Method for processing personal data, associated system and computer program
The method optimizes the processing of personal data by using homomorphic encryption and parallel processing to reduce calculation times and memory usage, enhancing identification speed and capacity.
Patent Information
- Application Number
- FR2023006007
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2023-06-13
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2043-06-13
AI Technical Summary
Existing methods for processing personal data, particularly biometric data, in an encrypted domain are costly in terms of calculation time and memory space, limiting identification speed and the number of identifications that can be performed in a given time.
A method that processes personal data using a system with a database of homomorphically encrypted reference data, employing a homomorphic cryptographic scheme to determine distances between candidate and reference data through specific operations like Hadamard product and vector addition, optimizing calculations in the encrypted domain.
Reduces calculation times and memory consumption while maintaining identification efficiency, allowing for faster and more numerous identifications by leveraging parallel processing capabilities.
Smart Images

Figure 00000022_0000 
Figure 00000023_0000
Abstract
Description
Title of the invention: Method for processing personal data, associated system and computer program
[0001] The invention relates to a method for processing personal data. The invention also relates to a system and an associated computer program.
[0002] Identification schemes are already known in which a user presents to a trustworthy processing unit, for example to a unit belonging to a customs office, an airport, etc., a freshly acquired biometric data item on the user (called candidate biometric data item) which the unit compares with one or more reference biometric data items recorded in a database to which it has access.
[0003] This database gathers the reference biometric data of authorized individuals (such as passengers on a flight before boarding).
[0004] Such a solution provides satisfaction, but poses the problem of the confidentiality of the reference biometric database to guarantee the privacy of users.
[0005] To avoid any clear manipulation of biometric data, it is possible to use an encryption of a homomorphic cryptographic scheme and carry out the processing on the biometric data (typically distance calculations) in the encrypted domain. A homomorphic cryptographic scheme in fact makes it possible to carry out certain mathematical operations on previously encrypted data instead of the clear data. Thus, for a given calculation, it becomes possible to encrypt the data, carry out certain calculations associated with said given calculation on the encrypted data, and decrypt them, obtaining the same result as if said given calculation had been carried out directly on the clear data.
[0006] To limit the calculations in the encrypted domain while benefiting from a computer architecture with parallelism capacity, for example a SIMD architecture (abbreviation of "Single Instruction Multiple Data" in Anglo-Saxon terminology), which allows the same operation to be carried out on N data, a method is known for processing personal data implemented by a system storing a base of K personal reference data homomorphically encrypted in the form of reference cryptograms in a group provided with a first operation which is an addition, and a second operation which is a multiplication, the method comprising the determination in the encrypted domain, for each personal reference data item in the base, of a distance between the same candidate personal data item and said personal reference data item,said distance being a scalar product of the candidate personal data and said reference person data. The candidate personal data and each reference personal data are vectors of l components, and each reference cryptogram is a vector of N components, with K, N and / natural integers strictly greater than 1, and N a multiple of l. For this known method, each reference cryptogram is the image, by an encryption function of a homomorphic cryptographic scheme, of the concatenation of all components of 2L personal reference data.
[0007] This method determines in the encrypted domain distances between the candidate personal data and 2L reference personal data with the following steps: a) obtaining an intermediate cryptogram in the form of a vector of pluralities of / components, by applying a Hadamard product between a candidate cryptogram and the reference cryptogram associated with the JX data per reference numbers, the candidate cryptogram being the image by the encryption function, of the concatenation of IL iterations of the candidate personal data (i.e. iterations of all components of the personal data candidate), b) obtaining a final cryptogram in the form of a vector of pluralities of l components, each component of a plurality of l components of the final cryptogram, resulting from the application of the first operation between all the components of the same plurality of / components of the intermediate cryptogram.
[0008] However, this solution remains costly in terms of calculation time and memory space.
[0009] This restriction limits the identification speed and the number of identifications performed. readable in a given time.
[0010] To overcome these drawbacks, the present invention proposes, according to a first aspect, a method for processing personal data implemented by a system storing a base of K homomorphically encrypted personal reference data in the form of jxl reference cryptograms in a group provided with a first operation and a second operation, - said method comprising the determination in the encrypted domain, for each personal reference data item in the database, of a distance between the same candidate personal data item and said personal reference data item, and - where the first operation is an addition and the second operation is a multiplication, - for any P ranging from 1 to the personal reference data of rank P is a vector of / components having respective indices ranging from 1 to / , - for everything ? going beyond[ÆlxZ, the reference cryptogram of rank V is a vector of N components having respective indices ranging from 1 to N, and - the candidate personal data is a vector of / components having respective indices ranging from 1 to / , - with K, N and l natural integers strictly greater than 1, said method being characterized in that: - for all i ranging from I to T Æ 1 and for all j ranging from 1 to / , the reference cryptogram of rank (z - 1) x / + j , is the image, by an encryption function of a homomorphic cryptographic scheme, of the concatenation of the components of index j of each personal reference data having a rank between ix N - N + 1 and zx N, - for all i ranging from 1 to A., the determination in the numerical domain of the distances between the candidate personal data and each reference personal data having a rank between ix N - N + 1 and ix N, includes: a) for all j ranging from 1 to / , obtaining an intermediate cryptogram of rank (z - 1) x / + j in the form of a vector of N components, by applying a Hadamard product between the reference cryptogram of rank (i - 1) xl + j and a candidate cryptogram of rank j, the candidate cryptogram of rank j being the image by the encryption function, of the concatenation of N components each having the value of the component of index j of the candidate personal data, b) obtaining a final cryptogram of rank i in the form of a vector of N components, by applying a vector addition between the l intermediate cryptograms obtained, - the distance between the candidate personal data and a reference personal data of rank P being the antecedent by the encryption function of the component index p _ Q £ j _ XM of the final cryptogram of rank
[0011] According to advantageous and non-limiting characteristics: - the method further comprises a step of obtaining the [ K 1 x / cryptograms I A1 I of reference, during which for all i ranging from 1 to Æ j and for all j ranging from 1 to l, the reference cryptogram of rank (i - 1) x Z + j is obtained by application of the encryption function, to the concatenation of the components of index j of each personal reference data having a rank between ixN-N + 1 and ix N; - the data storage module stores the F Æ 1 x / cryptograms of reference ; - the j” Æ "jx / reference cryptograms constitute the homomorphically encrypted representation of the K personal reference data; - the method further comprises a step of obtaining candidate cryptograms, during which for all j ranging from 1 to / , the candidate cryptogram of rank j is obtained by applying the encryption function to the concatenation of N components each having the value of the component of index j of the candidate personal data; - the candidate's personal data is acquired using an acquisition interface; - the method further comprises a step of decrypting the final cryptograms; - the decryption of each final cryptogram is by applying a decryption function of the homomorphic cryptographic scheme, to the final cryptogram concerned or to the components of said final cryptogram; - personal data are biometric data, in particular data representing faces; - K is a multiple of N; - the homomorphic cryptographic scheme is the Brakerski-Fan-Vercauteren scheme or the Cheon-Kim-Kim-Song scheme; - when the system is equipped with parallelism capacity, for example according to a SIMD architecture, allowing the same operation to be carried out on M data, N preferably has the value M if the homomorphic cryptographic scheme is the Brakerski-Fan-Vercauteren scheme, j if the homomorphic cryptographic scheme is the Cheon-Kim-Kim-Song scheme.
[0012] According to a second aspect, the invention proposes a computer program comprising instructions executable by a processor and adapted to implement a method for processing personal data as defined previously, when these instructions are executed by the processor.
[0013] This program may use any programming language, and be in the form of source code, object code, or code intermediate between source code and object code, such as in a partially compiled form, or in any other desirable form.
[0014] According to a third aspect, the invention proposes a non-transitory medium readable by a computer and storing instructions executable by a processor for the execution of a method for processing personal data as defined above.
[0015] A tangible or non-transitory medium may include a storage medium such as a hard disk drive, a magnetic tape device, or a solid-state memory device and the like.
[0016] At least a portion of the methods according to the invention may be computer-implemented. Accordingly, the present invention may take the form of an all-hardware embodiment, an all-software embodiment (including firmware, resident software, microcode, etc.) or an embodiment combining software and hardware aspects which may all be collectively referred to herein as a "module".
[0017] According to a fourth aspect, the invention proposes a personal data processing system comprising: - a data storage module storing a base of K homomorphically encrypted personal reference data in the form of jx / reference cryptograms in a group provided with a first operation and a second operation, and - a data processing module configured to determine in the encrypted domain, for each personal reference data item in the database, a distance between the same candidate personal data item and said personal reference data item, Or : - the first operation is an addition and the second operation is a multiplication, - for any P ranging from 1 to K, the personal reference data of rank P is a vector of / components having respective indices ranging from 1 to / , - for all ci ranging from 1 to T Æ 1 xl, the reference cryptogram of rank # is a vector of N components having respective indices ranging from 1 to N, and - the candidate personal data is a vector of / components having respective indices ranging from 1 to / , - with K, N and l natural integers strictly greater than 1, the system being characterized in that: - for any z ranging from 1 to |" Æ and for any j ranging from 1 to / , the reference cryptogram of rank (i - 1) x / + j , is the image, by an encryption function of a homomorphic cryptographic scheme, of the concatenation of the components of index j of each personal reference data having a rank between ix N - N + 1 and ix N, - for any i ranging from 1 to 1, the determination in the encrypted domain, by the data processing module, of the distances between the candidate personal data and each reference personal data having a rank between ix N -N +1 and ix N, includes: a) for all j going from I to obtaining an intermediate cryptogram of rank (i - 1) x / + j in the form of a vector of N components, by applying a Hadamard product between the reference cryptogram of rank (z - 1) x / + j and a candidate cryptogram of rank j, the candidate cryptogram of rank j being the image by the encryption function, of the concatenation of N components each having the value of the index component j of the candidate personal data, b) obtaining a final cryptogram of rank i in the form of a vector of N components, by applying a vector addition between the l intermediate cryptograms obtained, - the distance between the candidate personal data and a personal data of reference of rank P being the antecedent by the encryption function of the component index p - ( [ £ ] - 1) x of the final cryptogram of rank ~ "j •
[0018] This personal data processing system may further comprise an acquisition interface configured to acquire the candidate personal data.
[0019] According to one embodiment, the personal data is biometric data and the system comprises a biometric acquisition means for obtaining the candidate personal data.
[0020] Preferably, the data processing module is provided with parallelism capacity, for example the data processing module is according to a SIMD architecture, allowing the same operation to be carried out on M data.
[0021] According to one implementation mode, when the homomorphic cryptographic scheme is the Brakerski-Fan-Vercauteren scheme, M and N preferably have the same value, when the homomorphic cryptographic scheme is the Cheon-Kim-Kim-Song scheme, N preferably has the value j.
[0022] This system can be configured to implement each of the embodiment possibilities envisaged for the personal data processing method as defined above.
[0023] Of course, the various features, variants and embodiments of the invention may be combined with each other in various combinations to the extent that they are not incompatible or mutually exclusive.
[0024] Other characteristics and advantages of the present invention will emerge from the description given below, with reference to the appended figures which illustrate exemplary embodiments thereof which are not in any limiting nature.
[0025] In the figures:
[0026] [Fig.l] schematically represents a preferred embodiment of a system for implementing a method according to the invention;
[0027] [Fig.2] illustrates the steps of an embodiment of a method for processing personal data, according to the invention.
[0028] With reference to [Fig.l], a system for processing personal data for the identification of individuals is schematically represented.
[0029] System 1 typically implements an identification of a candidate individual, i.e. compares a candidate personal data X (freshly acquired on the candidate individual), to all personal reference data from a database, in order to determine the identity of the candidate individual.
[0030] By candidate personal data, we mean here personal data intended to be acquired in a controlled and voluntary manner by an acquisition interface, for example using a biometric acquisition means, a user interface or by optical reading.
[0031] The candidate personal data X is a vector of l components ( X [ 1], ..., X[Z]) having respective indices ranging from 1 to / , with / a natural integer strictly greater than 1.
[0032] The base contains K personal reference data, with K a natural integer strictly greater than 1, and for any P ranging from 1 to K, the personal reference data y G7) of rank P in the base, is a vector of / components ( [ 1] y^) p J ) having respective indices ranging from 1 to l.
[0033] By personal data, we mean in particular biometric data (and we will take this example in the remainder of this description), but we will understand that it can be any data specific to an individual on the basis of which a user can be identified, such as alphanumeric data, a signature, etc.
[0034] This system 1 is equipment owned and controlled by an entity with whom the identification must be carried out, for example a government entity, customs, a company, etc. In the remainder of this description, the example of an airport will be taken, the system 1 typically aiming to control the access of passengers on a flight before their boarding.
[0035] The system 1 comprises a data processing module 11, that is to say a computer such as for example a processor, a microprocessor, a controller, a microcontroller, an FPGA etc. This computer is configured to execute code instructions to implement certain steps of the personal data processing method which will be presented below.
[0036] Preferably, the data processing module 11 is provided with parallelism capacity, for example the data processing module 11 is according to a SIMD architecture, allowing the same operation to be carried out on M data, M being a natural integer strictly greater than 1.
[0037] The system 1 also comprises a data storage module 12 (a memory, for example a hard disk or a flash memory) and where appropriate, a user interface 13 (typically a screen and / or a keyboard) and / or biometric acquisition means 14 (see below).
[0038] In the preferred biometric embodiment, the system 1 is capable of generating a so-called candidate biometric data from a biometric trait of an individual. The biometric trait may for example be the shape of the face, one or more fingerprints, or one or more irises of the individual. The extraction of the biometric data is implemented by processing the image of the biometric trait which depends on the nature of the biometric trait. Various image processing methods for extracting biometric data are known to those skilled in the art. By way of non-limiting example, the extraction of the biometric data may comprise an extraction (in particular by a neural network) of a vector representative of particular points, or of a shape of the face in the case where the image is an image of the individual's face.
[0039] The biometric acquisition means 14 thus typically consist of an image sensor, for example a digital camera or a digital camera, adapted to acquire at least one image of a biometric trait of an individual, see further on.
[0040] Generally speaking, there will always be a candidate personal data item and at least one reference personal data item to compare. If alphanumeric personal data is used, the candidate data item can simply be entered on the user interface 13 or, for example, be obtained by optical reading from an image.
[0041] The data storage module 12 stores a reference personal database, i.e. at least one “expected” personal data item of an authorized individual, for example the passengers checked in for the flight. Each reference personal data item is advantageously data recorded in an identity document of the individual. For example, the personal data item may be the biometric data item obtained from a facial image appearing on an identity document (for example a passport), or from a facial image, at least one fingerprint, or at least one iris of the individual recorded in a radiofrequency chip contained in the document.
[0042] Each personal reference data is stored encrypted in a homomorphic manner, that is to say according to a homomorphic cryptographic scheme. Any homomorphic cryptographic scheme having the required properties may be used, for example the Brakerski-Fan-Vercauteren (BFV) scheme or the Cheon-Kim-Kim-Song (CKKS) scheme.
[0043] It is assumed that the personal reference database is created in advance. For example, passengers may have presented their identity document in advance.
[0044] Where appropriate, the system 1 may also comprise an enrollment module 20, another user interface 23 (typically a screen and / or a keyboard), and / or other biometric acquisition means 24 and / or a document reader 26 to constitute the personal reference database.
[0045] The enrollment module 20 is another computer, configured to execute ins code instructions to implement certain steps of the personal data processing process which will be presented below.
[0046] The information provided about the biometric acquisition means 14 applies to the other biometric acquisition means 24.
[0047] Said other biometric acquisition means 24 make it possible to obtain at least one reference biometric data item.
[0048] Generally, a reference biometric data item is generated by the enrollment module 20 from a biometric trait provided by one of the other biometric acquisition means 24, but the other biometric acquisition means 24 may comprise their own processing means for extracting the reference biometric data item. Such another biometric acquisition means may, if necessary, encrypt the reference biometric data item on the fly by applying an encryption function of the homomorphic cryptographic scheme in the form of a reference cryptogram (see the method described below).
[0049] According to another possibility, the enrollment module 20 can encrypt the reference biometric data by applying an encryption function of the homomorphic cryptographic scheme in the form of a reference cryptogram.
[0050] The document reader 26 is typically an image sensor, such as for example a digital camera or a digital camera, adapted to acquire an image of an identity document (for example a passport), and / or a contact-type or contactless-type communication means (for example NFC, UHF, etc.) adapted to read the content of a chip of an identity document.
[0051] The document reader 26 makes it possible to obtain personal reference data from an individual's identity document.
[0052] If alphanumeric personal data is used, the personal reference data can simply be entered on the other user interface 23 or, for example, be obtained by optical reading from an image.
[0053] The system 1 can be arranged locally (for example in the airport), but can be separated into one or more remote “cloud” type servers hosting the data processing module 11, the data storage module 12 and the enrollment module 20, the data processing module 11 being connected to the biometric acquisition means 14 which must necessarily remain on site (typically at the boarding gate for boarding control). In the example of [Fig.l], the enrollment module 20 and the data storage module 12 are remote.
[0054] When several remote “cloud” type servers host the data processing module 11, the data storage module 12 and the enrollment module 20, the communication between the servers can be wired or wireless, and uses any communication protocol (Wi-Fi, Bluetooth, etc.).
[0055] The user interface 13 and the biometric acquisition means 14 are connected to the data processing module 11 by any type of connection means, wired or not (Wi-Fi, Bluetooth, Ethernet, USB, etc.).
[0056] The other user interface 23, the other biometric acquisition means 24 and the document reader 26 are connected to the enrollment module 20 by connection means of any type, wired or not (Wi-Fi, Bluetooth, Ethernet, USB, etc.).
[0057] The system 1 implements an identification of the individual, that is to say compares the so-called candidate personal data (freshly acquired on the individual in the case of biometric data, or otherwise simply requested from the individual if it is alphanumeric data for example), with all the reference personal data of said base, in order to determine the identity of the individual.
[0058] The system 1 can finally comprise access control means (for example an automatic door P in [Fig.l]) controlled according to the result of the identification: if an authorized user is recognized, access is authorized.
[0059] Said biometric acquisition means 14 can be directly mounted on said access control means.
[0060] The biometric acquisition means 14 make it possible to obtain candidate biometric data. Generally, the candidate biometric data is generated by the data processing module 11 from a biometric trait provided by the biometric acquisition means 14, but the biometric acquisition means 14 may comprise their own processing means and for example take the form of an automatic device provided by the control authorities (in the airport) to extract the candidate biometric data. Such a biometric acquisition means may, if necessary, encrypt the candidate biometric data on the fly by applying an encryption function of the homomorphic cryptographic scheme in the form of candidate cryptograms (see the method described below). Thus, the candidate biometric data are also completely protected.
[0061] According to another possibility, the data processing module 11 can encrypt the candidate biometric data by applying an encryption function of the homomorphic cryptographic scheme in the form of candidate cryptograms.
[0062] Preferably, the biometric acquisition means 14 are capable of detecting the living, so as to ensure that the candidate biometric data comes from a “real” trait.
[0063] In the case where the biometric acquisition means 14 and the rest of the system are remote, the communication between the two can itself be encrypted.
[0064] Implementing the comparison includes calculating a distance between the data. The distance between the data advantageously includes the calculation of a scalar product.
[0065] This type of comparison and this type of distance are known to those skilled in the art and will not be described in further detail.
[0066] The individual is identified if the comparison reveals a similarity rate between the candidate personal data and a reference personal data exceeding a certain threshold, the definition of which depends on the type of personal data.
[0067] [Fig.2] illustrates the steps of an embodiment of a method for processing personal data, according to the invention.
[0068] This method is implemented here by the system 1 and determines in the encrypted domain, for each personal reference data item in a database, a distance between the same candidate personal data item X and said personal reference data item.
[0069] The distance between a candidate personal data X and a reference personal data is here the scalar product of the candidate personal data by said reference personal data.
[0070] The candidate personal data X is a vector of l components (X[ 1 ], ..., X[l] ) having respective indices ranging from 1 to / , with l a natural integer strictly greater than 1.
[0071] As explained, the personal reference database may have been created in advance.
[0072]
[0073]
[0074]
[0075]
[0076] System 1 stores a base of K personal reference data y( 1) y(A') homomorphically encrypted in the form of jxl reference cryptograms î ) [?Hx / ) in a group equipped with a first operation and a second operation, the first operation being an addition and the second operation being a multiplication, with K and N natural integers strictly greater than 1. Each personal reference data, of the K personal reference data, is therefore stored homomorphically encrypted, typically by the data storage module 12. For any P ranging from 1 to X, the personal reference data y(p) of rank P is a vector of / components y(p) y(p) [ / ] ) having respective indices ranging from 1 to / . For any ? going beyond^lx / Ue reference cryptogram) of rank is a vector of N components [ 1 j [N] having indices respective ranging from 1 to N. As we will see, the invention is distinguished in that for all / ranging from 1 to |" ÆJ,
[0077]
[0078]
[0079]
[0080]
[0081]
[0082] that is, for all i ranging from 1 to the upper integer part of K, and for all j N ranging from 1 to / , the reference cryptogram of rank (i - 1) x / + j, is the image by an encryption function of a homomorphic cryptographic scheme, of the concatenation of the components of index j of each personal reference data having a rank between ix N - N + 1 and iX N, that is to say the ranks ix N - N + 1 and i XN inclusive. Alternatively, the personal reference database may not have been established in advance. In this respect, with reference to Figure 2, the process can begin with a step (step El02) of obtaining the j- A. jx / reference cryptograms £<0 during which for all i ranging from 1 to [ A. 1 and for all j ranging from 1 to / , the reference cryptogram of rank (i - 1) x 1 + j is obtained by application of the encryption function, to the concatenation of the components of index j of each personal reference data having a rank between ix N - N + 1 and ix N. Typically, the reference cryptogram J) of rank (i - 1) x / + / is calculated as follows: y (;XV-ïV+ !) jy j Y(i*N) with ENC the encryption function of the homomorphic cryptographic scheme. For any P ranging from 1 to N, we have: = ENC^Y(^N+p} [j])- When for a value of i, there are not N personal reference data having a rank between ix N - N + 1 and ix N, the reference cryptogram of rank (i - 1) xl + j is obtained by applying the encryption function, to the concatenation: - components of index j of each personal reference data having a rank between ix N - N + 1 and ix N, and - any data having the same format as a personal data component for each of the other ranks between ix N - N + 1 and ix N. For example, if there is personal reference data for all ranks between ix N - N + 1 and ix N - 2, but no personal reference data for ranks ix N - 1 and ix N, the reference cryptogram of K rank (i - 1) x / + j is calculated as follows: (ixN-2) with ENC the encryption function of the homomorphic cryptographic scheme, any first data having the same format as a personal data component and Q2 any second data having the same format as a component of personal data.
[0083] This step is typically implemented by the enrollment module 20.
[0084] Thus this step can further comprise the transmission to the storage module of | xl cryptograms of data 12 from the enrollment module 20, [ A. reference obtained.
[0085] The data storage module 12 stores the F 1 x Z cryptograms of INI reference zA9 X[ v ]^ ). V y , . . » , U y
[0086] The ['A.'] x Z reference cryptograms (Al) constitute the representation homomorphically encrypted representation of the K personal reference data y( L
[0087] The step (step E102) of obtaining the Æ x Z reference cryptograms y ]*0 can also include obtaining the K data per reference sites.
[0088] In this case, according to a first advantageous example, each personal reference data item can be obtained from data recorded in an identity document of a reference individual, typically by the document reader 26, from an image of the face appearing on an identity document (for example a passport), or from an image of the face or at least one iris or at least one fingerprint of the individual recorded in a radiofrequency chip contained in the identity document.
[0089] According to a second example, each personal reference data can be obtained by another biometric acquisition means 24, directly from a biometric trait of a reference individual.
[0090] According to a third example, if alphanumeric personal data is used, each personal reference data can simply be entered on the other user interface 23 or for example obtained by optical reading from an image.
[0091] The method itself begins with a step (step El04) of obtaining candidate cryptograms (A b (A0, during which for any j ranging from 1 to / , a candidate cryptogram (A. / ) of rank j is obtained by applying the function of JC encryption by concatenation of N components each having the value of the component of index j of the candidate personal data X[ j] •
[0092] Thus, the candidate cryptogram (A / ) of rank j is the image by the encryption function, of the concatenation of N components each having the value of the component of index j of the candidate personal data X: X[y]•
[0093]
[0094]
[0095]
[0096]
[0097]
[0098]
[0099]
[0100]
[0101]
[0102]
[0103]
[0104] Typically, the candidate cryptogram (p) of rank j is calculated as follows: if) _ piYrcdY1 ;] Yi >1^ with ENC the encryption function of the scheme homomorphic cryptography. For all p ranging from 1 to N, we have: = FNC[X[ j ] j- This step allows obtaining candidate cryptograms. It is typically implemented by the data processing module 11. This step (step El04) of obtaining candidate cryptograms may further include obtaining the candidate personal data. In this case, according to a first advantageous example, the candidate personal data can be obtained by a biometric acquisition means 14, directly from a biometric trait of a candidate individual. According to a second example, if alphanumeric personal data is used, the candidate personal data can simply be entered on the user interface 13 or, for example, obtained by optical reading from an image. The method continues with a step (step E106) of determining in the encrypted domain the distances between the candidate personal data X and each reference personal data in the database. This step is typically implemented by the data processing module 11. During this step, for all i ranging from 1 to j, system 1 implements a processing of index i (processing T106_i) during which system 1 determines in the encrypted domain the distances between the candidate personal data X and each reference personal data having a rank between ix NN + 1 and ix N. Said index i treatment (T106_i treatment) includes: a) for all j ranging from 1 to / , obtaining an intermediate cryptogram) of rank (i - 1) xl + j in the form of a vector of N components, by applying a Hadamard product between the reference cryptogram ) of rank (i - 1) xl + j and a candidate cryptogram ¢47) of rank j; b) obtaining a final cryptogram ¢40 of rank i in the form of a vector of N components, by applying a vector addition between the intermediate cryptograms obtained. In other words, during the treatment for a given i (treatment T106_i) - for all j ranging from 1 to / and for all P ranging from 1 to N; - for all P ranging from 1 to N; '
[0105] The calculation of a component of an intermediate cryptogram results from the application of the second operation between a component of a reference cryptogram and a component of a candidate cryptogram.
[0106] The calculation of a component of a final cryptogram results from the application of the first operation between components of the intermediate cryptograms.
[0107] The step (step E106) of determining in the encrypted domain the distances between the candidate personal data X and each reference personal data of the base, therefore makes it possible to obtain j final cryptograms.
[0108] The distance between the candidate personal data X and a reference personal data y(p) of rank P is the antecedent by the encryption function of the index component "J _ x N' of the final cryptogram of rank [: dF[p-([£l - i)xat[
[0109] In other words:^]^ yWjjavec ) the distance between the candidate personal data X and the reference personal data y(p), that is to say here the scalar product of the candidate personal data X by said reference personal data y(p).
[0110] The treatments of index i (treatment T106_i), i ranging from 1 to [ Æ 1 determine IN I' thus in the encrypted domain the distances between the candidate personal data X and each reference personal data in the database.
[0111] The method makes it possible to limit the calculation times and the memory space consumed by the system 1.
[0112] The method only requires x ( / - 1) application of vector addition between two intermediate cryptograms, i.e. the application of Æ "J x NX (1 - 1) first operation between components of different vectors, and does not require any application of a rotation to the components of a vector. The method also does not require the application of the first operation between components of the same vector. Finally, the distance between the candidate personal data and a reference personal data of a given rank corresponds to a single and unique final cryptogram component.
[0113] It will be noted that according to one implementation possibility, all the treatments of index i (treatment T106_i), i going from I to can be executed sequentially by system 1.
[0114] According to another implementation possibility, several of the index processing operations / (processing T106_i), i ranging from 1 to Æ j, can be executed in parallel by the system 1, for example by means of a processor comprising several cores, each core being configured to execute at least one processing operation of the plurality, and / or by means of several processors, each processor being configured to execute at least one processing operation of the plurality.
[0115] The method may further comprise a step (step E108) of decrypting the final cryptograms.
[0116] The decryption of each final cryptogram is by applying a decryption function of the homomorphic cryptographic scheme, to the final cryptogram concerned or to the components of said final cryptogram concerned.
[0117] The method thus makes it possible to obtain, for each personal reference data item in the database, a clear distance between the candidate personal data item and said personal reference data item, while limiting the calculation times and the memory space consumed. The distance between the candidate personal data item and a personal reference data item corresponds to only one single final cryptogram component. The method therefore does not decrypt redundant components and / or does not require a selection of the final cryptogram components to be decrypted.
[0118] The method can further continue with a step (step E1 10) of determining a control result, during which the system 1 determines whether a distance between the candidate personal data and a reference personal data item in the database does not exceed a predetermined threshold.
[0119] Under these conditions, the system 1, typically the data processing module 11, can command in an access control step (step E1 12), an opening of the gate P, in order to allow the candidate individual to access a secure area.
[0120] This step (step E1 10) of determining a control result is typically implemented by the data processing module 11.
[0121] In practice, the control result can be a boolean.
[0122] The system 1 can determine the control result from clear distances obtained during the step (step E108) of decrypting the final cryptograms.
[0123] According to another possibility, the system 1 can determine the control result directly from components of final cryptograms, by operating in the group of the homomorphic cryptographic scheme, i.e. in the encrypted domain. In this case, the step (step E108) of decrypting the final cryptograms can be omitted.
[0124] As already indicated, any homomorphic cryptographic scheme exhibiting the required properties can be used, for example the Brakerski-
[0125]
[0126]
[0127]
[0128]
[0129]
[0130] Fan-Vercauteren (BFV) or the Cheon-Kim-Kim-Song (CKKS) scheme. When the system has parallelism capabilities, for example using a SIMD architecture, allowing the same operation to be performed on M data, N preferably has the value: - M if the homomorphic cryptographic scheme is the Brakerski- Fan-Vercauteren; ,MI if the homomorphic cryptographic scheme is the Cheon- Kim-Kim-Song, that is, the lower whole part of The process is thus optimized for the parallelism capacity of the system. Furthermore, K is preferably a multiple of N. In this case, there exists a non-zero integer such that K is equal to the product of this non-zero integer and N. The time performance of the process is thus optimal, each component of each reference cryptogram being the image by the encryption function of a component of a personal reference data. Advantageously, the personal data is biometric data, in particular data representing faces. In the above, a particular application of the method has been discussed, in which the result of the control conditions access to a secure area. It is however understood that the method described can be used for other applications.
Claims
1. Claims Method for processing personal data implemented by a system (1) storing a base of K homomorphically encrypted personal reference data in the form of K. jxl reference cryptograms in a group provided with a first operation and a second operation, - said method comprising the determination (El06) in the encrypted domain, for each personal reference data item in the database, of a distance between the same candidate personal data item and said personal reference data item, and - where the first operation is an addition and the second operation is a multiplication, - for any P ranging from 1 to K, the personal reference data of rank P is a vector of / components having respective indices ranging from 1 to k - for everything from I to A. jxl, the rank reference cryptogram is a vector of N components having respective indices ranging from 1 to N, and - the candidate personal data is a vector of / components having respective indices ranging from 1 to / , - with K, N and l natural integers strictly greater than 1, said method being characterized in that: - for all i ranging from 1 to |" A. and for all j ranging from 1 to / , the reference cryptogram of rank (i- 1) x 1 + j, is the image, by an encryption function of a homomorphic cryptographic scheme, of the concatenation of the components of index j of each personal reference data having a rank between ix N - N + 1 and ix N •> - for all i ranging from 1 to K "j, the determination in the encrypted domain of the distances between the candidate personal data and each reference personal data having a rank between ix N - N + 1 and ix N, includes: a) for all j ranging from 1 to / , obtaining an intermediate cryptogram of rank {i - 1) xl + j in the form of a vector of N components, by applying a Hadamard product between the reference cryptogram of rank (i - 1) xl + j and a candidate cryptogram of rank j, the candidate cryptogram of rank j being the image by the encryption function, of the concatenation of N components each having the value of the index component j of the candidate personal data, b) obtaining a final cryptogram of rank i in the form of a vector of N components, by applying a vector addition between the l intermediate cryptograms obtained, - the distance between the candidate personal data and a reference personal data of rank P being the antecedent by the encryption function of the index component A j _ |) x of the final cryptogram of rank
2. Method for processing personal data according to the preceding claim, the method further comprising a step (El02) of obtaining the f A. 1 x / reference cryptograms, during which for any i ranging from 1 to Aj and for any J ranging from 1 to / , the reference cryptogram of rank (i - 1) xl + / is obtained by applying the encryption function to the concatenation of the components of index j of each personal reference data item having a rank between ix N - N + 1 and i: x N.
3. Method for processing personal data according to any one of the preceding claims, the method further comprising a step (El04) of obtaining candidate cryptograms, during which for any j ranging from 1 to / , the candidate cryptogram of rank j is obtained by applying the encryption function to the concatenation of N components each having the value of the index component j of the candidate personal data.
4. A method of processing personal data according to any one of the preceding claims, wherein the candidate personal data is acquired using an acquisition interface (13,14).
5. Method for processing personal data according to any one of the preceding claims, the method further comprising a step (E108) of decrypting the final cryptograms.
6. A method of processing personal data according to any one of the preceding claims wherein the personal data are biometric data, in particular data representative of faces.
7. A method of processing personal data according to any one of the preceding claims wherein K is a multiple of N.
8. A method of processing personal data according to any one of the preceding claims wherein the homomorphic cryptographic scheme is the Brakerski-Fan-Vercauteren scheme or the Cheon-Kim-Kim-Song scheme.
9. Computer program comprising instructions executable by a processor and adapted to implement a method for processing personal data according to any one of the preceding claims, when these instructions are executed by the processor.
10. A non-transitory computer-readable medium storing processor-executable instructions for performing a personal data processing method according to any one of claims 7 to 8.
11. System (1) for processing personal data comprising: - a data storage module (12) storing a base of K homomorphically encrypted personal reference data in the form of 1 x / reference cryptograms in a group provided with a first operation and a second operation, and - a data processing module (11) configured to determine in the encrypted domain, for each personal reference data item in the base, a distance between the same candidate personal data item and said personal reference data item, where: - the first operation is an addition and the second operation is a multiplication, - for any P ranging from 1 to the personal reference data item of rank P is a vector of / components having respective indices ranging from 1 to / , - for any 9 ranging from 1 to Æ jx / 3c reference cryptogram of rank P is a vector of N components having respective indices ranging from 1 to N,and - the candidate personal data is a vector of l components having respective indices ranging from 1 to l, - with K, N and l natural integers strictly greater than 1, the system being characterized in that: - for all i ranging from 1 to 1 and for all j ranging from 1 to l, the reference cryptogram of rank (z - 1) x / + / , is the image, by an encryption function of a homomorphic cryptographic scheme, of,
12. the concatenation of the components of index j of each personal reference data having a rank between ix N - N + 1 and ix N - for any i ranging from 1 to Â. j, the determination in the encrypted domain, by the data processing module (11), of the distances between the candidate personal data and each reference personal data having a rank between ix N - N + 1 and i * N, comprises: a) for any j ranging from 1 to / , obtaining an intermediate cryptogram of rank (i- 1) xl + j in the form of a vector of N components, by applying a Hadamard product between the reference cryptogram of rank (z - 1) xl + j and a candidate cryptogram of rank j, the candidate cryptogram of rank j being the image by the encryption function, of the concatenation of N components each having the value of the index component j of the candidate personal data, b) obtaining a final cryptogram of rank i in the form of a vector of N components, by applying a vector addition between the / intermediate cryptograms obtained, - the distance between the candidate personal data and a reference personal data of rank P being the antecedent by the encryption function of the index component p.QiL | x N' of the final cryptogram of rank JL j. System (1) for processing personal data according to the preceding claim further comprising an acquisition interface (13, 14) configured to acquire the candidate personal data.