PassBio: Privacy-Preserving User-Centric Biometric Authentication
Kai Zhou, Jian Ren

TL;DR
PassBio introduces a user-centric biometric authentication scheme that allows end-users to encrypt their templates, ensuring privacy and security by preventing the server from accessing raw biometric data while enabling distance-based comparisons.
Contribution
The paper proposes a novel Threshold Predicate Encryption scheme enabling secure, privacy-preserving biometric authentication with encrypted templates and flexible distance metric evaluation.
Findings
Templates remain encrypted during authentication.
The scheme prevents template information leakage under passive and active attacks.
Supports multiple distance metrics like Hamming and Euclidean distances.
Abstract
The proliferation of online biometric authentication has necessitated security requirements of biometric templates. The existing secure biometric authentication schemes feature a server-centric model, where a service provider maintains a biometric database and is fully responsible for the security of the templates. The end-users have to fully trust the server in storing, processing and managing their private templates. As a result, the end-users' templates could be compromised by outside attackers or even the service provider itself. In this paper, we propose a user-centric biometric authentication scheme (PassBio) that enables end-users to encrypt their own templates with our proposed light-weighted encryption scheme. During authentication, all the templates remain encrypted such that the server will never see them directly. However, the server is able to determine whether the distance…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsCryptography and Data Security · Chaos-based Image/Signal Encryption · User Authentication and Security Systems
