A Framework for the Security and Privacy of Biometric System Constructions under Defined Computational Assumptions

Sam Grierson,William J Buchanan,Craig Thomson,Baraq Galeb,Chris Eckl
2024-11-26
Abstract:Biometric systems, while offering convenient authentication, often fall short in providing rigorous security assurances. A primary reason is the ad-hoc design of protocols and components, which hinders the establishment of comprehensive security proofs. This paper introduces a formal framework for constructing secure and privacy-preserving biometric systems. By leveraging the principles of universal composability, we enable the modular analysis and verification of individual system components. This approach allows us to derive strong security and privacy properties for the entire system, grounded in well-defined computational assumptions.
Cryptography and Security
What problem does this paper attempt to address?
The main problem that this paper attempts to solve is the deficiency of biometric systems in providing strict security guarantees. Although biometric technology provides convenience for user authentication, the design of its protocols and components is often ad - hoc, which hinders a comprehensive proof of the security of the system. Therefore, this paper aims to introduce a formal framework for constructing secure and privacy - protecting biometric systems. Specifically, the authors focus on: 1. **Lack of a strict theoretical basis**: The security and privacy guarantees of current biometric systems are usually based on experience or assumptions in specific scenarios, lacking a unified formal verification method. 2. **Modular analysis and verification**: By using the principle of universal composability, each system component can be independently analyzed and verified, thereby ensuring the security and privacy of the entire system. 3. **Defining ideal functions**: An ideal function definition of a biometric authentication system is proposed, which can be used to prove the security and privacy of the system architecture, and these proofs are based on clear computational assumptions. To achieve the above - mentioned goals, the following contributions are made in the paper: - A framework for ensuring the security and privacy of biometric system architectures has been developed. - Focus on defining the function of an ideal biometric authentication system so as to prove its security and privacy through universal composability. - By using the power of universal composability, the security and privacy of biometric system constructions can be formally proven, ensuring that they are resistant to a wide range of attacks. Through these efforts, this research hopes to provide a solid foundation for the design of future biometric systems, making these systems not only convenient to use but also more secure and reliable.