Homomorphic Encryption for Secure Biometric Collation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing biometric authentication techniques face challenges in maintaining confidentiality and preventing impersonation, as they often require decrypting distances between templates and target data, making them vulnerable to hill climbing attacks.
Innovation Solution
A cipher-information generation device and method using homomorphic encryption to calculate and encrypt values within a range based on a threshold, applying computations to encrypted cipher-texts representing similarity, generating encrypted sums without decrypting the distance, thereby enhancing security in collation processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If biometric authentication techniques decrypt distances between templates and target data for collation, then collation accuracy is improved, but security against hill climbing attacks deteriorates
Solution Approach 1:
The patent introduces an intermediary coordinate system transformation that operates on encrypted data. Instead of directly comparing biometric templates in the original space, the system transforms both the template and target data into a different coordinate system using encrypted coordinate values, performs collation in this transformed space, and then transforms the result back. This intermediary transformation layer allows accurate collation while preventing direct access to the original biometric data, thereby blocking hill climbing attacks that rely on analyzing distance relationships in the original space.
Solution Approach 2:
The patent changes the parameter space by applying coordinate system transformations to the biometric data. By transforming the coordinate values of both templates and target data into a different reference frame, the system maintains the relative distance relationships needed for accurate collation while altering the absolute coordinate values. This parameter transformation ensures that even if an attacker obtains encrypted distance information, it cannot be used to reconstruct the original biometric template or perform hill climbing attacks, as the coordinate system has been fundamentally changed.
2Measurement precision
If biometric templates are stored in original form for accurate authentication, then authentication accuracy is improved, but confidentiality of biometric information deteriorates
Solution Approach 1:
The patent uses coordinate system transformation as an intermediary mechanism to store and process biometric templates. Instead of storing original biometric coordinates, the system stores transformed coordinate values in a different reference frame. This intermediary representation maintains the essential geometric relationships needed for accurate authentication while obscuring the original biometric information. When authentication occurs, both the stored template and the presented target data undergo the same transformation, allowing accurate comparison without exposing the original biometric secrets.
3Loss of information
If coordinate values are added to conceal biometric data, then confidentiality is improved, but collation accuracy deteriorates
Solution Approach 1:
The patent applies coordinate system transformation as a parameter change that simultaneously achieves confidentiality and maintains accuracy. By transforming the coordinate values into a different reference frame using a consistent transformation rule, the system conceals the original biometric coordinate information while preserving the relative distance relationships. The key insight is that the transformation is applied uniformly to both templates and target data, so the distance relationships remain intact despite the coordinate changes, enabling accurate collation of the transformed data.
Data Source
AI summary
The present invention provides a crypto-information creation device, etc., with which it is possible to create information that enables a safer collation process between information that is the subject of collation and information to be referenced. This crypto-information creation device 501 has: a range encryption unit 502 for calculating a first value included in a range based on a threshold value and encrypting the calculated first value in accordance with a homomorphic encryption scheme, thereby creating a first cryptogram in which the first value is encrypted; and a computation unit 503 for applying a computation according to the encryption scheme to the first cryptogram and to a second cryptogram in which a second value representing the degree of similarity is encrypted in accordance with the encryption scheme, thereby creating a third cryptogram in which a value obtained by adding together the first value and the second value is encrypted.


