Suppr超能文献

一种基于可取消虹膜和隐写术的物联网用户认证系统。

A Cancelable Iris- and Steganography-Based User Authentication System for the Internet of Things.

作者信息

Yang Wencheng, Wang Song, Hu Jiankun, Ibrahim Ahmed, Zheng Guanglou, Macedo Marcelo Jose, Johnstone Michael N, Valli Craig

机构信息

Security Research Institute, Edith Cowan University, Perth, WA 6207, Australia.

Department of Engineering, La Trobe University, Melbourne, VIC 3083, Australia.

出版信息

Sensors (Basel). 2019 Jul 6;19(13):2985. doi: 10.3390/s19132985.

Abstract

Remote user authentication for Internet of Things (IoT) devices is critical to IoT security, as it helps prevent unauthorized access to IoT networks. Biometrics is an appealing authentication technique due to its advantages over traditional password-based authentication. However, the protection of biometric data itself is also important, as original biometric data cannot be replaced or reissued if compromised. In this paper, we propose a cancelable iris- and steganography-based user authentication system to provide user authentication and secure the original iris data. Most of the existing cancelable iris biometric systems need a user-specific key to guide feature transformation, e.g., permutation or random projection, which is also known as key-dependent transformation. One issue associated with key-dependent transformations is that if the user-specific key is compromised, some useful information can be leaked and exploited by adversaries to restore the original iris feature data. To mitigate this risk, the proposed scheme enhances system security by integrating an effective information-hiding technique-steganography. By concealing the user-specific key, the threat of key exposure-related attacks, e.g., attacks via record multiplicity, can be defused, thus heightening the overall system security and complementing the protection offered by cancelable biometric techniques.

摘要

物联网(IoT)设备的远程用户认证对于物联网安全至关重要,因为它有助于防止对物联网网络的未经授权访问。生物识别技术因其相对于传统基于密码的认证的优势,是一种有吸引力的认证技术。然而,生物识别数据本身的保护也很重要,因为如果生物识别原始数据遭到泄露,就无法替换或重新发行。在本文中,我们提出了一种基于可撤销虹膜和隐写术的用户认证系统,以提供用户认证并保护原始虹膜数据。现有的大多数可撤销虹膜生物识别系统需要特定于用户的密钥来指导特征变换,例如置换或随机投影,这也被称为密钥依赖变换。与密钥依赖变换相关的一个问题是,如果特定于用户的密钥遭到泄露,一些有用信息可能会被对手泄露和利用,以恢复原始虹膜特征数据。为了减轻这种风险,所提出的方案通过集成一种有效的信息隐藏技术——隐写术来增强系统安全性。通过隐藏特定于用户的密钥,可以化解与密钥暴露相关攻击的威胁,例如通过记录多样性的攻击,从而提高整体系统安全性,并补充可撤销生物识别技术提供的保护。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/e177/6651016/eeb04eb5d0b8/sensors-19-02985-g001.jpg

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验