A biometric recognition system can operate in two distinct modes, identification or verification. In the first mode, the system recognizes an individual by searching the enrolled templates of all the users for a match. In the second mode, the system validates a claimed identity by comparing the fresh template with the enrolled template for this identity. Both the experimentally determined false match rate and false non-match rate through recognition threshold adjustment define the recognition accuracy, and hence the security of the system. The biometric transformation schemes usually produce binary templates that are better handled by cryptographic schemes. One of the requirements for these transformation schemes is their irreversibility. In this work, we rely on probabilistic modelling to quantify the security strength of binary templates. We investigate the influence of template size, database size and threshold on the probability of having a near-collision, and we highlight two attacks on biometric systems. We discuss the choice of parameters through the generic presented attacks.
翻译:生物识别系统可运行于两种不同模式:识别模式或验证模式。在第一种模式下,系统通过搜索所有用户注册模板以寻找匹配来识别个体。在第二种模式下,系统通过比对新鲜模板与对应身份的注册模板来验证声明的身份。通过识别阈值调整所确定的实验性误匹配率与误非匹配率共同定义了识别精度,进而决定了系统安全性。生物特征变换方案通常生成便于密码学方案处理的二进制模板,其要求之一在于不可逆性。本文基于概率建模量化二进制模板的安全强度,研究模板规模、数据库规模及阈值对近碰撞发生概率的影响,并重点阐述了针对生物识别系统的两种攻击方法。通过所提出的通用攻击范式,我们讨论了参数选择策略。