scieee Science in your language
[en] (orig)

A post-quantum biometric template protection scheme based on Learning Parity with Noise (LPN) commitments

Abstract

Biometric recognition has the potential to authenticate individuals by an intrinsic link between the individual and their physical, physiological and/or behavioral characteristics. This leads a higher security level than the authentication solely based on knowledge or possession. One of the reasons why biometrics is not completely accepted is the lack of trust in the storage of biometric templates in external servers. Biometric data are sensitive data which should be protected as is contemplated in the data protection regulation of many countries. In this work, we propose the use of biometric Learning Parity With Noise (LPN) commitments as template protection scheme. To the best of our knowledge, this is the first proposal for biometric template protection based on the LPN problem (that is, the difficulty of decoding random linear codes), which offers post-quantum security. Biometric features are compared in the protected domain. Irreversibility, revocability, and unlinkability properties are satisfied as well as resistance to False Acceptance Rate (FAR), crossmatching, Stolen Token, and similarity-based attacks. A recognition accuracy with a 0% FAR is achieved, because user-specific secret keys are employed, and the False Rejection Ratio (FRR) can be adjusted depending on a threshold to preserve the accuracy of the unprotected scheme in the Stolen Token scenario. A good performance in terms of execution time, template storage and operation complexity is obtained for security levels at least of 80 bits. The proposed scheme is employed in a dual-factor authentication protocol from the literature to illustrate how it provides security using authentication and database (cloud) servers that can be malicious. The proposed LPN-based protected scheme can be applied to any biometric trait represented by binary features and any matching score based on Hamming or Jaccard distances. In particular, experimental results are included of a practical finger vein-based recognition system implemented in Matlab.

Read accessible full text

A post-quantum biometric template protection scheme based on Learning Parity with Noise (LPN) commitments

Author: Arjona, Rosario; Baturone Castillo, María Iluminada
Publisher: Institute of Electrical and Electronics Engineers (IEEE)
Year: 2020
DOI: 10.1109/ACCESS.2020.3028703
Source: https://idus.us.es/bitstreams/72c2fa5f-53c9-4bf2-ac50-f28253929330/download
SPECIAL SECTION ON INTELLIGENT BIOMETRIC SYSTEMS FOR SECURE SOCIETIES
Recei ed Sep embe 16, 2020, accep ed Sep embe 28, 2020, da e o publica ion Oc obe 5, 2020, da e o cu en e sion Oc obe 16, 2020.
Digi al Objec Iden i ie 10.1109/ACCESS.2020.3028703
A Pos -Quan um Biome ic Templa e P o ec ion
Scheme Based on Lea ning Pa i y Wi h
Noise (LPN) Commi men s
ROSARIO ARJONA AND ILUMINADA BATURONE
Ins i u o de Mic oelec ónica de Se illa (IMSE-CNM), Uni e sidad de Se illa-CSIC, 41092 Se ille, Spain
Co esponding au ho : Rosa io A jona ([email p o ec ed])
This wo k was suppo ed in pa by he Spanish Agencia Es a al de In es igación and Fondo Eu opeo de Desa ollo Regional (FEDER)
unde P ojec TEC2017-83557-R and P ojec RTC-2017-6595-7, and in pa by he Conseje ía de Economía, Conocimien o, Emp esas y
Uni e sidad de la Jun a de Andalucía, unde P ojec AT17_5926_USE and P ojec US-1265146. The wo k o Rosa io A jona was
suppo ed by a Pos doc o al Fellowship om he Spanish Na ional Cybe secu i y Ins i u e (INCIBE).
ABSTRACT Biome ic ecogni ion has he po en ial o au hen ica e indi iduals by an in insic link be ween
he indi idual and hei physical, physiological and/o beha io al cha ac e is ics. This leads a highe secu i y
le el han he au hen ica ion solely based on knowledge o possession. One o he easons why biome ics is
no comple ely accep ed is he lack o us in he s o age o biome ic empla es in ex e nal se e s. Biome ic
da a a e sensi i e da a which should be p o ec ed as is con empla ed in he da a p o ec ion egula ion o many
coun ies. In his wo k, we p opose he use o biome ic Lea ning Pa i y Wi h Noise (LPN) commi men s as
empla e p o ec ion scheme. To he bes o ou knowledge, his is he i s p oposal o biome ic empla e
p o ec ion based on he LPN p oblem ( ha is, he di icul y o decoding andom linea codes), which o e s
pos -quan um secu i y. Biome ic ea u es a e compa ed in he p o ec ed domain. I e e sibili y, e ocabili y,
and unlinkabili y p ope ies a e sa is ied as well as esis ance o False Accep ance Ra e (FAR), c oss-
ma ching, S olen Token, and simila i y-based a acks. A ecogni ion accu acy wi h a 0% FAR is achie ed,
because use -speci ic sec e keys a e employed, and he False Rejec ion Ra io (FRR) can be adjus ed
depending on a h eshold o p ese e he accu acy o he unp o ec ed scheme in he S olen Token scena io.
A good pe o mance in e ms o execu ion ime, empla e s o age and ope a ion complexi y is ob ained o
secu i y le els a leas o 80 bi s. The p oposed scheme is employed in a dual- ac o au hen ica ion p o ocol
om he li e a u e o illus a e how i p o ides secu i y using au hen ica ion and da abase (cloud) se e s
ha can be malicious. The p oposed LPN-based p o ec ed scheme can be applied o any biome ic ai
ep esen ed by bina y ea u es and any ma ching sco e based on Hamming o Jacca d dis ances. In pa icula ,
expe imen al esul s a e included o a p ac ical inge ein-based ecogni ion sys em implemen ed in Ma lab.
INDEX TERMS Biome ic empla e p o ec ion, pos -quan um secu i y, LPN commi men s, dual- ac o
au hen ica ion, au hen ica ion p o ocol, inge eins.
I. INTRODUCTION
Nowadays, ou socie y has accep ed ex ensi ely he use o
biome ic sys ems as a way o use au hen ica ion. The p ob-
lem is ha biome ic da a, which a e s o ed as empla e a
he egis a ion phase o en ollmen , a e sensi i e and, hence,
should be p o ec ed, as con empla ed in he da a p o ec ion
egula ion o many coun ies [1]. Ano he p oblem is ha
biome ic da a ha a e e ealed canno be employed any
The associa e edi o coo dina ing he e iew o his manusc ip and
app o ing i o publica ion was Ma ina Ga ilo a .
mo e o a oid impe sona ion and p i acy a acks. This also
mo i a es o p o ec empla es since people canno p o ide
many biome ic ai s.
The ISO/IEC 24745 s anda d on biome ic in o ma ion
p o ec ion es ablishes he equi emen s o i e e sibili y,
unlinkabili y, and e ocabili y o biome ic empla e p o-
ec ion schemes [1]. I e e sibili y means ha no in o ma-
ion ela ed o he biome ic da a can be eco e ed e en i
p o ec ed empla es a e comp omised. Hence, biome ic da a
emain p i a e. Unlinkabili y means ha no ad e sa y can
know which indi idual is he owne o he p o ec ed empla e,
VOLUME 8, 2020 This wo k is licensed unde a C ea i e Commons A ibu ion 4.0 License. Fo mo e in o ma ion, see h ps://c ea i ecommons.o g/licenses/by/4.0/ 182355
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
hus allowing use iden i y p i acy. In case a p o ec ed em-
pla e is comp omised, i should be e ocable o enewable
o ob ain a new p o ec ed empla e om he same biome ic
sample.
T adi ionally, biome ic empla e p o ec ion schemes ha e
been classi ied in o 1) biome ic c yp osys ems and 2) ea u e
ans o ma ions o cancelable biome ics [2].
Biome ic c yp osys ems bind a sec e c yp og aphic key o
he biome ic da a. Among hem, uzzy ex ac o , uzzy aul
and uzzy commi men schemes we e p oposed, he la e
being widely employed [3]–[5]. In Fuzzy Commi men s [6],
he commi men s a e Auxilia y o Helpe Da a gene a ed
as a combina ion o biome ic da a wi h an e o co ec-
ion codewo d indexed by a c yp og aphic key. A c yp o-
g aphic hash o he sec e key (o o he e o co ec ion
codewo d) is s o ed oge he wi h he Helpe Da a. Bio-
me ic da a should be ep esen ed as bina y s ings and he
Hamming dis ance is used as he dis ance me ic. Ma ch-
ing is pe o med by a emp ing o eco e he c yp og aphic
key om he Helpe Da a and he inpu biome ic da a,
applying e o co ec ion decoding. I e e sibili y is based
on he compu a ional di icul y o e ie e ei he he key
o he biome ic da a om he s o ed Helpe Da a. Unlink-
abili y and e ocabili y a e based on employing di e en
keys.
The ecogni ion accu acy o biome ic c yp osys ems is
wo se han he sys ems wi hou p o ec ion, also known as he
baseline sys ems. Hence, hei secu i y is e y much lowe
han a c yp og aphic sys em because hei False Accep ance
Ra e (FAR) is no su icien ly small. Conside ing a b u e-
o ce a ack (also known as FAR a ack), FAR should be
smalle han 2−N o achie e a leas N-bi secu i y. Howe e ,
he FAR o biome ic sys ems usually anges om 10−5
(17 bi s) o 10−7(24 bi s) [4]. The e o e, mul ibiome ic
usion should be employed o imp o e secu i y. Ano he
limi a ion o biome ic c yp osys ems ha o ces he use
o mul ibiome ic usion is he low en opy o biome ic
ai s [4].
In he ea u e ans o ma ion app oach, he biome ic em-
pla e is p o ec ed by a ans o ma ion unc ion, which is
applied a he egis a ion and he e i ica ion phases. The e-
o e, biome ic da a a e compa ed in he p o ec ed domain.
T ans o ma ions can be non-in e ible o in e ible (sal -
ing). T ans o ma ion unc ions p oposed in he li e a u e
a e BioHashing [7], Alignmen -Robus Hashing (ARH) [8],
e-mapping and wa ping [9], and Bloom il e s [10]. Unlinka-
bili y and e ocabili y a e based on he a ia ion o he pa am-
e e s o he ans o ma ion unc ions. I e e sibili y depends
on he di icul y o ob ain he o iginal biome ic da a om he
ans o med da a.
T ans o med empla es o en con ain less in o ma ion han
he o iginal empla es. Hence, he usual consequence is a
ecogni ion pe o mance deg ada ion compa ed o he base-
line e sion (wi hou ans o ma ion) [7]–[11]. As in biome -
ic c yp osys ems, mul ibiome ic usion should be employed
o imp o e secu i y [12].
The accu acy ob ained wi h he ans o ma ion can be
imp o ed due o he en opy added by a use -speci ic sec e
key as in sal ing schemes. In ac , he ad an age o sal ing
schemes, such as BioHashing [7], is ha , heo e ically, he e
is he possibili y o achie ing a 0% e o a e due o he
use o a dual ecogni ion based on he biome ic in o ma ion
and he use -speci ic sec e key. Howe e , his is isky and
no ad isable because an a acke can use he de ice wi h
he use -speci ic sec e key o imp o e he chances o suc-
cess ul au hen ica ion. This is known as he S olen Token
scena io [7]. Besides, as happens o biome ic c yp osys ems,
a limi a ion o many sal ing schemes is ha hei secu i y is
e y much lowe han a c yp og aphic sys em because hey
a e no obus o FAR a acks [13].
In he o he side, mos o cancelable biome ic schemes
apply simila i y-p ese ing ans o ma ions, also called
Locali y Sensi i e Hashing, in o de o p ese e in he p o-
ec ed domain he accu acy pe o mance ob ained in he
unp o ec ed domain [14], [15]. The p oblem is ha his
simila i y o dis ance-p ese ing p ope y (dis ances be ween
unp o ec ed samples a e nea ly he same as he dis ances
be ween p o ec ed samples) can be exploi ed by simila i y-
based a acks ha b eak hese schemes. I an a acke can
access he p o ec ed empla e, he/she can apply a sea ch
algo i hm o gene a e i s guesses andomly, ans o m hem
o he p o ec ed domain, compu e he dis ances wi h he p o-
ec ed empla e, use he in o ma ion o imp o e he p obabil-
i y o success wi h new guesses, and epea he p ocess un il
eaching a success ul guess. The wo k in [15] con i ms he
ulne abili y o BioHashing and Bloom- il e schemes o a
Gene ic Algo i hm enabled simila i y-based a ack. The wo k
in [14] in oduces non-linea i y in he ans o ma ion wi h
he aid o a deep neu al ne wo k, bu his equi es e aining
whene e a new use is en olled.
An al e na i e app oach ecen ly p oposed o p ese e
he accu acy o baseline sys ems is homomo phic enc yp-
ion [16]. When i is employed in a biome ic applica ion,
he empla e and he inpu biome ic da a a e enc yp ed by
using a public key. The compa ison is pe o med in he
enc yp ed domain by means o an enc yp ed sco e compu-
a ion ope a ion. Thus, he esul ing sco e a e compa ison
is enc yp ed. In o de o ob ain he inal sco e, a dec yp ion
ope a ion by using a p i a e key should be applied.
The p ac ical implemen a ion o Fully Homomo phic
Enc yp ion schemes is s ill a challenge because no all he
ope a ions needed o ob ain an enc yp ed sco e a e easi-
ble due o hei high cos in compu a ional and memo y
equi emen s [2]. The p ac ical p oposals o biome ic Homo-
mo phic Enc yp ion schemes only allow a limi ed subse
o ope a ions (addi ions o mul iplica ions) in he enc yp ed
domain. The mos used app oach is he addi i ely homo-
mo phic scheme and, speci ically, he Paillie homomo phic
enc yp ion scheme [17]. In he schemes based on Paillie
homomo phic enc yp ion, he secu i y o he ope a ions
employed a e based on ha d p oblems ha canno be sol ed
nowadays in polynomial ime, such as he Disc e e Loga i hm
182356 VOLUME 8, 2020
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
P oblem and he In ege Fac o iza ion P oblem. Howe e ,
hese p oblems a e no so complex o quan um compu e s,
which is a ele an h ea o conside , because p o ec ed
schemes ha nowadays a e conside ed secu e will no be so
in he u u e.
Among he sys ems belie ed o esis he a acks o
quan um compu e s, la ice-based c yp og aphy has a ac ed
mos in e es . La ice c yp og aphy uses high-dimensional
geome ic s uc u es o hide in o ma ion c ea ing p oblems
ha a e conside ed impossible o sol e i he p i a e key
is unknown, e en o quan um compu e s. Homomo phic
enc yp ion can be also cons uc ed on he la ice p oblem un-
damen als. In [18], wo a ian s o Homomo phic Enc yp ion
a e employed based on ideal-la ice and, pa icula ly, ing-
LWE ( ing Lea ning Wi h E o s) schemes, which a e an
example o ideal la ice c yp og aphy.
The d awback o homomo phic enc yp ion-based
app oaches is no only hei high compu a ional cos bu also
hei memo y equi emen s since he size o he p o ec ed
empla e is a ound wo o de o magni ude g ea e han
he unp o ec ed empla e [18]. In addi ion, a simple a ack
algo i hm has been epo ed o he au hen ica ion se e ha
compu es he inal dec yp ed sco e. The biome ic da a can
be e ealed in a mos 2N−T que ies, whe e N is he bi -
leng h o he biome ic empla e and T is he au hen ica ion
h eshold [19].
In his wo k, we p opose a pos -quan um ligh weigh solu-
ion based on la ice c yp og aphy. Speci ically, Lea ning Pa -
i y wi h Noise (LPN) commi men s a e employed o p o ec
biome ic da a. Ou p oposal o biome ic LPN commi men s
uses a public gene a o ma ix o con e biome ic da a
o linea codewo ds ha hen a e andomized wi h a use -
speci ic sec e . LPN commi men s a e no opened ( he sec e s
a e no e ealed) bu compa ed in he p o ec ed domain.
The commi men s using impos o sec e s a e de ec ed and
di ec ly ejec ed wi hou p oceeding o calcula e a biome ic
simila i y sco e. Hence, False Accep ance Ra e is 0%.
In compa ison, con en ional Fuzzy Commi men s also
uses a public gene a o ma ix bu o con e a sec e o a
linea codewo d ha is hen combined wi h he biome ic
da a. Biome ic c yp osys ems using Fuzzy Commi men s
accep an indi idual i he commi men can be opened ( he
sec e can be econs uc ed) because he biome ic da a p o-
ided a e i ica ion is enough simila o he da a p o ided a
en ollmen . Hence, FAR is no 0% and FAR a acks can be
success ul.
LPN-based schemes ha e been applied o pseudo andom
gene a o s, symme ic key enc yp ion, sec e -key au hen ica-
ion p o ocols, public-key iden i ica ion, and ze o-knowledge
p oo s [20], [21]. Howe e , o he bes o ou knowledge, his
is he i s p oposal o LPN-based c yp og aphy o biome ic
empla e p o ec ion. The main con ibu ions o his pape a e
he ollowing:
•The i s biome ic empla e p o ec ion scheme based on
LPN commi men s, whose ha dness is a NP comple e
p oblem o classical and quan um compu e s.
•A low cos solu ion in e ms o compu a ional and mem-
o y equi emen s o p o ec ed empla e gene a ion and
s o age (lowe han app oaches based on homomo phic
enc yp ion).
•High secu i y agains a acks o eco e he biome -
ic da a, because compa ison is done in he p o ec ed
domain, using e icien c yp og aphic p o ocols.
•Resis ance o simila i y-based a acks because LPN
commi men s a e andom (compu a ionally hiding) and,
hence, do no p ese e he dis ance alues ob ained
be ween unp o ec ed samples wi h espec o he dis-
ance alues ob ained be ween p o ec ed samples.
•A ecogni ion accu acy wi h a FAR o 0% because
use -speci ic sec e keys a e employed in he biome ic
LPN commi men s. In case o he S olen Token sce-
na io, whe e an a acke uses a clien de ice wi h a
use -speci ic sec e key, he accu acy o he unp o ec ed
app oach is p ese ed.
•A secu i y le el compa able o a c yp og aphic sys em,
e en wi h unibiome ic sys ems.
•Expe imen al esul s a e included om a p ac ical
implemen a ion in Ma lab.
•The p oposed solu ion was applied o a inge ein-
based biome ic sys em, compa ed o o he sys ems,
and e alua ed in e ms o i e e sibili y, e ocabil-
i y and unlinkabili y, as es ablished in he s anda d
ISO/IEC 24745.
This wo k is s uc u ed as ollows. Sec ion II desc ibes ou
p oposal o applica ion o LPN commi men s o biome ic
empla e p o ec ion. The ope a ions equi ed a e de ined,
and a secu i y analysis is ca ied ou , conside ing a dis-
ibu ed scena io wi h cloud-based se ices whe e ou scheme
is included in an au hen ica ion p o ocol p oposed in he
li e a u e. The implemen a ion o biome ic LPN commi -
men s by using Ma lab unc ions is explained in Sec ion III.
Pa ame e s a e selec ed o achie e se e al secu i y le els and
pe o mance is e alua ed in e ms o execu ion ime, empla e
s o age and ope a ion complexi y. In addi ion, a compa i-
son o homomo phic enc yp ion-based p oposals is included.
A p ac ical ealiza ion is p esen ed in Sec ion IV by using
inge eins. Accu acy, i e e sibili y, e ocabili y, unlink-
abili y, and esis ance o a acks a e p o en and compa ed
o o he p oposals o biome ic empla e p o ec ion schemes
applied o inge eins. Finally, Sec ion V concludes he
wo k.
II. PROPOSAL OF BIOMETRIC TEMPLATE PROTECTION
BASED ON LPN COMMITMENTS
A. DEFINITION OF BIOMETRIC LPN COMMITMENTS
Commi men schemes a e undamen al c yp og aphic p im-
i i es o c yp og aphic p o ocols. A commi men scheme
allows a pa y o commi o a message by using a sec e
key o main ain i hidden o o he s. The secu i y p ope ies
equi ed by a commi men a e he hiding and binding p ope -
ies. Hiding means ha one canno lea n any hing abou he
commi ed message om he commi men . Binding means
VOLUME 8, 2020 182357
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
ha he commi men c ea ed o a message is di e en o he
commi men c ea ed o a di e en message.
An LPN commi men is based on encoding a message
(in ou p oposal, biome ic da a) by using a andom linea
code wi h some noise added o he codewo d. Fo mally,
he LPN commi men o an m-bi message B∈{0,1}mis as
ollows [21]:
Com (B)=A·( ||B)⊕e(1)
whe e ·applies he bi wise AND and XOR ope a ions; || is
he conca ena ion o wo ec o s; ⊕is he bi wise XOR ope -
a ion; is a uni o mly andom ec o ∈{0,1}lincluded o
add andomness; eis a low-weigh uni o mly andom ec o
∈{0,1}n ollowing a Be noulli dis ibu ion wi h pa ame e τ
(0 < τ < 1/2), i.e., e e y bi in ehas a p obabili y τo being
1 and p obabili y (1−τ) o being 0 (e[i]has P [e[i]=1]=τ
and P [e[i]=0]=1−τ); and Ais a uni o mly andom
ma ix A=A0||A00 ∈{0,1}n×kwi h k=l+mand n≥k.
The esul ing Com (B)is a ec o ∈{0,1}n. The weigh w
o eis de e mined by he Hamming Weigh (HW) o e( ha is,
w=Pn
i=1e[i]). When he weigh o eis exac ly nτ, ins ead
o expec ed, he LPN p oblem is named as exac LPN (xLPN
o sho ) [21].
Using he same no a ion as abo e, he sea ch e sion o he
LPN p oblem wi h pa ame e s k∈N( he leng h o a sec e
s), τ∈R( he noise a e in he e[i]), and n∈N( he numbe o
samples), asks o ind a k-bi sec e s om he nnoisy linea
equa ions esul ing om b=A·s⊕e, whe e Ais public.
In ou case, and B( he biome ic da a) conca ena ed o m
he sec e . The compu a ionally ha d p oblem unde lying he
secu i y (i.e., he compu a ional hiding p ope y) o he LPN
commi men scheme is he sea ch LPN p oblem, which can
be s a ed as he NP comple e p oblem o decoding andom
linea codes [22]. Since he decoding p oblem in andom
linea codes is known o be obus o quan um as well as o
classical compu e s, he sea ch LPN p oblem is sui able o
he cons uc ion o quan um- esis an commi men s o sec e
biome ic da a B.
Se ing n=θ(k)=θ(l+m) la ge enough, he commi -
men scheme becomes compu a ionally hiding and pe ec ly
binding (wi h o e whelming p obabili y o e he choice o
A). On he one hand, he binding p ope y is sa is ied by he
la ge dis ance o he code gene a ed by he andom ma ix A.
On he o he hand, he hiding p ope y is sa is ied by he LPN
assump ion which implies ha A·s⊕eis pseudo andom.
Le us de ine a linea code Cas a k-dimensional subspace
o {0,1}n. In he decoding p oblem, he inpu is a noisy
e sion o a codewo d c∈C,c⊕e, wi h e o ec o
e∈{0,1}no Hamming weigh w. In a ypical se ing,
he weigh wis uppe bounded by he code dis ance d, which
is he minimum Hamming dis ance be ween wo codewo ds
( ull dis ance decoding). The a ge o decoding is o eco e
he codewo d c(which is equi alen o ind e).
E e y ins ance o he LPN p oblem is an ins ance o a
synd ome decoding p oblem whe e nis he leng h o he
codewo d, kis he linea code ank, Ais he gene a o ma ix,
and wis he linea code dis ance (d) ob ained om an e o
pa ame e τas w=nτ. Le nbe he numbe o samples,
we can w i e an LPN ins ance as he ollowing ma ix- ec o
uple:
A·s∈{0,1}n×k×{0,1}ksa is ying A·s=b⊕e(2)
whe e e=(e1,...,en) and he i h ow o Aand b ep esen
he i h LPN sample.
Nowadays, he bes algo i hms o decoding andom bina y
linea codes o mula ed as a synd ome decoding p oblem
a e based on In o ma ion Se Decoding (ISD) [23], a p ob-
abilis ic decoding s a egy ha essen ially ies o guess k
co ec posi ions in he noisy ecei ed wo d, b. The unning
ime, T, o decoding algo i hms is ypically a unc ion o he
pa ame e s n,kand w. I he Gilbe -Va shamow bound is
used, wis a unc ion o nand k, and he e o e he unning
ime can be exp essed as a unc ion o nand konly. Fo
all In o ma ion Se Decoding algo i hms, he highes unning
ime is achie ed when he code a e k/nis sligh ly below
1/2. In ha case, he ISD algo i hms o e exponen ial un-
ning imes o he o m T(n)=2an whe e αis a cons an
which can be used as a me ic o compa e he di e en
algo i hms.
B. COMPARISON OF BIOMETRIC LPN COMMITMENTS
IN THE PROTECTED DOMAIN
In gene al, he algo i hms o a commi men scheme a e:
key gene a ion (KGen), which esul s a public commi men
key; commi men gene a ion (Com), which ou pu s a com-
mi men o a message; and e i ica ion Ve , which e i ies
he commi men . In he LPN commi men scheme p oposed
in [21], KGen gene a es he public key A;Com ou pu s he
andomness and he commi men om he public key A
and a message m:Com (m)=A·( ||m)⊕e; and Ve
akes he key A, he andomness , he commi men Com (m),
and he message m, and ou pu s 1 (success ul e i ica ion) i
Com(m)⊕A·( ||m) has weigh w, and 0 ( ailed e i ica ion)
o he wise.
In ou p oposal o biome ic LPN commi men s, he mes-
sage is he biome ic da a, B a en ollmen , and B a ma ch-
ing, which should be always p o ec ed. The e o e, in ou
p oposal, KGen gene a es he public ma ix A,Com ou pu s
and Com (B )=A·( ||B )⊕e a en ollmen , and and
Com (B )=A·( ||B )⊕e a ma ching, and Ve is modi ied
o wo k only wi h p o ec ed da a, ha is, wi h commi men s.
Ou e i ie combines he biome ic LPN commi men s by a
XOR ope a ion as ollows:
Com (B )⊕Com (B )=A·[( ||B )⊕( ||B )]⊕e ⊕e
(3)
This esul can be conside ed as a sys em o linea
equa ions wi h A as coe icien ma ix and A|[Com (B )⊕
Com (B )] as augmen ed ma ix. I Com (B )and Com (B )
a e gene a ed om he genuine p o e , e =e . Hence,
he XOR ope a ion applied o genuine commi men s esul s
182358 VOLUME 8, 2020
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
FIGURE 1. En ollmen phase o he au hen ica ion p o ocol based on biome ic LPN commi men s.
[Com (B )⊕Com (B )]=A·[( ||B )⊕( ||B )]. Sol ing he
sys em o linea equa ions (by means o Gaussian elimina-
ion, o ins ance), [( ||B )⊕( ||B )]=( ⊕ ||B ⊕B )
is ob ained.
Since and can be known by he e i ie , i can be
checked i ( ⊕ ) is co ec . Then, he e i ie employs
(B ⊕B ) o compu e he sco e measu emen o he empla e
and he inpu ea u es. Typically, he sco e is based on he
F ac ional Hamming Dis ance (FHD), which can be com-
pu ed as ollows:
FHD (B ,B )=HD(B ,B )
m=Pm
i=1(B [i]⊕B [i])
m(4)
whe e HD is he Hamming Dis ance and mis he o al numbe
o bi s in he biome ic da a.
In addi ion, he sco e can be based on he Jacca d Dis ance
(JD), which can be compu ed as ollows:
JD(B ,B )=2·FHD(B ,B )
FHD (B ,B )+FHW(B )+FHW(B )(5)
whe e FHW is he F ac ional Hamming Weigh ( ha is
FHW(B)=(Pm
i=1B[i])/m).
In he case o Jacca d dis ance, he Hamming weigh s o he
biome ic da a a e needed, bu his is no a p oblem since hey
do no e eal any sensi i e in o ma ion abou biome ic da a.
I he sco e calcula ed (based on FHD (B ,B )o JD(B ,B ))
is below an au hen ica ion h eshold, he e i ica ion ou pu s
1 (success), and ou pu s 0 ( ailu e), o he wise.
I Com (B )and Com (B )a e gene a ed om genuine and
impos o p o e s, e 6= e . In his case, he sys em o linea
equa ions wi h A as coe icien ma ix and A|[Com (B )⊕
Com (B )] as augmen ed ma ix canno be sol ed, because
he ank o he augmen ed ma ix is highe han he ank
o he coe icien ma ix. As s a ed by he Rouché–F obenius
heo em, he sys em has solu ion i and only i he anks o
he coe icien ma ix and he augmen ed ma ix a e equal.
The e o e, he impos o is di ec ly ejec ed wi hou p oceed-
ing o a sco e measu emen .
C. USE OF BIOMETRIC LPN COMMITMENTS IN AN
AUTHENTICATION PROTOCOL
In his wo k, we apply biome ic LPN commi men s in he
ypical scena io whe e cloud-based se ices and dis ibu ed
a chi ec u es a e employed, as p oposed in [13]. The en i ies
in ol ed a e: 1) Nuse s (i=1,...,N), each one wi h a
clien de ice; 2) a clien de ice which ob ains use biome ics,
iden i ies and keys; 3) an au hen ica ion se e in cha ge o
he e i ica ion o biome ic LPN commi men s; and 4) a
da abase se e o (cloud) s o age. In his p o ocol, he e
a e wo au hen ica ion ac o s: 1) he biome ics, and 2) he
knowledge o a use key o he possession o a oken wi h he
use key s o ed in a secu e memo y o econs uc ed wi h a
Physical Unclonable Func ion (PUF) [24]. In he ollowing,
he knowledge o a use key is conside ed, as being mo e
gene al [13].
The en ollmen and e i ica ion phases a e illus a ed
in Fig. 1 and Fig. 2. Du ing he en ollmen phase, he clien
de ice acqui es he biome ic samples s i, he use key ki
and he use iden i y IDi. F om he biome ic samples s i,
he clien de ice ex ac s he biome ic ea u es B i.eiis
de i ed by using wha we call a Weigh ed Key De i a ion
Func ion (WKDF) om he use key kiand he use iden i y
IDi. This unc ion s a s om an all-ze o ec o o nelemen s.
Since he esul ing ec o eimus ha e a cons an weigh w,
as commen ed in Subsec ion II.A, i means ha w=nτones
a e inse ed in he sequence o ze os. The posi ions in which
he wones a e in oduced ollow a uni o m dis ibu ion o
andom alues in he ange [1, n] p o ided by a de e minis ic
andom gene a o . The de e minis ic andom gene a o p o-
ides he same posi ions i he use in oduces he same ki
and IDi. I a andom posi ion is epea ed, i is disca ded, and
a new posi ion is gene a ed un il wones a e inse ed. Mo e
de ails abou his unc ion a e gi en in he ollowing Sec ion.
A p ac ical implemen a ion can be seen in [25].
The andom ec o i is gene a ed by using a Random
Numbe Gene a o (RNG). The public ma ix Ai, which is
ob ained by he KGen algo i hm, can be s o ed locally in
VOLUME 8, 2020 182359

R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
FIGURE 2. Ve i ica ion phase o he au hen ica ion p o ocol based on biome ic LPN commi men s.
he clien de ice. Then, he associa ed biome ic LPN com-
mi men Com (B i)=Ai·( i||B i)⊕eiis c ea ed. The
clien de ice sends (IDi,Com (B i), i) o he au hen ica ion
se e . The au hen ica ion se e maps IDi o a unique index i,
s o es (i,IDi) in i s local da abase and sends (i,Com (B i), i)
o he da abase se e o s o age.
Du ing he e i ica ion phase, he clien de ice acqui es he
biome ic samples s i, he use key kiand he use iden i y IDi.
The inpu biome ic ea u es B i a e ex ac ed om he bio-
me ic samples s i,eiis de i ed by using he WKDF om he
inpu use key kiand he use iden i y IDi, and i is gene a ed
by using he RNG. Then, he associa ed biome ic LPN com-
mi men Com (B i)=Ai·( i||B i)⊕eiis c ea ed using he
e ie ed Ai. The clien de ice sends (IDi,Com (B i), i) o
he au hen ica ion se e , and also Ai(al hough his is a public
ma ix ha could be ob ained in ano he way). The au hen i-
ca ion se e eco e s i om i s local da abase associa ed o
he ecei ed IDiand (Com (B i), i) om he da abase se e
by using a p i a e in o ma ion e ie al (PIR) scheme. Then,
he au hen ica ion se e ca ies ou he e i ica ion algo-
i hm as desc ibed in Subsec ion II.B. A P i a e In o ma ion
Re ie al (PIR) is a p o ocol ha allows he au hen ica ion
se e o e ie e an elemen o he da abase se e wi hou he
owne o he da abase being able o de e mine which elemen
was que ied. A secu e PIR is employed oge he wi h he
da abase anonymiza ion, as p oposed in [13], o sa is y he
use iden i y p i acy.
The communica ion channels among he p o ocol en i ies
a e assumed o be secu e, which is a usual scena io. This
means ha an ex e nal ad e sa y canno in e cep o modi y
a message which is communica ed h ough he channels.
Besides, he clien de ice is assumed o be us ed, ha is,
we do no conside i s o es use IDs, keys o biome ic
samples, o execu es a malicious so wa e. Finally, a he
en ollmen phases, all he en i ies a e assumed o beha e
hones ly.
Howe e , an ex e nal ad e sa y can use he clien de ice
o ca y ou impe sona ion a acks, which is he S olen Token
scena io commen ed in In oduc ion, and can a ack also he
in o ma ion s o ed in he da abase se e . Biome ic LPN
commi men s a e obus o hese a acks as desc ibed in he
ollowing sec ion.
In addi ion, since ex e nal ad e sa ies canno ob ain mo e
in o ma ion han he in e nal ones, he p o ocol conside s
malicious au hen ica ion and da abase se e s a he e i ica-
ion phase. I he au hen ica ion se e is malicious, he a -
ge is o lea n he use biome ics o keys. Howe e , his
is no possible because he au hen ica ion se e does no
ha e access o his in o ma ion. I he da abase is malicious,
he a ge is o ob ain he link be ween he commi men and
he use iden i y. Howe e , since he da abase is anonymized
and a PIR p o ocol is employed, he use iden i y p i acy is
sa is ied.
D. SECURITY ANALYSIS OF THE BIOMETRIC LPN
COMMITMENT AS TEMPLATE PROTECTION SCHEME
Acco ding o he ISO/IEC 24745:2011 s anda d on biome ic
in o ma ion p o ec ion [1], he biome ic empla e p o ec ion
schemes should ully mee he secu i y equi emen s o i e-
e sibili y, e ocabili y (o enewabili y) and unlinkabili y.
I e e sibili y is ela ed o he di icul y o eco e he
o iginal biome ic ea u es om he p o ec ed empla e. I e-
e sibili y in an LPN commi men is based on he secu i y o
he LPN p oblem, which is he ha dness o decoding andom
linea codes (a NP comple e p oblem esis an o quan um
algo i hms) [20]. Since Aand ea e bo h andom, he esul ing
LPN commi men is andom. Hence, in e ms o Shannon
en opy, he en opy in bi s o he biome ic LPN commi -
men s is p ac ically 100%, independen ly o he biome ic
ea u e. The en opy p o ided by Fuzzy Commi men s is
lowe , as depic ed in Table 1, wi h da a aken om [5].
Re ocabili y (o enewabili y) is ela ed o he abili y o
c ea e a new and di e en p o ec ed empla e om he same
biome ic ea u es o he same indi idual iby using di e en
keys. This secu i y equi emen is associa ed o he binding
p ope y o an LPN commi men [21]. I Com (B i)=Ai·
( i||B i)⊕eiis c ea ed om he biome ic ea u es B i and
ano he andom Com0(B i)=A0
i·( 0 i||B i)⊕e0
ican be c ea ed
182360 VOLUME 8, 2020
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
TABLE 1. En opy in bi s o uzzy commi men s [5] and LPN commi men s.
om he same biome ic ea u es B i,Com (B i)6= Com0(B i)
wi h Com (B i)and Com0(B i) andom (compu a ionally hid-
ing). This is also ue i Ai=A0
i.
Unlinkabili y a oids possible c oss-compa isons wi h
o he da abases, hus ensu ing he indi idual p i acy. This
p ope y is ela ed o he di icul y o de e mine i wo p o-
ec ed empla es c ea ed om di e en biome ic samples o
he same indi idual iand di e en keys belong o he same
indi idual. Simila ly o e ocabili y, Com (B i)6= Com(B0
i)
wi h Com (B i)and Com(B0
i) andom (compu a ionally hid-
ing) i Com (B i)=Ai·( i||B i)⊕eiand Com B0
i=
A0
i·( 0 i||B0 i)⊕e0
i. This is also ue i Ai=A0
i.
The decodabili y based c oss-ma ching a ack p esen ed in
[26] o Fuzzy Commi men s is based on XOR-ing wo Fuzzy
Commi men s c ea ed wi h he same linea E o Co ec ion
Code. The a ack checks whe he he esul is decodable
and, hence, de ec s ha he biome ic ea u es a e simila .
In biome ic LPN Commi men s his a ack is no possible
since eiand e0
ishould be equal o decode he sys em o linea
equa ions.
FAR a ack occu s due o in e class co ela ion be ween
biome ic samples om di e en indi iduals ha a e e y
simila . I educes conside ably he secu i y o Fuzzy Com-
mi men s and sal ing schemes, as commen ed in In oduc-
ion. Fo LPN biome ic commi men s, i he alue o e
is unknown, he A|[Com (B )⊕Com (B )]-based equa ion
sys em canno be esol ed al hough he biome ic ea u es
B and B we e simila . The e o e, FAR a acks a e a oided
by a biome ic LPN commi men -based empla e p o ec ion
scheme.
In addi ion o hese secu i y equi emen s, a empla e p o-
ec ion scheme should main ain he secu i y unde he named
S olen Token scena io. O iginally, he S olen Token scena io
comes om he Biohashing echnique [27], whe e a physical
de ice o oken s o es he use key. In ou con ex applica ion,
his scena io is possible since an a acke can access he clien
de ice and employ i o ecogni ion du ing he e i ica ion
phase. The commi men is c ea ed wi h e =e and he
e i ie ob ains a ma ching sco e om [B ⊕B ]. Howe e ,
B belongs o he genuine indi idual and B belongs o he
impos o indi idual. The e o e, he ecogni ion esul s a e he
same as in he unp o ec ed sys em.
Conce ning simila i y-based a acks, i an a acke knows
he p o ec ed empla e Com (B i)=Ai·( i||B i)⊕ei, gen-
e a es i s guesses andomnly, and ans o ms hem o he
p o ec ed domain, Com B0=Ai·( 0||B0)⊕e0, he dis ance
be ween Com (B i)and Com B0does no e eal in o ma ion
abou he dis ance be ween B i and B0, because Com (B i)
and Com B0a e andom (compu a ionally hiding). To ca y
ou a simila i y-based a ack in he au hen ica ion p o ocol
desc ibed abo e, he a acke should be success ul o disco e
he associa ion be ween a commi men and a use iden i y,
ha is, he a acke should b eak he da abase anonymiza ion
and, in addi ion, should employ he clien de ice o ha use ,
ha is, should be in he S olen Token scena io. Only hen,
he a acke is able o gene a e Com B0=Ai·( 0||B0)⊕
ei, and om he dis ance be ween Com (B i)and Com B0
is able o ex ac in o ma ion abou he dis ance be ween
B i and B0.
III. IMPLEMENTATION AND PERFORMANCE
EVALUATION
A. SOFTWARE IMPLEMENTATION OF THE BIOMETRIC
LPN COMMITMENT-BASED PROTECTION SCHEME
Ou p oposal has been de eloped in Ma lab and hus he
implemen a ion o ope a ions is based on Ma lab unc ions.
The i s s ep o c ea e a biome ic LPN commi men is o
gene a e he keys. The gene a ion o he n·(l+m)-bi ma ix
A equi es a uni o mly dis ibu ed andom gene a o . This
is possible by employing he Ma lab unc ion and i he
esul is ounded. The gene a ion o he n-bi ec o e equi es
a weigh ed uni o m andom bi gene a o wi h Hamming
weigh equals o nτ. The Ma lab unc ion andpe m de e -
mines andomly he posi ions o he nτelemen s o ewi h
alue 1. The es o he elemen s a e es ablished o 0. A seed
is employed by andpe m which is associa ed o he use
iden i y and key. In his way, he Ma lab unc ion andpe m
ac s as a Weigh ed Key De i a ion Func ion (WKDF).
The LPN commi men Com (B)=A·( ||B)⊕eis com-
posed o bina y (AND) mul iplica ions and bina y (XOR)
addi ions. The LPN commi men ope a ion is ansla ed o
Ma lab code as a 2-modulo ope a ion applied o he addi ion
o A·( ||B) and e. P e iously, he biome ic ea u es B
a e ex ac ed and conca ena ed o . The gene a ion o l-bi
ec o s is pe o med wi h a uni o mly dis ibu ed andom
gene a o based on he Ma lab unc ion and.
A he e i ica ion phase, he au hen ica ion se e has o
sol e he sys em o linea equa ions composed o Aas coe i-
cien ma ix, [Com (B )⊕Com (B )] as ma ix o independen
e ms and A|[Com (B )⊕Com (B )] as augmen ed ma ix.
In o de o employ Gaussian elimina ion, supe io ma ix
iangula iza ion is applied o A. The g lineq Ma lab unc ion
used o his ope a ion inds a pa icula solu ion o e p ime
Galois ield o wo elemen s. Two ypes o ope a ions a e
equi ed: 1) swap a cu en ow wi h a ow con aining a majo
elemen , and 2) clea all non-ze o elemen s in he column
excep he majo elemen and se he majo elemen o one by
adding o one ow a scala mul iple o ano he and applying a
2-module ope a ion. Gi en he independen e ms composed
o [Com (B )⊕Com (B )], he au hen ica ion se e checks
i s ly i he ank o he augmen ed ma ix A|[Com (B )⊕
Com (B )] is k(like he coe icien ma ix A). I he anks a e
di e en , he au hen ica ion se e inishes he e i ica ion
wi h a ailu e.
VOLUME 8, 2020 182361
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
TABLE 2. Pe o mance o biome ic LPN commi men -based p o ec ion schemes.
TABLE 3. Compa ison o empla e s o age and ope a ion equi emen s.
B. BIOMETRIC LPN COMMITMENT PARAMETERS AND
PERFORMANCE
The LPN commi men pa ame e s can be selec ed acco d-
ing o he la es esul s on In o ma ion Se Decoding (ISD)
algo i hms p esen ed in [23]. In ha wo k, he wo s -case
unning ime ob ained o decoding andom bina y lin-
ea codes (conside ing ull dis ance decoding) is 20.0885·n,
which means a secu i y le el o 0.0885·nbi s. I is achie ed
o k/n=0.46 wi h ela i e dis ance w/n=d/n=0.1237,
by using an imp o ed p oposal o he BJMM decoding algo-
i hm o Becke e al. [28]. The alue o nis selec ed o
achie e he secu i y le el and hen kand w a e ob ained. Fo
di e en secu i y le els, Table 2 shows execu ion imes o
he main ope a ions in he LPN commi men -based empla e
p o ec ion schemes. Execu ion imes co espond o a e age
o en uns, execu ing he so wa e implemen a ion desc ibed
abo e in an In el Co e 3.3 GHz i5-7400 CPU. The mos
iming consuming ope a ion is he iangula iza ion o he
ma ix A. Howe e , he ope a ions and he alues equi ed o
he supe io ma ix iangula iza ion can be p e-calcula ed a
he en ollmen phase and can be known by he au hen ica ion
se e o speed up he compa ison o biome ic LPN commi -
men s a he e i ica ion phase.
Table 3 shows a compa ison o ou p oposal o o he s
p oposals om he li e a u e based on homomo phic enc yp-
ion. The p oposal in [18] o e s a secu i y le el as high
as ou s (mo e han 80-bi secu i y agains exhaus i e-sea ch
and bi hday a acks). The esul s o ou p oposal conside
he pa ame e s selec ed in Table 2. The n alues de e mine
he p o ec ed ec o leng h while he k alues de e mine he
unp o ec ed ec o leng h. The s o age equi emen s o ou
p oposal a e he lowes . Rega ding he cos o he ope a-
ions a he e i ica ion phase, enc yp ions and dec yp ions
a e he mos cos ly ope a ions o homomo phic enc yp ion
app oaches [29]. In con as , ou p oposal does no equi e
dec yp ion and he ope a ions in ol ed a e he simples .
IV. PRACTICAL REALIZATION WITH FINGER VEINS
A. BIOMETRIC RECOGNITION BASED ON FINGER VEINS
Al hough ou p oposal can be applied o any biome ic ai
ep esen ed by bina y ea u es, his Sec ion p oposes an
example o ealiza ion o p o ec inge ein ea u es. The
ex ac o o inge eins employed is based on he Wide Line
De ec o , which is a s a e-o -a inge ein ex ac o [30]
ini ially p oposed in [31].
The inpu o he Wide Line De ec o is he b igh ness o a
inge - ein image Fand he ou pu is a bina y ea u e image
Vwhose backg ound pixels ha e he logic alue ‘0’ and he
ein pixels ha e he logic alue ‘1’. A ci cula neighbo hood
egion Nwi h adius is de ined o each cen e pixel (x0,y0)
om Fas ollows:
N(x0,y0)=n(x,y)|(x−x0)2+(y−y0)2≤ 2o(6)
and he b igh ness simila i y be ween wo pixels is mea-
su ed by:
b(x,y,x0,y0,u)=0F(x,y)−F(x0,y0)>u
1o he wise (7)
whe e uis a b igh ness con as h eshold.
Then, each pixel (x0,y0) in Vis de ined as ollows:
V(x0,y0)=(0,i m (x0,y0)>g
1,o he wise (8)
whe e mis he summa ion o he simila i ies wi hin he
ci cula neighbo hood egion:
m(x0,y0)=X(x,y)∈N(x0,y0)b(x,y,x0,y0,u)(9)
and gis a geome ic h eshold de ined as hal he maximum
alue ha mcan ake.
Since he ea u e ec o s ex ac ed a e unbalanced (wi h a
g ea di e ence o he numbe o 1’s and 0’s), we p opose
o measu e he ma ching sco e wi h he Jacca d dis ance,
which is he sco e al eady commen ed in Subsec ion II.B as
Equa ion (5). Wi h he knowledge o FHW(B ) and
FHW(B ), he au hen ica ion se e can compu e his sco e
om he biome ic LPN commi men s, and compa e i wi h
a h eshold o ou pu a success o a ailu e. We poin ou ha
ou ma ching sco e is no malized, while ha p oposed in [32]
is no .
182362 VOLUME 8, 2020
R. A jona, I. Ba u one: Pos -Quan um Biome ic Templa e P o ec ion Scheme
B. ACCURACY ANALYSIS OF THE
UNPROTECTED APPROACH
In o de o ob ain biome ic ecogni ion esul s, we applied
he Wide Line De ec o o ex ac ea u es om he in-
ge ein images om he Tsinghua Uni e si y Finge Vein
da abase [33], in pa icula om THU-FVFDT3 FV3_Tes
(which con ains 4 samples o inge ein images o each
610 indi iduals). We use he Wide Line De ec o implemen a-
ion om [34] wi h he pa ame e s =5, u=1 and g=41.
Ma ching expe imen s we e pe o med ollowing he
FVC (Finge p in Ve i ica ion Compe i ion) p o ocol [35]:
Genuine compa isons we e made be ween e e y pai o sam-
ples co esponding o he same indi idual (in o al, (4·3/2)·
610 =3,660 compa isons). Impos o compa isons we e
made be ween he i s sample o an indi idual and he
i s sample o he es o he indi iduals (in o al, (610·
609/2) =185,745 compa isons).
The inge ein image has 370 ·576 pixels, bu he a ea
cen e ed on he middle o he image, which co esponds
oughly o he middle phalanx, is usually desc ibed as he
mos s able and he mos disc iminan a ea o inge ein
ecogni ion, as indica ed in [3]. Hence, we ha e e alua ed
ea u e ec o s o inge eins o med by 32 ·64 bi s ( ha is,
2,048 bi s), and no displacemen s we e applied o he ea u e
ec o s, as in [3]. The EER (Equal E o Ra e) ob ained (when
he False Rejec ion Ra e equals o he False Accep ance Ra e)
was 0.34 %.
C. RECOGNITION ACCURACY ANALYSIS OF THE
PROTECTED APPROACH
The analysis is pe o med by conside ing he pa ame e s
selec ed in Table 2 o an 80-bi secu i y wi h k=416,
which de e mines he numbe o di isions o he unp o ec ed
ea u e ec o , and n=904, which de e mines he p o ec ed
ea u e ec o leng h acco ding o he numbe o di isions o
he unp o ec ed ea u e ec o . Fo a 2,048-bi unp o ec ed
ea u e ec o , eigh 256-bi di isions a e conside ed (wi h
l=160,m=256 and k=l+m=416). The
ime o compa e wo commi men s is 101,84 ms using he
abo e desc ibed Ma lab implemen a ion. Al hough his ime
is compe i i e, i can be educed conside ably i he code is
op imized.
Table 4 shows a compa ison o he ecogni ion accu acy o
ou p oposal and o he empla e p o ec ion schemes based on
inge eins. Ou p oposal is he only one ha does no educe
he ecogni ion accu acy in he p o ec ed domain. The False
Accep ance Ra e o he p o ec ed app oach is 0% because an
impos o , who does no know he use -speci ic sec e key ( he
use key in he au hen ica ion p o ocol in Subsec ion II.C),
is di ec ly ejec ed. The False Rejec ion Ra e (FRR) can be
adjus ed depending on he au hen ica ion h eshold selec ed
o he biome ic da a. I he au hen ica ion h eshold o he
EER o he unp o ec ed domain is also used in he p o ec ed
app oach, he FRR =0.34%, as shown in Table 4. In ha case,
in he S olen Token scena io, he EER =0.34% is p ese ed.
TABLE 4. Compa ison o ecogni ion accu acy o he unp o ec ed and
p o ec ed app oaches applied o inge eins wide line de ec o .
In all he o he p oposals, he ecogni ion accu acy when
using he p o ec ed app oach is always educed.
D. SECURITY ANALYSIS OF THE PROTECTED APPROACH
In o de o e alua e unlinkabili y, we applied he amewo k
p oposed in [36] by conside ing he dis ibu ions o ma ed
and non-ma ed ins ances. The Jacca d dis ances o ma ed
ins ances a e compu ed wi h he commi men s o empla es
ex ac ed om di e en samples o he same ins ance by
using di e en e alues. The Jacca d dis ances o non-ma ed
ins ances a e compu ed wi h he commi men s o empla es
ex ac ed om samples o di e en ins ances by using di e -
en e alues. I bo h dis ibu ions coincide, he unlinkabili y
o a scena io is p o en. Fig. 3 p o es he unlinkabili y o ou
p oposal.
The e ocabili y p ope y is sa is ied i di e en p o ec ed
empla es can be gene a ed om he same sample by using
di e en e alues. The esul s a e shown in Fig. 3. This
dis ibu ion o e laps ex ensi ely wi h he wo abo e, and,
he e o e, he e ocabili y o ou p oposal is also p o en.
Rega ding unlinkabili y, ou p oposal ou pe o ms he
esul s ob ained by using e-mapping, wa ping and
Alignmen -Robus Hashing p oposals included in [8]. The
es o he p oposals do no p o ide unlinkabili y esul s.
Re ocabili y esul s a e no p o ided by he p oposals
conside ed.
The e alua ion o he esis ance o simila i y-based a acks
o he biome ic LPN commi men s was pe o med acco d-
ing o [14], which conside s ha p o ec ed empla es a e
secu e only i he mu ual in o ma ion be ween he no malized
VOLUME 8, 2020 182363