Title of article :
A Collusion Attack on the Fuzzy Vault Scheme.
Author/Authors :
Ting Poon, Hoi University of Ottawa. - School of Information Technology and Engineering, Canada. , Miri, Ali University of Ottawa. - School of Information Technology and Engineering, Canada.
Abstract :
The Fuzzy Vault scheme is an encryption scheme, which can tolerate errors in the keys. This leads to the possibility of enhancing the security in environments where these errors can be common, such as biometrics storage systems. Although several researchers have provided implementations, we find that the scheme is vulnerable to attacks when not properly used. This paper describes an attack on the Fuzzy Vault scheme where the attacker is assumed to have access to multiple vaults locked by the same key and where a non-maximal vault size is used. The attack effectively reduces the vault size by identifying and removing chaff points. As the vault size decreases, the rate at which chaff points are identifed increases exponentially. Several possible defences against the attack are also discussed.
Keywords :
Biometric Encryption , Fuzzy Vault , Vulnerability.
Journal title :
ISeCure - The ISC International Journal of Information Security
Journal title :
ISeCure - The ISC International Journal of Information Security