BIDO: A Biometric Identity Online Authentication Framework
Aditya Mithra, Sibi Chakkaravarthy S, Srinivas Kankanala

TL;DR
BIDO is a device-free biometric authentication framework that securely generates cryptographic keys from live facial biometrics without storing PII, achieving high accuracy and security standards compatible with existing web authentication protocols.
Contribution
It introduces a novel method for deterministic key derivation from live biometric data without persistent storage, ensuring privacy and broad compatibility.
Findings
Achieved 99.51% verification accuracy on LFW.
Attained 92.14% Rank-1 identification on MegaFace with 1 million distractors.
Cryptographic FAR of 0.03% and FRR of 0.90%.
Abstract
Security systems demand continuous, cryptograph- ically robust identity verification without requiring subjects to carry physical tokens, smart cards, or dedicated hardware authenticators. This paper presents BIDO (Biometric Identity Online), a device-free authentication standard that achieves Au- thenticator Assurance Level 2 (AAL2) per NIST SP 800-63B with- out storing long-lived biometric templates, facial images, or any other form of Personally Identifiable Information (PII). BIDO derives Elliptic Curve Digital Signature Algorithm (ECDSA) key material deterministically from a live biometric measurement salted with a user-defined memorized secret at every authen- tication event, eliminating persistent private-key storage while enabling verification from any commodity sensor terminal. The generated credentials are non-discoverable (non-resident) Web Authentication (WebAuthn)…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
