Biometric Systems: Privacy and Secrecy Aspects

Biometric Systems: Privacy and Secrecy Aspects
复制标题

DOI:
10.1109/tifs.2009.2033228
复制
发表时间:
2009-12-01
影响因子:
6.8
通讯作者:
Willems, Frans M. J.
Willems, Frans M. J.
中科院分区:
计算机科学1区
文献类型:
--
作者:
Ignatenko, Tanya;Willems, Frans M. J.

文献摘要

被引文献

相似文献

本文讨论了生物特征保密系统中的隐私泄漏问题。四个设置进行了研究。第一种是标准的Ahlswede-Csiszar秘密生成设置,其中两个终端观察两个相关序列。他们通过交换公共信息形成了一个共同的秘密。这个消息应该只包含关于秘密的可忽略的信息量,但是在这里,另外,我们要求它泄漏尽可能少的关于生物特征数据的信息。对于第一种情况,确定了秘密密钥和隐私泄漏率之间的基本权衡。同样对于第二种设置,其中秘密不是生成的,而是独立选择的,基本的秘密密钥与隐私泄漏率的平衡被发现。在这里,公开消息应该只包含关于秘密和生物特征序列的可忽略量的信息。为了实现这一点,需要私钥,该私钥只能由终端观察。对于生成秘密和选择秘密模型,确定了可实现的秘密密钥与私有密钥速率对的区域。对于所有四种设置,确定了无条件和有条件隐私泄露的基本平衡。
This paper addresses privacy leakage in biometric secrecy systems. Four settings are investigated. The first one is the standard Ahlswede-Csiszar secret-generation setting in which two terminals observe two correlated sequences. They form a common secret by interchanging a public message. This message should only contain a negligible amount of information about the secret, but here, in addition, we require it to leak as little information as possible about the biometric data. For this first case, the fundamental tradeoff between secret-key and privacy-leakage rates is determined. Also for the second setting, in which the secret is not generated but independently chosen, the fundamental secret-key versus privacy-leakage rate balance is found. Settings three and four focus on zero-leakage systems. Here the public message should only contain a negligible amount of information on both the secret and the biometric sequence. To achieve this, a private key is needed, which can only be observed by the terminals. For both the generated-secret and the chosen-secret model, the regions of achievable secret-key versus private-key rate pairs are determined. For all four settings, the fundamental balance is determined for both unconditional and conditional privacy leakage.