Cryptographically Verifiable Fingerprint Authentication Using PEP Hash -- IEEE 16th Annual Ubiquitous Computing, Electronics & Mobile Communication Conference (UEMCON) Academic Article uri icon

Abstract

  • Current authentication protocols, such as Passkeys, typicallyrely on device-resident credentials unlocked with locally storedbiometric templates. While trusted hardware modules can protectsuch designs, they pose significant risks for resource-constrainedplatforms like IoT devices, which often lack secure storage forbiometrics. To address this limitation, we propose an authentica-tion framework based on Publicly Evaluatable Perceptual (PEP)hash, which combines lightweight homomorphic encryption (HE)with perceptual hashing (PH) to eliminate the need for localfingerprint storage. In our framework, an IoT device generates aPH of the user’s fingerprint via Secure Function Evaluation (SFE)and transmits it securely to the server for verification withoutexposing the PH algorithm or persisting biometric templateslocally. We formally analyze the security guarantees of the designand demonstrate its practicality using benchmark fingerprintdatasets and established PH algorithms. By decoupling privacyprotection from matching accuracy, our approach enables user-centric biometric authentication that is viable on devices withouttrusted computing modules (TPMs) and aligns with privacy-by-design principles.

Publication Date

  • 2025-10-01

Published In