Evaluation of a template protection approach to integrate fingerprint biometrics in a PIN-based payment infrastructure

被引:9
作者
Breebaart, Jeroen [1 ]
Buhan, Ileana
de Groot, Koen [2 ]
Kelkboom, Emile [2 ]
机构
[1] Civolution, NL-5656 AE Eindhoven, Netherlands
[2] Philips Res, NL-5656 AE Eindhoven, Netherlands
关键词
ATMs; Authentication; Biometrics; Payment systems; PIN; Point of sale; Smart cards; GENERATE STRONG KEYS; FUZZY EXTRACTORS;
D O I
10.1016/j.elerap.2011.07.004
中图分类号
F [经济];
学科分类号
02 ;
摘要
Biometric authentication has a great potential to improve the security, reduce cost, and enhance the customer convenience of payment systems. Despite these benefits, biometric authentication has not yet been adopted by large-scale point-of-sale and automated teller machine systems. This paper aims at providing a better understanding of the benefits and limitations associated with the integration of biometrics in a PIN-based payment authentication system. Based on a review of the market drivers and deployment hurdles, a method is proposed in which biometrics can be seamlessly integrated in a PIN-based authentication infrastructure. By binding a fixed binary, renewable string to a noisy biometric sample, the data privacy and interoperability between issuing and acquiring banks can improve considerably compared to conventional biometric approaches. The biometric system security, cost aspects, and customer convenience are subsequently compared to PIN by means of simulations using fingerprints. The results indicate that the biometric authentication performance is not negatively influenced by the incorporation of key binding and release processes, and that the security expressed as guessing entropy of the biometric key is virtually identical to the current PIN. The data also suggest that for the fingerprint database under test, the claimed benefits for cost reduction, improved security and customer convenience do not convincingly materialize when compared to PIN. This result can in part explain why large-scale biometric payment systems are virtually non-existent in Europe and the United States, and suggests that other biometric modalities than fingerprints may be more appropriate for payment systems. (C) 2011 Elsevier B. V. All rights reserved.
引用
收藏
页码:605 / 614
页数:10
相关论文
共 68 条
[1]  
[Anonymous], 2006, 78132006 ISOIEC
[2]  
[Anonymous], P COMP VIS PATT REC
[3]  
[Anonymous], 2008, PROC BIOSIG BIOMETRI
[4]  
[Anonymous], 2009, BANKING AUTOMATION B
[5]  
[Anonymous], 2006, PROC 6 ICRASC
[6]  
[Anonymous], 2010, 24745 ISOIEC JTC1 SC
[7]  
[Anonymous], 2005, CONS ATT BIOM ID DOC
[8]  
Article 29 - Data Protection Working Party, 2003, WORK DOC BIOM
[9]  
Berkman O, 2007, LECT NOTES COMPUT SC, V4886, P224, DOI 10.1007/978-3-540-77366-5_20
[10]  
Bhatla TP., 2003, Understanding Credit Card Frauds