Biometric matching involves storing and processing sensitive user information. Maintaining the privacy of this data is thus a major challenge, and homomorphic encryption offers a possible solution. We propose a privacy-preserving biometrics-based authentication protocol based on fully homomorphic encryption, where the biometric sample for a user is gathered by a local device but matched against a biometric template by a remote server operating solely on encrypted data. The design ensures that 1) the user's sensitive biometric data remains private, and 2) the user and client device are securely authenticated to the server. A proof-of-concept implementation building on the TFHE library is also presented, which includes the underlying basic operations needed to execute the biometric matching. Performance results from the implementation show how complex it is to make FHE practical in this context, but it appears that, with implementation optimisations and improvements, the protocol could be used for real-world applications.
翻译:生物测定匹配涉及储存和处理敏感的用户信息。因此,维护这些数据的隐私是一项重大挑战,同质加密提供了一种可能的解决办法。我们提议基于完全同质加密的基于隐私保存生物测定的认证协议,即用户的生物测定样本由本地设备收集,但与仅使用加密数据的远程服务器的生物测定模板相匹配。设计确保了(1)用户的敏感生物测定数据仍然保密,(2)用户和客户设备被安全地认证给服务器。还介绍了TFHE图书馆的验证概念实施,其中包括执行生物测定匹配所需的基本操作。执行的绩效结果表明,使FHE在这种背景下实际操作非常复杂,但随着实施优化和改进,协议似乎可用于现实世界应用程序。