Partially distributed identity verification method
The partially distributed identity verification method addresses the inefficiency and security concerns of conventional methods by using encrypted biometric data and distributed decryption and masking across distinct devices, achieving fast and secure identity verification in systems with a single database.
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- IDEMIA PUBLIC SECURITY FRANCE
- Filing Date
- 2023-03-01
- Publication Date
- 2026-05-15
AI Technical Summary
Conventional identity verification methods, such as the Colmade process, suffer from excessive execution time and require centralized steps that are inefficient and potentially insecure due to the calculation of scores in plaintext.
A partially distributed identity verification method that calculates a numerical score using encrypted biometric data points through a decryption and masking process across distinct devices, ensuring security by never calculating the score in plaintext, and combining partial results to achieve a control result.
The method significantly reduces execution time while maintaining security by using encrypted biometric data and distributed calculations, allowing rapid verification without exposing plaintext scores, and can be implemented in systems with a single database.
Smart Images

Figure 00000020_0000 
Figure 00000020_0001 
Figure 00000020_0002
Abstract
Description
Title of the invention: Partially distributed identity control method FIELD OF INVENTION
[0001] This disclosure relates to an identity verification process. STATE OF THE ART
[0002] A conventional method for verifying whether an individual is enrolled in a database comprises the following steps. A test biometric data point relating to the individual to be checked is acquired. Then, a score representing the distance between the test biometric data point and a reference biometric data point contained in the database is calculated. This score is then compared with a threshold. A control result indicating whether the test biometric data point corresponds to the reference biometric data point is obtained from this comparison.
[0003] In the document entitled "Colmade: Collaborative Masking in Auditable Decryption for BFV-based Homomorphic Encryption," a process based on this general principle was described, with the following particularities. First, the Colmade process calculates the score and compares it to a threshold in the cipher domain. Second, the Colmade process includes centralized steps and steps distributed across several entities: these entities perform calculations in parallel, producing partial results, which are then recombined to arrive at the audit result.
[0004] However, the execution time of the Colmade process proves to be long. Description of the invention
[0005] One object of the invention is to verify whether an individual is enrolled in a database without requiring excessive execution time and in a secure manner.
[0006] This goal is achieved by a process comprising the following steps: • Calculation of a numerical score representing the distance between a test biometric data point relating to an individual and a reference biometric data point, the numerical score being previously calculated from the test biometric data point and a numerical value of the reference biometric data point, the numerical value of the reference biometric data point resulting from encryption of the reference biometric data point using a primary encryption key, • For i being equal to 1 and 2, implementation of the following steps by a device with index i: • application of a decryption and masking process to encrypted score using a secondary decryption key of index i and a secondary mask of index i, the decryption and masking process producing data representing the score in a decrypted form masked by a primary mask, without having calculated the score in plaintext, generation of a partial result of index i from the data and a demasking data of index i associated with the secondary mask of index i, in which: The devices with respective indices 1 and 2 are distinct, The secondary decryption keys with respective indices 1 and 2 are derived from a primary decryption key associated with the encryption key. The secondary masks with respective indices 1 and 2 are derived from the primary mask.
[0007] In the proposed method, the step of calculating the score is a centralized step that is much faster to execute than the centralized step performed in the Colmade method. The inventors have observed that this centralized step in com Combining treatments distributed across at least one pair of participating devices allows for a more rapid control result. than with the Colmade process, with equal computing resources. In particular, the masking performed provides security because the score in plain text is never calculated.
[0008] Another advantage of the proposed method is that it can be implemented in a system where the reference biometric data is stored in a single database. data. This is an advantage compared to processes requiring the combined use of several different databases.
[0009] The proposed method may also include the following features, taken alone or combined with each other whenever possible.
[0010] Preferably, the decryption and masking process implemented by the device of index i comprises the following steps: • Calculation of an intermediate value of index i from the following data: the first part of the score figure, the secondary decryption key with index i, the secondary mask with index i, and a hazard generated by the index i device, reception of an intermediate data point with index j sent by the device with index j^i, calculation of the data representing the score in a deciphered form using
[0011]
[0012]
[0013]
[0014]
[0015]
[0016]
[0017]
[0018] the secondary decryption key (sk) with index i, then masked by the mask, from the following data: • the intermediate data for respective indices 1 and 2, • a second part of the score figure. Preferably, the intermediate data point with index i is calculated as follows: • in which • Csb is the first part of the score number, • ( sk ) .est the secondary decryption key with index i, • ( r ) is the secondary mask with index i, ' i • ei is the randomness generated by the device with index i. Preferably, the data representing the score in a decrypted form using the secondary decryption key (sk) of index i and then masked using the primary mask is calculated as follows: Jz in which is the intermediate data point with index 1, is the intermediate data point with index 2, Y / 2 • This is the second part of the score number. • 1 and # are two integers that constitute parameters of a scheme of Brakerski / Fan-Vercauteren encryption, • [ ... ] denotes the operator for rounding to the nearest integer, * [ ... ] denotes the modulo q operator, * [ .. ■ ] denotes the modulo t operator. Preferably, the control result is equal to the sum of the partial results of respective indices 1 and 2. Preferably, at least one of the following data points is a single-use data point for the biometric test data, or even for the score number: • the secondary mask with index i, • the unmasking data with index i, • the secondary decryption key with index i. Preferably, the calculation of the score number is a linear or polynomial calculation. Preferably, • the calculation of the encrypted value is implemented by a server separate from the devices with indices 1 and 2, and / or • The output result is calculated from the partial results of respective indices 1 and 2 by an output device separate from the index devices 1 and 2.
[0019] A computer program product is also proposed, comprising program code instructions for executing the steps of the proposed process when this program is executed by a device or set of devices. A computer-readable memory is further proposed, storing instructions executable by a device for executing the steps of the proposed process.
[0020] A system comprising is also proposed: • a server configured to calculate a cipher of a score representing a distance between a test biometric data relating to an individual and a reference biometric data, the score cipher being previously calculated from the test biometric data and a cipher of the reference biometric data, the cipher of the reference biometric data resulting from an encryption of the reference biometric data using a primary encryption key, • two devices with respective indices 1 and 2, in which, for i equal to 1 and 2, the device with index i is configured to: • apply a decryption and masking process to the encrypted score using a secondary decryption key with index i and a secondary mask with index i, the decryption and masking process producing data representing the score in a decrypted form masked by a primary mask, without having calculated the score in plaintext, • generation of a partial result of index i from the data and a demasking data of index i associated with the secondary mask of index i, • in which: • The secondary decryption keys with respective indices 1 and 2 are derived from a primary decryption key associated with the encryption key, • Secondary masks with respective indices 1 and 2 are derived from the primary mask, • the partial results of respective indices 1 and 2 allow the calculation of a control result indicating whether the test biometric data corresponds or not to the reference biometric data. DESCRIPTION OF THE FIGURES
[0021] Other features, objectives and advantages of the invention will become apparent from the following description, which is purely illustrative and not limiting, and which should be read in conjunction with the accompanying drawings on which:
[0022] Fig. 1 and Fig. 2 schematically illustrate different devices forming part of a system according to one embodiment, usable for controlling the identity of individuals.
[0023] Fig. 3 is a flowchart of steps of an identity control process according to one embodiment.
[0024] Throughout the figures, similar elements bear identical references. DETAILED DESCRIPTION OF THE INVENTION System for verifying an individual's identity
[0025] With reference to [Fig.1] and [Fig.2], a system comprises a control device 1, a storage server 2, and at least one pair of participating devices 3, a trust server 4 and an enrollment device 6.
[0026] The control device 1 includes a processor 10, a communication interface 12 for communicating with the storage server 2 and each participating device, a memory 14 and a biometric sensor 16.
[0027] The processor 10 is configured to implement certain steps of a process that will be described later. The processor can have any structure. The processor comprises one or more cores, each core being configured to execute the code instructions of a program in such a way as to implement the aforementioned steps.
[0028] The communication interface 12 is for example of the wireless radio type, and uses any communication protocol (Wi-Fi, Bluetooth, etc.).
[0029] The memory 14 is adapted to store data manipulated or produced by the processor. The memory 14 is of any type. Conventionally, the memory comprises volatile memory for storing data temporarily, and non-volatile memory for storing data persistently, that is, in a way that retains the data when the non-volatile memory is powered off.
[0030] The biometric sensor 16 is configured to acquire biometric data relating to individuals. For example, the biometric sensor includes a camera configured to acquire images showing an individual's face and to extract biometric data from such images. Alternatively or in addition, the biometric sensor includes a fingerprint sensor and / or an iris scanner.
[0031] In one embodiment, the control device 1 further comprises a gate 18 that can be closed to prevent an individual from accessing a secure area, and opened to allow such access. The processor 10 is configured in this case to control the opening and closing of the gate 18. For example, the control device 1 is located in an airport, and the secure area is a boarding area; in this particular application, the individuals wishing to access the boarding area are the passengers of a flight, whose identity must be verified before boarding.
[0032] The storage server 2 includes a processor 20, a communication interface 22 for communicating with the control device 1, and a memory 24. The information provided above about the processor 10 and the communication interface 12 is also applicable to the processor 20 and the communication interface 22.
[0033] Memory 24 stores a confidentially protected biometric database. The database contains biometric data relating to previously enrolled individuals. The biometric data of an enrolled individual is not stored in plain text in the database, but is instead confidentially protected; that is, it is encrypted using an encryption method that will be described later.
[0034] Each participating device 3 includes a processor 30, a communication interface 32 for communicating with the control device 1 and / or the other participating devices 3, and a memory 34. The information provided above concerning the processor 10 and the communication interface 12 also applies to the processor 30 and the communication interface 32. Communications between interfaces 12, 22 and communications between interfaces 12, 32 may use the same or different protocols.
[0035] The participating devices 3 are distinct from one another. In what follows, we will detail an embodiment in which the participating devices 3 are distinct from the control device 1, the storage server 2, the enrollment device 4, and the enrollment device 6, as shown in [Fig. 1]. However, in other embodiments, it may be envisaged that the control device 1, the storage server 2, the enrollment device 4, and / or the enrollment device 6 constitute one of the participating devices 3.
[0036] The function of the trust server 4 is to generate cryptographic keys, some of which are used by other system components. The trust server 4 comprises a processor 40, a communication interface 42 for communicating with the enrollment device 6 and with each participating device 3, and a memory 44. The information provided above concerning the processor 10, of The communication interface 12 and the memory 14 are also applicable to the processor 40, the communication interface 42 and the memory 44.
[0037] The enrollment device 6 comprises a processor 60, a communication interface 62 for communicating with the trust server 4 and with the storage server 2, a memory 64, and a biometric sensor 66. The information provided above concerning the processor 10, the communication interface 12, the memory 14, and the biometric sensor 16 also applies to the processor 60, the interface 62, the memory 64, and the biometric sensor 66. In the following, an embodiment in which the enrollment device 6 is distinct from the control device 1 will be detailed. However, in other embodiments, the control device 1 could be used as the enrollment device. Key generation
[0038] The following steps are implemented on a preliminary basis within the system.
[0039] The processor 40 of the trust server 4 generates a pk encryption key and a The associated decryption key sk, the two keys forming a cryptographic key pair, typically an asymmetric key pair. The keys are, for example, randomly generated.
[0040] The keys pk, sk are stored in memory 44.
[0041] Trust server 4 sends the encryption key pk to the enrollment device; this key is therefore a public key. The decryption key sk, on the other hand, is a private key specific to trust server 4 and is therefore not communicated outside of trust server 4. Enrollment
[0042] It is assumed that a reference individual to be enrolled presents themselves near the enrollment device 6. In practice, the reference individual may be an individual who has been granted access to the secure area discussed previously. When the control device 1 is located in an airport, the secure area may provide access to an aircraft, in which case the right to access the secure area is conferred by a travel pass issued to the reference individual.
[0043] The biometric sensor 66 of the enrollment device 6 acquires a reference biometric data yu relating to the reference individual.
[0044] The processor 60 encrypts the reference biometric data yu using the encryption key pk, so as to obtain a ciphertext Cy« of the biometric data yu. Denoting BFV£ncrÇ) the encryption function used in this step, we have:
[0045] Cy< - BFVencr (yu, pk)
[0046] In particular, it is possible to use during this step an encryption according to the Brakerski / Fan-Vercauteren (BFV) scheme.
[0047] The cipher Cy« is transmitted by the enrollment device 6 to the storage server 2 via the communication interface 62.
[0048] The storage server receives the encrypted Cy» via its communication interface 22, and adds it to the database contained in its memory 24. The reference individual is then enrolled.
[0049] The preceding steps are repeated by the enrollment device 6 for several reference individuals to be enrolled, whereby the database contained in memory 24 stores a plurality of ciphertexts relating to different reference individuals. Each time, the same encryption key pk is used by the processor 60. Identity check
[0050] With reference to [Fig. 3], a process carried out using the system comprises the following steps. Where it is referred to hereafter that the control device 1, the server 2, a participating device 3, or the trust server 4 implements a process, it will be understood that this process is more precisely implemented by the corresponding processor 10, 20, 30, 40.
[0051] It is assumed that an individual whose identity is to be checked presents himself near the control device 1. For example, the individual to be checked presents himself at a boarding gate of an airport where the control device 1 has been installed, with the intention of boarding a plane.
[0052] In a step 102, the biometric sensor 16 acquires a biometric data x relating to the individual to be checked. In the following, this biometric data x is called "test biometric data" in order to distinguish it from the reference biometric data discussed previously, the respective ciphers of which are stored by the storage server 2.
[0053] In a step 104, the control device 1 sends the biometric proof data x to the server 2, via the communication interface 12.
[0054] In a step 202, the server 2 receives the biometric proof data via the communication interface 22.
[0055] In a step 204, server 2 applies a BFVxlist process taking as input the test biometric data x and the cipher Cyu, the process producing the cipher Ev of a score J, this score s representing a distance between the test biometric data x and the reference biometric data yu:
[0056] q = BFVÂis^x, Cy)
[0057] The ciphertext calculation is performed during this step in the ciphertext domain. In other words, this step does not include calculating the score in plaintext. A person skilled in the art can use the homomorphic encryption methods known from the state of the technical.
[0058] The function BFV.dist( ) is preferably a linear or polynomial function.
[0059] For example, the distance represented by the score is a dot product between the test biometric data x and the reference biometric data yw. Thus, the cipher cs is the cipher of such a dot product.
[0060] In what follows, we will consider an embodiment in which the cipher cs of the score is presented in the form of a pair of data c\ c\ These two data constitute two different portions of the cipher.
[0061] In a step 206, the storage server sends the cipher C to the device 1 in response to the proof biometric data A.
[0062] In a step 106, the control device 1 receives the cipher C.
[0063] In step 108, the control device 1 sends to the trusted server 4 a query associated with the cipher F.
[0064] In step 110, the control device 1 sends the ciphertext C to each of the participating devices 3. Steps 108 and 110 can be carried out in any order or be simultaneous.
[0065] In a 402 step, the trust server 4 receives the request issued during step 108.
[0066] In a 404 step, the trust server 4 generates two secondary decryption keys (sk) , (sk)derived from the decryption key sk.
[0067] Furthermore, in a step 406, the trust server 4 generates a primary mask r. The primary mask r is generated by a function FSS.Setup(). The function FSSSetupO can, for example, be the FunshadeSetUfA function described in the document "Funshade: Functional Secret Sharing for Two-Party Secure Thresholded Distance Evaluation".
[0068] In a 408 step, the server generates: • two secondary masks (r), (derived from the primary mask r, and • two k2 unmasking data associated with them.
[0069] Steps 404 and 406 can be carried out in any order. In particular, step 404 can be performed before, during or after steps 406 and 408.
[0070] In a step 410 implemented for i being equal to 1 and 2, the trusted server 4 transmits to the participating device 3 of index i: • the secondary decryption key (sk), with index i, • the secondary mask (r) with index i, and • the unmasking data k, index i, which is associated with the secondary mask (r) of index i.
[0071] On the other hand, any index 1 data generated by the trust server 4 in steps 402, 404 is not sent to the participating device 3 of index 2, and vice versa.
[0072] For i being equal to 1 and 2, the participating device 3 of index i implements the following steps.
[0073] In a step 302, the participating device 3 of index i receives the cipher O.
[0074] In step 304, the participating device 3 with index i receives: • the secondary decryption key (sk). of index i, • the secondary mask (r) of index i, and • the unmasking data k( of index i, which is associated with the secondary mask (r) of index i.
[0075] Steps 302 and 304 can occur in any order, depending on how the control device 1 operates.
[0076] In step 306, the participating device 3 with index i applies a decryption and masking process ColMaskDecr() to the ciphertext cs of the score. This process produces a data point s representing the score in a decrypted form using the primary decryption key and then masked using the mask r. We can thus note:
[0077] §_ ColMaskDecr({sk(r} J
[0078] If the ciphertext C were decrypted using the primary decryption key sk, the score s would be obtained in plaintext. If a masking was then applied to the plaintext score ' using the primary mask r, the data l would be obtained.
[0079] However, the decryption and masking process ColMaskDecr() does not operate according to this sequence of operations. The decryption and masking process ColMaskDecr() has the particular property of arriving at the data $ without performing an intermediate calculation of the score 5 in plaintext.
[0080] We will now detail an embodiment of the decryption and masking process ColMaskDecr^ ) in which this property is obtained. In this embodiment, the cipher O of the score is presented in the form of a data pair c\ These two data constitute two different portions of the cipher (k.
[0081] The participating device 3 with index i calculates an intermediate data item with index 'Sb' i i from the following data: the Csb part of the cipher O, the secondary decryption key (sk) of index i, the mask (r) of index i, and a random number ei generated by the device of index i.
[0082] This calculation can be as follows:
[0083] (cK ). = (sk) +(r) + l ' 1
[0084] The participating device 3 with index i sends the intermediate data with index i to the other participating device 3 with index j^i. Furthermore, the participating device 3 index i receives an intermediate data / p \ of index j ^i produced by the other ' -¾ lj participating device with index j^i.
[0085] Ultimately, two intermediate data / \ \ are exchanged between the \ sb ! p ' ! y two participating devices 3 with respective indices 1 and 2.
[0086] The participating device 3 with index i calculates the data  from the intermediate data / \ / c>. \ , and from the part of the cipher (C) of the score. This calculation \ sb ! \ st> ! T can be done as follows:
[0087]
[0088]
[0089]
[0090] in which * (oj is the intermediate data point with index 1, • \ is the intermediate data point with index 2, ' ' 2 • Cs is the second part of the numerical value (C) of the score, • r and are two integers constituting parameters of a Brakerski / Fan-Vercauteren encryption scheme, • [ ... ] denotes the operator for rounding to the nearest integer, * [ • - • ] denotes the modulo q operator, * [ ... ] f denotes the modulo t operator. In this embodiment, we have: â = 5 + r In this equation, the = sign represents equality. Thus, the data s turns out to be equal to the sum of the score 5 in plaintext and the primary mask. However, this sum calculation is not the one implemented by the participating device 3 with index i. Moreover, the participating device 3 with index i is not aware of the primary mask r, but only of the secondary mask (r) derived from it.
[0091] In a step 308, the participating device 3 of index i calculates a partial result °> of index i from the data and the unmasking data kf of index i:
[0092] Oi = FSS.eval(s, ïq)
[0093] In a step 310, the participating device 3 of index i sends the partial result F to the control device 1.
[0094] The processing carried out by the participating device 3 of index i is complete.
[0095] As previously stated, the processing consisting of steps 302 to 310 is implemented twice: once by the participating device with index 1 and once by the participating device with index 2. Thus, two partial results °1, °2 are generated.
[0096] The pair of partial results °1, °2 has the property of allowing the calculation of a control result 0 indicating whether the test biometric data x corresponds or not to the reference biometric data. On the other hand, it is not possible to calculate this control result on the basis of only one of the two partial results °\ ^2.
[0097] In a step 112, the control device 1 receives the two partial results °1, °2 respectively generated and sent by the two participating devices 3.
[0098] In step 114, the control device 1 calculates the control result 0 from the two partial results °1, °2 received. As indicated above, the control result indicates whether the test biometric data corresponds to the reference biometric data.
[0099] In one embodiment, the control result 0 is obtained by summing the partial results, as follows:
[0100] « = «, + «2
[0101] Ultimately, the cryptographic processing performed jointly by the two participating devices 3 and the control result calculation step o represent a comparison between a threshold and the distance between the test biometric data and the reference biometric data. The threshold is defined in the FSS.SetupO function used for generating the primary mask r, the secondary decryption keys, and the unmasking data (the threshold is, in a way, encoded by this data).
[0102] In practice, the result of control 0 can be a boolean.
[0103] If the control result 0 indicates that the biometric test data corresponds to the reference biometric data, then it is considered that the individual to whom the test biometric data xa relates has previously been enrolled with server 2. Under these conditions, the processor 10 can command in a step 116 an opening of the gate 18, in order to allow the individual to access a secure area.
[0104] If the control result indicates that the test biometric data does not correspond to the reference biometric data, then it is considered that the individual being checked is not the reference individual to whom the reference biometric data yu relates.
[0105] The preceding steps (in particular those implemented by the participating devices 3) can be implemented U times for different ciphers stored by the storage server 2, and relating to different reference biometric data. These U implementations can be sequential. Alternatively, We can therefore launch U processes in parallel, each implementing steps 202 to 116 described previously, and aggregate the final results at step 308 (therefore ",=The?" ou à ré,ape 114 (donc "=LJ"
[0106] The process described above may be subject to other variations.
[0107] It will be noted that in the embodiment of the process shown in [Fig. 3] and As discussed so far, new masks, new demasking data, and new secondary decryption keys are generated at steps 404 and 408 each time a score cipher is generated during an implementation of step 204. Thus, for i equal to 1 and 2, the associated secondary mask with index i, demasking data with index i, and secondary decryption key with index i constitute one-time-use data for a particular cipher calculated during an implementation of step 204. This embodiment is particularly robust to replay attacks.
[0108] In another embodiment, the data generated in steps 404, 408 could be single-use data for a proof biometric data item x, implying that this data is reused several times for different reference users referenced in the database of the storage server 2, during an identity check of the individual to whom x relates. In this other embodiment, the control device 1 can request the generation of new single-use data from the trust server 4 each time a new proof biometric data item x is acquired.
[0109] Although this is advantageous in terms of security, the secondary mask index i, the demasking data index i and the associated secondary decryption key index i may not be single-use data.
[0110] Furthermore, it has been assumed up to this point that the data provided by server 4 (secondary keys, masks, unmasking data) are generated after the receipt of biometric data x. However, this is not mandatory. Alternatively, this data can be generated during the preliminary phase in which the pk and sk keys are generated and stored in the respective memories of the participating devices 3 in advance, therefore before the acquisition of biometric data x. Thus, all or part of steps 404, 406, 408, 410, and 304 can occur before step 102 (in which case, step 108 is not implemented, nor is step 402).
[0111] In a particularly advantageous embodiment, only one pair of participating devices 3 with respective indices 1 and 2 is used. The inventors have found that this embodiment is simple to implement, while also being reasonably fast and secure. However, it is also possible to use several pairs of participating devices implementing the method described above. The indices of the participating devices 3 of a pair are exchanged only between the dis- positive participants 3 of said pair. Furthermore, for each pair of devices by For participants 3, the sum of the partial results of the pair is equal to the control result °. In contrast, the trust server 4 can provide different participant pairs with different secondary keys and different masking / unmasking data. The benefit of using multiple pairs of devices 3 is to provide redundancy to ensure that no pair has made a calculation error, for example, in the event of an attack.
[0112] In the foregoing, a particular application of the identity verification method has been discussed, in which the result of the verification determines access to a secure area. It is understood, however, that the described method can be used for other applications.
Claims
1. Demands A process comprising: • calculation (204) of a cipher (^) of a score representing a distance between a test biometric data (x) relating to an individual and a reference biometric data (?«), the cipher (c0 of the score being previously calculated from the test biometric data and a cipher (C v«) of the reference biometric data, the cipher of the reference biometric data resulting from an encryption of the reference biometric data (yu) using a primary encryption key (pk), • for i being equal to 1 and 2, implementation of the following steps by a device with index i: • application (306) of a decryption and masking process to the ciphertext (cs) of the score using a secondary decryption key ({sk}.) of index i and a secondary mask ({r} ) of index i, the decryption and masking process producing a data (S) representing the score in a decrypted form masked by a primary mask (r), and this without having calculated the score in plaintext, • generation (308) of a partial result (°0 of index i from the data (î) and a demasking data (&0 of index i associated with the secondary mask ( ( r ).) of index i, • in which: • The devices with respective indices 1 and 2 are distinct, • The secondary decryption keys ( (sk} , {sk} J with respective indices 1 and 2 are derived from a primary decryption key (sk) associated with the encryption key (pk), • secondary masks ((r) , ^n^ces respective 1 and 2 are derived from the primary mask (z ), • the partial results (°i, °2) of respective indices 1 and 2 allow the calculation of a control result ( <?) indiquant si la donnée biométrique d’épreuve corresponds or does not correspond to the reference biometric data.
2. A method according to the preceding claim, wherein the decryption and masking process implemented by the device of index i comprises the following steps: calculation of an intermediate data point) of index i to based on the following data: • a first part (Cs.'>) of the numerical value (f3) of the score, • the secondary decryption key ( ( sk ).) with index i, • the secondary mask ({r}) of index i, and • a random event (e0) generated by the device with index i, reception of an intermediate data point (^A) with index j sent by the index device j^i, calculation of the data (i) representing the score in a deciphered form using the secondary decipherment key (sk) of index i then masked by the mask (?), from the following data: intermediate data ( / \ ) \ \ / 2 of respective indices 1 and 2, a second part (6¾) of the numbered (c?) of the score.
3. A method according to the preceding claim, wherein the intermediate data le- \ of index i is calculated as follows: +{r) +e, • in which • Csi> is the first part of the cipher (c0 of the score, • (sk) is the secondary decryption key index i, • ( r} is the secondary mask with index i, • e> is the randomness generated by the device with index i.
4. A method according to any one of claims 2 and 3, wherein the data (J) representing the score in a form deciphered using the secondary decipherment key (sk) of index i and then masked using the primary mask (r) is calculated as follows: r 2= l[^-u+(¾ ) + (¾} LL 1 Jr • where • (r* \ is the intermediate data of index 1, • ( r- \ is the intermediate data of index 2, ' / 2 • ca is the second part of the ciphertext (^) of the score, • ? and 7 are two integers constituting parameters of a Brakerski / Fan-Vercauteren cipher scheme, • ] denotes the nearest integer rounding operator, * [ ... ] denotes the modulo q operator, * [ ... ] denotes the modulo t operator.
5. Method according to any one of the preceding claims, in the control result (°) is equal to the sum of the partial results (°i' ^2) of respective indices 1 and 2.
6. A method according to any one of the preceding claims, wherein at least one of the following data is a single-use data for the biometric proof data (x), or even for the cipher (cv) of the score: • the secondary mask of index i, • the unmasking data of index i, • the secondary decryption key of index i.
7. A method according to any one of the preceding claims, wherein the calculation of the score digit (cs) is a linear or polynomial calculation.
8. A method according to any one of the preceding claims, in which • The calculation of the cipher d is implemented by a server separate from the devices of indices 1 and 2, and / or • The output result is calculated from the partial results (°2) of respective indices 1 and 2 by an output device separate from the devices of indices 1 and 2.
9. Product computer program comprising program code instructions for carrying out the steps of the process according to any one of the preceding claims, when this program is executed by a system comprising the devices of respective indices 1 and 2.
10. Computer-readable memory storing instructions executable by a device for carrying out the steps of the process according to any one of claims 1 to 8.
11. System comprising: • a server (2) configured to calculate a cipher (c0) of a score representing a distance between a test biometric data (x) relating to an individual and a reference biometric data () "), the cipher (69) of the score being previously calculated from the test biometric data and a cipher (Cy ") of the reference biometric data, the cipher of the reference biometric data resulting from an encryption of the reference biometric data ()'M) using a primary encryption key (pk), • two devices (3) of respective indices 1 and 2, wherein for i being equal to 1 and 2, the device of index i is configured to: • apply a decryption and masking process to the cipher (f3) of the score using a secondary decryption key ((sk).) of index i and a secondary mask ((r) ) of index i, the decryption and masking process producing a data (i) representing the score in a decrypted form and masked by a primary mask (r), and this without having calculated the score in plain text, • generation of a partial result (^) of index i from. of the data ($) and a demasking data (£,) of index i associated with the secondary mask ((r).) of index i, in which: • the secondary decryption keys ((sk) , (sk) J with respective indices 1 and 2 are derived from a primary decryption key (sk) associated with the encryption key (pk), • the secondary masks ( (r) , (r) J with respective indices 1 and 2 are derived from the primary mask (r), • the partial results (°i, °2) of respective indices 1 and 2 allow the calculation of a control result (°) indicating whether the test biometric data corresponds or not to the reference biometric data.