arXiv:2412.13099cs.CRcs.CV2024-12

揭示生物识别系统准确率瓶颈如何威胁安全,尤其在大规模数据库中。

Accuracy Limits as a Barrier to Biometric System Security

  • 分析未定向攻击下伪造用户所需尝试次数与数据库规模的关系。
  • 推导出保障安全所需的临界错误匹配率(FMR)和最大用户数阈值。
  • 指出当前系统在小规模数据库中已难满足安全需求,大库更严峻。

生物识别系统广泛用于身份验证与识别,其匹配过程依赖于新模板与注册模板间的相似性度量。错误匹配率(FMR)是评估系统准确性和可靠性的关键指标。本文基于FMR分析生物识别系统的安全性,主要贡献有二:一是研究未定向攻击——攻击者试图冒充数据库中任意用户,确定成功伪造所需的尝试次数,并推导出维持特定安全水平所允许的最大用户数(临界人口规模),以及随数据库增大所需达到的临界FMR值;二是重新审视生物识别生日问题,计算数据库中两人发生碰撞(可互相冒充)的近似与精确概率,进而得出在给定概率下限制碰撞发生的临界人口规模与临界FMR值。这些阈值为防范冒充与碰撞风险提供了设计依据。结果表明,当前生物识别系统即使在小规模数据库中也无法提供足够准确率以保障安全,而最先进的系统在数据库扩大时更难以应对生物识别生日问题。

原文摘要 · Abstract (English)

Biometric systems are widely used for identity verification and identification, including authentication (i.e., one-to-one matching to verify a claimed identity) and identification (i.e., one-to-many matching to find a subject in a database). The matching process relies on measuring similarities or dissimilarities between a fresh biometric template and enrolled templates. The False Match Rate FMR is a key metric for assessing the accuracy and reliability of such systems. This paper analyzes biometric systems based on their FMR, with two main contributions. First, we explore untargeted attacks, where an adversary aims to impersonate any user within a database. We determine the number of trials required for an attacker to successfully impersonate a user and derive the critical population size (i.e., the maximum number of users in the database) required to maintain a given level of security. Furthermore, we compute the critical FMR value needed to ensure resistance against untargeted attacks as the database size increases. Second, we revisit the biometric birthday problem to evaluate the approximate and exact probabilities that two users in a database collide (i.e., can impersonate each other). Based on this analysis, we derive both the approximate critical population size and the critical FMR value needed to bound the likelihood of such collisions occurring with a given probability. These thresholds offer insights for designing systems that mitigate the risk of impersonation and collisions, particularly in large-scale biometric databases. Our findings indicate that current biometric systems fail to deliver sufficient accuracy to achieve an adequate security level against untargeted attacks, even in small-scale databases. Moreover, state-of-the-art systems face significant challenges in addressing the biometric birthday problem, especially as database sizes grow.

生物识别安全评估错误匹配率攻击分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。