论文标题
生物识别系统的安全
Security in biometric systems
论文作者
论文摘要
生物识别系统的目的是提供识别机制。这种标识机制可用于实现多个目标。最常见的是,与资源提供安全性有关,通常是对授权人员的身份验证或检测未经授权的人员的检测。从技术的角度来看,这两个目标可以包含在一个点中,因为大多数功能都是通过对所讨论系统数据库中先前确定的人进行搜索来实现的。在第一种情况下,将访问在数据库中输入的人员,在第二种情况下,访问权限是给未输入数据库的人。尽管这是两个最常见的攻击,但我们将在本章中讨论其他攻击。本章的结构如下。本章的第一部分概述了攻击的基本类型,并描述了通常的保护措施(第1、2和3节)。本章的第二部分描述了基于指纹,面部识别和虹膜识别的系统可以进行的几项攻击(第4和5节)。一旦描述了攻击方法,还将讨论一些特定的保护措施(第4节和第5节)。最后,描述了侧渠道攻击及其与其他可能的攻击结合使用的实用性(第6节)。
The objective of biometric systems is to provide an identification mechanism. This identification mechanism can be used to fulfil several objectives. The most common, related to providing security to a resource, is usually authentication or detection of authorized personnel and detection of unauthorized personnel. From the technical point of view, these two objectives can be included in a single point since most functionalities are achieved by making searches of people previously identified in the database of the system in question. In the first case access is given to people entered in the database and in the second case access is given to people who are not entered in the database. Although these are the two most common attacks there are also others that we will discuss in this chapter. The structure of the chapter is as follows. The first part of the chapter gives an overview of the basic types of attacks and describes the usual protection measures (Sections 1, 2 and 3). The second part of the chapter describes several attacks that can be made on systems based on fingerprinting, face recognition, and iris recognition (Sections 4 and 5). Once the attack methodologies have been described, some specific protection measures are also discussed (Sections 4 and 5). Finally, side channel attacks and their usefulness in combination with other possible attacks are described (Section 6).