{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:17:08Z","timestamp":1766441828094,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":39,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T00:00:00Z","timestamp":1763769600000},"content-version":"vor","delay-in-days":3,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["194691"],"award-info":[{"award-number":["194691"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"NWO (Dutch Research Council)","award":["VI.Vidi.193.066"],"award-info":[{"award-number":["VI.Vidi.193.066"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3744886","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:32:38Z","timestamp":1763854358000},"page":"3620-3634","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["May the Force\n                    <i>Not<\/i>\n                    Be With You: Brute-Force Resistant Biometric Authentication and Key Reconstruction"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-7019-884X","authenticated-orcid":false,"given":"Alexandra","family":"Boldyreva","sequence":"first","affiliation":[{"name":"Georgia Institute of Technology, Atlanta, GA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9370-3060","authenticated-orcid":false,"given":"Deep Inder","family":"Mohan","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology, Atlanta, GA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2179-6709","authenticated-orcid":false,"given":"Tianxin","family":"Tang","sequence":"additional","affiliation":[{"name":"Eindhoven University of Technology, Eindhoven, Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417287"},{"key":"e_1_3_2_1_2_1","unstructured":"Sohaib Ahmad Sixia Chen Luke Demarest Benjamin Fuller Caleb Manicke Alexander Russell and Amey Shukla. 2024. IrisLock: Iris Biometric Key Derivation with 42 bits of security. Cryptology ePrint Archive Paper 2024\/100. https:\/\/eprint.iacr.org\/archive\/2024\/100\/20241106:010157"},{"key":"e_1_3_2_1_3_1","volume-title":"Unconstrained Iris Segmentation Using Convolutional Neural Networks. In Computer Vision - ACCV 2018 Workshops, Gustavo Carneiro and Shaodi You (Eds.). Springer International Publishing, Cham, 450-466","author":"Ahmad Sohaib","year":"2019","unstructured":"Sohaib Ahmad and Benjamin Fuller. 2019. Unconstrained Iris Segmentation Using Convolutional Neural Networks. In Computer Vision - ACCV 2018 Workshops, Gustavo Carneiro and Shaodi You (Eds.). Springer International Publishing, Cham, 450-466."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Michael Armbrust Armando Fox Rean Griffith Anthony D. Joseph Randy H. Katz Andrew Konwinski Gunho Lee David A. Patterson Ariel Rabkin and Matei Zaharia. 2009. Above the Clouds: A Berkeley View of Cloud Computing. Technical Report.","DOI":"10.1145\/1721654.1721672"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-68379-4_2"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3380915"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626232.3653269"},{"key":"e_1_3_2_1_8_1","volume-title":"Deep Inder Mohan, and Tianxin Tang","author":"Boldyreva Alexandra","year":"2025","unstructured":"Alexandra Boldyreva, Deep Inder Mohan, and Tianxin Tang. 2025. May the Force not Be with you: Brute-Force Resistant Biometric Authentication and Key Reconstruction. Cryptology ePrint Archive, Paper 2025\/1211. https:\/\/eprint.iacr.org\/2025\/1211"},{"key":"e_1_3_2_1_9_1","volume-title":"Flynn","author":"Bowyer Kevin W.","year":"2016","unstructured":"Kevin W. Bowyer and Patrick J. Flynn. 2016. The ND-IRIS-0405 Iris Image Dataset. CoRR, Vol. abs\/1606.04853 (2016). arXiv:1606.04853 http:\/\/arxiv.org\/abs\/1606.04853"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/11426639_9"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-49890-3_5"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"crossref","unstructured":"S\u00edlvia Casacuberta Julia Hesse and Anja Lehmann. 2022. SoK: Oblivious Pseudorandom Functions. Cryptology ePrint Archive Report 2022\/302. https:\/\/eprint.iacr.org\/2022\/302","DOI":"10.1109\/EuroSP53844.2022.00045"},{"key":"e_1_3_2_1_13_1","unstructured":"Yu Chen and Yiling He. 2023. BrutePrint: Expose Smartphone Fingerprint Authentication to Brute-force Attack. arXiv:2305.10791 [cs.CR] https:\/\/arxiv.org\/abs\/2305.10791"},{"key":"e_1_3_2_1_14_1","volume-title":"32nd USENIX Security Symposium, USENIX Security 2023","author":"Chen Yu","year":"2023","unstructured":"Yu Chen, Yang Yu, and Lidong Zhai. 2023. InfinityGauntlet: Expose Smartphone Fingerprint Authentication to Brute-force Attack. In 32nd USENIX Security Symposium, USENIX Security 2023, Anaheim, CA, USA, August 9-11, 2023, Joseph A. Calandrino and Carmela Troncoso (Eds.). USENIX Association, 2027-2041. https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/chen-yu"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3487552.3487854"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-38551-3_11"},{"key":"e_1_3_2_1_17_1","volume-title":"Computer Security - ESORICS","author":"Oliveira Nunes Ivan De","year":"2023","unstructured":"Ivan De Oliveira Nunes, Peter Rindal, and Maliheh Shirvanian. 2024. Oblivious Extractors and\u00a0Improved Security in\u00a0Biometric-Based Authentication Systems. In Computer Security - ESORICS 2023, Gene Tsudik, Mauro Conti, Kaitai Liang, and Georgios Smaragdakis (Eds.). Springer Nature Switzerland, Cham, 290-312."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","unstructured":"Henry de Valence Jack Grigg Mike Hamburg Isis Lovecruft George Tankersley and Filippo Valsorda. 2023. The ristretto255 and decaf448 Groups. RFC 9496. https:\/\/doi.org\/10.17487\/RFC9496","DOI":"10.17487\/RFC9496"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-24676-3_31"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-78372-7_13"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2019.2961349"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-64834-3_26"},{"key":"e_1_3_2_1_23_1","first-page":"547","volume-title":"The Pythia PRF Service. In 24th USENIX Security Symposium (USENIX Security 15)","author":"Everspaugh Adam","year":"2015","unstructured":"Adam Everspaugh, Rahul Chaterjee, Samuel Scott, Ari Juels, and Thomas Ristenpart. 2015a. The Pythia PRF Service. In 24th USENIX Security Symposium (USENIX Security 15). USENIX Association, Washington, D.C., 547-562. https:\/\/www.usenix.org\/conference\/usenixsecurity15\/technical-sessions\/presentation\/everspaugh"},{"key":"e_1_3_2_1_24_1","volume-title":"USENIX Security","author":"Everspaugh Adam","year":"2015","unstructured":"Adam Everspaugh, Rahul Chatterjee, Samuel Scott, Ari Juels, and Thomas Ristenpart. 2015b. The Pythia PRF Service. In USENIX Security 2015, Jaeyeon Jung and Thorsten Holz (Eds.). USENIX Association, 547-562."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","unstructured":"Sebastian Faller Tobias Handirk Julia Hesse M\u00e1t\u00e9 Horv\u00e1th and Anja Lehmann. 2024. Password-Protected Key Retrieval with(out) HSM Protection. ACM CCS. https:\/\/doi.org\/10.1145\/3658644.3690358","DOI":"10.1145\/3658644.3690358"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-30576-7_17"},{"key":"e_1_3_2_1_27_1","unstructured":"GDPR.EU. 2020. GDPR compliance. https:\/\/gdpr.eu\/."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.3390\/cryptography8020014"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","unstructured":"Shay Gueron Adam Langley and Yehuda Lindell. 2019. AES-GCM-SIV: Nonce Misuse-Resistant Authenticated Encryption. RFC 8452. https:\/\/doi.org\/10.17487\/RFC8452","DOI":"10.17487\/RFC8452"},{"key":"e_1_3_2_1_30_1","unstructured":"Horizon.Research. 2024. Horizon Grand View Research. Global Biometric Technology Market Size & Outlook. https:\/\/www.grandviewresearch.com\/horizon\/outlook\/biometric-technology-market-size\/global."},{"key":"e_1_3_2_1_31_1","unstructured":"ISO.ORG. 2022. ISO\/IEC 24745:2022 Information security cybersecurity and privacy protection \u2014 Biometric information protection. https:\/\/www.iso.org\/standard\/75302.html."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/2897845.2897880"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","unstructured":"Stanislaw Jarecki Hugo Krawczyk and Jiayu Xu. 2018. OPAQUE: An Asymmetric PAKE Protocol Secure Against Pre-computation Attacks. In Advances in Cryptology - EUROCRYPT 2018 - 37th Annual International Conference on the Theory and Applications of Cryptographic Techniques Tel Aviv Israel April 29 - May 3 2018 Proceedings Part III (Lecture Notes in Computer Science Vol. 10822) Jesper Buus Nielsen and Vincent Rijmen (Eds.). Springer 456-486. https:\/\/doi.org\/10.1007\/978-3-319-78372-7_15","DOI":"10.1007\/978-3-319-78372-7_15"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10623-005-6343-z"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/3412841.3442131"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-30215-3_23"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-07085-3_23"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484746"},{"key":"e_1_3_2_1_39_1","volume-title":"Goldman","author":"Young Matthew R.","year":"2013","unstructured":"Matthew R. Young, Stephen J. Elliott, Catherine J. Tilton, and James E. Goldman. 2013. International Journal of Computer Science Engineering and Technology (IJCSET), Vol. 3, 2 (2013), 43-47."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Taipei Taiwan","acronym":"CCS '25"},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3744886","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3744886","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:13:07Z","timestamp":1766441587000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3744886"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":39,"alternative-id":["10.1145\/3719027.3744886","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3744886","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}