METHOD AND SYSTEM FOR PROCESSING BIOMETRIC DATA
The method addresses the privacy and security concerns in biometric authentication by using functional encryption to securely compare biometric data without exposing the original data, ensuring secure and privacy-friendly authentication.
Patent Information
- Application Number
- FR2021005268
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2021-05-20
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-05-20
AI Technical Summary
Existing biometric authentication systems face challenges in ensuring the privacy and security of reference biometric data, as the entity with access to the decryption key can potentially misuse the data and perform unauthorized operations.
The method employs functional encryption, using a functional encryption public key to encrypt candidate biometric data and generating functional decryption private keys for polynomial functions parameterized with personal reference data, allowing secure comparison without exposing the original data.
This approach ensures secure and privacy-friendly authentication by preventing the exposure of biometric data and limiting operations to those consented by users, while maintaining system efficiency and reliability.
Smart Images

Figure 00000017_0000 
Figure 00000017_0001
Abstract
Description
Title of the invention: METHOD AND SYSTEM FOR PROCESSING BIOMETRIC DATA FIELD OF THE INVENTION
[0001] The invention relates to a method for processing personal data, for the comparison between a candidate personal data item and at least one reference personal data item. STATE OF THE ART
[0002] Identification or authentication schemes are already known in which a user presents to a trustworthy processing unit, for example to a unit belonging to a customs office, an airport, etc., a freshly acquired biometric data item on the user which the unit compares with one or more reference biometric data items recorded in a database to which it has access.
[0003] This database gathers the reference biometric data of authorized individuals (such as passengers on a flight before boarding).
[0004] Such a solution provides satisfaction, but poses the problem of the confidentiality of the reference biometric database to guarantee the privacy of users. It is therefore mandatory to encrypt this database.
[0005] To avoid any manipulation of the biometric data in clear text, homomorphic encryption can be used and the processing on the biometric data (typically distance calculations) can be carried out in the encrypted domain. A homomorphic cryptographic system allows certain mathematical operations to be carried out on previously encrypted data instead of the clear text data. Thus, for a given calculation, it becomes possible to encrypt the data, perform certain calculations associated with said given calculation on the encrypted data, and decrypt them, obtaining the same result as if said given calculation had been performed directly on the clear text data.
[0006] Thus the custodian of the private key of the homomorphic cryptographic system can then obtain the desired result of the identification or authentication of an individual.
[0007] However, even if this depositary is a trusted entity, it has the ability with this key to decrypt the biometric data, which remains problematic.
[0008] In addition, the depository may perform mathematical operations on the previously encrypted data, other than those to which the users who presented their biometric data have consented.
[0009] It would therefore be desirable to have a simple, reliable, secure, and totally privacy-friendly solution for identifying / authenticating an individual. PRESENTATION OF THE INVENTION
[0010] According to a first aspect, the invention relates to a method for processing personal data, characterized in that it comprises the implementation by a system of steps of: a. Functional encryption of a candidate personal data using a functional encryption public key; b. For at least one personal reference data, functional decryption of the encrypted candidate biometric data using a functional decryption private key for a polynomial function of degree 1 or 2 parameterized with said personal reference data.
[0011] According to advantageous and non-limiting characteristics:
[0012] Said polynomial function of degree 1 or 2 parameterized with said personal reference data is a distance function with said personal reference data.
[0013] The method comprises a step (aO) of generating said private functional decryption key for said polynomial function of degree 1 or 2 parameterized with said personal reference data, from a master key and said personal reference data.
[0014] Said functional decryption private key for the distance function with said personal reference data is generated by applying said distance function between said master key and said personal reference data.
[0015] Step (aO) comprises generating said functional encryption public key from said master key.
[0016] Step (aO) comprises generating said master key; obtaining at least one personal reference data item; and, for each personal reference data item obtained, generating the functional decryption private key for said polynomial function of degree 1 or 2 parameterized with said personal reference data item, so as to constitute a functional decryption private key base.
[0017] Said personal data is biometric data, wherein step (a) comprises obtaining said candidate biometric data from a biometric trait using biometric acquisition means of the system.
[0018] Said functional encryption public key is entrusted to an authority controlling the implementation of step (a).
[0019] Said system comprises a hardware security module, the authority making available to the hardware security module the functional encryption public key to implement step (a).
[0020] Step (aO) comprises storing said functional encryption public key in a hardware security module of the authority for implementing step (a).
[0021] Said system comprises a security hardware module storing said functional decryption private key for the polynomial function of degree 1 or 2 parameterized with said personal reference data and implementing step (b).
[0022] Step (aO) comprises storing said functional decryption private key base in said security hardware module, in particular by instantiating a binary with said functional decryption private keys.
[0023] Said system comprises a data processing module implementing step (a), the encrypted candidate biometric data being transmitted to the security hardware module.
[0024] Said system comprises a security hardware module (10), step (b) further comprising the processing by said security hardware module (10) of the result of the polynomial function so as to obtain another data representative of the result of a comparison between the candidate personal data and the reference personal data.
[0025] Said security hardware module is an enclave of the data processing module, such as an SGX enclave.
[0026] According to a second aspect, the invention proposes a biometric data processing system, characterized in that it is configured for the implementation of steps of: a. Functional encryption of a candidate personal data using a functional encryption public key; b. For at least one personal reference data, functional decryption of the encrypted candidate biometric data using a functional decryption private key for a polynomial function of degree 1 or 2 parameterized with said personal reference data.
[0027] According to a third and a fourth aspect, the invention provides a computer program product comprising code instructions for executing a method according to the first aspect of processing biometric data; and a storage means readable by computer equipment on which a computer program product comprises code instructions for executing a method according to the first aspect of processing biometric data. DESCRIPTION OF FIGURES
[0028] Other characteristics, aims and advantages of the present invention will appear on reading the detailed description which follows, with regard to the appended figures, given as non-limiting examples and in which: - [Fig.l]: [Fig.l] schematically represents a preferred embodiment of a system for implementing a method according to the invention; - [Fig.2]: [Fig.2] illustrates the steps of an embodiment of a method according to the invention. DETAILED DESCRIPTION
[0029] Architecture
[0030] With reference to [Fig.l], a system 1 for processing personal data is schematically represented for implementing a method for processing personal data for the authentication / identification of individuals.
[0031] This system 1 is equipment owned and controlled by an entity with whom the authentication / identification must be carried out, for example a government entity, customs, a company, etc. In the remainder of this description, the example of an airport will be taken, the system 1 typically aiming to control the access of passengers on a flight before their boarding.
[0032] By personal data, we mean in particular biometric data (and we will take this example in the remainder of this description), but we will understand that it can be any data specific to an individual on the basis of which a user can be authenticated, such as alphanumeric data, a signature, etc.
[0033] Conventionally, the system 1 comprises a data processing module 11, i.e. a computer such as, for example, a processor, a microprocessor, a controller, a microcontroller, an FPGA, etc. This computer is adapted to execute code instructions to implement, where appropriate, part of the data processing which will be presented below.
[0034] The system 1 also comprises a data storage module 12 (a memory, for example flash) and advantageously a user interface 13 (typically a screen), and biometric acquisition means 14 (see below).
[0035] Furthermore, the system 1 advantageously comprises at least one hardware security module 10, in English "Hardware Security Module" or simply HSM (in French we also find the name "Transactional Black Box" or BNT). This is a device considered to be tamper-proof offering cryptographic functions, which can be for example a PCI plug-in electronic card on a computer or an external SCSI / IP box, but also a secure enclave of the data processing module 11. The hardware security module 10 can be controlled by an authority, see below.
[0036] The system 1 can be arranged locally (for example in the airport), but can be separated into one or more remote servers hosting the electronic components (modules 10, 11, 12) connected to the biometric acquisition means 14 which must necessarily remain on site (at the gate for boarding control). In the example of [Fig.l], the storage module 12 is remote.
[0037] In the preferred biometric embodiment, the system 1 is capable of generating a so-called candidate biometric data from a biometric trait of an individual. The biometric trait may for example be the shape of the face, or one or more irises of the individual. The extraction of the biometric data is implemented by processing the image of the biometric trait which depends on the nature of the biometric trait. Various image processing operations for extracting biometric data are known to those skilled in the art. By way of non-limiting example, the extraction of the biometric data may comprise an extraction of particular points or a shape of the face in the case where the image is an image of the face of the individual.
[0038] The biometric acquisition means 14 typically consist of an image sensor, for example a digital camera or a digital camera, adapted to acquire at least one image of a biometric trait of an individual, see below.
[0039] Generally speaking, there will always be a candidate personal data item and at least one reference personal data item to compare, if alphanumeric personal data are used the candidate data item can simply be entered on the means 13 or for example obtained by optical reading from an image.
[0040] If the data storage module 12 generally stores a personal reference database, that is to say at least one personal data item “expected” from an authorized individual, for example the passengers registered for the flight, as will be seen this is not necessarily the case in the present invention, and it will be possible to be satisfied with a private decryption key base each associated with a personal reference data item (and from which it is constructed - it is not necessary to keep the biometric reference data item afterwards), but not allowing one to go back to this personal reference data item. This is also very advantageous in terms of data storage size.
[0041] In all cases, each personal reference data item is advantageously data recorded in an identity document of the individual. For example, the personal data item may be biometric data obtained from an image of the face appearing on an identity document (for example a passport), or from an image of the face or at least one iris of the individual recorded in a radiofrequency chip contained in the document.
[0042] As will be seen, the invention is distinguished in that said private decryption keys, and in general all the cryptographic keys that will be used, are those of an asymmetric cryptosystem called functional (FE, Functional Encryption). There is a pair of a set of private functional decryption keys (one for each reference biometric data) preferentially stored in the hardware security module 10 or the base of the storage module 12, and a public encryption key.Functional encryption is a generalization of asymmetric encryption in which the use of the private decryption key on encrypted data makes it possible not to find the original data, but the result of applying a given function to said original data, in particular a polynomial function of degree 1 or 2, preferably a distance function, and in particular at least one scalar product as will be seen later, i.e. functional encryption of the IPFE type (inner-product functional encryption). It is understood that functional encryption "restricts" the result of the decryption since it is no longer possible to go back to the original data, which will be cleverly used in the present invention.
[0043] In mathematical terms, if we denote c Enc(pk, x) the encryption of the data x with the public key pk of functional encryption, and y Dec(sk (f), c) the decryption of the ciphertext c with the private key 5 k (f) of functional encryption for the function / (here a scalar product), then y=f(x).
[0044] Those skilled in the art may further implement any known technique to provide additional security properties, for example by hiding the inputs.
[0045] In one embodiment, the system 1 implements an authentication of the individual, that is to say compares the so-called candidate personal data (freshly acquired on the individual in the case of biometric data, or otherwise simply requested from the individual if it is alphanumeric data for example), to a single reference personal data, supposed to come from the same individual, in order to verify that the individual from whom the two data were obtained is indeed the same.
[0046] In another embodiment, the system 1 implements an identification of the individual, that is to say compares the candidate personal data to all the reference personal data of said base, in order to determine the identity of the individual.
[0047] The system 1 may finally comprise access control means (for example an automatic door P in [Fig.l]) controlled according to the result of the authentication / identification: if an authorized user is recognized, access is authorized. Said biometric acquisition means 14 may be directly mounted on said access control means.
[0048] Enrollment
[0049] The personal reference database may have been created in advance. For example, passengers may have presented their identity document in advance, so as to generate a database stored in the storage module 12.
[0050] The present invention proposes to use functional encryption for a polynomial function of degree 1 or 2 parameterized with a personal reference data item. It is thus understood that there are as many different functions as there are personal reference data items. Preferably, said polynomial function parameterized with a personal reference data item is a “distance with the personal reference data item” function, thus making it possible to compare the input of the function with the personal reference data item, and preferably the “scalar product with the personal reference data item” function, even if other distance functions could be used, for example the Euclidean distance which is of degree 2.
[0051] Thus, if we take as input data a data to be compared with the personal reference data, the result of the functional decryption of this encrypted data is directly the result (in clear) of the application to this input data of the polynomial function of degree 1 or 2 parameterized with the personal reference data, i.e. the distance of this data with said personal reference data. It is thus sufficient to have several private decryption keys each associated with a personal reference data (skl, sk2...) in order to be able to calculate the polynomial function for each personal reference data, i.e. distances with all these personal reference data as many different functions.
[0052] Noting: - ref i the i-th personal reference data, - can a candidate personal data, - fi =freji said polynomial function of degree 1 or 2 parameterized with ref h - ti=st (fi) the functional decryption key for the function / ,, then if the polynomial function is a distance function we have:
[0053] Dec(ski, Enc(pk, can)) = / , (can) = d(can, ref t).
[0054] Preferably, the private decryption key(s) associated with each personal reference data item are generated on the fly from said personal reference data item, so that the personal reference data item is not stored (which avoids any risk of disclosure, and is also very economical in terms of storage size), and a base of private decryption keys is directly constituted rather than said personal reference database. For example, each private decryption key is directly generated upon reading the corresponding identity document.
[0055] In this respect, with reference to [Fig.2], the method preferably begins with a step (aO), called enrollment, of generation of said private functional decryption key for the polynomial function of degree 1 or 2 parameterized with said personal reference data, from a master key and said personal reference data.
[0056] Indeed, functional encryption provides this possibility of using a secret master key, and in the case of a distance function, said private functional decryption key for the distance function with said personal reference data is typically generated as the distance (obtained by the application of said distance function) between said master key and said personal reference data, eg by at least one scalar product between said master key and said personal reference data if said function is the scalar product.
[0057] Step (aO) may also comprise the generation of said functional encryption public key from the same master key, which makes it possible to have associated public and private keys.
[0058] It is possible to have a single master key stored in a very secure manner, for example only in the security hardware module 10, but alternatively there is a master key per “session”, i.e. per group of identifications / authentications. For example, in the case of passenger control before boarding, there is a master key per flight, which can be drawn from a list, generated randomly, etc.
[0059] Thus, in a particularly preferred manner, step (aO) comprises the generation of said master key; obtaining at least one personal reference data item; and, for each personal reference data item obtained, the generation of the functional decryption private key for the polynomial function of degree 1 or 2 parameterized with said personal reference data item, so as to constitute a base of functional decryption private keys. The public key is also generated at the same time.
[0060] To limit the use of the public key and / or private keys, it / they are advantageously entrusted to an authority (for example governmental), and / or stored in step (a0) in one (or more) hardware security module 10 (which can therefore be a hardware security module 10 controlled by said authority), although as explained it is possible to simply use the storage module 12 in particular for the private keys. Preferably and as will be seen, on the one hand the public key is entrusted to an authority and on the other hand the private keys are stored in the hardware security module 10 (by instantiating a binary with the private keys), which the authority controls via the public key.
[0061] Method for processing personal data
[0062] The method itself begins with a step (a) of functional encryption of a candidate personal data using said functional encryption public key.
[0063] It is important to understand that if enrollment can be implemented well before authentication / identification itself, in the biometric case the candidate data must be obtained at worst a few minutes before, to guarantee the “freshness” of this candidate data.
[0064] The functional encryption public key is preferably entrusted to an authority so that the latter can control the implementation of step (a). This is quite paradoxical because this key remains a public key (and not a private key) which alone does not allow anything to be decrypted, but as will be explained later, the present method is distinguished in that it has a single public key and numerous private keys, rather than the reverse, hence the fact that it may be interesting to protect this public key in particular to prevent any intentional use by a third party who would try to obtain information on said polynomial function. Thus this control by an authority can be exercised by means of the hardware security module 10, i.e.it is the authority which makes the public key available to the module 10 to implement step (a), or it is a security module 10 of the authority which directly stores the functional decryption public key for implementing step (a).
[0065] It is of course entirely possible, in addition or as an alternative, to entrust the private functional decryption keys to this authority.
[0066] The objective of entrusting the public key (rather than the private keys) is also so that the authority can verify before its use that the person submitting the fresh candidate data is indeed a natural person.
[0067] As explained, the system 1 further comprises biometric acquisition means 14 for obtaining said candidate biometric data. Generally, the candidate biometric data is generated by the data processing module 11 from a biometric trait provided by the biometric acquisition means 14, but the biometric acquisition means 14 may comprise their own processing means and for example take the form of an automatic device provided by the control authorities (in the airport) to extract the candidate biometric data. Such a device may, if necessary, encrypt the candidate biometric data on the fly, advantageously directly with the functional encryption public key. Thus, the candidate biometric data are also completely protected.
[0068] Preferably, the biometric acquisition means 14 are capable of detecting the living, so as to ensure that the candidate biometric data comes from a “real” trait.
[0069] In the case where the means 14 and the rest of the system are remote, the communication between the two can itself be encrypted.
[0070] The present method is distinguished, as explained, in a very original manner in that no comparison is actually made between the candidate personal data and the reference personal data. However, a result is obtained from this comparison, and this without the personal data having been accessible once.
[0071] Indeed, in the following step (b), we simply functionally decrypt the encrypted candidate biometric data using the functional decryption private key for the polynomial function of degree 1 or 2 parameterized with said personal reference data: thanks to the properties of functional encryption, the result is not the candidate biometric data in clear, but directly the result of the application to the candidate biometric data of the polynomial function of degree 1 or 2 parameterized with the personal reference data, for example their scalar product, which is indeed the result of their comparison.
[0072] It is noted that basing the private decryption key on the reference data and not the candidate data (i.e. it is indeed a functional decryption key for the polynomial function of degree 1 or 2 parameterized with the personal reference data, and not with the personal candidate data) is counter-intuitive, because this requires having as many private decryption keys as reference data whereas usually the public key is used to encrypt the reference data, which requires calculating the functional private key associated with each candidate data to perform the associated comparison, but this solution proves to be very reliable and makes it possible to eliminate the risks and the high storage size inherent in the storage of a personal reference database.
[0073] This step (b) is implemented for at least one personal reference data item, advantageously for each personal reference data item, i.e. if there is a base of private functional decryption keys, the cipher of the candidate personal data item is decrypted independently as many times as there are private keys in the base, the result of said decryption is thus the result of the application to the candidate biometric data item of each polynomial function of degree 1 or 2 parameterized with a personal reference data item, i.e. the scalar product with each personal reference data item in the preferred embodiment.
[0074] This step (b) is typically implemented by the hardware security module 10 if it is the one that stores the private keys.
[0075] Step (b) may further comprise processing the result of the polynomial function (i.e. the result of the decryption of the encrypted candidate personal data) so as to obtain another data item, in particular a data item representative of the result of said comparison. Generally speaking, this data item representative of the result of said comparison is a result of identification / authentication of the individual, i.e. typically a Boolean of belonging to the base.
[0076] Indeed, the individual is authenticated if the decryption reveals a similarity rate between the candidate data and the “target” reference data exceeding a certain threshold, the definition of which may depend on the calculated distance. In such an embodiment, the system 1 (and more specifically the hardware security module 10 if it is the one that performs this processing, it may very well be the module 11) can return the boolean depending on whether the threshold is exceeded, or directly the similarity rate (or another score calculated from said similarity rate, for example a discrete “level” of similarity to limit the quantity of information, or a normalized version, or even slightly noisy).
[0077] In the case of an identification, the system 1 can return for example the different similarity rates / scores associated with each reference data, or the identifiers of the reference data(s) for which the similarity rate exceeds said threshold.
[0078] For other types of personal data, for example alphanumeric, the reference data and the candidate data must be identical, so that a boolean can be returned directly indicating whether this is the case.
[0079] Generally, any data representative of the result of the comparison may be used as output data. Note that said data representative of the result of the comparison may be directly this result of the comparison (for example the value of the distance).
[0080] In the preferred embodiment in which a hardware security module 10 stores the public key and / or the private keys and implements step (a) and / or step (b) respectively, the person skilled in the art may draw inspiration from the IRON architecture using the SGX system to enable all the calculations previously mentioned (i.e. distances, normalizations, thresholds, etc.) to be carried out easily and securely, see the document Ben Fisch, Dhinakaran Vinayagamurthy, Dan Boneh, Sergey Gorbunov: IRON: Functional Encryption using Intel SGX, which describes how the attestation of a function (instantiated by its binary) is signed to ensure that its execution is limited to this particular function. In IRON, the operand data of the function are encrypted under a classic public key whose private decryption key becomes available upon presentation of the valid signature of this local attestation.
[0081] Here the originality is that it is preferentially the reverse: it is the public encryption key that the authority can make available or use when conditions are respected, for example when the other checks linked to identification have passed (check of an identity document, of the living during the acquisition of the candidate personal data, etc.), to control the implementation of step (a).
[0082] Indeed, the public key makes it possible to control the encryption of the candidate personal data and therefore the use of each private decryption key. More precisely, if the public key is entrusted to an authority, its implementation for encryption is carried out under its control in a first module 10. In parallel, the binary with the private encryption keys can be instantiated in a second module 10, and the public encryption key can be requested from the authority not the private decryption keys but the public encryption key.If the above-mentioned conditions are verified, the authority makes available the public key of the first module 10 and the latter can encrypt the candidate personal data (step (a)) and send it to the second module 10 to execute the binary (step (b)), so as to obtain each result, for example each distance, and where appropriate said other data representative of the result of said comparison (its calculation after the decryption(s) can be defined in the binary) in a totally secure manner.
[0083] SGX in fact allows: - the creation of a secure enclave isolated in confidentiality and integrity from other processes running on the same data processing module; in particular from the underlying OS, - certification that calculations have been carried out in the given secure enclave, - the possibility of preserving the code and the data of the secure enclave.
[0084] Finally, the method advantageously further comprises a step (c) of implementing an access control based on the result of the functional decryption of the encrypted candidate biometric data, i.e. of said data representative of the result of said comparison. In other words, if the individual to whom the candidate personal data belongs has been correctly identified / authenticated, he is “authorized” and other actions such as the opening of the automatic door P can occur.
[0085] Computer program product
[0086] According to a third and a fourth aspect, the invention relates to a computer program product comprising code instructions for the execution (in particular on the data processing module 11 and / or the security hardware module 10 of the system 1) of a method according to the first aspect of the invention, as well as storage means readable by computer equipment (a data storage module 12 of the system 1 and / or a memory space of the security hardware module 10) on which this computer program product is found.
Claims
Claims
1. Method for processing personal data, characterized in that it comprises the implementation by a system (1) of steps of: (aO) generation of a master key, obtaining a plurality of reference personal data and, for each of the reference personal data of the plurality of reference personal data, generation of a functional decryption private key for a polynomial function of degree 1 or 2 parameterized with the reference personal data, from the master key and the reference personal data considered, so as to constitute a base of functional decryption private keys; a. Functional encryption of a candidate personal data item using a functional encryption public key, the candidate personal data item being a biometric data item of an individual; b.For at least one of the reference personal data, functional decryption of the encrypted candidate personal data using the functional decryption private key for the polynomial function of degree 1 or 2 parameterized with the considered reference personal data, the functional decryption private key being included in the functional decryption private key base.
2. Method according to claim 1, wherein said one polynomial function of degree 1 or 2 parameterized with said personal reference data is a distance function with said personal reference data, in particular a scalar product with said personal reference data.
3. A method according to claims 1 and 2 in combination, wherein said functional decryption private key for the distance function with said personal reference data is generated by applying said distance function between said master key and said personal reference data.
4. Method according to one of claims 1 to 3, wherein step (aO) comprises generating said functional encryption public key from said master key.
5. Method according to one of claims 1 to 4, in which step (a) comprises obtaining said candidate biometric data from a biometric trait using biometric acquisition means (14) of the system (1).
6. Method according to one of claims 1 to 5, in which said functional encryption public key is entrusted to an authority controlling the implementation of step (a).
7. A method according to claim 6, wherein said system (1) comprises a hardware security module (10), said authority making available to the hardware security module (10) the functional encryption public key for implementing step (a).
8. Method according to one of claims 1 to 7, wherein said system (1) comprises a hardware security module (10) storing said private functional decryption key for the polynomial function of degree 1 or 2 parameterized with said personal reference data and implementing step (b).
9. A method according to claims 1 and 8 in combination, wherein step (aO) comprises storing said functional decryption private key base in said hardware security module (10), in particular by instantiating a binary with said functional decryption private keys.
10. Method according to one of claims 1 to 9, in which said system (1) comprises a hardware security module (10), step (b) further comprising the processing by said hardware security module (10) of the result of the polynomial function so as to obtain another data representative of the result of a comparison between the candidate personal data and the reference personal data.
11. Biometric data processing system, characterized in that it is configured for implementing steps of: (aO) generation of a master key, obtaining a plurality of personal reference data, for each of the personal reference data of the plurality of personal reference data, generation of a private functional decryption key for a polynomial function of degree 1 or 2 parameterized with the personal reference data, from the master key and the personal reference data considered, so as to constitute a base of private functional decryption keys; a. Functional encryption of a candidate personal data item using a functional encryption public key, the candidate personal data item being a biometric data item of an individual; b. For a plurality of reference personal data items of the plurality of reference personal data items, functional decryption of the encrypted candidate personal data item using a functional decryption private key for the polynomial function of degree 1 or 2 parameterized with the considered reference personal data item, the functional decryption private key being included in the functional decryption key base.
12. Computer program product comprising code instructions for executing a method according to one of claims 1 to 10 for processing biometric data, when said method is executed on a computer.
13. Storage means readable by computer equipment on which a computer program product comprises code instructions for executing a method according to one of claims 1 to 10 for processing biometric data.