DNA fingerprinting is a cornerstone for human identification in forensics, where the sequence of highly polymorphic short tandem repeats (STRs) from an individual is compared against a DNA database. This presents significant privacy risks to individuals with DNA profiles in the database due to hacking by malicious attackers who may access the data and misuse it for secondary purposes. In this paper, we propose a novel cryptographic framework for jointly encrypting DNA-based fingerprints (STRs) with other biometric data, for example, facial images, such that the STRs and biometrics information of an individual are revealed only when a positive match is found, i.e. the STRs act as decryption keys. Specifically, when a search is performed on the encrypted database using STR sequences of an individual in the database, a perfect match generates the facial image and/ or other biometrics of the individual while the lack of a match returns a null result. By jointly encrypting DNA fingerprints and other biometrics using the unique STRs generated keys, our approach ensures perfect privacy of the encrypted information with decryption of only the record with STRs matching the query. This safeguards the information of other individuals in the same database. The proposed approach can also be used to securely authenticate the identity of individuals or biological material in scenarios beyond forensics including tracking the identity of samples for clinical genetics and cell therapies.
翻译:DNA指纹是法医中人类识别的基石,在法医中,个人高度多元短时间串联重复(STRs)的顺序与DNA数据库比较,这对数据库中具有DNA特征的个人构成重大隐私风险,因为恶意攻击者黑客可能访问数据并滥用数据进行二次用途。在本文件中,我们提议建立一个新型的加密框架,用于联合加密DNA指纹(STRs)和其他生物鉴别数据,例如面部图像,例如,只有在发现肯定匹配的情况下,才会披露个人的报告和生物鉴别信息,即,STRs作为解密钥匙。具体来说,当利用数据库中个人的STRs序列对加密数据库进行搜索时,一个完美的匹配可以产生个人的面部图像和/或其他生物鉴别结果,而缺乏匹配则可以产生无效的结果。通过联合加密DNA指纹和其他生物鉴别数据,我们的方法确保个人加密信息与解密信息完全保密,只有找到记录,只有与法医数据库中的记录进行解密,并且与法医特征的精确跟踪方法相匹配,这一信息也可以用于法医身份的安全性分析。