CROct 3, 2019

Comments on a recently proposed Privacy Preserving Lightweight Biometric Authentication System for IoT Security

arXiv:1910.01446v22.7
Originality Synthesis-oriented
AI Analysis

This work highlights critical security issues in a specific IoT biometric system, which is important for developers and users in that domain, though it is incremental as it critiques an existing method.

The paper identifies security vulnerabilities in a recently proposed lightweight adaptation of the Minutia Cylinder-Code fingerprint matching algorithm for IoT biometric authentication, showing that intruders can illegitimately authenticate and that the adaptation has privacy flaws.

In this paper, we show that a recently published lightweight adaptation of a Fingerprint matching algorithm called the Minutia Cylinder-Code may not be secure as intruders may be able to illegitimately yet successfully authenticate themselves to the system under consideration. We also show that the lightweight adaptation has other privacy related vulnerabilities that make it unsuitable for use in Biometrics. We make it clear that we are neither investigating nor commenting on the security of the original Minutia Cylinder-Code algorithm by itself, rather we highlight the vulnerabilities of the lightweight adaptation. In the process of doing this, we provide a high-level overview of the role of one-way functions in cryptography and biometrics to provide a context to the aforementioned lightweight algorithm and its deficiencies.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes