Voice authentication using short phrases: Examining accuracy, security and privacy issues
R. C. Johnson, Terrance E. Boult, Walter J. Scheirer · 2013
This paper examines a novel security model for voice biometrics that decomposes the overall problem into bits of “biometric identity security,” bits of “knowledge security,” and bits of “traditional encryption security.” This is the first paper to examine balancing security gained from text-dependent and text-independent voice biometrics under this model. Our formulation allows for text-dependent voice biometrics to address both what you know and who you are. A text-independent component is added to defeat replay attacks. Further, we experimentally examine an extension of the recently introduced Vaulted Voice Verification protocol and the security tradeoffs of adding these elements. We show that by mixing text-dependent with text-independent voice verification and by expanding the challenge-response protocol, Vaulted Voice Verification can preserve privacy while addressing the problematic issues of voice as a remote/mobile biometric identifier. The resulting model supports both authentication and key release with the matching taking place client side, where a mobile device may be used. This novel security model addresses a real and crucial problem: that of security on a mobile device.