TY - JOUR
T1 - Fuzzy-in-the-Loop-Driven Low-Cost and Secure Biometric User Access to Server
AU - Irshad, Azeem
AU - Usman, Muhammad
AU - Chaudhry, Shehzad Ashraf
AU - Bashir, Ali Kashif
AU - Jolfaei, Alireza
AU - Srivastava, Gautam
PY - 2021/9
Y1 - 2021/9
N2 - Fuzzy systems can aid in diminishing uncertainty and noise from biometric security applications by providing an intelligent layer to the existing physical systems to make them reliable. In the absence of such fuzzy systems, a little random perturbation in captured human biometrics could disrupt the whole security system, which may even decline the authentication requests of legitimate entities during the protocol execution. In the literature, few fuzzy logic-based biometric authentication schemes have been presented; however, they lack significant security features including perfect forward secrecy (PFS), untraceability, and resistance to known attacks. This article, therefore, proposes a novel two-factor biometric authentication protocol enabling efficient and secure combination of physically unclonable functions, a physical object analogous to human fingerprint, with user biometrics by employing fuzzy extractor-based procedures in the loop. This combination enables the participants in the protocol to achieve PFS. The security of the proposed scheme is tested using the well-known real-or-random model. The performance analysis signifies the fact that the proposed scheme not only offers PFS, untraceability, and anonymity to the participants, but is also resilient to known attacks using light-weight symmetric operations, which makes it an imperative advancement in the category of intelligent and reliable security solutions.
AB - Fuzzy systems can aid in diminishing uncertainty and noise from biometric security applications by providing an intelligent layer to the existing physical systems to make them reliable. In the absence of such fuzzy systems, a little random perturbation in captured human biometrics could disrupt the whole security system, which may even decline the authentication requests of legitimate entities during the protocol execution. In the literature, few fuzzy logic-based biometric authentication schemes have been presented; however, they lack significant security features including perfect forward secrecy (PFS), untraceability, and resistance to known attacks. This article, therefore, proposes a novel two-factor biometric authentication protocol enabling efficient and secure combination of physically unclonable functions, a physical object analogous to human fingerprint, with user biometrics by employing fuzzy extractor-based procedures in the loop. This combination enables the participants in the protocol to achieve PFS. The security of the proposed scheme is tested using the well-known real-or-random model. The performance analysis signifies the fact that the proposed scheme not only offers PFS, untraceability, and anonymity to the participants, but is also resilient to known attacks using light-weight symmetric operations, which makes it an imperative advancement in the category of intelligent and reliable security solutions.
KW - Biometric fuzzy extractor (FE)
KW - fuzzy systems
KW - mutual authentication
KW - physical unclonable function (PUF)
KW - user access
UR - http://www.scopus.com/inward/record.url?scp=85114319201&partnerID=8YFLogxK
U2 - 10.1109/TR.2020.3021794
DO - 10.1109/TR.2020.3021794
M3 - Article
AN - SCOPUS:85114319201
SN - 0018-9529
VL - 70
SP - 1014
EP - 1025
JO - IEEE TRANSACTIONS ON RELIABILITY
JF - IEEE TRANSACTIONS ON RELIABILITY
IS - 3
ER -