BioVault locks up biometrics: Using biometrics for encryption, digital signatures
July 31, 2009A system that allows biometric data to be used to create a secret key for data encryption has been developed by researchers in South Africa. They describe details of the new technology in the International Journal of Electronic Security and Digital Forensics this month.
If a user, a web customer say, wishes to send a message or other data to another user, an online shop, over an unsecured network, the message must be encrypted to avoid interception of sensitive information such as passwords and credit card information.
Encryption relies on authentication being symmetric to work. In other words, the user's password or PIN must match the password or PIN stored by the online shop to lock and unlock the data. This is because encryption systems use the password or PIN to produce, or seed, a random number that is used as the cipher for encrypting the data. If the passwords do not match exactly then the seed will be incorrect, the random number different and the decryption will fail.
One way to avoid users having to remember endless, complicated passwords is to use biometrics, including fingerprints, iris pattern, face recognition. However, biometrics is not a symmetric process. The initial recording of biometric data samples only a limited amount of the information, the pigment patter in one's iris, for instance. The unlocking process then compares the iris pattern, or other biometric "token", being presented for access with the sample stored in the database. If the match is close enough, the user can gain entry.
The reason for this asymmetry is that any biometric system takes only a digital sample of data from the fingerprint or iris, for instance. Moreover, even the legitimate user will not be able to present exactly the same biometric data repeatedly. The close enough aspect of biometrics does not make biometrics insecure, provided that the closeness is very precise, but it does mean that biometric tokens cannot be used to create a secret key for an encryption algorithm.
Bobby Tait and Basie von Solms of the University of Johannesburg, Gauteng, South Africa, explain how biometrics can nevertheless be used to make a consistent secret key for encryption.
In conventional encryption, if Alice wishes to send a secret message to Bill, then she must encrypt the message, whether it is an email or credit card details transmitted from her computer to the online shop. In order for the encryption algorithm to provide cipher text that is random, a secret key must be provided. Alice and Bill must share exact copies of their secret key for this to work.
Aside from the asymmetry in biometrics, this approach will not work because Alice and Bill cannot provide the same biometric token to encrypt and decrypt the message. Now, Tait and von Solms have used the so-called BioVault infrastructure to provide a safe and secure way for Alice and Bill to share biometric tokens and so use their fingerprints, iris pattern, or other biometric to encrypt and decrypt their data without their biometrics being intercepted.
The BioVault encryption system works as follows:
In phase 1, Alice identifies herself to the authentication server, and indicates that she wants to send an encrypted message to Bill and requests Bill's biometric key from the server.
In phase 2, the server retrieves a random biometric key from Bill's stored biometric keys.
In phase 3, Alice uses the biometric key to encrypt her message and sends it to Bill.
In phase 4, Bill receives the message sent by Alice, and decrypts the message by testing the biometric keys in his database against the received cipher text.
The fact that each biometric key (data) is unique means that the BioVault system can irrevocably identify and authenticate users through their biometric keys (data) and detect fraudulent use of biometric keys.
Tait adds that the same approach could also be used to digitally sign electronic documents, files, or software executables using biometrics. He will be presenting the team's results on this aspect of their work in the UK at the beginning of September. "If passwords or tokens are used for authentication, only the password or token is proven as authentic - not the user that supplied the token or password," he explains, "Biometrics authenticates the user directly - this was one of the drivers behind the BioVault development."
More information: "BioVault: biometrically based encryption" in Int. J. Electronic Security and Digital Forensics, 2009, 2, 269-279
-
Keeping an eye on intruders
Sep 04, 2008 |
not rated yet |
0
-
Photo safeguards confidential information
Oct 22, 2008 |
not rated yet |
0
-
In Brief: Biometrics more popular with Asian banks
Jun 21, 2006 |
not rated yet |
0
-
Biometrics for secure mobile communications
Jul 20, 2006 |
not rated yet |
0
-
Fingerprint Advances Will Fight Cybercrime
Feb 24, 2006 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (33) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (5) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (2) |
0
-
Flushing RAM in Mathematica
5 hours ago
-
Synergistic relations between computer science and technology.
Feb 06, 2012
-
how do iphone gloves work?
Feb 05, 2012
-
iPhone battery over time
Jan 30, 2012
-
Best alternate Tablet to an iPad for writing math or physics equations?
Jan 26, 2012
-
Sending SMS to a website
Jan 20, 2012
- More from Physics Forums - Computing & Technology
More news stories
Researchers' paper wins Best Paper Award for 2011
A paper written by Dr. Paul Gratz and his graduate student, Reena Panda, from the Department of Electrical and Computer Engineering at Texas A&M University was selected as one of the best papers from IEEE Computer Architecture ...
Technology / Computer Sciences
9 minutes ago |
not rated yet |
0
Hacker claims porn site users compromised
A hacker claims to have compromised the personal information of more than 350,000 users after breaking into a disused website operated by pornography provider Brazzers.
1 hour ago |
5 / 5 (1) |
0
AT&T customers surprised by 'unlimited data' limit
(AP) -- Mike Trang likes to use his iPhone 4 as a GPS device, helping him get around in his job. Now and then, his younger cousins get ahold of it, and play some YouTube videos and games.
2 hours ago |
5 / 5 (2) |
0
Japan's Fukushima reactor may be reheating: operator
Temperature readings at one of the crippled Fukushima nuclear reactors have risen above Japan's stringent new safety standard but there was no immediate danger, its operator said Sunday.
Technology / Energy & Green Tech
3 hours ago |
3 / 5 (2) |
0
Microsoft India retail site down after 'cyber attack'
Microsoft India's retail website was down on Monday after reportedly being hacked by a Chinese group calling itself Evil Shadow Team.
51 minutes ago |
not rated yet |
0
New molecule has potential to help treat genetic diseases and HIV
(PhysOrg.com) -- Chemists at The University of Texas at Austin have created a molecule that's so good at tangling itself inside the double helix of a DNA sequence that it can stay there for up to 16 days before ...
Social psychologist: Lust makes you smarter and evidence that seven deadly sins are good for you
(Medical Xpress) -- Good news for lovers on Valentine’s Day - the seven deadly sins, including Lust, are good for you. University of Melbourne social psychologist Dr Simon Laham uses modern research to make a compelling ...
Research finds injuries to professional athletes from routine play or practice often reported as 'freak accidents' in me
(Medical Xpress) -- A new report from the Johns Hopkins Center for Injury Research and Policy finds injuries to professional athletes from routine play or practice are often characterized as freak accidents in ...
Low levels of amplitude-modulated electromagnetic fields elicit therapeutic responses cancer patients
Ryne Ramaker, a senior UALR Donaghey Scholar and University Science Scholar with a double major in biology and chemistry, is a co-author of a cancer research paper creating excitement among other researchers. The article ...
Rapunzel, Leonardo and the physics of the ponytail
(PhysOrg.com) -- New research provides the first mathematical understanding of the shape of a ponytail and could have implications for the textile industry, computer animation and personal care products.
Climate change causes harmful algal blooms in North Atlantic: study
Warming oceans and increases in windiness could be causing of an abundance of harmful algal blooms in the North Atlantic Ocean and North Sea, according to new research.