用左右眼融合生成可撤销的虹膜模板,无需密钥也能保障安全。
Cancelable Biometric Template Protection Based on Multi-Instance Fusion: A Contralateral Iris Approach

- 通过左右眼虹膜融合与盐值置换生成唯一模板。
- 跨设备测试下错误率最低达0.36%,最高10.80%。
- 无需外部密钥,适合高安全需求的生物识别系统。
生物特征模板若未加密存储易遭窃取,而虹膜无法像密码一样重置。现有可撤销生物特征方案多依赖外部密钥或令牌,引入额外攻击面。本文提出一种无令牌的对侧虹膜可撤销模板保护方法,满足ISO/IEC 24745的不可逆性、不可关联性和机密性要求。通过多数投票融合每只眼的三个注册样本生成稳定模板,并基于用户注册ID生成盐值进行比特置换。将左右眼置换后的模板按位异或,生成单一受保护融合模板。由于左右虹膜模式统计独立,融合提升识别精度。攻击者需同时获取双虹膜码与双盐值才能恢复信息,有效密钥空间大于单虹膜方案。在CASIA-IrisV4-Interval、CASIA-IrisV2(两设备)、CASIA-Iris-Thousand三数据集上,等错误率(EER)分别为0.36%、4.88%、10.80%和3.35%;最高值来自更具挑战性的跨设备场景。实验表明该方法优于未保护基线,且与先进可撤销方法相当。消融实验验证其在性能与安全性上的优势。据我们所知,这是首个结合无令牌多实例融合与对侧绑定的方案,符合ISO/IEC 24745标准。
原文摘要 · Abstract (English)
Biometric templates are vulnerable to theft if stored without protection. Unlike passwords, a compromised iris cannot be reissued. Although existing cancelable biometric schemes address this problem, most still require an external key or token, introducing an additional attack surface. This paper proposes a cancelable contralateral iris template protection scheme that eliminates the need for a separate token or stored secret, satisfying the three requirements of ISO/IEC 24745: irreversibility, unlinkability, and confidentiality. The method fuses three enrollment samples per eye using Majority Vote Fusion to produce a stable template, and applies a salt-based bit permutation derived from the subject's enrollment ID. Combining the left- and right-permuted templates via a bitwise XOR produces a single Protected Fused Template. Since left and right iris patterns are statistically independent, fusing contralateral irises improves the accuracy of the system. An attacker must possess both iris codes and both salts to recover any useful information, yielding a larger effective key space than single-iris schemes. Experiments on three datasets, CASIA-IrisV4-Interval, CASIA-IrisV2 (two devices), and CASIA-Iris-Thousand, yield EERs of $0.36$\%, $4.88$\%, $10.80$\%, and $3.35$\%, respectively; the highest value reflects the more challenging cross-device scenario. These results demonstrate that our contralateral approach outperforms unprotected baselines while remaining competitive with state-of-the-art cancelable methods. %In addition, an ablation study confirms the benefit on both recognition performance and security. To the best of our knowledge, this is the first scheme to combine tokenless multi-instance fusion and contralateral binding under ISO/IEC 24745.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。