AI 中文总结
研究大规模外包环境下生物特征识别问题,提出BioZKFHE框架,结合BGV同态计算等技术。采用SCMV打包和PVSC方法,减少加密存储、避免旋转密集匹配、使证明生成可行。实验表明该框架能实现接近无损识别,减少加密存储,缩短运行时间。
AI 中文摘要
在外部环境中的大规模生物特征识别需要同时具备两个属性:生物特征模板和查询在计算过程中必须受到保护,并且在发布任何应用结果之前,由不可信计算节点产生的加密相似性输出必须可验证地正确。现有的基于全同态加密(FHE)的生物识别系统主要解决保密性问题,而实际的可验证性在底层加密的1:N匹配层引入了两个瓶颈:旋转和带宽密集的相似性评估以及证明重复同态相似性轨迹的高成本。我们提出了BioZKFHE,这是一个通过可验证的同态相似性评估实现可扩展加密生物特征识别的框架,它将BGV同态计算与委员会介导的证明开启/解密以及对开启的证明批次的智能合约验证相结合。为了减少加密存储并避免旋转密集的加密1:N匹配,我们提出了单系数多值(SCMV)打包,通过基数-T扩展将多个量化嵌入值绑定到每个明文条目中。为了使证明生成切实可行,我们提出了可并行化和可验证的相似性计算(PVSC),它利用BGV的双中国剩余定理(Double-CRT)执行结构将每个逐块相似性轨迹分解为并行证明实例,在结果发布之前进行开启和检查。在标准格假设和明确的委员会/验证者假设下,我们分析了可恢复性、噪声增长、保密性、加密输出完整性和最终结果完整性。在FaceNet和MobileFaceNet上的实验表明,生物特征识别效用接近无损,加密存储减少高达67%,对于10k到40k个模板,端到端证明验证运行时间约为22到44秒。
英文摘要
Large-scale biometric identification in outsourced settings requires two properties simultaneously: biometric templates and queries must remain protected during computation, and the encrypted similarity outputs produced by an untrusted compute node must be verifiably correct before any application result is released. Existing FHE-based biometric systems primarily address confidentiality, while practical verifiability introduces two bottlenecks in the underlying encrypted 1:N matching layer: rotation- and bandwidth-heavy similarity evaluation and the high cost of proving repeated homomorphic similarity traces. We present BioZKFHE, a framework for scalable encrypted biometric identification via verifiable homomorphic similarity evaluation that combines BGV homomorphic computation with committee-mediated proof opening/decryption and smart-contract verification of opened proof batches. To reduce encrypted storage and avoid rotation-heavy encrypted 1:N matching, we propose Single-Coefficient Multi-Value (SCMV) packing, which binds multiple quantized embedding values into each plaintext entry through base-T expansion. To make proof generation practical, we propose Parallelizable and Verifiable Similarity Computation (PVSC), which exploits the Double-CRT execution structure of BGV to decompose each blockwise similarity trace into parallel proof instances that are opened and checked before result release. Under standard lattice assumptions and explicit committee/verifier assumptions, we analyze recoverability, noise growth, confidentiality, encrypted-output integrity, and finalized-result integrity. Experiments on FaceNet and MobileFaceNet show near-lossless biometric utility, up to 67 percent encrypted-storage reduction, and about 22 to 44 seconds end-to-end proof-verified runtime for 10k to 40k templates.
CommentsAccepted for publication in IEEE Transactions on Dependable and Secure Computing. 28 pages, including supplementary material
Journal refIEEE Transactions on Dependable and Secure Computing, early access, 23 July 2026