The Internet of Things (IoT) is built on a strong internet infrastructure and many wireless sensor devices. Presently, Radio Frequency Identification embedded (RFID-embedded) smart cards are ubiquitous, used for many things including student ID cards, transportation cards, bank cards, prepaid cards, and citizenship cards. One example of places that require smart cards is libraries. Each library, such as a university library, city library, local library, or community library, has its own card and the user must bring the appropriate card to enter a library and borrow material. However, it is inconvenient to bring various cards to access different libraries. Wireless infrastructure has been well developed and IoT devices are connected through this infrastructure. Moreover, the development of biometric identification technologies has continued to advance. Blockchain methodologies have been successfully adopted in various fields. This paper proposes the BlockMetrics library based on integrated technologies using blockchain and finger-vein biometrics, which are adopted into a library collection management and access control system. The library collection is managed by image recognition, RFID, and wireless sensor technologies. In addition, a biometric system is connected to a library collection control system, enabling the borrowing procedure to consist of only two steps. First, the user adopts a biometric recognition device for user authentication and then performs a collection scan with the RFID devices. All the records are recorded in a personal borrowing blockchain, which is a peer-to-peer transfer system and permanent data storage. In addition, the user can check the status of his collection across various libraries in his personal borrowing blockchain. The BlockMetrics library is based on an integration of technologies that include blockchain, biometrics, and wireless sensor technologies to improve the smart library.
Sarang Chaudhari, Michael Clear, Philip Bradish, Hitesh Tewari
Uniquely identifying individuals across the various networks they interact with on a daily basis remains a challenge for the digital world that we live in, and therefore the development of secure and efficient privacy preserving identity mechanisms has become an important field of research. In addition, the popularity of decentralised decision making networks such as Bitcoin has seen a huge interest in making use of distributed ledger technology to store and securely disseminate end user identity credentials. In this paper we describe a mechanism that allows one to store the COVID-19 vaccination details of individuals on a publicly readable, decentralised, immutable blockchain, and makes use of a two-factor authentication system that employs biometric cryptographic hashing techniques to generate a unique identifier for each user. Our main contribution is the employment of a provably secure input-hiding, locality-sensitive hashing algorithm over an iris extraction technique, that can be used to authenticate users and anonymously locate vaccination records on the blockchain, without leaking any personally identifiable information to the blockchain.
Blockchain technology is attracting attention as an innovative system for decentralized payments in fields such as financial area. On the other hand, in a decentralized environment, management of a secret key used for user authentication and digital signature becomes a big issue because if a user loses his/her secret key, he/she will also lose assets on the blockchain. This paper describes the secret key management issues in blockchain systems and proposes a solution using a biometrics-based digital signature scheme. In our proposed system, a secret key to be used for digital signature is generated from the user's biometric information each time and immediately deleted from the memory after using it. Therefore, our blockchain system has the advantage that there is no need for storage for storing secret keys throughout the system. As a result, the user does not have a risk of losing the key management devices and can prevent attacks from malware that steals the secret key.
In the communication environment of smart homes, personal data, control messages, and sensitive data are transmitted through wireless sensor networks (WSNs). Therefore, to prevent an invasion of privacy, communication has to be encrypted, and the data have to be stored securely. In this paper, we propose a new secure privacy-preserving authentication scheme for smart homes. We propose the concept of non-interactive chaotic zero-knowledge proof (NCZKP) and use it for our scheme to resist ephemeral secrets leakage (ESL) impersonation attack, which assures that the adversary can extract the sensitive information stored in gateway note, and use it to impersonate as a legal user. Also, the formal security analysis Random-or-real model is used to prove that our scheme is secure against different known attacks. In the end, according to the experiment, our scheme has low computation and communication costs compare with other related schemes.
Moses Arhinful Acquah, Na Chen, Jeng‐Shyang Pan, Hong-Mei Yang · 5 authors
Biometrics, with its uniqueness to every individual, has been adapted as a security authentication feature by many institutions. These biometric data are processed into templates that are saved on databases, and a central authority centralizes and controls these databases. This form of storing biometric data, or in our case fingerprint template, is asymmetric and prone to three main security attacks, such as fake template input, template modification or deletion, and channel interception by a malicious attacker. In this paper, we secure an encrypted fingerprint template by a symmetric peer-to-peer network and symmetric encryption. The fingerprint is encrypted by the symmetric key algorithm: Advanced Encryption Standard (AES) algorithm and then is uploaded to a symmetrically distributed storage system, the InterPlanetary File system (IPFS). The hash of the templated is stored in a decentralized blockchain. The slow transaction speed of the blockchain has limited its use in real-life applications, such as large file storage, hence, the merge with IPFS to store just the hashes of large files. The encrypted template is uploaded to the IPFS, and its returned digest is stored on the Ethereum network. The implementation of IPFS prevents storing the raw state of the fingerprint template on the Ethereum network in order to reduce cost and also prevent identity theft. This procedure is an improvement of previous systems. By adopting the method of template hashing, the proposed system is cost-effective and efficient. The experimental results depict that the proposed system secures the fingerprint template by encryption, hashing, and decentralization.
Open access
Biometric Identification and Security
Advanced Steganography and Watermarking Techniques
Morampudi Mahesh Kumar, Munaga V. N. K. Prasad, U. S. N. Raju
Multi‐biometric systems have been widely accepted in various applications due to its capability to solve the limitations of unimodal systems. Directly storing the biometric templates into a centralised server leads to privacy concerns. In the past few years, many biometric authentication systems based on homomorphic encryption have been introduced to provide security for the templates. Most of the existing solutions rely on an implication of the assumption that the server is ‘honest‐but‐curious’. Therefore, the compromise of server results into the entire system vulnerability and fails to provide the integrity. To address this, we propose a novel multi‐instance iris authentication system, BMIAE to deal with malicious attacks over the transmission channel and at the untrusted server. BMIAE encrypt the iris templates using ElGamal encryption to guarantee confidentiality and Smart contract running on a Blockchain helps to achieve the integrity of templates and matching result. BMIAE also addresses the limitations of using Blockchain for biometrics like privacy and expensive storage. To check the effectiveness and robustness, BMIAE has experimented on CASIA‐V3‐Interval, IITD and SDUMLA‐HMT iris databases. Experimental results show that BMIAE provides improved accuracy, and eliminates the need to trust the centralised server when compared to the state‐of‐the‐art approaches.
Open access
Biometric Identification and Security
User Authentication and Security Systems
Advanced Steganography and Watermarking Techniques
Oscar Delgado-Mohatar, Julián Fiérrez, Rubén Tolosana, Rubén Vera-Rodríguez
Blockchain technologies provide excellent architectures and practical tools for securing and managing the sensitive and private data stored in biometric templates, but at a cost. We discuss opportunities and challenges in the integration of blockchain and biometrics, with emphasis in biometric template storage and protection, a key problem in biometrics still largely unsolved. Key tradeoffs involved in that integration, namely, latency, processing time, economic cost, and biometric performance are experimentally studied through the implementation of a smart contract on the Ethereum blockchain platform, which is publicly available in github for research purposes.
National security is a top priority to mitigate intrusions and criminal acts. Governments require robust national surveillance system that can cover all geographical areas, including the blind spots that may hold violence and criminal incidents' triggers i.e. malls, stadiums, airports, and other key sites. Integrating existing surveillance infrastructures rather than creating centralized solutions will have great potential on scalability as well as providing more liberal framework that is not run by a single point of control. However, this definitely requires establishing secure communication and mutual trust amongst these entities, which is a real challenge. Towards this end, we propose an efficient smart surveillance architecture that combines machine learning and Blockchain technologies to facilitate the exchange of relevant surveillance events as admitted transactions into a permissioned Hyperledger fabric Blockchain. We conducted comprehensive analysis to demonstrate the feasibility of blockchain and the efficiency of the machine learning-based face recognition and matching for real-time surveillance of suspects using heterogeneous surveillance infrastructure. The proposed architecture proved scalability and real-time behavior after putting the system through multiple test cases. With very high matching accuracy, and end-to-end latency of less than 12.8 seconds, the system proves to be scalable, and fast enough for a smart surveillance use case.
Kevin Putra Dirgantoro, Jae Min Lee, Dong‐Seong Kim
This paper proposes a face recognition for security system based on artificial intelligence and edge computing with a limited dataset. Generative adversarial networks (GANs) are used to manipulate the dataset in order to overcome the accuracy issue of the limited dataset. The average accuracy of GANs outperforms the limited dataset up to 92.79%. Edge computing is used to overcome a high latency of cloud computing with Jetson Nano board, which produces an average of 8.8 frame-per-second. Furthermore, the detected face will make a payment using a smart contract to the blockchain network with low static difficulty to open a gate or door's lock. In comparison, a low static difficulty outperforms the Proof-of- Work consensus algorithm in terms of transaction time around 33-39 milliseconds.
Face recognition and analysis
Biometric Identification and Security
Advanced Steganography and Watermarking Techniques
In recent years, due to the rapid development of information techniques and network technologies, more and more medical documents have been replaced by electronic files for sharing and transmitting in real time. However, medical data transmitted over public communication channels may suffer from security attacks and privacy threats. Blockchain technology has been gotten many attentions in different areas due to its unique properties such as anonymity, verifiability, immutability and decentralization. In order to secure patient privacy and provide more personal healthcare services, in this paper, we propose a data aggregation scheme based on Blockchain technology for medical environments. Moreover, in order to implement remote medical monitoring, we design a group authentication mechanism for multiple authorized users (such as patient, doctors, caregivers, family and friends) to freely access patient's personal health records. The authorized group members in a group will agree on a group session key and use it to protect patient's sensitive information. In case of a new member joins the medical group or an old member leaves the medical group, the group session key needs to be updated at any time. Finally, the electronic medical system will become more secure, reliable and useful by our proposed scheme.
Recently, application scenario of crowdsourcing IoT has covered to e-healthcare service, smart home, smart city, internet of vehicles due to the proliferation of smart devices such as smart mobile devices, smart wearable device, smart medical devices and smart furniture, etc. Patient's data collected by the smart devices send to the various remote medical servers. A group of medical professionals remote access patient data stored at the medical server database. Smart home users want to remote real-time access information of smart devices at home. All these operations need via wireless remote communication, which is suffering from various kinds of threat and attacks. Hence, there are a large number of multi-factor remote authentication and key agreement schemes designed for the application of crowdsourcing IoT. However, in most existing related multi-factor schemes, all factors for identity authentication only act as a parameter for encrypting the local secret key. In this paper, we propose a new secure remote multi-factor authentication scheme that includes three factors: 1) user identity; 2) password; and 3) user biometrics, which are authenticated by the remote server, act as a part of the secret key and participate in the key agreement process. We choose the chaotic map since it has a smaller key size and lower computational overhead, and then achieve remote multi-factor authentication and key agreement by artfully employ it to zero-knowledge technology and the fuzzy extractor technology. Our scheme is more secure and robust since the user revealing nothing sensitive information, and the adversary cannot impersonate any user even if he gets the server's master key. We have done security proof for our proposed scheme using the Random-Or-Real(ROR) model, Burrows-Abadi-Needham (BAN) logic, and ProVerif 2.00 to show that the presented scheme is secure. Also, we give an additional security analysis for other various attacks. Finally, according to the test and simulation result, the proposed scheme is very suitable for the power-constrained smart devices, and in the next generation 5G communication environment, its applicability and usability will be greatly enhanced.
The Internet of things (IoT), as an extension of the Internet, has become a trend of network development nowadays. In order to protect the integrity and authenticity of the information in the IoT, an identity authentication protocol applied to the networked devices is designed in this paper, using the physical unclonable function (PUF) to extract the uniqueness and tamper resistance of the randomness in the manufacturing process of the physical device. We propose the protocol including the database, accessed devices, access devices and users in the specific network environment. Relying on the unique identification information generated by the PUF embedded in devices and passwords set by users, devices and users identities could be verified through zero-knowledge proofs. The performance analysis and the experiment at the end of this work show that our protocol provides users with a strong security guarantee for IoT devices.
Physical Unclonable Functions (PUFs) and Hardware Security
User authentication can rely on various factors (e.g., a password, a cryptographic key, biometric data) but should not reveal any secret or private information. This seemingly paradoxical feat can be achieved through zero-knowledge proofs. Unfortunately, naive password-based approaches still prevail on the web. Multi-factor authentication schemes address some of the weaknesses of the traditional login process, but generally have deployability issues or degrade usability even further as they assume users do not possess adequate hardware. This assumption no longer holds: smartphones with biometric sensors, cameras, short-range communication capabilities, and unlimited data plans have become ubiquitous. In this paper, we show that, assuming the user has such a device, both security and usability can be drastically improved using an augmented password-authenticated key agreement (PAKE) protocol and message authentication codes.
Blockchain has been emerging as a promising technology that could totally change the landscape of data security in the coming years, particularly for data access over Internet-of-Things and cloud servers. However, blockchain itself, though secured by its protocol, does not identify who owns the data and who uses the data. Other than simply encrypting data into keys, in this paper, we proposed a protocol called Biometric Blockchain (BBC) that explicitly incorporate the biometric cues of individuals to unambiguously identify the creators and users in a blockchain-based system, particularly to address the increasing needs to secure the food logistics, following the recently widely reported incident on wrongly labelled foods that caused the death of a customer on a flight. The advantage of using BBC in the food logistics is clear: it can not only identify if the data or labels are authentic, but also clearly record who is responsible for the secured data or labels. As a result, such a BBC-based solution can great ease the difficulty to control the risks accompanying the food logistics, such as faked foods or wrong gradient labels.
Images are critical part of investigations, they are referred to and regarded, to gather information, document and create “memory” of a crime scene. Crime scene images are considered as vital criminal evidence in the court of law; hence, it is imperative that the authenticity of such images be maintained and that they be verifiable. The advancement in technology in this digitally proliferated era allows for easy doctoring of crime scene images. Digital watermarking, and blockchain have been used in other research works to authenticate and verify digital content or digital documents. In this paper we propose the use of watermarking and cryptographic blockchain to validate forensic crime scene images.
Advanced Steganography and Watermarking Techniques
Mehmet Aydar, Salih Cemil Cetin, Serkan Ayvaz, Betul Aygun
The disruptive technology of blockchain can deliver secure solutions without the need for a central authority. In blockchain protocols, assets that belong to a participant are controlled through the private key of an asymmetric key pair that is owned by the participant. Although, this lets blockchain network participants to have sovereignty on their assets, it comes with the responsibility of managing their own keys. Currently, there exists two major bottlenecks in managing keys; $a)$ users don't have an efficient and secure way to store their keys, $b)$ no efficient recovery mechanism exists in case the keys are lost. In this study, we propose secure methods to efficiently store and recover keys. For the first, we introduce an efficient encryption mechanism to securely encrypt and decrypt the private key using the owner's biometric signature. For the later, we introduce an efficient recovery mechanism using biometrics and secret sharing scheme. By applying the proposed key encryption and recovery mechanism, asset owners are able to securely store their keys on their devices and recover the keys in case they are lost.
Oscar Delgado-Mohatar, Julián Fiérrez, Rubén Tolosana, Rubén Vera-Rodríguez
We explore practical tradeoffs in blockchain-based biometric template storage. We first discuss opportunities and challenges in the integration of blockchain and biometrics, with emphasis in biometric template storage and protection, a key problem in biometrics still largely unsolved. Blockchain technologies provide excellent architectures and practical tools for securing and managing the sensitive and private data stored in biometric templates, but at a cost. We explore experimentally the key tradeoffs involved in that integration, namely: latency, processing time, economic cost, and biometric performance. We experimentally study those factors by implementing a smart contract on Ethereum for biometric template storage, whose cost-performance is evaluated by varying the complexity of state-of-the-art schemes for face and handwritten signature biometrics. We report our experiments using popular benchmarks in biometrics research, including deep learning approaches and databases captured in the wild. As a result, we experimentally show that straightforward schemes for data storage in blockchain (i.e., direct and hash-based) may be prohibitive for biometric template storage using state-of-the-art biometric methods. A good cost-performance tradeoff is shown by using a blockchain approach based on Merkle trees.
Recently, blockchain has been a disruptive technology for many systems, such as finance, e-health, supply-chain, and etc. Secure access to blockchain is the grand challenge for many systems. Key management is one of challenges to ensure secure access to blockchain. In this paper, we propose a framework for secure accessing to blockchain via multi-factor authentication. We combine both biometric and password authentications to secure private keys of users. The framework contains a secure device which has a biometric sensor to ensure secure access to private keys that extends the usability for secure accessing to blockchain.
Oscar Delgado-Mohatar, Julián Fiérrez, Rubén Tolosana, Rubén Vera-Rodríguez
Blockchain technology has become a thriving topic in the last years, making possible to transform old-fashioned operations to more fast, secured, and cheap approaches. In this study we explore the potential of blockchain for biometrics, analyzing how both technologies can mutually benefit each other. The contribution of this study is twofold: 1) we provide a short overview of both blockchain and biometrics, focusing on the opportunities and challenges that arise when combining them, and 2) we discuss in more detail blockchain for biometric template protection.
In this paper we propose a novel system for identity verification by amalgamating online signature verification, machine learning, IOT and blockchain to garner their potentials to cope up and to contain this risk of identity theft specifically in the case of online transactions. In this system signals of roll, pitch and yaw values retrieved from MPU6050 sensor (Inertial Measurement Unit) are analysed using Digital Time Wrapping to obtain DTW minimum distance to verify the identity of the user. In case of cryptocurrencies, we propose a system where private key is not stored anywhere but the same unique private key, assigned to the user by Blockchain, is generated every time with the help of method incorporating biometrics and machine learning. The required data will then be sent to blockchain with the help of IOT system to complete the transaction.