Collaborative Research: Rigorous Cryptography from Biometrics and Other Noisy Data
Collaborative Research: Rigorous Cryptography from Biometrics and Other Noisy Data
批准号:
0515100
负责人:
Leonid Reyzin
金额:
$0.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2005
资助国家:
美国
项目状态:
已结题
起止时间:
2005-07-01 至 2008-06-30
中文摘要
熵的来源是不精确的可复制的,也不是均匀分布的,如生物特征,非传统的密码,或物理随机函数,越来越多地建议作为电子和物理安全的工具。然而,关于如何使用和储存这些来源,还有许多重大的问题尚未解决。该提案的重点是研究如何安全、可靠、私密和无恶意地使用它们。所研究的技术将有应用远远超出生物特征认证,设置噪声数据需要安全存储,私人比较,或使用密码。一个简单的激励方案,我们的研究是基于密码的身份验证。为了避免存储密码中固有的安全漏洞,系统通常存储单向哈希。当输入用户的密码进行验证时,首先对其进行散列,然后将其与存储的散列值进行比较。当然,密码的问题在于它们的熵很低。另一方面,使用高熵输入的问题在于,现成的输入很难精确地再现:人类在长密码短语中会犯打字错误,并且忘记了多个问题的一些答案,而机器无法精确地再现指纹和虹膜扫描从一个阅读到下一个。因此,单向散列函数方法不起作用,因为即使输入中的微小变化也会导致散列值的剧烈变化。如果没有额外的技术,人们别无选择,只能存储originalenrollment值,并接受固有的安全漏洞,或穷举搜索所有值接近的输入value.Intellectual优点的建议ProjectThe建议的研究将允许验证这种嘈杂的高熵输入,而不需要秘密存储或执行蛮力搜索。我们的工作与文献中相关的先前工作的区别在于,我们的方法是严格和通用的。我们建议研究的技术将允许使用不可靠的非均匀输入,不仅在上述密码认证的情况下,但也为密钥是任何加密应用程序。此外,相同的技术将有其他的应用,如隐私保护数据挖掘。我们的建议建立在最近的工作,这两个PI [42]。这项工作引入了使用不均匀和不可靠的数据加密的新概念:安全草图和模糊提取器。虽然这些概念已经得到了应用[40,39],但还需要做大量的工作来获得和分析各种输入类的实际结构,加强定义,并研究具体的新应用。拟议项目对安全系统的更广泛影响。通过消除对大容量分布式安全存储的需求,我们的工作有可能显着降低利用生物识别或其他敏感输入进行安全的系统的成本和潜在责任(如提案描述中所详述)。此外,它还可以使依赖于低熵密码的系统切换到更安全的方法,例如基于生物特征的密钥协商。需要认证的许多系统的显著缺点是用户体验到的隐私的损失(例如,当将他们的社会安全号码存储为他们的信用卡账户的密码时,或者当将他们的指纹存储为安全门的密码时)。这项工作将消除在许多应用程序中存储私有数据的需要。此外,正如提案描述中进一步详细说明的那样,隐私保护不仅将扩展到生物识别(或类似)密码,还将扩展到受其保护的数据,确保没有正确密码的人无法访问数据。这两名PI定期教授密码学和网络安全课程,并将能够将新成果纳入他们教授的课程。此外,该提案还有一个重要的研究生培训部分。
英文摘要
Sources of entropy that are not precisely reproducible nor uniformly distributed, such as biometrics, nontraditional passwords, or physical random functions, are increasingly suggested as tools in electronic and physical security. There are, however, many significant unresolved questions about exactly how such sources should be used and stored. This proposal focuses on investigating how to use them securely, reliably, privately and versatilely. The techniques studied will have applications well beyond biometric authentication, to settings where noisy data needs to be stored securely, compared privately, or used cryptographically.A simple motivating scenario for our research is that of password-based authentication. In order to avoid security vulnerabilities inherent in storing passwords, systems often store their one-way hashes instead. When a user's password is entered for verification, it is first hashed and then compared to the stored hash value. The problem with passwords, of course, is that their entropy is low. The problem with using highentropy inputs, on the other hand, is that the readily available ones are hard to reproduce precisely: humans make typographical errors in long passphrases and forget some of the answers to multiple questions, while machines cannot precisely reproduce fingerprints and iris scans from one reading to the next. Therefore, the one-way hash function approach does not work, because even slight variations in the input will results in drastic changes of the hash value. Without additional techniques, one has no choice but to store the originalenrollment value and accept the inherent security vulnerabilities, or to exhaustively search all values close to the input value.Intellectual Merits of the Proposed ProjectThe proposed research will allow verification of such noisy high-entropy inputs without requiring secret storage or performing brute-force search. What distinguishes our work from related prior work in the literature is that our approach is rigorous and versatile. The techniques we propose to study will allow the use of unreliable nonuniform inputs not only in the above password-authentication scenario, but also for keys is any cryptographic application. Moreover, the same techniques will have other applications, such as privacy-preserving data mining.Our proposal builds on the recent work of the two PIs [42]. That work introduced new notions for using nonuniform and unreliable data cryptographically: secure sketches and fuzzy extractors. While the notions are already finding applications [40, 39], much work is needed to obtain and analyze practical constructions for a variety of input classes, to strengthen definitions, and to study specific new applications.Broader Impacts of the Proposed ProjectON SECURE SYSTEMS. By removing the need for large-volume distributed secure storage, our work has the potential to significantly lower the costs and potential liabilities of systems that utilize biometric or other sensitive inputs for security (as detailed in the proposal description). Moreover, it may enable systems that have relied on low-entropy passwords to switch to more secure approaches, such as biometric-based key agreement.ON PRIVACY. A significant drawback of many systems that require authentication is the loss of privacy that users experience (e.g., when having their social security numbers stored as passwords for their credit card accounts, or when having their fingerprints stored as passwords for secure doors). This work will remove the need to store private data in many applications. Moreover, as further detailed in the proposal description, the privacy protection will extend not only to the biometric (or similar) password, but also to the data protected by it, ensuring that no one without the right password will have access to the data.ON EDUCATION. The two PIs regularly teach courses on cryptography and network security, and will be able incorporate the new results into the courses they teach. In addition, the proposal has a significant graduate student training component.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF Student Travel Fund for the 2020 Annual International Cryptology Conference (Crypto)
-
批准号:2024317
-
项目类别:Standard Grant
-
资助金额:$1.8万
-
财政年份:2020
-
负责人:Leonid Reyzin
-
依托单位:
TWC: Small: Noisy Secrets as Alternatives to Passwords and PKI
-
批准号:1422965
-
项目类别:Standard Grant
-
资助金额:$49.97万
-
财政年份:2014
-
负责人:Leonid Reyzin
-
依托单位:
CAREER: Cryptography Outside the Box
-
批准号:0546614
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2006
-
负责人:Leonid Reyzin
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: