SPECIAL SECTION ON INTELLIGENT BIOMETRIC SYSTEMS FOR SECURE SOCIETIES
Recei ed Sep embe 16, 2020, accep ed Sep embe 28, 2020, da e o publica ion Oc obe 5, 2020, da e o cu en e sion Oc obe 16, 2020.
Digi al Objec Iden i ie 10.1109/ACCESS.2020.3028703
A Pos -Quan um Biome ic Templa e P o ec ion
Scheme Based on Lea ning Pa i y Wi h
Noise (LPN) Commi men s
ROSARIO ARJONA AND ILUMINADA BATURONE
Ins i u o de Mic oelec ónica de Se illa (IMSE-CNM), Uni e sidad de Se illa-CSIC, 41092 Se ille, Spain
Co esponding au ho : Rosa io A jona ([email p o ec ed])
This wo k was suppo ed in pa by he Spanish Agencia Es a al de In es igación and Fondo Eu opeo de Desa ollo Regional (FEDER)
unde P ojec TEC2017-83557-R and P ojec RTC-2017-6595-7, and in pa by he Conseje ía de Economía, Conocimien o, Emp esas y
Uni e sidad de la Jun a de Andalucía, unde P ojec AT17_5926_USE and P ojec US-1265146. The wo k o Rosa io A jona was
suppo ed by a Pos doc o al Fellowship om he Spanish Na ional Cybe secu i y Ins i u e (INCIBE).
ABSTRACT Biome ic ecogni ion has he po en ial o au hen ica e indi iduals by an in insic link be ween
he indi idual and hei physical, physiological and/o beha io al cha ac e is ics. This leads a highe secu i y
le el han he au hen ica ion solely based on knowledge o possession. One o he easons why biome ics is
no comple ely accep ed is he lack o us in he s o age o biome ic empla es in ex e nal se e s. Biome ic
da a a e sensi i e da a which should be p o ec ed as is con empla ed in he da a p o ec ion egula ion o many
coun ies. In his wo k, we p opose he use o biome ic Lea ning Pa i y Wi h Noise (LPN) commi men s as
empla e p o ec ion scheme. To he bes o ou knowledge, his is he i s p oposal o biome ic empla e
p o ec ion based on he LPN p oblem ( ha is, he di icul y o decoding andom linea codes), which o e s
pos -quan um secu i y. Biome ic ea u es a e compa ed in he p o ec ed domain. I e e sibili y, e ocabili y,
and unlinkabili y p ope ies a e sa is ied as well as esis ance o False Accep ance Ra e (FAR), c oss-
ma ching, S olen Token, and simila i y-based a acks. A ecogni ion accu acy wi h a 0% FAR is achie ed,
because use -speci ic sec e keys a e employed, and he False Rejec ion Ra io (FRR) can be adjus ed
depending on a h eshold o p ese e he accu acy o he unp o ec ed scheme in he S olen Token scena io.
A good pe o mance in e ms o execu ion ime, empla e s o age and ope a ion complexi y is ob ained o
secu i y le els a leas o 80 bi s. The p oposed scheme is employed in a dual- ac o au hen ica ion p o ocol
om he li e a u e o illus a e how i p o ides secu i y using au hen ica ion and da abase (cloud) se e s
ha can be malicious. The p oposed LPN-based p o ec ed scheme can be applied o any biome ic ai
ep esen ed by bina y ea u es and any ma ching sco e based on Hamming o Jacca d dis ances. In pa icula ,
expe imen al esul s a e included o a p ac ical inge ein-based ecogni ion sys em implemen ed in Ma lab.
INDEX TERMS Biome ic empla e p o ec ion, pos -quan um secu i y, LPN commi men s, dual- ac o
au hen ica ion, au hen ica ion p o ocol, inge eins.
I. INTRODUCTION
Nowadays, ou socie y has accep ed ex ensi ely he use o
biome ic sys ems as a way o use au hen ica ion. The p ob-
lem is ha biome ic da a, which a e s o ed as empla e a
he egis a ion phase o en ollmen , a e sensi i e and, hence,
should be p o ec ed, as con empla ed in he da a p o ec ion
egula ion o many coun ies [1]. Ano he p oblem is ha
biome ic da a ha a e e ealed canno be employed any
The associa e edi o coo dina ing he e iew o his manusc ip and
app o ing i o publica ion was Ma ina Ga ilo a .
mo e o a oid impe sona ion and p i acy a acks. This also
mo i a es o p o ec empla es since people canno p o ide
many biome ic ai s.
The ISO/IEC 24745 s anda d on biome ic in o ma ion
p o ec ion es ablishes he equi emen s o i e e sibili y,
unlinkabili y, and e ocabili y o biome ic empla e p o-
ec ion schemes [1]. I e e sibili y means ha no in o ma-
ion ela ed o he biome ic da a can be eco e ed e en i
p o ec ed empla es a e comp omised. Hence, biome ic da a
emain p i a e. Unlinkabili y means ha no ad e sa y can
know which indi idual is he owne o he p o ec ed empla e,
VOLUME 8, 2020 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ 182355
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
hus allowing use iden i y p i acy. In case a p o ec ed em-
pla e is comp omised, i should be e ocable o enewable
o ob ain a new p o ec ed empla e om he same biome ic
sample.
T adi ionally, biome ic empla e p o ec ion schemes ha e
been classi ied in o 1) biome ic c yp osys ems and 2) ea u e
ans o ma ions o cancelable biome ics [2].
Biome ic c yp osys ems bind a sec e c yp og aphic key o
he biome ic da a. Among hem, uzzy ex ac o , uzzy aul
and uzzy commi men schemes we e p oposed, he la e
being widely employed [3]–[5]. In Fuzzy Commi men s [6],
he commi men s a e Auxilia y o Helpe Da a gene a ed
as a combina ion o biome ic da a wi h an e o co ec-
ion codewo d indexed by a c yp og aphic key. A c yp o-
g aphic hash o he sec e key (o o he e o co ec ion
codewo d) is s o ed oge he wi h he Helpe Da a. Bio-
me ic da a should be ep esen ed as bina y s ings and he
Hamming dis ance is used as he dis ance me ic. Ma ch-
ing is pe o med by a emp ing o eco e he c yp og aphic
key om he Helpe Da a and he inpu biome ic da a,
applying e o co ec ion decoding. I e e sibili y is based
on he compu a ional di icul y o e ie e ei he he key
o he biome ic da a om he s o ed Helpe Da a. Unlink-
abili y and e ocabili y a e based on employing di e en
keys.
The ecogni ion accu acy o biome ic c yp osys ems is
wo se han he sys ems wi hou p o ec ion, also known as he
baseline sys ems. Hence, hei secu i y is e y much lowe
han a c yp og aphic sys em because hei False Accep ance
Ra e (FAR) is no su icien ly small. Conside ing a b u e-
o ce a ack (also known as FAR a ack), FAR should be
smalle han 2−N o achie e a leas N-bi secu i y. Howe e ,
he FAR o biome ic sys ems usually anges om 10−5
(17 bi s) o 10−7(24 bi s) [4]. The e o e, mul ibiome ic
usion should be employed o imp o e secu i y. Ano he
limi a ion o biome ic c yp osys ems ha o ces he use
o mul ibiome ic usion is he low en opy o biome ic
ai s [4].
In he ea u e ans o ma ion app oach, he biome ic em-
pla e is p o ec ed by a ans o ma ion unc ion, which is
applied a he egis a ion and he e i ica ion phases. The e-
o e, biome ic da a a e compa ed in he p o ec ed domain.
T ans o ma ions can be non-in e ible o in e ible (sal -
ing). T ans o ma ion unc ions p oposed in he li e a u e
a e BioHashing [7], Alignmen -Robus Hashing (ARH) [8],
e-mapping and wa ping [9], and Bloom il e s [10]. Unlinka-
bili y and e ocabili y a e based on he a ia ion o he pa am-
e e s o he ans o ma ion unc ions. I e e sibili y depends
on he di icul y o ob ain he o iginal biome ic da a om he
ans o med da a.
T ans o med empla es o en con ain less in o ma ion han
he o iginal empla es. Hence, he usual consequence is a
ecogni ion pe o mance deg ada ion compa ed o he base-
line e sion (wi hou ans o ma ion) [7]–[11]. As in biome -
ic c yp osys ems, mul ibiome ic usion should be employed
o imp o e secu i y [12].
The accu acy ob ained wi h he ans o ma ion can be
imp o ed due o he en opy added by a use -speci ic sec e
key as in sal ing schemes. In ac , he ad an age o sal ing
schemes, such as BioHashing [7], is ha , heo e ically, he e
is he possibili y o achie ing a 0% e o a e due o he
use o a dual ecogni ion based on he biome ic in o ma ion
and he use -speci ic sec e key. Howe e , his is isky and
no ad isable because an a acke can use he de ice wi h
he use -speci ic sec e key o imp o e he chances o suc-
cess ul au hen ica ion. This is known as he S olen Token
scena io [7]. Besides, as happens o biome ic c yp osys ems,
a limi a ion o many sal ing schemes is ha hei secu i y is
e y much lowe han a c yp og aphic sys em because hey
a e no obus o FAR a acks [13].
In he o he side, mos o cancelable biome ic schemes
apply simila i y-p ese ing ans o ma ions, also called
Locali y Sensi i e Hashing, in o de o p ese e in he p o-
ec ed domain he accu acy pe o mance ob ained in he
unp o ec ed domain [14], [15]. The p oblem is ha his
simila i y o dis ance-p ese ing p ope y (dis ances be ween
unp o ec ed samples a e nea ly he same as he dis ances
be ween p o ec ed samples) can be exploi ed by simila i y-
based a acks ha b eak hese schemes. I an a acke can
access he p o ec ed empla e, he/she can apply a sea ch
algo i hm o gene a e i s guesses andomly, ans o m hem
o he p o ec ed domain, compu e he dis ances wi h he p o-
ec ed empla e, use he in o ma ion o imp o e he p obabil-
i y o success wi h new guesses, and epea he p ocess un il
eaching a success ul guess. The wo k in [15] con i ms he
ulne abili y o BioHashing and Bloom- il e schemes o a
Gene ic Algo i hm enabled simila i y-based a ack. The wo k
in [14] in oduces non-linea i y in he ans o ma ion wi h
he aid o a deep neu al ne wo k, bu his equi es e aining
whene e a new use is en olled.
An al e na i e app oach ecen ly p oposed o p ese e
he accu acy o baseline sys ems is homomo phic enc yp-
ion [16]. When i is employed in a biome ic applica ion,
he empla e and he inpu biome ic da a a e enc yp ed by
using a public key. The compa ison is pe o med in he
enc yp ed domain by means o an enc yp ed sco e compu-
a ion ope a ion. Thus, he esul ing sco e a e compa ison
is enc yp ed. In o de o ob ain he inal sco e, a dec yp ion
ope a ion by using a p i a e key should be applied.
The p ac ical implemen a ion o Fully Homomo phic
Enc yp ion schemes is s ill a challenge because no all he
ope a ions needed o ob ain an enc yp ed sco e a e easi-
ble due o hei high cos in compu a ional and memo y
equi emen s [2]. The p ac ical p oposals o biome ic Homo-
mo phic Enc yp ion schemes only allow a limi ed subse
o ope a ions (addi ions o mul iplica ions) in he enc yp ed
domain. The mos used app oach is he addi i ely homo-
mo phic scheme and, speci ically, he Paillie homomo phic
enc yp ion scheme [17]. In he schemes based on Paillie
homomo phic enc yp ion, he secu i y o he ope a ions
employed a e based on ha d p oblems ha canno be sol ed
nowadays in polynomial ime, such as he Disc e e Loga i hm
182356 VOLUME 8, 2020
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
P oblem and he In ege Fac o iza ion P oblem. Howe e ,
hese p oblems a e no so complex o quan um compu e s,
which is a ele an h ea o conside , because p o ec ed
schemes ha nowadays a e conside ed secu e will no be so
in he u u e.
Among he sys ems belie ed o esis he a acks o
quan um compu e s, la ice-based c yp og aphy has a ac ed
mos in e es . La ice c yp og aphy uses high-dimensional
geome ic s uc u es o hide in o ma ion c ea ing p oblems
ha a e conside ed impossible o sol e i he p i a e key
is unknown, e en o quan um compu e s. Homomo phic
enc yp ion can be also cons uc ed on he la ice p oblem un-
damen als. In [18], wo a ian s o Homomo phic Enc yp ion
a e employed based on ideal-la ice and, pa icula ly, ing-
LWE ( ing Lea ning Wi h E o s) schemes, which a e an
example o ideal la ice c yp og aphy.
The d awback o homomo phic enc yp ion-based
app oaches is no only hei high compu a ional cos bu also
hei memo y equi emen s since he size o he p o ec ed
empla e is a ound wo o de o magni ude g ea e han
he unp o ec ed empla e [18]. In addi ion, a simple a ack
algo i hm has been epo ed o he au hen ica ion se e ha
compu es he inal dec yp ed sco e. The biome ic da a can
be e ealed in a mos 2N−T que ies, whe e N is he bi -
leng h o he biome ic empla e and T is he au hen ica ion
h eshold [19].
In his wo k, we p opose a pos -quan um ligh weigh solu-
ion based on la ice c yp og aphy. Speci ically, Lea ning Pa -
i y wi h Noise (LPN) commi men s a e employed o p o ec
biome ic da a. Ou p oposal o biome ic LPN commi men s
uses a public gene a o ma ix o con e biome ic da a
o linea codewo ds ha hen a e andomized wi h a use -
speci ic sec e . LPN commi men s a e no opened ( he sec e s
a e no e ealed) bu compa ed in he p o ec ed domain.
The commi men s using impos o sec e s a e de ec ed and
di ec ly ejec ed wi hou p oceeding o calcula e a biome ic
simila i y sco e. Hence, False Accep ance Ra e is 0%.
In compa ison, con en ional Fuzzy Commi men s also
uses a public gene a o ma ix bu o con e a sec e o a
linea codewo d ha is hen combined wi h he biome ic
da a. Biome ic c yp osys ems using Fuzzy Commi men s
accep an indi idual i he commi men can be opened ( he
sec e can be econs uc ed) because he biome ic da a p o-
ided a e i ica ion is enough simila o he da a p o ided a
en ollmen . Hence, FAR is no 0% and FAR a acks can be
success ul.
LPN-based schemes ha e been applied o pseudo andom
gene a o s, symme ic key enc yp ion, sec e -key au hen ica-
ion p o ocols, public-key iden i ica ion, and ze o-knowledge
p oo s [20], [21]. Howe e , o he bes o ou knowledge, his
is he i s p oposal o LPN-based c yp og aphy o biome ic
empla e p o ec ion. The main con ibu ions o his pape a e
he ollowing:
•The i s biome ic empla e p o ec ion scheme based on
LPN commi men s, whose ha dness is a NP comple e
p oblem o classical and quan um compu e s.
•A low cos solu ion in e ms o compu a ional and mem-
o y equi emen s o p o ec ed empla e gene a ion and
s o age (lowe han app oaches based on homomo phic
enc yp ion).
•High secu i y agains a acks o eco e he biome -
ic da a, because compa ison is done in he p o ec ed
domain, using e icien c yp og aphic p o ocols.
•Resis ance o simila i y-based a acks because LPN
commi men s a e andom (compu a ionally hiding) and,
hence, do no p ese e he dis ance alues ob ained
be ween unp o ec ed samples wi h espec o he dis-
ance alues ob ained be ween p o ec ed samples.
•A ecogni ion accu acy wi h a FAR o 0% because
use -speci ic sec e keys a e employed in he biome ic
LPN commi men s. In case o he S olen Token sce-
na io, whe e an a acke uses a clien de ice wi h a
use -speci ic sec e key, he accu acy o he unp o ec ed
app oach is p ese ed.
•A secu i y le el compa able o a c yp og aphic sys em,
e en wi h unibiome ic sys ems.
•Expe imen al esul s a e included om a p ac ical
implemen a ion in Ma lab.
•The p oposed solu ion was applied o a inge ein-
based biome ic sys em, compa ed o o he sys ems,
and e alua ed in e ms o i e e sibili y, e ocabil-
i y and unlinkabili y, as es ablished in he s anda d
ISO/IEC 24745.
This wo k is s uc u ed as ollows. Sec ion II desc ibes ou
p oposal o applica ion o LPN commi men s o biome ic
empla e p o ec ion. The ope a ions equi ed a e de ined,
and a secu i y analysis is ca ied ou , conside ing a dis-
ibu ed scena io wi h cloud-based se ices whe e ou scheme
is included in an au hen ica ion p o ocol p oposed in he
li e a u e. The implemen a ion o biome ic LPN commi -
men s by using Ma lab unc ions is explained in Sec ion III.
Pa ame e s a e selec ed o achie e se e al secu i y le els and
pe o mance is e alua ed in e ms o execu ion ime, empla e
s o age and ope a ion complexi y. In addi ion, a compa i-
son o homomo phic enc yp ion-based p oposals is included.
A p ac ical ealiza ion is p esen ed in Sec ion IV by using
inge eins. Accu acy, i e e sibili y, e ocabili y, unlink-
abili y, and esis ance o a acks a e p o en and compa ed
o o he p oposals o biome ic empla e p o ec ion schemes
applied o inge eins. Finally, Sec ion V concludes he
wo k.
II. PROPOSAL OF BIOMETRIC TEMPLATE PROTECTION
BASED ON LPN COMMITMENTS
A. DEFINITION OF BIOMETRIC LPN COMMITMENTS
Commi men schemes a e undamen al c yp og aphic p im-
i i es o c yp og aphic p o ocols. A commi men scheme
allows a pa y o commi o a message by using a sec e
key o main ain i hidden o o he s. The secu i y p ope ies
equi ed by a commi men a e he hiding and binding p ope -
ies. Hiding means ha one canno lea n any hing abou he
commi ed message om he commi men . Binding means
VOLUME 8, 2020 182357
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
ha he commi men c ea ed o a message is di e en o he
commi men c ea ed o a di e en message.
An LPN commi men is based on encoding a message
(in ou p oposal, biome ic da a) by using a andom linea
code wi h some noise added o he codewo d. Fo mally,
he LPN commi men o an m-bi message B∈{0,1}mis as
ollows [21]:
Com (B)=A·( ||B)⊕e(1)
whe e ·applies he bi wise AND and XOR ope a ions; || is
he conca ena ion o wo ec o s; ⊕is he bi wise XOR ope -
a ion; is a uni o mly andom ec o ∈{0,1}lincluded o
add andomness; eis a low-weigh uni o mly andom ec o
∈{0,1}n ollowing a Be noulli dis ibu ion wi h pa ame e τ
(0 < τ < 1/2), i.e., e e y bi in ehas a p obabili y τo being
1 and p obabili y (1−τ) o being 0 (e[i]has P [e[i]=1]=τ
and P [e[i]=0]=1−τ); and Ais a uni o mly andom
ma ix A=A0||A00 ∈{0,1}n×kwi h k=l+mand n≥k.
The esul ing Com (B)is a ec o ∈{0,1}n. The weigh w
o eis de e mined by he Hamming Weigh (HW) o e( ha is,
w=Pn
i=1e[i]). When he weigh o eis exac ly nτ, ins ead
o expec ed, he LPN p oblem is named as exac LPN (xLPN
o sho ) [21].
Using he same no a ion as abo e, he sea ch e sion o he
LPN p oblem wi h pa ame e s k∈N( he leng h o a sec e
s), τ∈R( he noise a e in he e[i]), and n∈N( he numbe o
samples), asks o ind a k-bi sec e s om he nnoisy linea
equa ions esul ing om b=A·s⊕e, whe e Ais public.
In ou case, and B( he biome ic da a) conca ena ed o m
he sec e . The compu a ionally ha d p oblem unde lying he
secu i y (i.e., he compu a ional hiding p ope y) o he LPN
commi men scheme is he sea ch LPN p oblem, which can
be s a ed as he NP comple e p oblem o decoding andom
linea codes [22]. Since he decoding p oblem in andom
linea codes is known o be obus o quan um as well as o
classical compu e s, he sea ch LPN p oblem is sui able o
he cons uc ion o quan um- esis an commi men s o sec e
biome ic da a B.
Se ing n=θ(k)=θ(l+m) la ge enough, he commi -
men scheme becomes compu a ionally hiding and pe ec ly
binding (wi h o e whelming p obabili y o e he choice o
A). On he one hand, he binding p ope y is sa is ied by he
la ge dis ance o he code gene a ed by he andom ma ix A.
On he o he hand, he hiding p ope y is sa is ied by he LPN
assump ion which implies ha A·s⊕eis pseudo andom.
Le us de ine a linea code Cas a k-dimensional subspace
o {0,1}n. In he decoding p oblem, he inpu is a noisy
e sion o a codewo d c∈C,c⊕e, wi h e o ec o
e∈{0,1}no Hamming weigh w. In a ypical se ing,
he weigh wis uppe bounded by he code dis ance d, which
is he minimum Hamming dis ance be ween wo codewo ds
( ull dis ance decoding). The a ge o decoding is o eco e
he codewo d c(which is equi alen o ind e).
E e y ins ance o he LPN p oblem is an ins ance o a
synd ome decoding p oblem whe e nis he leng h o he
codewo d, kis he linea code ank, Ais he gene a o ma ix,
and wis he linea code dis ance (d) ob ained om an e o
pa ame e τas w=nτ. Le nbe he numbe o samples,
we can w i e an LPN ins ance as he ollowing ma ix- ec o
uple:
A·s∈{0,1}n×k×{0,1}ksa is ying A·s=b⊕e(2)
whe e e=(e1,...,en) and he i h ow o Aand b ep esen
he i h LPN sample.
Nowadays, he bes algo i hms o decoding andom bina y
linea codes o mula ed as a synd ome decoding p oblem
a e based on In o ma ion Se Decoding (ISD) [23], a p ob-
abilis ic decoding s a egy ha essen ially ies o guess k
co ec posi ions in he noisy ecei ed wo d, b. The unning
ime, T, o decoding algo i hms is ypically a unc ion o he
pa ame e s n,kand w. I he Gilbe -Va shamow bound is
used, wis a unc ion o nand k, and he e o e he unning
ime can be exp essed as a unc ion o nand konly. Fo
all In o ma ion Se Decoding algo i hms, he highes unning
ime is achie ed when he code a e k/nis sligh ly below
1/2. In ha case, he ISD algo i hms o e exponen ial un-
ning imes o he o m T(n)=2an whe e αis a cons an
which can be used as a me ic o compa e he di e en
algo i hms.
B. COMPARISON OF BIOMETRIC LPN COMMITMENTS
IN THE PROTECTED DOMAIN
In gene al, he algo i hms o a commi men scheme a e:
key gene a ion (KGen), which esul s a public commi men
key; commi men gene a ion (Com), which ou pu s a com-
mi men o a message; and e i ica ion Ve , which e i ies
he commi men . In he LPN commi men scheme p oposed
in [21], KGen gene a es he public key A;Com ou pu s he
andomness and he commi men om he public key A
and a message m:Com (m)=A·( ||m)⊕e; and Ve
akes he key A, he andomness , he commi men Com (m),
and he message m, and ou pu s 1 (success ul e i ica ion) i
Com(m)⊕A·( ||m) has weigh w, and 0 ( ailed e i ica ion)
o he wise.
In ou p oposal o biome ic LPN commi men s, he mes-
sage is he biome ic da a, B a en ollmen , and B a ma ch-
ing, which should be always p o ec ed. The e o e, in ou
p oposal, KGen gene a es he public ma ix A,Com ou pu s
and Com (B )=A·( ||B )⊕e a en ollmen , and and
Com (B )=A·( ||B )⊕e a ma ching, and Ve is modi ied
o wo k only wi h p o ec ed da a, ha is, wi h commi men s.
Ou e i ie combines he biome ic LPN commi men s by a
XOR ope a ion as ollows:
Com (B )⊕Com (B )=A·[( ||B )⊕( ||B )]⊕e ⊕e
(3)
This esul can be conside ed as a sys em o linea
equa ions wi h A as coe icien ma ix and A|[Com (B )⊕
Com (B )] as augmen ed ma ix. I Com (B )and Com (B )
a e gene a ed om he genuine p o e , e =e . Hence,
he XOR ope a ion applied o genuine commi men s esul s
182358 VOLUME 8, 2020
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
FIGURE 1. En ollmen phase o he au hen ica ion p o ocol based on biome ic LPN commi men s.
[Com (B )⊕Com (B )]=A·[( ||B )⊕( ||B )]. Sol ing he
sys em o linea equa ions (by means o Gaussian elimina-
ion, o ins ance), [( ||B )⊕( ||B )]=( ⊕ ||B ⊕B )
is ob ained.
Since and can be known by he e i ie , i can be
checked i ( ⊕ ) is co ec . Then, he e i ie employs
(B ⊕B ) o compu e he sco e measu emen o he empla e
and he inpu ea u es. Typically, he sco e is based on he
F ac ional Hamming Dis ance (FHD), which can be com-
pu ed as ollows:
FHD (B ,B )=HD(B ,B )
m=Pm
i=1(B [i]⊕B [i])
m(4)
whe e HD is he Hamming Dis ance and mis he o al numbe
o bi s in he biome ic da a.
In addi ion, he sco e can be based on he Jacca d Dis ance
(JD), which can be compu ed as ollows:
JD(B ,B )=2·FHD(B ,B )
FHD (B ,B )+FHW(B )+FHW(B )(5)
whe e FHW is he F ac ional Hamming Weigh ( ha is
FHW(B)=(Pm
i=1B[i])/m).
In he case o Jacca d dis ance, he Hamming weigh s o he
biome ic da a a e needed, bu his is no a p oblem since hey
do no e eal any sensi i e in o ma ion abou biome ic da a.
I he sco e calcula ed (based on FHD (B ,B )o JD(B ,B ))
is below an au hen ica ion h eshold, he e i ica ion ou pu s
1 (success), and ou pu s 0 ( ailu e), o he wise.
I Com (B )and Com (B )a e gene a ed om genuine and
impos o p o e s, e 6= e . In his case, he sys em o linea
equa ions wi h A as coe icien ma ix and A|[Com (B )⊕
Com (B )] as augmen ed ma ix canno be sol ed, because
he ank o he augmen ed ma ix is highe han he ank
o he coe icien ma ix. As s a ed by he Rouché–F obenius
heo em, he sys em has solu ion i and only i he anks o
he coe icien ma ix and he augmen ed ma ix a e equal.
The e o e, he impos o is di ec ly ejec ed wi hou p oceed-
ing o a sco e measu emen .
C. USE OF BIOMETRIC LPN COMMITMENTS IN AN
AUTHENTICATION PROTOCOL
In his wo k, we apply biome ic LPN commi men s in he
ypical scena io whe e cloud-based se ices and dis ibu ed
a chi ec u es a e employed, as p oposed in [13]. The en i ies
in ol ed a e: 1) Nuse s (i=1,...,N), each one wi h a
clien de ice; 2) a clien de ice which ob ains use biome ics,
iden i ies and keys; 3) an au hen ica ion se e in cha ge o
he e i ica ion o biome ic LPN commi men s; and 4) a
da abase se e o (cloud) s o age. In his p o ocol, he e
a e wo au hen ica ion ac o s: 1) he biome ics, and 2) he
knowledge o a use key o he possession o a oken wi h he
use key s o ed in a secu e memo y o econs uc ed wi h a
Physical Unclonable Func ion (PUF) [24]. In he ollowing,
he knowledge o a use key is conside ed, as being mo e
gene al [13].
The en ollmen and e i ica ion phases a e illus a ed
in Fig. 1 and Fig. 2. Du ing he en ollmen phase, he clien
de ice acqui es he biome ic samples s i, he use key ki
and he use iden i y IDi. F om he biome ic samples s i,
he clien de ice ex ac s he biome ic ea u es B i.eiis
de i ed by using wha we call a Weigh ed Key De i a ion
Func ion (WKDF) om he use key kiand he use iden i y
IDi. This unc ion s a s om an all-ze o ec o o nelemen s.
Since he esul ing ec o eimus ha e a cons an weigh w,
as commen ed in Subsec ion II.A, i means ha w=nτones
a e inse ed in he sequence o ze os. The posi ions in which
he wones a e in oduced ollow a uni o m dis ibu ion o
andom alues in he ange [1, n] p o ided by a de e minis ic
andom gene a o . The de e minis ic andom gene a o p o-
ides he same posi ions i he use in oduces he same ki
and IDi. I a andom posi ion is epea ed, i is disca ded, and
a new posi ion is gene a ed un il wones a e inse ed. Mo e
de ails abou his unc ion a e gi en in he ollowing Sec ion.
A p ac ical implemen a ion can be seen in [25].
The andom ec o i is gene a ed by using a Random
Numbe Gene a o (RNG). The public ma ix Ai, which is
ob ained by he KGen algo i hm, can be s o ed locally in
VOLUME 8, 2020 182359
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
FIGURE 2. Ve i ica ion phase o he au hen ica ion p o ocol based on biome ic LPN commi men s.
he clien de ice. Then, he associa ed biome ic LPN com-
mi men Com (B i)=Ai·( i||B i)⊕eiis c ea ed. The
clien de ice sends (IDi,Com (B i), i) o he au hen ica ion
se e . The au hen ica ion se e maps IDi o a unique index i,
s o es (i,IDi) in i s local da abase and sends (i,Com (B i), i)
o he da abase se e o s o age.
Du ing he e i ica ion phase, he clien de ice acqui es he
biome ic samples s i, he use key kiand he use iden i y IDi.
The inpu biome ic ea u es B i a e ex ac ed om he bio-
me ic samples s i,eiis de i ed by using he WKDF om he
inpu use key kiand he use iden i y IDi, and i is gene a ed
by using he RNG. Then, he associa ed biome ic LPN com-
mi men Com (B i)=Ai·( i||B i)⊕eiis c ea ed using he
e ie ed Ai. The clien de ice sends (IDi,Com (B i), i) o
he au hen ica ion se e , and also Ai(al hough his is a public
ma ix ha could be ob ained in ano he way). The au hen i-
ca ion se e eco e s i om i s local da abase associa ed o
he ecei ed IDiand (Com (B i), i) om he da abase se e
by using a p i a e in o ma ion e ie al (PIR) scheme. Then,
he au hen ica ion se e ca ies ou he e i ica ion algo-
i hm as desc ibed in Subsec ion II.B. A P i a e In o ma ion
Re ie al (PIR) is a p o ocol ha allows he au hen ica ion
se e o e ie e an elemen o he da abase se e wi hou he
owne o he da abase being able o de e mine which elemen
was que ied. A secu e PIR is employed oge he wi h he
da abase anonymiza ion, as p oposed in [13], o sa is y he
use iden i y p i acy.
The communica ion channels among he p o ocol en i ies
a e assumed o be secu e, which is a usual scena io. This
means ha an ex e nal ad e sa y canno in e cep o modi y
a message which is communica ed h ough he channels.
Besides, he clien de ice is assumed o be us ed, ha is,
we do no conside i s o es use IDs, keys o biome ic
samples, o execu es a malicious so wa e. Finally, a he
en ollmen phases, all he en i ies a e assumed o beha e
hones ly.
Howe e , an ex e nal ad e sa y can use he clien de ice
o ca y ou impe sona ion a acks, which is he S olen Token
scena io commen ed in In oduc ion, and can a ack also he
in o ma ion s o ed in he da abase se e . Biome ic LPN
commi men s a e obus o hese a acks as desc ibed in he
ollowing sec ion.
In addi ion, since ex e nal ad e sa ies canno ob ain mo e
in o ma ion han he in e nal ones, he p o ocol conside s
malicious au hen ica ion and da abase se e s a he e i ica-
ion phase. I he au hen ica ion se e is malicious, he a -
ge is o lea n he use biome ics o keys. Howe e , his
is no possible because he au hen ica ion se e does no
ha e access o his in o ma ion. I he da abase is malicious,
he a ge is o ob ain he link be ween he commi men and
he use iden i y. Howe e , since he da abase is anonymized
and a PIR p o ocol is employed, he use iden i y p i acy is
sa is ied.
D. SECURITY ANALYSIS OF THE BIOMETRIC LPN
COMMITMENT AS TEMPLATE PROTECTION SCHEME
Acco ding o he ISO/IEC 24745:2011 s anda d on biome ic
in o ma ion p o ec ion [1], he biome ic empla e p o ec ion
schemes should ully mee he secu i y equi emen s o i e-
e sibili y, e ocabili y (o enewabili y) and unlinkabili y.
I e e sibili y is ela ed o he di icul y o eco e he
o iginal biome ic ea u es om he p o ec ed empla e. I e-
e sibili y in an LPN commi men is based on he secu i y o
he LPN p oblem, which is he ha dness o decoding andom
linea codes (a NP comple e p oblem esis an o quan um
algo i hms) [20]. Since Aand ea e bo h andom, he esul ing
LPN commi men is andom. Hence, in e ms o Shannon
en opy, he en opy in bi s o he biome ic LPN commi -
men s is p ac ically 100%, independen ly o he biome ic
ea u e. The en opy p o ided by Fuzzy Commi men s is
lowe , as depic ed in Table 1, wi h da a aken om [5].
Re ocabili y (o enewabili y) is ela ed o he abili y o
c ea e a new and di e en p o ec ed empla e om he same
biome ic ea u es o he same indi idual iby using di e en
keys. This secu i y equi emen is associa ed o he binding
p ope y o an LPN commi men [21]. I Com (B i)=Ai·
( i||B i)⊕eiis c ea ed om he biome ic ea u es B i and
ano he andom Com0(B i)=A0
i·( 0 i||B i)⊕e0
ican be c ea ed
182360 VOLUME 8, 2020
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
TABLE 1. En opy in bi s o uzzy commi men s [5] and LPN commi men s.
om he same biome ic ea u es B i,Com (B i)6= Com0(B i)
wi h Com (B i)and Com0(B i) andom (compu a ionally hid-
ing). This is also ue i Ai=A0
i.
Unlinkabili y a oids possible c oss-compa isons wi h
o he da abases, hus ensu ing he indi idual p i acy. This
p ope y is ela ed o he di icul y o de e mine i wo p o-
ec ed empla es c ea ed om di e en biome ic samples o
he same indi idual iand di e en keys belong o he same
indi idual. Simila ly o e ocabili y, Com (B i)6= Com(B0
i)
wi h Com (B i)and Com(B0
i) andom (compu a ionally hid-
ing) i Com (B i)=Ai·( i||B i)⊕eiand Com B0
i=
A0
i·( 0 i||B0 i)⊕e0
i. This is also ue i Ai=A0
i.
The decodabili y based c oss-ma ching a ack p esen ed in
[26] o Fuzzy Commi men s is based on XOR-ing wo Fuzzy
Commi men s c ea ed wi h he same linea E o Co ec ion
Code. The a ack checks whe he he esul is decodable
and, hence, de ec s ha he biome ic ea u es a e simila .
In biome ic LPN Commi men s his a ack is no possible
since eiand e0
ishould be equal o decode he sys em o linea
equa ions.
FAR a ack occu s due o in e class co ela ion be ween
biome ic samples om di e en indi iduals ha a e e y
simila . I educes conside ably he secu i y o Fuzzy Com-
mi men s and sal ing schemes, as commen ed in In oduc-
ion. Fo LPN biome ic commi men s, i he alue o e
is unknown, he A|[Com (B )⊕Com (B )]-based equa ion
sys em canno be esol ed al hough he biome ic ea u es
B and B we e simila . The e o e, FAR a acks a e a oided
by a biome ic LPN commi men -based empla e p o ec ion
scheme.
In addi ion o hese secu i y equi emen s, a empla e p o-
ec ion scheme should main ain he secu i y unde he named
S olen Token scena io. O iginally, he S olen Token scena io
comes om he Biohashing echnique [27], whe e a physical
de ice o oken s o es he use key. In ou con ex applica ion,
his scena io is possible since an a acke can access he clien
de ice and employ i o ecogni ion du ing he e i ica ion
phase. The commi men is c ea ed wi h e =e and he
e i ie ob ains a ma ching sco e om [B ⊕B ]. Howe e ,
B belongs o he genuine indi idual and B belongs o he
impos o indi idual. The e o e, he ecogni ion esul s a e he
same as in he unp o ec ed sys em.
Conce ning simila i y-based a acks, i an a acke knows
he p o ec ed empla e Com (B i)=Ai·( i||B i)⊕ei, gen-
e a es i s guesses andomnly, and ans o ms hem o he
p o ec ed domain, Com B0=Ai·( 0||B0)⊕e0, he dis ance
be ween Com (B i)and Com B0does no e eal in o ma ion
abou he dis ance be ween B i and B0, because Com (B i)
and Com B0a e andom (compu a ionally hiding). To ca y
ou a simila i y-based a ack in he au hen ica ion p o ocol
desc ibed abo e, he a acke should be success ul o disco e
he associa ion be ween a commi men and a use iden i y,
ha is, he a acke should b eak he da abase anonymiza ion
and, in addi ion, should employ he clien de ice o ha use ,
ha is, should be in he S olen Token scena io. Only hen,
he a acke is able o gene a e Com B0=Ai·( 0||B0)⊕
ei, and om he dis ance be ween Com (B i)and Com B0
is able o ex ac in o ma ion abou he dis ance be ween
B i and B0.
III. IMPLEMENTATION AND PERFORMANCE
EVALUATION
A. SOFTWARE IMPLEMENTATION OF THE BIOMETRIC
LPN COMMITMENT-BASED PROTECTION SCHEME
Ou p oposal has been de eloped in Ma lab and hus he
implemen a ion o ope a ions is based on Ma lab unc ions.
The i s s ep o c ea e a biome ic LPN commi men is o
gene a e he keys. The gene a ion o he n·(l+m)-bi ma ix
A equi es a uni o mly dis ibu ed andom gene a o . This
is possible by employing he Ma lab unc ion and i he
esul is ounded. The gene a ion o he n-bi ec o e equi es
a weigh ed uni o m andom bi gene a o wi h Hamming
weigh equals o nτ. The Ma lab unc ion andpe m de e -
mines andomly he posi ions o he nτelemen s o ewi h
alue 1. The es o he elemen s a e es ablished o 0. A seed
is employed by andpe m which is associa ed o he use
iden i y and key. In his way, he Ma lab unc ion andpe m
ac s as a Weigh ed Key De i a ion Func ion (WKDF).
The LPN commi men Com (B)=A·( ||B)⊕eis com-
posed o bina y (AND) mul iplica ions and bina y (XOR)
addi ions. The LPN commi men ope a ion is ansla ed o
Ma lab code as a 2-modulo ope a ion applied o he addi ion
o A·( ||B) and e. P e iously, he biome ic ea u es B
a e ex ac ed and conca ena ed o . The gene a ion o l-bi
ec o s is pe o med wi h a uni o mly dis ibu ed andom
gene a o based on he Ma lab unc ion and.
A he e i ica ion phase, he au hen ica ion se e has o
sol e he sys em o linea equa ions composed o Aas coe i-
cien ma ix, [Com (B )⊕Com (B )] as ma ix o independen
e ms and A|[Com (B )⊕Com (B )] as augmen ed ma ix.
In o de o employ Gaussian elimina ion, supe io ma ix
iangula iza ion is applied o A. The g lineq Ma lab unc ion
used o his ope a ion inds a pa icula solu ion o e p ime
Galois ield o wo elemen s. Two ypes o ope a ions a e
equi ed: 1) swap a cu en ow wi h a ow con aining a majo
elemen , and 2) clea all non-ze o elemen s in he column
excep he majo elemen and se he majo elemen o one by
adding o one ow a scala mul iple o ano he and applying a
2-module ope a ion. Gi en he independen e ms composed
o [Com (B )⊕Com (B )], he au hen ica ion se e checks
i s ly i he ank o he augmen ed ma ix A|[Com (B )⊕
Com (B )] is k(like he coe icien ma ix A). I he anks a e
di e en , he au hen ica ion se e inishes he e i ica ion
wi h a ailu e.
VOLUME 8, 2020 182361
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
TABLE 2. Pe o mance o biome ic LPN commi men -based p o ec ion schemes.
TABLE 3. Compa ison o empla e s o age and ope a ion equi emen s.
B. BIOMETRIC LPN COMMITMENT PARAMETERS AND
PERFORMANCE
The LPN commi men pa ame e s can be selec ed acco d-
ing o he la es esul s on In o ma ion Se Decoding (ISD)
algo i hms p esen ed in [23]. In ha wo k, he wo s -case
unning ime ob ained o decoding andom bina y lin-
ea codes (conside ing ull dis ance decoding) is 20.0885·n,
which means a secu i y le el o 0.0885·nbi s. I is achie ed
o k/n=0.46 wi h ela i e dis ance w/n=d/n=0.1237,
by using an imp o ed p oposal o he BJMM decoding algo-
i hm o Becke e al. [28]. The alue o nis selec ed o
achie e he secu i y le el and hen kand w a e ob ained. Fo
di e en secu i y le els, Table 2 shows execu ion imes o
he main ope a ions in he LPN commi men -based empla e
p o ec ion schemes. Execu ion imes co espond o a e age
o en uns, execu ing he so wa e implemen a ion desc ibed
abo e in an In el Co e 3.3 GHz i5-7400 CPU. The mos
iming consuming ope a ion is he iangula iza ion o he
ma ix A. Howe e , he ope a ions and he alues equi ed o
he supe io ma ix iangula iza ion can be p e-calcula ed a
he en ollmen phase and can be known by he au hen ica ion
se e o speed up he compa ison o biome ic LPN commi -
men s a he e i ica ion phase.
Table 3 shows a compa ison o ou p oposal o o he s
p oposals om he li e a u e based on homomo phic enc yp-
ion. The p oposal in [18] o e s a secu i y le el as high
as ou s (mo e han 80-bi secu i y agains exhaus i e-sea ch
and bi hday a acks). The esul s o ou p oposal conside
he pa ame e s selec ed in Table 2. The n alues de e mine
he p o ec ed ec o leng h while he k alues de e mine he
unp o ec ed ec o leng h. The s o age equi emen s o ou
p oposal a e he lowes . Rega ding he cos o he ope a-
ions a he e i ica ion phase, enc yp ions and dec yp ions
a e he mos cos ly ope a ions o homomo phic enc yp ion
app oaches [29]. In con as , ou p oposal does no equi e
dec yp ion and he ope a ions in ol ed a e he simples .
IV. PRACTICAL REALIZATION WITH FINGER VEINS
A. BIOMETRIC RECOGNITION BASED ON FINGER VEINS
Al hough ou p oposal can be applied o any biome ic ai
ep esen ed by bina y ea u es, his Sec ion p oposes an
example o ealiza ion o p o ec inge ein ea u es. The
ex ac o o inge eins employed is based on he Wide Line
De ec o , which is a s a e-o -a inge ein ex ac o [30]
ini ially p oposed in [31].
The inpu o he Wide Line De ec o is he b igh ness o a
inge - ein image Fand he ou pu is a bina y ea u e image
Vwhose backg ound pixels ha e he logic alue ‘0’ and he
ein pixels ha e he logic alue ‘1’. A ci cula neighbo hood
egion Nwi h adius is de ined o each cen e pixel (x0,y0)
om Fas ollows:
N(x0,y0)=n(x,y)|(x−x0)2+(y−y0)2≤ 2o(6)
and he b igh ness simila i y be ween wo pixels is mea-
su ed by:
b(x,y,x0,y0,u)=0F(x,y)−F(x0,y0)>u
1o he wise (7)
whe e uis a b igh ness con as h eshold.
Then, each pixel (x0,y0) in Vis de ined as ollows:
V(x0,y0)=(0,i m (x0,y0)>g
1,o he wise (8)
whe e mis he summa ion o he simila i ies wi hin he
ci cula neighbo hood egion:
m(x0,y0)=X(x,y)∈N(x0,y0)b(x,y,x0,y0,u)(9)
and gis a geome ic h eshold de ined as hal he maximum
alue ha mcan ake.
Since he ea u e ec o s ex ac ed a e unbalanced (wi h a
g ea di e ence o he numbe o 1’s and 0’s), we p opose
o measu e he ma ching sco e wi h he Jacca d dis ance,
which is he sco e al eady commen ed in Subsec ion II.B as
Equa ion (5). Wi h he knowledge o FHW(B ) and
FHW(B ), he au hen ica ion se e can compu e his sco e
om he biome ic LPN commi men s, and compa e i wi h
a h eshold o ou pu a success o a ailu e. We poin ou ha
ou ma ching sco e is no malized, while ha p oposed in [32]
is no .
182362 VOLUME 8, 2020
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
B. ACCURACY ANALYSIS OF THE
UNPROTECTED APPROACH
In o de o ob ain biome ic ecogni ion esul s, we applied
he Wide Line De ec o o ex ac ea u es om he in-
ge ein images om he Tsinghua Uni e si y Finge Vein
da abase [33], in pa icula om THU-FVFDT3 FV3_Tes
(which con ains 4 samples o inge ein images o each
610 indi iduals). We use he Wide Line De ec o implemen a-
ion om [34] wi h he pa ame e s =5, u=1 and g=41.
Ma ching expe imen s we e pe o med ollowing he
FVC (Finge p in Ve i ica ion Compe i ion) p o ocol [35]:
Genuine compa isons we e made be ween e e y pai o sam-
ples co esponding o he same indi idual (in o al, (4·3/2)·
610 =3,660 compa isons). Impos o compa isons we e
made be ween he i s sample o an indi idual and he
i s sample o he es o he indi iduals (in o al, (610·
609/2) =185,745 compa isons).
The inge ein image has 370 ·576 pixels, bu he a ea
cen e ed on he middle o he image, which co esponds
oughly o he middle phalanx, is usually desc ibed as he
mos s able and he mos disc iminan a ea o inge ein
ecogni ion, as indica ed in [3]. Hence, we ha e e alua ed
ea u e ec o s o inge eins o med by 32 ·64 bi s ( ha is,
2,048 bi s), and no displacemen s we e applied o he ea u e
ec o s, as in [3]. The EER (Equal E o Ra e) ob ained (when
he False Rejec ion Ra e equals o he False Accep ance Ra e)
was 0.34 %.
C. RECOGNITION ACCURACY ANALYSIS OF THE
PROTECTED APPROACH
The analysis is pe o med by conside ing he pa ame e s
selec ed in Table 2 o an 80-bi secu i y wi h k=416,
which de e mines he numbe o di isions o he unp o ec ed
ea u e ec o , and n=904, which de e mines he p o ec ed
ea u e ec o leng h acco ding o he numbe o di isions o
he unp o ec ed ea u e ec o . Fo a 2,048-bi unp o ec ed
ea u e ec o , eigh 256-bi di isions a e conside ed (wi h
l=160,m=256 and k=l+m=416). The
ime o compa e wo commi men s is 101,84 ms using he
abo e desc ibed Ma lab implemen a ion. Al hough his ime
is compe i i e, i can be educed conside ably i he code is
op imized.
Table 4 shows a compa ison o he ecogni ion accu acy o
ou p oposal and o he empla e p o ec ion schemes based on
inge eins. Ou p oposal is he only one ha does no educe
he ecogni ion accu acy in he p o ec ed domain. The False
Accep ance Ra e o he p o ec ed app oach is 0% because an
impos o , who does no know he use -speci ic sec e key ( he
use key in he au hen ica ion p o ocol in Subsec ion II.C),
is di ec ly ejec ed. The False Rejec ion Ra e (FRR) can be
adjus ed depending on he au hen ica ion h eshold selec ed
o he biome ic da a. I he au hen ica ion h eshold o he
EER o he unp o ec ed domain is also used in he p o ec ed
app oach, he FRR =0.34%, as shown in Table 4. In ha case,
in he S olen Token scena io, he EER =0.34% is p ese ed.
TABLE 4. Compa ison o ecogni ion accu acy o he unp o ec ed and
p o ec ed app oaches applied o inge eins wide line de ec o .
In all he o he p oposals, he ecogni ion accu acy when
using he p o ec ed app oach is always educed.
D. SECURITY ANALYSIS OF THE PROTECTED APPROACH
In o de o e alua e unlinkabili y, we applied he amewo k
p oposed in [36] by conside ing he dis ibu ions o ma ed
and non-ma ed ins ances. The Jacca d dis ances o ma ed
ins ances a e compu ed wi h he commi men s o empla es
ex ac ed om di e en samples o he same ins ance by
using di e en e alues. The Jacca d dis ances o non-ma ed
ins ances a e compu ed wi h he commi men s o empla es
ex ac ed om samples o di e en ins ances by using di e -
en e alues. I bo h dis ibu ions coincide, he unlinkabili y
o a scena io is p o en. Fig. 3 p o es he unlinkabili y o ou
p oposal.
The e ocabili y p ope y is sa is ied i di e en p o ec ed
empla es can be gene a ed om he same sample by using
di e en e alues. The esul s a e shown in Fig. 3. This
dis ibu ion o e laps ex ensi ely wi h he wo abo e, and,
he e o e, he e ocabili y o ou p oposal is also p o en.
Rega ding unlinkabili y, ou p oposal ou pe o ms he
esul s ob ained by using e-mapping, wa ping and
Alignmen -Robus Hashing p oposals included in [8]. The
es o he p oposals do no p o ide unlinkabili y esul s.
Re ocabili y esul s a e no p o ided by he p oposals
conside ed.
The e alua ion o he esis ance o simila i y-based a acks
o he biome ic LPN commi men s was pe o med acco d-
ing o [14], which conside s ha p o ec ed empla es a e
secu e only i he mu ual in o ma ion be ween he no malized
VOLUME 8, 2020 182363