Fuzzy-in-the-Loop-Driven Low-Cost and Secure Biometric User Access to Server


Creative Commons License

Irshad A., Usman M., Chaudhry S. A., Bashir A. K., Jolfaei A., Srivastava G.

IEEE Transactions on Reliability, vol.70, no.3, pp.1014-1025, 2021 (SCI-Expanded) identifier

  • Publication Type: Article / Article
  • Volume: 70 Issue: 3
  • Publication Date: 2021
  • Doi Number: 10.1109/tr.2020.3021794
  • Journal Name: IEEE Transactions on Reliability
  • Journal Indexes: Science Citation Index Expanded (SCI-EXPANDED), Scopus, Academic Search Premier, Aerospace Database, Applied Science & Technology Source, Business Source Elite, Business Source Premier, Communication Abstracts, Compendex, Computer & Applied Sciences, INSPEC, Metadex, zbMATH, Civil Engineering Abstracts
  • Page Numbers: pp.1014-1025
  • Keywords: Biometric fuzzy extractor (FE), fuzzy systems, mutual authentication, physical unclonable function (PUF), user access
  • Istanbul Gelisim University Affiliated: Yes

Abstract

© 1963-2012 IEEE.Fuzzy systems can aid in diminishing uncertainty and noise from biometric security applications by providing an intelligent layer to the existing physical systems to make them reliable. In the absence of such fuzzy systems, a little random perturbation in captured human biometrics could disrupt the whole security system, which may even decline the authentication requests of legitimate entities during the protocol execution. In the literature, few fuzzy logic-based biometric authentication schemes have been presented; however, they lack significant security features including perfect forward secrecy (PFS), untraceability, and resistance to known attacks. This article, therefore, proposes a novel two-factor biometric authentication protocol enabling efficient and secure combination of physically unclonable functions, a physical object analogous to human fingerprint, with user biometrics by employing fuzzy extractor-based procedures in the loop. This combination enables the participants in the protocol to achieve PFS. The security of the proposed scheme is tested using the well-known real-or-random model. The performance analysis signifies the fact that the proposed scheme not only offers PFS, untraceability, and anonymity to the participants, but is also resilient to known attacks using light-weight symmetric operations, which makes it an imperative advancement in the category of intelligent and reliable security solutions.