Comparison of biometric data in the encrypted domain
The method employs pre-calculated correspondence tables and masked scores with homomorphic encryption to efficiently and securely verify biometric data, addressing execution time and security issues in existing systems.
Patent Information
- Application Number
- FR2024004052
- Authority / Receiving Office
- FR · FR
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-04-18
- Publication Date
- 2025-10-24
AI Technical Summary
Existing biometric verification methods in the encrypted domain face challenges with excessive execution time and security vulnerabilities, particularly in systems involving homomorphic encryption and decentralized calculations.
A method utilizing pre-calculated correspondence tables and masked scores, combined with homomorphic encryption and secondary decryption keys, allows for secure and efficient comparison of biometric data without revealing sensitive information, by calculating a masked score in the encrypted domain using pre-computed tables and distributed decryption processes.
This approach reduces computational load and execution time while ensuring secure biometric verification, preventing unauthorized access and protecting sensitive data from collusion attacks.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
Title of the invention: Comparison of biometric data in the encrypted domain FIELD OF THE INVENTION
[0001] The present disclosure relates to the comparison of biometric data in the encrypted domain, in particular for identity control. STATE OF THE ART
[0002] A conventional method for verifying whether an individual is enrolled in a database comprises the following steps. A test biometric data item relating to the individual to be checked is acquired. Then, a score representative of a distance between the test biometric data item and a reference biometric data item contained in the database is calculated. This score is then compared with a threshold. A control result indicating whether or not the test biometric data item corresponds to the reference biometric data item is obtained at the end of this comparison.
[0003] Ibarrondo, Alberto, et al. "Colmade: Collaborative masking in auditable decryption for bfv-based homomorphic encryption." Proceedings of the 2022 ACM Workshop on Information Hiding and Multimedia Security, 2022, describes a method that follows this general principle, but with the following particularities. First, the Colmade method performs the calculation of the score and the comparison with a threshold in the encrypted domain. Second, the Colmade method includes centralized steps, and steps distributed over several entities: these entities perform calculations in parallel producing partial results, these partial results then having to be recombined in order to arrive at the control result.
[0004] However, the execution time of the Colmade process turns out to be long.
[0005] In particular, a fairly expensive operation in homomorphic encryption is multiplication.
[0006] Bassit, Amina, et al. "Multiplication-free biometric recognition for faster processing under encryption." 2022 IEEE International Joint Conference on Biometrics (IJCB). IEEE, 2022 proposes to calculate the score cipher using pre-computed look-up tables. The mathematical function f to calculate the score cipher is the sum of subfunctions / p..., fd. The different look-up tables used represent these subfunctions. Thus, to obtain the score cipher, it is sufficient to determine d portions of the cipher by searching in the d look-up tables, then to sum these d portions. Seen Since this treatment only uses tables and additions, it is very light in terms of computational load.
[0007] However, this solution is not entirely satisfactory.
[0008] First, this solution is implemented in a system comprising a service provider (SP) having a decryption key sk and a storage server (DB) storing reference biometric data ciphers which does not have knowledge of the decryption key sk. The storage server returns to the service provider the cipher of information indicating whether a test biometric data corresponds to a reference biometric data, and the service provider decrypts this cipher using its decryption key sk. However, in the event of collusion between SP (which has sk) and the storage server DB (which has the reference biometric data ciphers), the base constituted by the reference biometric data ciphers can be revealed.
[0009] Second, the first proposed solution presents a threshold that can be used in the encrypted domain, without any trickery, and is therefore not very efficient. The second proposed alternative solution presents a threshold that is carried out after decryption, and therefore in clear text. This leads to a security problem and is therefore not satisfactory. Presentation of the invention
[0010] An aim of the invention is to verify whether an individual is enrolled in a database without requiring excessive execution time and in a secure manner.
[0011] This object is achieved by a method comprising steps of: • calculation of a figure of a masked score, the masked score representing the result of the application of a primary mask r to a score representing a distance between a test biometric data item x relating to an individual and a reference biometric data item yu, the calculation comprising: • for all j ranging from 1 to k and for all i ranging from 1 to d, with k > 1 and d > 2, determination in a precalculated correspondence table of a term equal to (Tu + (r) ■ mod Ÿ in correspondence with a pair consisting of a portion of the biometric test data x and a portion of an encrypted version of the reference biometric data, where: • the encryption of the reference biometric data cyu results from an encryption of the reference biometric data yu using a primary encryption key pk, • n is a predefined integer, • a sum j mod ^eS ^l68 Ti.j constitutes an estimate of a figure of the score in unmasked form, • the primary mask r is linked to secondary masks < r} by the following relation: ( < r} if ) mod T = r mod T' • implementation of the following summation so as to obtain the figure of the hidden score + f. • for all i ranging from 1 to d, implementation of the following steps by a decryption device of index i: • decryption of the hidden score cipher using a secondary decryption key ( sk)f of index i, the decryption producing a data * representing the hidden score modulo 2rt, • generation of a partial result °t of index i from the data $ and an unmasking data kj of index i, • in which: • the secondary decryption keys {sk ) ?..., ( sk ) d with respective indices ranging from 1 to d come from a primary decryption key sk associated with the encryption key pk, • the partial results °i,..., °d with respective indices ranging from 1 to d allow the calculation of a control result ° indicating whether or not the test biometric data x corresponds to the reference biometric data.
[0012] In the proposed method, the decryption of the hidden score cipher, which takes place at the same time as the generation of the partial result, representative of the comparison with a threshold, is distributed between several decryption devices of index i. This reduces the risk of collusion.
[0013] The proposed method may also comprise the following optional features, taken alone or in combination whenever possible:
[0014] - the determination of the term Tj + {r) —) mod 2” includes the following steps: • determination in a first correspondence table of index i of a pointer of index i in correspondence with the pair, the pointer of index i pointing to a position, in a second table of 2” terms, where the term of index i is stored,
[0015]
[0016]
[0017]
[0018] • determination of the term with index i in the second table using the index pointer i; - the method further comprises steps of: • permutation of the second table, then • repetition of the calculation of the hidden score figure for a new biometric test data; - on ak > 1, for all j ranging from 1 to k and for all i ranging from 1 to d, the determination of the term equal to (Ti j + mod 2n is implemented by a storage server 2 of index j, for all j ranging from 1 to k, the server of index j calculates a portion of index j of the encrypted score masked by the following summation: / j. (r) \ mod 2?' Ct For any ia"ant from 1 to d, the device of index decryption i calculates the encrypted value of the masked score by summing the respective index portions ranging from 1 to k of the encrypted value of the masked score; - on ak = 1 and the calculation of the hidden score figure is implemented by a single storage server; - the decryption implemented by the decryption device with index i comprises the following steps: • calculation of an intermediate data (} of index i from the data following: • a first part Csi' of the hidden score figure, • the secondary decryption key { sk ). of index i, and • a random number ei generated by the decryption index device i, • for any decryption device of index j^i, reception of an intermediate data item (¾) of index j sent by the decryption device of index j, calculation of the data $ representing the hidden score from the following data: the intermediate data {c$b) , • • ■, {csb} of respective indices ranging from 1 to d, • a second part Cs of the hidden score figure;
[0019] - the intermediate data (¾} of index i is calculated as follows:
[0020] (¾}
[0021] in which Cst is the first part of the ciphertext cs of the masked score, ( sk)^ is the secondary decryption key of index i, and eî is the random number generated by the device of index i;
[0022] - the data * representing the hidden score modulo 2” is calculated as follows:
[0024] in which ( . is the intermediate data of index i, Cs« is the second part of the ciphertext (c«) of the score, * and # are two integers constituting parameters of a Brakerski / Fan-Vercauteren encryption scheme, L- 1 denotes the rounding to the nearest integer operator, [.]? denotes the modulo q operator, [.] denotes the modulo t operator.
[0025] - the control result 0 is equal to the sum of the partial results °i' of indices respective ranging from 1 to d;
[0026] - at least one of the following data is a single-use data for the data biometric test x, or even for the hidden score code: • the unmasking data of index i, • the secondary decryption key with index i.
[0027] The present disclosure also relates to a computer program product comprising program code instructions for executing the steps of the method described above, when this program is executed by a system.
[0028] The present disclosure also relates to a computer-readable memory storing executable instructions for carrying out the steps of the method described above.
[0029] According to another aspect, the present disclosure relates to a system comprising a control device, a storage server, at least two decryption devices, a trusted server and an enrollment device, in which said devices and servers comprise processors configured to implement the steps of the method described above.
[0030] The method described above can be implemented by a method for controlling access of an individual to a secure area for identification of the individual. DESCRIPTION OF THE FIGURES
[0031] Other characteristics, aims and advantages of the invention will emerge from the following description, which is purely illustrative and non-limiting, and which must be read in conjunction with the appended drawings in which:
[0032] [Fig.l] schematically illustrates interactions between different devices forming part of a system according to one embodiment, usable for controlling the identity of individuals.
[0033] [Fig.2] schematically illustrates different devices forming part of a system according to one embodiment.
[0034] [Fig. 3] is a flowchart of steps of a method according to an implementation mode artwork.
[0035] Throughout the figures, similar elements bear identical references. DETAILED DESCRIPTION OF THE INVENTION
[0036] In the following description, the following conventions are adopted: • A cipher of a data represents the result of an encryption applied to the data. • A masked data represents the result of a masking applied to this data. • By combining the two preceding principles, the “encryption of a masked data” represents the result of an encryption applied to a masked data, this masked data itself representing the result of a masking applied to the data. • A modulo 2” summation of terms is an operation comprising a summation of the terms, followed by the application of the modulo 2” operator to the resulting sum. System for controlling the identity of an individual
[0037] With reference to Figures 1 and 2, a system comprises a control device 1, at least one storage server 2, at least two decryption devices 3, a trusted server 4 and an enrollment device 6.
[0038] We note k the number of storage servers 2 of the system, where ak > 1. By convention, we will use the silent index j to designate one or the other of the storage servers 2.
[0039] We also note d the number of decryption devices 3, we ad > 2. By convention, we will use the silent index i to designate one or the other of the decryption devices 3.
[0040] The control device 1 comprises a processor 10, a communication interface 12 for communicating with the storage server 2, a memory 14 and a biometric sensor 16.
[0041] The processor 10 is configured to implement certain steps of a method which will be described later. The processor 10 may have any structure. The processor 10 comprises one or more cores, each core being configured to execute the code instructions of a program so as to implement the aforementioned steps.
[0042] The communication interface 12 is for example of the wireless radio type, and uses any communication protocol (Wi-Fi, Bluetooth, etc.).
[0043] The memory 14 is adapted to store data manipulated or produced by the processor 10. The memory 14 is of any type. Conventionally, the memory 14 comprises a volatile memory for storing data temporarily, and non-volatile memory for storing data persistently, that is, in a manner that retains the data when the non-volatile memory is powered down.
[0044] The biometric sensor 16 is configured to acquire biometric data relating to individuals. For example, the biometric sensor 16 comprises a camera configured to acquire images showing the face of an individual, and to extract biometric data from such images. Alternatively or additionally, the biometric sensor 16 comprises a fingerprint sensor and / or an iris sensor.
[0045] In one embodiment, the control device 1 further comprises a gate 18 that can be closed to prevent an individual from accessing a secure area, and opened to allow such access. The processor 10 is in this case configured to control the opening and closing of the gate 18. For example, the control device 1 is located in an airport, and the secure area is a boarding area; in this particular application, the individuals wishing to access the boarding area are the passengers of a flight, whose identity is to be checked before boarding.
[0046] In [Fig.l], only one storage server 2 is shown, but this is only an example. Each storage server 2 comprises a processor 20, a communication interface 22 for communicating with the control device 1, and a memory 24. The information provided above about the processor 10 and the communication interface 12 is also applicable to the processor 20 and the communication interface 22.
[0047] The memory 24 stores a database of confidentially protected biometric databases. The database contains biometric data relating to previously enrolled individuals. The biometric data of an enrolled individual is not in clear text in the database, but is instead confidentially protected, i.e. is an encrypted form, using homomorphic encryption.
[0048] The memory 24 also stores pre-calculated correspondence tables, making it possible to obtain the result of a mathematical function applied to input data (this mathematical function will be described in more detail below). It will be noted that the expression “correspondence table” must be understood as any set of organized data making it possible to establish, without calculation, correspondences between the antecedents and the images of this mathematical function.
[0049] Each decryption device 3 comprises a processor 30, a communication interface 32 for communicating with the control device 1 and / or the other decryption devices 3, and a memory 34. The information provided above about the processor 10 and the communication interface 12 are also applicable to the processor 30 and the communication interface 32. The communications between the interfaces 12, 22 and the communications between the interfaces 12, 32 may use identical or different protocols.
[0050] The decryption devices 3 are distinct from each other. In the following, an embodiment will be detailed in which the decryption devices 3 are distinct from the control device 1, from each storage server 2, from the enrollment device 4 and from the enrollment device 6, as shown in [Fig. 1]. However, in other embodiments, it may be envisaged that the control device 1, the storage server 2, the enrollment device 4 and / or the enrollment device 6 is included in one of the decryption devices 3.
[0051] The trusted server 4 has the function of generating cryptographic keys, some of which are used by other components of the system. The trusted server 4 comprises a processor 40, a communication interface 42 for communicating with the enrollment device 6 and with each decryption device 3, and a memory 44. The information provided above about the processor 10, the communication interface 12 and the memory 14 is also applicable to the processor 40, the communication interface 42 and the memory 44.
[0052] The enrollment device 6 comprises a processor 60, a communication interface 62 for communicating with the trusted server 4 and with the storage server 2, a memory 64 and a biometric sensor 66. The information provided above about the processor 10, the communication interface 12, the memory 14 and the biometric sensor 16 is also applicable to the processor 60, the interface 62, the memory 64 and the biometric sensor 66. In the following, an embodiment will be detailed in which the enrollment device 6 is distinct from the control device 1. However, in other embodiments, the control device 1 could be used as an enrollment device. Correspondence tables
[0053] Let us denote by yu a reference biometric data item. We have seen previously that the memory 24 of a storage server 2 does not store the data item y^ but rather an encrypted form cyu of this data item. More precisely, the encrypted form cyu of the reference biometric data item yu results from an encryption of the reference biometric data item yu using a primary encryption key pk. This is true for each reference biometric data item stored in encrypted form in the storage server(s) 2. The encryption is homomorphic.
[0054] A classic operation consists of calculating a score s representative of a distance between a test biometric data x and a reference biometric data yh stored. The distance represented by the score is for example a scalar product between the test biometric data x and the reference biometric data yu.
[0055] It is possible to calculate an encrypted cs of the score representative of the distance between the test biometric data x and the reference biometric data yu, while remaining in the encrypted domain using the key pk. In particular, there is a score function f, known to those skilled in the art, which produces this encrypted value, as explained in Bassit, Amina, et al. “Multiplication-free biometric recognition for faster processing under encryption.” 2022 IEEE International Joint Conference on Biometrics (IJCB). IEEE, 2022. We thus understand that the encrypted cs is a score obtained from the data x and cyu (we will note here that the input data cyu is already encrypted, whereas x is not). We therefore have:
[0056] C^f(x,Cyu)
[0057] The score function f is itself decomposable into dxk sub-functions f..
[0058]
[0059]
[0060]
[0061]
[0062]
[0063] known to those skilled in the art, which respect the following property of additivity: cs = f(x,cyu ) nf..) Or : • Pij is a portion of the input biometric data x. • ref \ . is a portion of the ciphertext cyu of the reference biometric data yu. The portions Pj j, ref. were determined upstream by a treatment of quantization known from the state of the art, for example as described in Bassit, Amina, et al. “Multiplication-free biometric recognition for faster processing under encryption.” 2022 IEEE International Joint Conference on Biometrics (IJCB). IEEE, 2022. As a reminder, the indices i and j traverse the integers from 1 to d, number of encryption devices 3, and the integers from 1 to k, number of storage servers 2, respectively. An advantage of this decomposition is that it is computationally less expensive to go through the subfunctions f. . before summing their respective images to obtain the score cs. In particular, addition is a cheap operation. Let us now suppose that we replace the sub-functions f by pre-calculated correspondence tables Tij. From a pair of values p^ the table Ti j would be able to provide, by a set of correspondences, the output value / ..(p... ref-jY There is therefore a correspondence table T;j per sub-function f.„ In other words, each table Tq would provide the following term, constituting a portion of the cipher cs:
[0064] ref^
[0065] It would then be sufficient to sum the dxk portions provided to obtain an estimate of the result of the function f, in other words to obtain the number ca of the score as follows:
[0066] = ref..)
[0067] With such tables, the computational resources required to obtain the score s would be further reduced: in fact, it is less expensive to search in a pre-computed correspondence table Tij for an output corresponding to input data than to apply the sub-function f. . to the same input data.
[0068] We will now see that the storage servers 2 store correspondence tables S / j that are more complex than the tables T / j, because the tables Sÿ integrate within them an implicit operation of masking the score4.
[0069] For any j ranging from 1 to k, the storage server with index j stores d correspondence tables ..., Sij, ...,}-. There are therefore, for each storage server 2, a correspondence table Sjj for each encryption device 3 of index i.
[0070] The aim of the correspondence table Sjj is not to obtain a portion of the encrypted value of the score 4 representative of a distance between x and yu, as presented above, but to obtain a portion of the encrypted value of a masked score, this masked score resulting from a masking of the score s using a primary mask r. We denote by cs+r the encrypted value of the masked score.
[0071] The correspondence table Sij is constructed so as to return the following term, from the portions P^j and re:
[0072] S^p.? ref..) = (Tij(Pi,f refij) + 2”
[0073] where: • n is a predefined integer greater than or equal to 1, • (r) .j is a secondary mask constituting a portion of the primary mask r, • mod denotes the modulo operator.
[0074] The secondary masks ( r ) are linked together by the following relation:
[0075] (r}) mod 2n = r mod 2n
[0076] Furthermore, in the same spirit as the scenario described previously not using masking, / p. . mod constitutes an estimate of the number c* of the score ' (in unmasked form).
[0077] It should be noted that the modulo 2n operation is an expensive operation in the encrypted domain. As this operation is integrated into the correspondence tables Sjj, it will not have to be applied.
[0078] As we will see later, by summing the dxk terms provided by the tables Sjj, we obtain not the number cs of the score but the number cs+r of the masked score s + r:
[0079] r _yrfy* ç / n . Cs+r - Li=iLj=^tj { P^ rej)
[0080] Generation of keys, masks and correspondence tables
[0081] The following steps are implemented preliminary within the system.
[0082] The processor 40 of the trusted server 4 generates the encryption key pk and a key associated sk decryption, the two keys forming a cryptographic key pair, typically an asymmetric key pair. The keys are for example randomly generated.
[0083] The keys pk, sk are stored in memory 44.
[0084] The trusted server 4 sends the encryption key pk to the enrollment device, which is therefore a public key. The decryption key sk is, on the contrary, a private key specific to the trusted server 4, and which is therefore not communicated outside the trusted server 4.
[0085] Furthermore, the correspondence tables S / j are precalculated so as to respect the constraints defined previously. This precalculation is based on prior knowledge of the d secondary masks ( T ) ..., { r / which themselves derive from the primary mask r. The primary mask can also be generated by the processor 40 of the trusted server 4. The primary mask r can be generated by the function FunshadeSetUf^} described in Ibarrondo et al., Funshade: Functional Secret Sharing for Two-Party Secure Thresholded Distance Evaluation, Cryptology ePrint Archive, Paper 2022 / 1688, 2022. Enrollment
[0086] It is assumed that a reference individual to be enrolled presents himself near the enrollment device 6. In practice, the reference individual may be an individual who has obtained the right to access the secure area discussed previously. When the control device 1 is placed in an airport, the secure area may give access to an aircraft, in which case the right to access the secure area is conferred by a transport ticket allocated to the reference individual.
[0087] The biometric sensor 66 of the enrollment device 6 acquires a reference biometric data yu relating to the reference individual.
[0088] The processor 60 encrypts the reference biometric data yu using the encryption key pk, so as to obtain the encrypted cyu of the biometric data yu. In particular, it is possible to use during this step an encryption according to the scheme Brakerski -Fan-Vercauteren (BFV) as described in Fan, Junfeng, and Frederik Vercauteren. “Somewhat practical fully homomorphic encryption. » Cryptology ePrint Archive (2012).
[0089] The encrypted cyu is transmitted by the enrollment device 6 to the storage server 2 via the communication interface 62.
[0090] The storage server 2 receives the encrypted cyu via its communication interface 22, and adds it to the database contained in its memory 24. The reference individual is then enrolled.
[0091] The preceding steps are repeated by the enrollment device 6 for several reference individuals to be enrolled, whereby the database contained in the memory 24 stores a plurality of ciphers, each cipher relating to a different reference individual. Each time, the same encryption key pk is used by the processor 60. Identity check
[0092] With reference to [Fig. 3], a method implemented by means of the system comprises the following steps. When it is mentioned below that the control device 1, a storage server 2, a decryption device 3 or the trusted server 4 implements a processing, it will be understood that this processing is more precisely implemented by the corresponding processor 10, 20, 30, 40.
[0093] It is assumed that an individual whose identity is to be checked presents himself near the control device 1. For example, the individual to be checked presents himself at a boarding gate of an airport where the control device 1 has been installed, with the intention of boarding an airplane.
[0094] In a step 102, the biometric sensor 16 acquires a biometric data item x relating to the individual to be checked. In the following, this biometric data item x is called “test biometric data item” in order to distinguish it from the reference biometric data discussed previously, the respective encrypted data of which are stored by the storage server 2.
[0095] In a step 104, the control device 1 sends, for all j ranging from 1 to k, the biometric test data x to the storage server 2 of index j via the communication interface 12. In other words, the k storage servers 2 receive the biometric test data x.
[0096] Furthermore, in a step 106, the control device 1 sends to the trusted server 4 a request associated with the test data x.
[0097] Steps 104 and 106 can be performed in any order.
[0098] In a step 202, the storage server 2 of index j receives the biometric test data x via the communication interface 22.
[0099] In a step 204, the storage server 2 of index j determines in the precalculated correspondence table Sq the equal term (Pu-refu) + mod 2n in correspondence with the pair consisting of the portion P^- of the biometric test data x and the portion ref.. of the cipher cyu of the reference biometric data.
[0100] During step 204, the storage server 2 of index j repeats this determination for all i ranging from 1 to d and therefore determines d terms p^ ref constituting d portions of the ciphertext cs+r of the score s masked by the primary mask r, each portion corresponding to a correspondence table Sÿ and therefore to an encryption device 3.
[0101] This step 204 is quick to execute due to the use of precalculated correspondence tables.
[0102] In a step 206, the storage server 2 of index j transmits the d terms pj, ref..] that it has determined to each of the d decryption devices 3. Each storage server 2 of index j includes a correspondence table Sjj for each encryption device 3 of index i, so there are d^-k correspondence tables in total.
[0103] In a step 402, the trusted server 4 receives the request sent during step 106.
[0104] In a step 404, the trusted server 4 generates secondary decryption keys (sk) ],..., (sk issues from the decryption key sk, i.e. one for each encryption device 3.
[0105] In a step 406, the trusted server 4 generates unmasking data k^ ..., kd which are associated with the primary mask r.
[0106] Steps 404 and 406 may be implemented in any order.
[0107] In a step 408 implemented for all i ranging from 1 to d, the trusted server 4 transmits to the decryption device 3 of index i: • the secondary decryption key {sk}. of index i, • the unmasking data k{ of index i.
[0108] On the other hand, any data of index i generated by the trusted server 4 in steps 404, 406 is not sent to any decryption device 3 of index j different from i.
[0109] For any i ranging from 1 to d, the decryption device 3 of index i implements the following steps.
[0110] In a step 302, the decryption device 3 of index i receives the dxk terms Sîj(Pif ref ij)' 9^ sent by the k storage servers 2. It is recalled that each storage server 2 requested provides d terms.
[0111] In a step 303, the decryption device 3 of index i calculates the ciphertext cs+r of the masked score s + r by performing a summation of the dk portions that it received in step 302, as follows:
[0112] yd yk ç
[0113] Each of the d encryption devices 3 performs this operation. In a step 304, the decryption device 3 of index i receives: • the secondary decryption key {sk ) of index i, • the unmasking data kt of index i.
[0114] Steps 302 and 304 may occur in any order, depending on how the control device 1 operates.
[0115] In a step 306, the decryption device 3 of index i applies a decryption processing ColMaskDecr{ ) to the encrypted masked score, as described in Ibarrondo, Alberto, et al. “Colmade: Collaborative masking in auditable decryption for bfv-based homomorphic encryption.” Proceedings of the 2022 ACM Workshop on Information Hiding and Multimedia Security, 2022. This processing produces a data item ' representing the score in a form decrypted using the primary decryption key, but still masked using the primary mask r. We can thus note:
[0116] s = ColMaskDecr(cs+r, {sk}^
[0117] If we decrypted the ciphertext cs using the primary decryption key sk, we would not obtain the score ' in plaintext, but the score masked using the primary mask r. The decryption and masking process ColMaskDecri ) has the property of arriving at the data ® without performing an intermediate calculation of the scores in plaintext. Indeed, the ciphertext taken as input already relates to a masked score, and not to the score ' in plaintext.
[0118] We will now detail an embodiment of the decryption and masking processing ColMaskDecr^ )• In this embodiment, the ciphertext cs+r of the masked score is presented in the form of a pair of data Cs«, Cso. These two data constitute two different portions of the ciphertext Cg+r.
[0119] The decryption device 3 of index i calculates an intermediate data (c-sh}. of index i from the following data: the part of the ciphertext cs+r, the secondary decryption key ( sk). of index i, and a random number e< generated by the device of index i.
[0120] This calculation can be as follows:
[0121] (^.^(skj. + tf,.
[0122] The decryption device 3 of index i sends the intermediate data ). of index i to any other decryption device 3 of index j^i. Furthermore, the decryption device 3 of index i receives an intermediate data (¾). of index j^i produced by any other decryption device with index j^i.
[0123] The decryption device 3 of index i calculates the data $ from the intermediate data (and from the part Cs« of the ciphertext cs. This calculation can be carried out as follows:
[0124] a [ r \ 1 1 $ = "^+4=1¾.] HE L ,J 9 J, • in which • ( . is the intermediate data of index i (calculated or received), • Cs« is the second part of the cipher c*+r, • z and are two integers constituting parameters of a Brakerski-Fan-Vercauteren encryption scheme, • 1...1 denotes the rounding operator to the nearest integer, • [•■•]? denotes the modulo q operator, • [ ... ]f denotes the modulo t operator.
[0125] In this embodiment, we have:
[0126] sEs + r
[0127] In this equation, the sign = represents an equality. Thus, the data* turns out to be the masked score, that is, the sum of the score' in clear and the primary mask r.
[0128] In a step 308, the decryption device 3 of index i calculates a partial result °t of index i from the data and the unmasking data k, of index i:
[0129] oi = FSS£val(s,
[0130] Obtaining the partial result is described in Ibarrondo et al., Funshade: Functional Secret Sharing for Two-Party Secure Thresholded Distance Evaluation, Cryptology ePrint Archive, Paper 2022 / 1688, 2022. The acronym 'FSS' refers to the sharing of a secret function ("Function Secret Sharing"). In a step 310, the decryption device 3 of index i sends the partial result °t to the control device 1.
[0131] The processing implemented by the decryption device 3 of index i is completed.
[0132] As indicated previously, the processing constituted by steps 302 to 310 is implemented times: once per decryption device of index i. Thus, d partial results °i,..., °d are generated.
[0133] The duplet of partial results °i,...has the property of allowing the calculation of a control result 0 indicating whether or not the test biometric data x corresponds to the reference biometric data yu. On the other hand, it is not possible to calculate this control result on the basis of a sub-part of this duplet.
[0134] In a step 112, the control device 1 receives the d partial results od respectively generated and sent by the d decryption devices 3.
[0135] In a step 114, the control device 1 calculates the control result 0 from the d partial results °i,_.., received. As indicated above, the control result indicates whether or not the test biometric data x corresponds to the reference biometric data yu.
[0136] In one embodiment, the control result 0 is obtained by summing the partial results, as follows:
[0137] 0 = ^
[0138] The cryptographic processing carried out jointly by the d decryption devices 3 and the step of calculating the control result o represent a comparison between a threshold and the distance between the biometric test data x and the biometric reference data yu. The threshold is defined in the FSSSetup() function used for the generation of the primary mask r, the secondary decryption keys and the unmasking data (the threshold is in some way encoded by these data).
[0139] In practice, the result of control 0 can be a boolean.
[0140] If the control result 0 indicates that the biometric test data x corresponds to the reference biometric data yu, that is to say that the value of the control result 0 is equal to 1 (or 'True'), then it is considered that the individual to whom the test biometric data x relates has previously been enrolled with the server 2. Under these conditions, the processor 10 can command in a step 116 an opening of the gate 18, in order to allow the individual to access a secure area.
[0141] If the control result indicates that the test biometric data x does not correspond to the reference biometric data yu, that is to say that the value of the control result 0 is equal to 0 (or 'False'Y then it is considered that the individual controlled is not the reference individual to which the reference biometric data yu relates. Special methods of implementation
[0142] In one embodiment, k=l is chosen. Thus, a single storage server 2 is used to produce portions of the encrypted cs+r of the hidden score.
[0143] The equations discussed above can be written more simply as follows: [°144] es = f(x,Cyu)=^=lfi(pi. ref.)
[0145] ref.) = (TijÇp., ref.) + (r^) mod T
[0146] ref.)
[0147] Here, the single storage server 2 used alone determines all the d portions 5) ( p., ref. ) allowing the C+r figure of the hidden score to be found.
[0148] Under these conditions, the storage server 2 can directly calculate the ciphertext cs+r by summing the d portions S) ( p? ref^, then transmit this ciphertext to all the decryption devices 3, rather than letting each decryption device 3 implement this step (step 305 in what was described previously). Thus, a summation operation which was carried out once in step 305 is here carried out only once by the single storage server 2 requested.
[0149] In one embodiment, it is chosen d - 2 (possibly in combination with 1). In this embodiment, two decryption devices 3 are involved. Two intermediate data} are exchanged between the two devices of decryption 3 of respective indices 1 and 2.
[0150] Optimizations of the correspondence table S / j
[0151] As the calculations carried out are reduced modulo 2”, a term Si j ( p^ ref.. j can only have one value among 2” possible.
[0152] In an advantageous embodiment, the correspondence table Sfj comprises two tables: • a first table which matches the pair p. ref.. with a pointer, • a second table of 2 terms, corresponding to the 2 values that each term S;j ( pj, ref.j ) can take.
[0153] The pointer provided by the first table points to a position in the second table where the value of the searched term P- ~ ref ) is stored.
[0154] Thus, the determination of this term is done in two stages: the storage server 2 begins by determining the pointer matched with the entry pair in the first table, then determines the term in the second table using the pointer with index i.
[0155] This decomposition into two tables has the advantage of drastically reducing the memory footprint of the correspondence tables. The pointers constituting the output values of the first table are much more compact than the terms S / j ( P-~ re fjj}- For example, a pointer can simply take the form of a position index in the second table, therefore have an integer value between 0 and 2” - 1- Thus, the first table only includes compact output values, and the terms p. ref, the number of which is limited (2W), are relocated in the second table, of limited length.
[0156]
[0157]
[0158] The index storage server i can thus use the following tables: • to first tables which each match the pair Pij reh . with a pointer, • a second common table “pointed” by the preceding pointers. Permutation of the correspondence tables before repeating the process Up to now, an identification method has been described based on a test biometric data item x, to check the identity of an individual to whom this data item x relates. This method is intended to be repeated for several different test biometric data items, likely to relate to different individuals.
[0159] Preferably, at least one of the following data is a single-use data item for the biometric test data x, or even for the encrypted cs+r of the masked score: • the unmasking data of index i, • the secondary decryption key with index i.
[0160] These measures help to better protect the system against replay attacks.
[0161] Another measure that makes it possible to achieve this objective of protection against replay attacks by means of very simple operations consists of carrying out a permutation of the second table discussed previously, before applying the steps of the method to a new biometric test data x to be checked. By carrying out such a permutation, the secondary masks ( r ) (.■ are “distributed” differently. Other embodiments
[0162] In the above, a particular application of the identity control method has been discussed, in which the result of the control conditions access to a secure area. It is however understood that the method described can be used for other applications.
Claims
Claims
1. A method comprising steps of: - calculation of a figure of a masked score, the masked score representing the result of the application of a primary mask r to a score representing a distance between a test biometric data item (x) relating to an individual and a reference biometric data item (3'„), the calculation comprising: - for all j ranging from 1 to k and for all i ranging from 1 to d, with k > 1 and d > 2, determination in a precalculated correspondence table of a term equal to (T, ; + {r). -i mod 2n in correspondence with a pair consisting of a portion of the test biometric data (x) and a portion of a cipher (Oj of the reference biometric data, where: - the encryption of the reference biometric data ( <X) résulte d’un chiffrement de la donnée biométrique de référence (¾ à l’aide d’une clé de chiffrement primaire ( Pk), - n is a predefined integer, a sum (y» _ j mnd of the tables Ty constitutes an estimate of a figure of the score in unmasked form, - the primary mask r is linked to secondary masks {r} by the following relation: ( mo^ “ rm°d \ 1—1 J— l hj / - implementation of the following summation in order to obtain the hidden score figure: - for all i ranging from 1 to d, implementation of the following steps by a decryption device (3) of index i: - decryption of the hidden score cipher using a secondary decryption key ( ( sk of index i, the decryption producing a data k) representing the hidden score modulo 2”, - generation of a partial result (0^ of index i from the data (s) and an unmasking data of index i, in which: - the secondary decryption keys ( ( sk} (,..., (sk} j) of respective indices ranging from 1 to d come from a primary decryption key (sk) associated with the encryption key (Pk), - the partial results (°i,..., of respective indices ranging from 1 to d allow the calculation of a control result (°) indicating whether the biometric test data (x) corresponds or not to the reference biometric data.
2. The method of claim 1, wherein determining the term Tjj + mod 2n comprises the following steps: - determining in a first correspondence table of index i a pointer of index i corresponding to the pair, the pointer of index i pointing to a position, in a second table of 2” terms, where the term of index i is stored, - determining the term of index i in the second table using the pointer of index i.
3. Method according to claim 2, further comprising steps of: - permutation of the second table, then - repetition of the calculation of the encrypted value of the masked score for a new biometric test data.
4. Method according to any one of claims 1 to 3, in which: k>l - for all j ranging from 1 to k and for all i ranging from 1 to d, the determination of the term equal to ( Ttj + ; j) mod 2n is implemented by a storage server (2) of index j, - for all j ranging from 1 to k, the storage server (2) of index j calculates a portion of index j of the encrypted value of the masked score by the following summation: rnod^ - for any i ranging from 1 to d, the decryption device (3) of index i calculates the encrypted value of the masked score by summing the portions of respective indices ranging from 1 to k of the encrypted value of the masked score.
5. A method according to any one of claims 1 to 3, wherein k = 1 and the calculation of the hidden score cipher is implemented by a single storage server (2).
6. Method according to any one of claims 1 to 5, in which the decryption implemented by the decryption device (3) of index i comprises the following steps: - calculation of an intermediate data item ((¾).) of index i from the following data: - a first part (Cç«) of the encrypted masked score, - the secondary decryption key (( sk).) of index i, and - a random number (^) generated by the decryption device (3) of index i, - for any decryption device (3) of index j^i, reception of an intermediate data item ((¾} .) of index j sent by the decryption device (3) of index j, - calculation of the data item (*) representing the masked score from the following data: - the intermediate data ((¾} of respective indices ranging from 1 to d, - a second part of the hidden score figure.
7. Method according to claim 6, in which the intermediate data (¾ ). of index i is calculated as follows ( csb}. — ) j + in which - is the first part of the cipher (c«) of the masked score, - {sk}. is the secondary decryption key of index i, - ei is the random number generated by the device of index i.
8. Method according to any one of claims 6 and 7, in which the data ($) representing the hidden score modulo 2” is calculated as follows: LL J, in which - (C^} is the intermediate data of index i, - Cs« is the second part of the score ciphertext, - f and # are two integers constituting parameters of a Brakerski / Fan-Vercauteren encryption scheme, - L. 1 denotes the rounding to the nearest integer operator, - [. ] $ denotes the modulo q operator, - [. ]t denotes the modulo t operator.
9. Method according to any one of claims 1 to 8, in which the control result (°) is equal to the sum of the partial results ( , od^ J respective indices ranging from 1 to d.
10. Method according to any one of claims 1 to 9, in which at least one of the following data is a single-use data for the biometric test data (x), or even for the encrypted masked score: - the unmasking data of index i, - the secondary decryption key of index i.
11. A computer program product comprising program code instructions for executing the steps of the method according to any one of claims 1 to 10, when this program is executed by a system.
12. Computer readable memory storing executable instructions for carrying out the steps of the method according to one of claims 1 to 10.
13. System comprising a control device (1), a storage server (2), at least two decryption devices (3), a trusted server (4) and an enrollment device (6), wherein said devices (1,3,6) and servers (2,4) comprise processors configured to implement the steps of the method according to any one of claims 1 to 10.
14. A method of controlling access of an individual to a secure area, comprising implementing the steps of the method according to one of any of claims 1 to 10 for identification of the individual