基于LWE加密的分布式隐私保护生物特征认证方案
网络出版日期: 2026-01-04
基金资助
国家自然科学基金(62202090,62173101);辽宁省自然科学基金面上项目(2025-MS-046)
版权
Distributed privacy-preserving biometric authentication scheme based on LWE encryption
Online published: 2026-01-04
Copyright
当前生物特征认证系统普遍采用以服务器为中心的集中式架构,用户须依赖服务端存储和管理其生物模板,存在严重的隐私泄露风险。为改善隐私保护能力,研究者提出了以用户为中心的方案,通过本地设备存储和加密处理生物特征数据,这类方案虽然增强了用户控制权,但受限于设备依赖性、计算性能和可扩展性,难以支持多终端或大规模环境下的高效认证,在隐私性、计算开销和系统扩展性之间难以取得平衡。为解决上述问题,提出一种融合区块链技术与基于格的密码学的分布式隐私保护生物特征认证框架。该框架采用区块链驱动的多因素认证架构,实现生物特征数据的去中心化存储与智能合约控制的验证机制,并设计了一种基于容错学习(Learning With Errors,LWE)问题的函数隐藏内积加密方案(Function-Hiding Inner Product Encryption,FHIPE)。实验表明,该LWE-FHIPE方案在计算效率和通信开销方面显著优于传统方法,能够为去中心化环境提供兼具隐私保护、扩展能力与后量子安全性的身份认证解决方案。
蔡俊 , 金明星 , 王子豪 , 王强 , 武彦平 . 基于LWE加密的分布式隐私保护生物特征认证方案[J]. 网络空间安全科学学报, 2025 , 3(4) : 53 -66 . DOI: 10.20172/j.issn.2097-3136.250405
At present, biometric authentication systems generally adopt a server-centric centralized architecture, and users need to rely on the server to store and manage their biometric templates, which has a serious risk of privacy leakage. In order to improve the privacy protection ability, the researchers proposed a user-centered scheme, which stores and encrypts biometric data through local devices, which enhances user control, but is limited by device dependency, computing performance and scalability, and is difficult to support efficient authentication in multi-terminal or large-scale environments. The existing two types of solutions struggle to strike a balance between privacy, computational overhead, and system scalability. In order to solve the above problems, a distributed privacy-preserving biometric authentication framework integrating blockchain technology and lattice-based cryptography was proposed. The framework adopts a blockchain-driven multi-factor authentication architecture to realize the decentralized storage of biometric data and the verification mechanism controlled by smart contracts, and designs a Function-Hiding Inner Product Encryption (FHIPE) scheme based on the Learning With Errors (LWE) assumption. Experiments show that the LWE-FHIPE scheme is significantly better than the traditional method in terms of computing efficiency and communication overhead, and can provide an identity authentication solution with privacy protection, scalability and post-quantum security for the decentralized environment.
表 1 不同方案的计算开销比较Table 1 Comparison of the computational cost of different scenarios |
| 方案 | 阶段 | 计算复杂度 | 运算时间 |
| Pairing-FHIPE | Setup | ||
| Keygen | |||
| Encrypt | |||
| Decrypt | |||
| LWE-FHIPE | Setup | ||
| Keygen | |||
| Encrypt | |||
| Decrypt |
表 2 两种方案的存储和通信开销Table 2 Storage and communication overhead of the two schemes |
| 方案 | 通信开销 | 存储开销 | ||||
| 初始化 | 注册 | 认证 | 终端 | 区块链 | ||
| Pairing-FHIPE | 8.48 KB | 36.06 KB | 68.06 KB | 8.01 MB | 96.00 m+8.48 KB | |
| LWE-FHIPE | 0.39 KB | 12.03 KB | 12.12 KB | 12.00 MB | 24.00 m+0.39 KB | |
| 1 |
NAOR M, PINKAS B. Visual authentication and identification[C]//Annual International Cryptology Conference. Berlin, Heidelberg: Springer, 1997: 322-336.
|
| 2 |
BLUE J, CONDELL J, LUNNEY T. A review of identity, identification and authentication[J]. International Journal for Information Security Research, 2018, 8 (2): 794- 804.
|
| 3 |
BANERJEE S P, WOODARD D L. Biometric authentication and identification using keystroke dynamics: A survey[J]. Journal of Pattern Recognition Research, 2012, 7 (1): 116- 139.
|
| 4 |
JAIN A K, NANDAKUMAR K, ROSS A. 50 years of biometric research: Accomplishments, challenges, and opportunities[J]. Pattern Recognition Letters, 2016, 79, 80- 105.
|
| 5 |
BHATTACHARYYA D, RANJAN R, ALISHEROV F, et al. Biometric authentication: A review[J]. International Journal of u- and e- Service, Science and Technology, 2009, 2 (3): 13- 28.
|
| 6 |
ALRAWILI R, ALQAHTANI A A S, KHAN M K. Comprehensive survey: Biometric user authentication application, evaluation, and discussion[J]. Computers and Electrical Engineering, 2024, 119, 109485.
|
| 7 |
ZHOU K, REN J. PassBio: Privacy-preserving user-centric biometric authentication[J]. IEEE Transactions on Information Forensics and Security, 2018, 13 (12): 3050- 3063.
|
| 8 |
KÜMMEL K, VIELHAUER C. Reverse-engineer methods on a biometric hash algorithm for dynamic handwriting[C]//Proceedings of the 12th ACM Workshop on Multimedia and Security. New York: ACM, 2010: 67-72.
|
| 9 |
DWIVEDI R, DEY S, SHARMA M A, et al. A fingerprint based crypto-biometric system for secure communication[J]. Journal of Ambient Intelligence and Humanized Computing, 2020, 11 (4): 1495- 1509.
|
| 10 |
ZYSKIND G, NATHAN O. Decentralizing privacy: Using blockchain to protect personal data[C]//2015 IEEE Security and Privacy Workshops. Piscataway: IEEE, 2015: 180-184.
|
| 11 |
AZARIA A, EKBLAW A, VIEIRA T, et al. MedRec: Using blockchain for medical data access and permission management[C]//2016 2nd International Conference on Open and Big Data (OBD). Piscataway: IEEE, 2016: 25-30.
|
| 12 |
SHARMA P, JINDAL R, BORAH M D. A review of smart contract-based platforms, applications, and challenges[J]. Cluster Computing, 2023, 26 (1): 395- 421.
|
| 13 |
SUCASAS V, ALY A, MANTAS G, et al. Secure multi-party computation-based privacy-preserving authentication for smart cities[J]. IEEE Transactions on Cloud Computing, 2023, 11 (4): 3555- 3572.
|
| 14 |
GOMEZ-BARRERO M, MAIORANA E, GALBALLY J, et al. Multi-biometric template protection based on homomorphic encryption[J]. Pattern Recognition, 2017, 67, 149- 163.
|
| 15 |
MORAMPUDI M K, PRASAD M V N K, RAJU U S N. Privacy-preserving iris authentication using fully homomorphic encryption[J]. Multimedia Tools and Applications, 2020, 79 (27): 19215- 19237.
|
| 16 |
LIU W, HUANG Q, CHEN X, et al. Efficient functional encryption for inner product with simulation-based security[J]. Cybersecurity, 2021, 4 (1): 2.
|
| 17 |
GASTI P, ŠEDĚNKA J, YANG Q, et al. Secure, fast, and energy-efficient outsourced authentication for smartphones[J]. IEEE Transactions on Information Forensics and Security, 2016, 11 (11): 2556- 2571.
|
| 18 |
KARABAT C, KIRAZ M S, ERDOGAN H, et al. THRIVE: Threshold homomorphic encryption based secure and privacy preserving biometric verification system[J]. EURASIP Journal on Advances in Signal Processing, 2015, 2015 (1): 71.
|
| 19 |
KIM S, LEWI K, MANDAL A, et al. Function-hiding inner product encryption is practical[C]//International Conference on Security and Cryptography for Networks. Cham: Springer, 2018: 544-562.
|
| 20 |
ALAGIC G, APON D, ALAGIC G, et al. Status report on the third round of the NIST post-quantum cryptography standardization process[R]. Gaithersburg: NIST, 2022.
|
| 21 |
CHO J, SHIN D, HWANG Y, et al. Analyze Shor algorithm optimization trends and suggest optimization directions[C]//2024 International Conference on Platform Technology and Service (PlatCon). Piscataway: IEEE, 2024: 172-176.
|
| 22 |
PEIKERT C. A decade of lattice cryptography[J]. Foundations and Trends in Theoretical Computer Science, 2016, 10 (4): 283- 424.
|
| 23 |
AHARONOV D, REGEV O. Lattice problems in NP∩coNP[J]. Journal of the ACM, 2005, 52 (5): 749- 765.
|
| 24 |
REGEV O. Lattice-based cryptography[C]//Annual International Cryptology Conference. Berlin: Springer, 2006: 131-141.
|
| 25 |
REGEV O. On lattices, learning with errors, random linear codes, and cryptography[J]. Journal of the ACM, 2009, 56 (6): 1- 40.
|
| 26 |
PENG Z, SHI R, DING R, et al. A novel quantum protocol for secure Hamming distance computation[J]. Quantum Information Processing, 2024, 23 (5): 165.
|
| 27 |
LU S, LI C, FENG X, et al. Privacy-preserving Hamming distance protocol and its applications[C]//2021 2nd International Conference on Electronics, Communications and Information Technology (CECIT). Piscataway: IEEE, 2021: 848-853.
|
| 28 |
SRINIVAS J, DAS A K, WAZID M, et al. Anonymous lightweight chaotic map-based authenticated key agreement protocol for industrial Internet of Things[J]. IEEE Transactions on Dependable and Secure Computing, 2018, 17 (6): 1133- 1146.
|
| 29 |
XU M, WANG D. Practical two-factor authentication protocol for real-time data access in WSNs[J]. IEEE Transactions on Dependable and Secure Computing, 2025, DOI: 10.1109/TDSC.2025.3563552.
|
| 30 |
WANG Q, WANG D, CHENG C, et al. Quantum2FA: Efficient quantum-resistant two-factor authentication scheme for mobile devices[J]. IEEE Transactions on Dependable and Secure Computing, 2021, 20 (1): 193- 208.
|
| 31 |
OTHMAN N, DORIZZI B, GARCIA-SALICETTI S. OSIRIS: An open source iris recognition software[J]. Pattern Recognition Letters, 2016, 82, 124- 131.
|
| 32 |
ALBRECHT M R, PLAYER R, SCOTT S. On the concrete hardness of learning with errors[J]. Journal of Mathematical Cryptology, 2015, 9 (3): 169- 203.
|
| 33 |
LYNN B. PBC library-pairing-based cryptography[EB/OL]. (2007-07-01)[2025-03-12]. http: //crypto.stanford.edu/pbc/.
|
| 34 |
BARKER E, DANG Q. Recommendation for key management: Part 1-General: NIST SP 800-57 Part 1 Rev. 4[S]. Gaithersburg: NIST, 2016.
|
/
| 〈 |
|
〉 |