engineering tasks related to privacy\nrequirements by design and its final goal is to provide a\nsecure identity authentication, keeping hidden the biometric data,\npreserving renewability and privacy.
A significance statement is not available in the OpenAlex record.
A contribution statement is not available in the OpenAlex record.
Method details are not available in the OpenAlex metadata.
Findings are not separately available in the OpenAlex metadata.
Limitations are not available in the OpenAlex metadata.
Application details are not available in the OpenAlex metadata.
The use of biometrics in several domains, services\nand applications has never been a timelier endeavor. Researchers\nare expected to design and maintain systems considering the data\nprotection standards, security, usability and user’s privacy. In\nthe last decade, there are numerous proposals for enforcing the\nprivacy of biometric data. However, few concrete works exist for\narchitectures to support highly secure access control, qualitative\ntechnical assurances, convenient implementation and privacy\nmethodologies complying with frameworks for these sensitive information.\nIn this paper a three-party, two-factor authentication\nprotocol is presented, establishing a bridge between biometrics,\nknowledge-based authentication factors (passwords/tokens) and\ntraditional template protection schemes. To handle the security\nchallenges, instead of using homomorphic encryption techniques,\nsuch other single factor authentication protocols do, a novel userspecific\napproach for the binarization of biometrics combined\nwith fuzzy extractors is suggested. For providing a feasible protection\nmechanism, symmetric encryption is used to bind together\nthe binarization parameters with the produced password-derived\nkey. Precise security, privacy targets and adversaries are defined,\nespecially for those scenarios where impersonation, biometric\ndisclosure and user tracking among services are possible. Finally,\nthe design can be used for engineering tasks related to privacy\nrequirements by design and its final goal is to provide a\nsecure identity authentication, keeping hidden the biometric data,\npreserving renewability and privacy.
Key concepts: Access control, Computer science, Computer security, Protocol (science), Authentication protocol, Authentication (law), Internet privacy, Information privacy