Comments on biometric-based non-transferable credentials and their application in blockchain-based identity management. Issue 105 (June 2021)
- Record Type:
- Journal Article
- Title:
- Comments on biometric-based non-transferable credentials and their application in blockchain-based identity management. Issue 105 (June 2021)
- Main Title:
- Comments on biometric-based non-transferable credentials and their application in blockchain-based identity management
- Authors:
- Sarier, Neyire Deniz
- Abstract:
- Highlights: A brief review on biometric-based non-transferable credential schemes and the involved biometric key generation methods. Inefficiency of Adams' biometric-based credential system resulting from the missing Zero Knowledge Proof of Double Discrete Logarithm. Insecurity of Blanton et al.'s biometric-based credential scheme implemented for fuzzy vault-based biometic key generation. Modified credentials schemes improving the inefficiency of Adams' and Blanton et al.'s credential systems. Integration of our solutions into Blockchain-based Identity Management Systems (BBIM) to obtain non-transferability in BBIM. Abstract: In IT-ecosystems, access to unauthorized parties is prevented with credential-based access control techniques (locks, RFID cards, biometrics, etc.). Some of these methods are ineffective against malicious users who lend their credentials to other users. To obtain non-transferability, Adams proposed a combination of biometrics encapsulated in Pedersen commitment with Brands digital credential. However, Adams' work does not consider the Zero Knowledge Proof-of Knowledge (ZKPoK) system for Double Discrete Logarithm Representation of the credential. Besides, biometrics is used directly, without employing any biometric cryptosystem to guarantee biometric privacy, thus Adams' work cannot be GDPR-compliant. In this paper, we construct the missing ZKPoK protocol for Adam's work and show its inefficiency. To overcome this limitation, we present a newHighlights: A brief review on biometric-based non-transferable credential schemes and the involved biometric key generation methods. Inefficiency of Adams' biometric-based credential system resulting from the missing Zero Knowledge Proof of Double Discrete Logarithm. Insecurity of Blanton et al.'s biometric-based credential scheme implemented for fuzzy vault-based biometic key generation. Modified credentials schemes improving the inefficiency of Adams' and Blanton et al.'s credential systems. Integration of our solutions into Blockchain-based Identity Management Systems (BBIM) to obtain non-transferability in BBIM. Abstract: In IT-ecosystems, access to unauthorized parties is prevented with credential-based access control techniques (locks, RFID cards, biometrics, etc.). Some of these methods are ineffective against malicious users who lend their credentials to other users. To obtain non-transferability, Adams proposed a combination of biometrics encapsulated in Pedersen commitment with Brands digital credential. However, Adams' work does not consider the Zero Knowledge Proof-of Knowledge (ZKPoK) system for Double Discrete Logarithm Representation of the credential. Besides, biometrics is used directly, without employing any biometric cryptosystem to guarantee biometric privacy, thus Adams' work cannot be GDPR-compliant. In this paper, we construct the missing ZKPoK protocol for Adam's work and show its inefficiency. To overcome this limitation, we present a new biometric-based non-transferable credential scheme that maintains the efficiency of the underlying Brands credential. Secondly, we show the insecurity of the first biometric-based anonymous credential scheme designed by Blanton et al.. In this context, we present a brute-force attack against Blanton's biometric key generation algorithm implemented for fuzzy vault. Next, we integrate an Oblivious PRF (OPRF) protocol to solve the open problem in Blanton's work and improve its efficiency by replacing the underlying signature scheme with PS-signatures. Finally, we evaluate application scenarios for non-transferable digital/anonymous credentials in the context of Blockchain-based Identity Management (BBIM). We show that our modified constructions preserve biometric privacy and efficiency, and can easily be integrated into current BBIM systems built upon efficient Brands and PS-credentials. … (more)
- Is Part Of:
- Computers & security. Issue 105(2021)
- Journal:
- Computers & security
- Issue:
- Issue 105(2021)
- Issue Display:
- Volume 105, Issue 105 (2021)
- Year:
- 2021
- Volume:
- 105
- Issue:
- 105
- Issue Sort Value:
- 2021-0105-0105-0000
- Page Start:
- Page End:
- Publication Date:
- 2021-06
- Subjects:
- Biometrics security -- Non-transferability -- Digital credentials -- Anonymous credentials -- Fuzzy vault -- Fuzzy extractors -- Double discrete logarithm (DDL) -- Brands DLRep -- Selective disclosure -- Blockchain -- Identity management
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2021.102243 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 22892.xml