A Theoretical Analysis of Authentication, Privacy and Reusability Across Secure Biometric Systems
Ye Wang, Shantanu Rane, Stark C. Draper, Prakash Ishwar

TL;DR
This paper develops a theoretical framework to analyze privacy and security tradeoffs in biometric authentication systems, comparing fuzzy commitment and secure sketches, and examining their security, leakage, and reusability properties.
Contribution
It introduces an information-theoretic analysis of biometric systems, deriving bounds and comparing security and leakage, revealing key differences and tradeoffs between fuzzy commitment and secure sketches.
Findings
Fuzzy commitment and secure sketch systems have similar error and attack probabilities.
Secure sketch systems require less storage than fuzzy commitment.
The analysis highlights tradeoffs between reducing leakage and preventing attacks.
Abstract
We present a theoretical framework for the analysis of privacy and security tradeoffs in secure biometric authentication systems. We use this framework to conduct a comparative information-theoretic analysis of two biometric systems that are based on linear error correction codes, namely fuzzy commitment and secure sketches. We derive upper bounds for the probability of false rejection () and false acceptance () for these systems. We use mutual information to quantify the information leaked about a user's biometric identity, in the scenario where one or multiple biometric enrollments of the user are fully or partially compromised. We also quantify the probability of successful attack () based on the compromised information. Our analysis reveals that fuzzy commitment and secure sketch systems have identical and information leakage, but…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsBiometric Identification and Security · User Authentication and Security Systems · Advanced Steganography and Watermarking Techniques
