课题基金 / 基金详情

Collaborative Research: Rigorous Cryptography from Biometrics and Other Noisy Data

Collaborative Research: Rigorous Cryptography from Biometrics and Other Noisy Data
合作研究:来自生物识别和其他噪音数据的严格密码学
批准号:
0515100
负责人:
Leonid Reyzin
金额:
$0.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2005
资助国家:
美国
项目状态:
已结题
起止时间:
2005-07-01 至 2008-06-30

项目摘要

项目成果

Leonid Reyzin的其他基金

相似基金

相关文献

中文摘要
翻译
生物识别、非传统密码或物理随机函数等不能精确重现或均匀分布的信息源,越来越多地被建议作为电子和物理安全的工具。然而,关于这些资源究竟应该如何使用和存储,还有许多重大的悬而未决的问题。这项提案的重点是调查如何安全、可靠、私下和多功能地使用它们。所研究的技术将远远超越生物认证,应用于需要安全存储、私密比较或加密使用噪声数据的环境中。我们研究的一个简单激励方案是基于密码的认证。为了避免存储密码所固有的安全漏洞,系统通常会存储其单向散列。当输入用户密码进行验证时,首先对其进行散列,然后将其与存储的散列值进行比较。当然,密码的问题在于它们的信息熵很低。另一方面,使用高熵输入的问题在于,容易获得的输入很难精确复制:人类在长长的密码短语中会出现打字错误,会忘记多个问题的一些答案,而机器无法从一个读数精确地复制指纹和虹膜扫描。因此,单向散列函数方法不起作用,因为即使输入中的微小变化也会导致散列值的剧烈变化。在没有额外技术的情况下,人们别无选择,只能存储原始注册值并接受固有的安全漏洞,或者穷尽地搜索接近输入值的所有值。建议项目的智力优点建议的研究将允许验证此类噪声的高熵输入,而不需要秘密存储或执行暴力搜索。我们的工作与文献中相关的先前工作的不同之处在于,我们的方法是严格和通用的。我们建议研究的技术将不仅允许在上述密码身份验证场景中使用不可靠的非统一输入,而且还允许在任何密码应用程序中使用密钥。此外,同样的技术还将应用于其他应用,如隐私保护数据挖掘。我们的建议建立在两个PI最近的工作基础上[42]。这项工作引入了以加密方式使用非统一和不可靠数据的新概念:安全草图和模糊抽取器。虽然这些概念已经找到了应用[40,39],但还需要做很多工作来获得和分析各种输入类的实际结构,加强定义,并研究特定的新应用。通过消除对大容量分布式安全存储的需求,我们的工作有可能显著降低使用生物特征或其他敏感输入进行安全保护的系统的成本和潜在风险(详见提案说明)。此外,它可能会使依赖低熵密码的系统切换到更安全的方法,例如基于生物特征的密钥协商。关于隐私。许多需要认证的系统的显著缺点是用户所经历的隐私的丧失(例如,当将其社会安全号码存储为其信用卡账户的密码时,或者当将其指纹存储为用于安全门的密码时)。这项工作将消除在许多应用程序中存储私有数据的需要。此外,正如提案说明中进一步详细说明的那样,隐私保护将不仅扩展到生物特征(或类似)密码,还将扩展到受其保护的数据,以确保没有正确密码的人将无法访问这些数据。这两名私人助理定期教授关于密码学和网络安全的课程,并将能够将新的成果纳入他们教授的课程中。此外,该提案还包含一个重要的研究生培训部分。
英文摘要
Sources of entropy that are not precisely reproducible nor uniformly distributed, such as biometrics, nontraditional passwords, or physical random functions, are increasingly suggested as tools in electronic and physical security. There are, however, many significant unresolved questions about exactly how such sources should be used and stored. This proposal focuses on investigating how to use them securely, reliably, privately and versatilely. The techniques studied will have applications well beyond biometric authentication, to settings where noisy data needs to be stored securely, compared privately, or used cryptographically.A simple motivating scenario for our research is that of password-based authentication. In order to avoid security vulnerabilities inherent in storing passwords, systems often store their one-way hashes instead. When a user's password is entered for verification, it is first hashed and then compared to the stored hash value. The problem with passwords, of course, is that their entropy is low. The problem with using highentropy inputs, on the other hand, is that the readily available ones are hard to reproduce precisely: humans make typographical errors in long passphrases and forget some of the answers to multiple questions, while machines cannot precisely reproduce fingerprints and iris scans from one reading to the next. Therefore, the one-way hash function approach does not work, because even slight variations in the input will results in drastic changes of the hash value. Without additional techniques, one has no choice but to store the originalenrollment value and accept the inherent security vulnerabilities, or to exhaustively search all values close to the input value.Intellectual Merits of the Proposed ProjectThe proposed research will allow verification of such noisy high-entropy inputs without requiring secret storage or performing brute-force search. What distinguishes our work from related prior work in the literature is that our approach is rigorous and versatile. The techniques we propose to study will allow the use of unreliable nonuniform inputs not only in the above password-authentication scenario, but also for keys is any cryptographic application. Moreover, the same techniques will have other applications, such as privacy-preserving data mining.Our proposal builds on the recent work of the two PIs [42]. That work introduced new notions for using nonuniform and unreliable data cryptographically: secure sketches and fuzzy extractors. While the notions are already finding applications [40, 39], much work is needed to obtain and analyze practical constructions for a variety of input classes, to strengthen definitions, and to study specific new applications.Broader Impacts of the Proposed ProjectON SECURE SYSTEMS. By removing the need for large-volume distributed secure storage, our work has the potential to significantly lower the costs and potential liabilities of systems that utilize biometric or other sensitive inputs for security (as detailed in the proposal description). Moreover, it may enable systems that have relied on low-entropy passwords to switch to more secure approaches, such as biometric-based key agreement.ON PRIVACY. A significant drawback of many systems that require authentication is the loss of privacy that users experience (e.g., when having their social security numbers stored as passwords for their credit card accounts, or when having their fingerprints stored as passwords for secure doors). This work will remove the need to store private data in many applications. Moreover, as further detailed in the proposal description, the privacy protection will extend not only to the biometric (or similar) password, but also to the data protected by it, ensuring that no one without the right password will have access to the data.ON EDUCATION. The two PIs regularly teach courses on cryptography and network security, and will be able incorporate the new results into the courses they teach. In addition, the proposal has a significant graduate student training component.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
NSF Student Travel Fund for the 2020 Annual International Cryptology Conference (Crypto)
  • 批准号:
    2024317
  • 项目类别:
    Standard Grant
  • 资助金额:
    $1.8万
  • 财政年份:
    2020
  • 负责人:
    Leonid Reyzin
  • 依托单位:
TWC: Small: Noisy Secrets as Alternatives to Passwords and PKI
  • 批准号:
    1422965
  • 项目类别:
    Standard Grant
  • 资助金额:
    $49.97万
  • 财政年份:
    2014
  • 负责人:
    Leonid Reyzin
  • 依托单位:
CAREER: Cryptography Outside the Box
  • 批准号:
    0546614
  • 项目类别:
    Continuing Grant
  • 资助金额:
    $40.0万
  • 财政年份:
    2006
  • 负责人:
    Leonid Reyzin
  • 依托单位:
国内基金
海外基金
Research on Quantum Field Theory without a Lagrangian Description
  • 批准号:
    24ZR1403900
  • 项目类别:
    省市级项目
  • 资助金额:
    --
  • 批准年份:
    2024
  • 负责人:
    SATOSHI NAWATA
  • 依托单位:
Cell Research
Cell Research
Cell Research (细胞研究)