oBAKE: an Online Biometric-Authenticated Key Exchange Protocol
Haochen M. Kotoi-Xie, Takumi Moriyama

TL;DR
oBAKE is a novel biometric-authenticated key exchange protocol enabling secure, privacy-preserving, and efficient online mutual authentication between a stateless biometric sensing system and a user token, supporting multiple modalities and rounds.
Contribution
It introduces a new biometric key exchange protocol that is privacy-preserving, supports multiple modalities, and allows online authentication with minimal computational burden on the user token.
Findings
Protocol achieves secure mutual authentication without revealing biometric data.
Supports multiple biometric modalities through component-wise threshold matching.
Enables online, multi-round authentication with minimal user token computation.
Abstract
In this writing, we introduce a novel biometric-authenticated key exchange protocol that allows secure and privacy-preserving key establishment between a stateless biometric sensing system and a "smart" user token that possesses biometric templates of the user. The protocol yields a shared secret incorporating random nonce from both parties when they positively authenticate each other. Mutual positive authentication here is defined as when the feature vector calculated from the sensor data captured by the biometric sensing system only differs from the feature vector stored as the biometric template within the user token by less than a predefined threshold. The parties exchange only randomized data and cryptographically derived verifiers; no significant information regarding the vectors is ever exchanged. The protocol essentially utilizes the BBKDF scheme for feature vector matching,…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Authentication Protocols Security · Biometric Identification and Security
