scieee AI-readable full text Open interactive document viewer

A Cloud-Based Multifactor Authentication Scheme Using Post-Quantum Cryptography and Trusted Execution Environments

franco, claudia; ARJONA, ROSARIO; Baturone, Iluminada

Abstract

Since online transactions increase every day (banking, health services, etc.), authenticating the users in the cloud with a high level of assurance is a big concern. We propose a multifactor authentication scheme using post-quantum cryptography and trusted execution environments (TEEs). Three authentication factors are considered: what the user has (a device storing a secret), what the user knows (a password) and who the user is (with face biometrics). CRYSTALS-Kyber post-quantum public-key encryption is executed in an enclave of a TEE to encrypt a combination of the three factors mentioned. Instead of using the closed TEE solutions available in some personal devices, we propose an open solution that implements each personal enclave (linked to each personal device) in a biometric server. Instead of using a local authentication to unlock a personal device, we propose the use of another server (an authentication server), with another enclave, to authenticate each user in the cloud. The sensitive information concerning biometrics is always protected in a post-quantum manner, not only because it is obtained and encrypted inside an enclave on a biometric server but also because it is communicated, stored, and processed at the authentication server without being decrypted, thanks to the homomorphic property of Kyber. Our proposal is scalable for many users and secure against malicious adversaries. Experimental results using Intel SGX1 enclaves disabling hyper-threading and a facial recognition system show that the time to perform the crypto-biometric operations (excluding the feature extraction) is 1.55 ms and the accuracy considering only the biometric factor is 99.2% with an EER of 1.18%, which are competitive results compared to the state-of-the-art.

Full text

A Cloud-based Multifactor Authentication Scheme Using Post-Quantum Cryptography and Trusted Execution Environments Claudia Franco, Rosario Arjona and Iluminada Baturone Instituto de Microelectrónica de Sevilla (IMSE-CNM), University of Seville-CSIC, Seville, Spain [email protected], [email protected], [email protected] Abstract. Since online transactions increase every day (banking, health services, etc.), authenticating the users in the cloud with a high level of assurance is a big concern. We propose a multifactor authentication scheme using post-quantum cryptography and trusted execution environments (TEEs). Three authentication factors are considered: what the user has (a device storing a secret), what the user knows (a password) and who the user is (with face biometrics). CRYSTALSKyber post-quantum public-key encryption is executed in an enclave of a TEE to encrypt a combination of the three factors mentioned. Instead of using the closed TEE solutions available in some personal devices, we propose an open solution that implements each personal enclave (linked to each personal device) in a biometric server. Instead of using a local authentication to unlock a personal device, we propose the use of another server (an authentication server), with another enclave, to authenticate each user in the cloud. The sensitive information concerning biometrics is always protected in a post-quantum manner, not only because it is obtained and encrypted inside an enclave on a biometric server but also because it is communicated, stored, and processed at the authentication server without being decrypted, thanks to the homomorphic property of Kyber. Our proposal is scalable for many users and secure against malicious adversaries. Experimental results using Intel SGX1 enclaves disabling hyper-threading and a facial recognition system show that the time to perform the crypto-biometric operations (excluding the feature extraction) is 1.55 ms and the accuracy considering only the biometric factor is 99.2% with an EER of 1.18%, which are competitive results compared to the state-of-the-art. Keywords: Multifactor authentication, homomorphic encryption, post-quantum cryptography, trusted execution environments (TEEs), biometrics. 1 Introduction Online authentication of users with a high level of assurance is an increasing concern. Especially for important online services such as eBanking, eHealth, etc. The authentication of a user can be based on three different factors: what s/he has (device 2 F. Author and S. Author possession), what s/he knows (like the knowledge of a password or PIN), and who s/he is (with biometrics). An authentication scheme using two or more factors is called multifactor [1]. There are two main phases in an authentication process: enrollment and verification. At the enrollment phase, a new user is registered. At the verification phase, the authenticity of a user is proven by comparing the new information provided with the data provided at enrollment [1]. In the case of biometrics, the usual architecture of a biometric authentication system is formed by the modules shown in Fig. 1: acquisition, feature extractor, storage, comparison and decision. In the acquisition module, a biometric sample is taken from a biological trait (for example, a photo is taken from the face). The biometric sample is then processed by the feature extractor to obtain the biometric data (for example, the embeddings of the face). At enrollment, these biometric data are stored as template. At verification, the biometric data go directly to the comparison module where they are compared to the stored template. Finally, an authentication decision is made after evaluating if the comparison result is greater or smaller than a threshold value. Since biometric data are inherent to individuals and cannot be changed, they are protected by personal data regulations laws, and biometric systems need to follow standards like ISO/IEC 24745 [2]. Following this standard, biometric data should be protected to satisfy irreversibility, unlinkability, and revocability requirements. Irreversibility ensures that no information about the original biometric data is revealed by the protected biometric data. Unlinkability refers to obtaining different protected biometric data from different biometric samples from the same instance if old ones must be abandoned. Revocability refers to the ability to obtain new and different protected biometric data from the same biometric sample if the same individual is enrolled in different systems. A biometric recognition system can suffer several attacks, addressed to their modules or the communication channels between them [3]. We can classify the attacks based on the victim module as follows (shown in Fig. 1): Fig. 1. Usual architecture of a biometric recognition system. The step depicted with a dashed line is done only at enrollment. Red numbers indicate the possible attacks on an unprotected system. Contribution Title (shortened if too long) 3 • Acquisition attacks (1): fake biometric samples are presented at the input of the acquisition module (presentation attacks) or injected at its output (injection attacks). • Feature extractor attacks (2): the biometric data produced are learnt or altered. • Storage attacks (3): the template is stolen or manipulated. • Comparison (4) /decision (5) attacks: the inputs or outputs of these modules are altered. In order to avoid storage attacks, biometric data are protected before being stored at enrollment. Biometric cryptosystems (which use constructions such as fuzzy extractor, fuzzy commitment or fuzzy vault) are employed to reconstruct a secret key from biometric data or to bind a secret to them [4, 5]. At enrollment, the key is combined with the biometric data to generate helper data (the protected data that is stored). At verification, the key is reconstructed by using fresh biometric data and the stored helper data. To authenticate a user, the verifier checks that the same key is obtained. Other biometric systems use irreversible transformations to protect the biometric data [6]. These transformations preserve the distance between the biometric data, allowing comparisons to be performed on the transformed domain at verification, thus reducing some attacks at the comparison module. A disadvantage of both biometric cryptosystems and systems with irreversible transformations is that they decrease the recognition performance of the systems without protection [6, 7]. To avoid this disadvantage, another way to protect biometric systems is to use homomorphic encryption (HE). This solution preserves the recognition accuracy because it allows performing some operations on the encrypted data and obtaining the same result when decrypted as when applying other operations on the plaintext data [8]. This has been used to calculate distances/similarities between protected biometric data and templates without the need to decrypt them [9-11]. HE is based on public key encryption algorithms. The common public key encryption algorithms used today are based mainly on mathematical problems related to integer factorization, discrete logarithms, and elliptic curves. Since these problems will not be hard for quantum computers in the future, these encryption algorithms will be unsecure and all the data encrypted this way will be unsafe. Post-quantum cryptography is a part of cryptography that uses other mathematical problems that are not solvable by quantum computers [12, 13]. Since biometric data are sensitive and persistent, they should be protected against possible future attacks by quantum computers [6, 10, 11]. Trusted execution environments (TEEs) are another promising technology to increase the security of authentication systems. These are hardware-based secure environments that allow storing and processing sensitive data in a protected and immutable way [14]. Most mobile device TEEs are not open to developers. In addition, some old or low-end mobile phones may not even have one [15]. Cloud-based TEEs, on the other hand, are open to developers and do not depend on each user device, which makes them a more scalable and usable option. In this work, we combine post-quantum HE and TEEs to propose a multifactor authentication scheme that avoids the feature extractor, storage and comparison/decision attacks mentioned above. Our main contributions are the following: 4 F. Author and S. Author • A novel combination of homomorphic encryption and trusted execution environments to protect a cloud-based authentication system with three factors, ensuring a high level of assurance, confidentiality (privacy) and integrity (authenticity) of the data and the code executed and following the standard ISO/IEC 24745 on biometric information protection. • A multifactor authentication scheme that is secure against malicious adversaries, that is, actors in the authentication scheme that attempt to deviate from the defined protocol to achieve malicious interests, such as retrieving private information. • An open solution with scalability and usability, which does not impose any constraint on the personal device possessed by the user and employed to acquire the biometric trait and the password. • Experimental results using Intel SGX1 enclaves as TEEs, CRYSTALS-Kyber postquantum public-key homomorphic encryption, and a facial recognition system showing that our proposal is practical for a real implementation in terms of execution times, communication overheads and accuracy, and is competitive compared to other solutions in the state-of-the-art. The paper is structured as follows. Related work is included in Section 2 by describing the proposals related to biometric data protection techniques and trusted execution environments. Section 3 introduces the necessary background about CRYSTAL-Kyber and trusted execution environments. Section 4 presents the security model. Section 5 describes the authentication proposal. Experimental results are given in Section 6. Finally, Section 7 concludes our work. 2 Related Work Several schemes reported in the literature perform authentication based solely on biometric data. BRAKE [16] is a three-party protocol (between a client, a server and an evaluator) for biometric resilient Authenticated Key Exchange (AKE) that uses a fuzzy vault and an Oblivious Pseudo Random Function (OPRF). The latter is a cryptographic primitive that enables the client and the evaluator to evaluate a pseudorandom function without knowing each other’s inputs and with only the client learning the output, thus meeting the requirements of the ISO/IEC 24745 standard. They present a post-quantum proposal using a lattice-based OPRF and a post-quantum key-encapsulation mechanism that, in a practical realization, can only be considered in a semi-honest adversary model, which means that the parties can be curious but do not deviate from the defined protocol. Other works use face biometric data and protect them only with post-quantum homomorphic encryption (HE) [10, 11] or combining HE with a multi-party computation technique such as garbled circuits [17]. The work in [9] presents a multi-biometric system protected with fully homomorphic encryption (FHE) that is not resistant to the attacks of quantum computers. The proposals mentioned above preserve the privacy of the biometric data against semi-honest adversaries, which is an insufficient model for real-world adversaries that can be malicious. Other proposals of biometric authentication use zero knowledge Contribution Title (shortened if too long) 5 proofs (ZKPs) which enable a prover to convince a verifier of the authenticity of a statement without leaking any other information [18]. ZKPs are applied in works such as [18-21] to force the parties to follow some of the steps of the defined protocol but not all of them. The ZKPs employed are based on the hardness of solving discrete logarithms, which are not post-quantum resistant. Excluding the feature extraction step, these solutions have runtimes ranging from several hundreds of milliseconds to several seconds. The feature extraction module employed in [18] is a support-vector machine classifier that does not provide a high accuracy and requires to be trained for each user, what is not a scalable solution. Another solution to protect authentication against malicious parties is the use of trusted execution environments (TEEs). The system BioShare [22] employs a mobile TEE and a server TEE and performs the biometric authentication inside. While TEEs offer code attestation to ensure correct computation, attestation is never performed in the BioShare authentication protocol. Subsequently, the computation is not verified and, hence, the parties are not detected if they are malicious. The work in [21] combines the use of ZKPs and TEEs for authenticating the users to online services from their mobile phones. However, the authors regret that the mobile device they used for experiments did not allow them access to its TEE. TAKE [23] is a two-factor AKE using biometrics and a password. The system uses a fuzzy extractor and an OPRF that is not post-quantum. To protect the data inside the server, the data are encrypted and the key is saved inside a TEE, which is never attested and, hence, not detected if it is malicious. Protecting the feature extractor is a current topic of research [24]. The combination of TEEs and HE for neural networks is being studied [25, 26] as an option to ensure the integrity or authenticity of the code (with the TEE) and the data confidentiality or Table 1. Characteristics comparison with authentication systems of the related work Work Techniques used Multifactor authentication Post-quantum security Employment of TEE Security model [16] Fuzzy vault + OPRF No Yes No Semi-honest [23] Fuzzy extractor + OPRF + TEE Yes No Yes Semi-honest [17] HE + Garbled circuits No Yes No Semi-honest [18] Machine learning + ZKP No No No Honest/Semihonest [22] TEE No No Yes Semi-honest Ours HE + TEE Yes Yes Yes Malicious 6 F. Author and S. Author privacy (with the HE). Other ways of protecting the inference are also being studied, such as splitting the neural network [27] or using multi-party computation techniques [28]. Practical proposals of these solutions for authentication schemes have not been reported yet. In Table 1 we compare a spread of the most recent proposals discussed above that showcase the most used techniques employed in literature to design an authentication system, their characteristics, and the security model assumed. The last row includes our proposal presented in the following. 3 Background 3.1 CRYSTALS-Kyber In 2022, the post-quantum public-key encryption and key-encapsulating mechanism CRYSTALS-Kyber was chosen for standardization by the National Institute of Standards and Technology (NIST) [28]. In our proposal, CRYSTALS-Kyber, herein referred to as Kyber, is used for the encryption of the biometric data since homomorphic encryption based on Kyber can be employed as experimentally shown in [10] and satisfying irreversibility, revocability and unlikability properties. Kyber allows performing polynomial coefficient-wise subtractions in the encrypted domain as the XOR operation in the decrypted domain. This is shown in (1) where 𝑏1,𝑏2 are two binary strings, 𝐸𝑛𝑐 and 𝐷𝑒𝑐 are, respectively, the encryption and decryption algorithms, 𝑠𝑘 is the secret key associated with the public key 𝑝𝑘, and the function 𝑃𝑂𝐿𝑌.𝑠𝑢𝑏𝑠𝑡𝑟𝑎𝑐𝑡 performs the polynomial coefficient-wise subtractions between the ciphertexts, assuming that the ciphertexts are decompressed and the result is recompressed. 𝐷𝑒𝑐𝑠𝑘(𝑃𝑂𝐿𝑌.𝑠𝑢𝑏𝑠𝑡𝑟𝑎𝑐𝑡(𝐸𝑛𝑐𝑝𝑘(𝑏1),𝐸𝑛𝑐𝑝𝑘(𝑏2))) = 𝑏1⊕𝑏2 (1) Using this property, if 𝑏1 and 𝑏2 are biometric data, we are able to compare them in the encrypted domain and then calculate their Hamming distance (𝐻𝐷) as shown in (2) where 𝐻𝑊 is the Hamming weight of a binary string (the number of logic 1’s). 𝐻𝐷(𝑏1,𝑏2 ) = 𝐻𝑊(𝐷𝑒𝑐𝑠𝑘 (𝑃𝑂𝐿𝑌.𝑠𝑢𝑏𝑠𝑡𝑟𝑎𝑐𝑡(𝐸𝑛𝑐𝑝𝑘 (𝑏1 ),𝐸𝑛𝑐𝑝𝑘 (𝑏2)))) (2) 3.2 Trusted Execution Environment A trusted execution environment (TEE) is a secure area of a main processor that ensures that sensitive data can be stored, processed and protected in an isolated and secure environment [14]. A TEE provides confidentiality (privacy) and integrity (authenticity) of the data and the code executed as well as data access rights. To offer this, all TEEs must have the following security features: isolated execution, secure storage and cryptographic primitives, among others. Some TEEs also offer remote attestation [30], which means that third parties can be assured that the code is being run inside a TEE. Different types of remote attestation Contribution Title (shortened if too long) 7 exist: boot attestation (which ensures that the TEE was initialized in a correct way) and run-time attestation (which proves that the correct code is being run securely in a TEE) [31]. There are different types of TEEs. We can distinguish between two principal ones: TEEs in embedded devices and TEEs in servers. A TEE in an embedded device offers secure execution of a trusted application, that is, an application authorized by the device vendor or a trusted developer. For example, the TEE of a mobile device protects the use of several peripherals such as biometric sensors, cameras, etc. [14]. While this seems like a perfect way to protect applications on mobile devices, there are some issues with deployment. Most TEEs included in mobile devices are closed to external developers [15] (only mobile vendors can develop and establish trusted applications), which limits their use. Other TEEs are open but have differences between them that force developers to adapt every application to each type of TEE [32]. Hence, using TEEs in embedded devices has currently two main drawbacks: (1) several mobile devices do not have TEEs or cannot execute external apps on them, which reduces the usability of the solution, and (2) extensive work from the app developers is required to adapt the app to every possible TEE available, which reduces the scalability of the solution. Server TEEs, on the other hand, are open to developers, only one application has to be developed, and it does not depend on each user’s device. There are different types of TEEs for servers. We can distinguish between secure enclaves [33] and, more recently, secure Virtual Machines (VMs) [34]. A secure VM shields the contents of an entire VM from the cloud owner but gives full control to the VM owner. The enclaves are used to secure the data and the code they contain from potentially malicious owners and users of the servers. Among the TEEs for servers that offer enclaves, Intel Software Guard Extensions (SGX) is well known [33]. They provide integrity of all code and data and confidentiality of the data. When running an enclave, a measurement hash is calculated taking into account all the code loaded inside. Intel SGX processors include two secrets stored inside efuses, a type of one-time programmable memory. Each enclave can derive a unique symmetric sealing key 𝑘𝑆𝑒𝑎𝑙 from these secrets and its measurement hash, allowing it to store secrets encrypted in the long-term memory [33]. Remote attestation proves to a remote party that an enclave is running in an Intel SGX enabled processor and the correct code is running inside. An attestation quote is a report containing the enclave measurement hash and signed by a SGX Attestation Key used by a privileged enclave signed by Intel. The SGX Attestation Key is certified by a list of certificates, including an Intel signature [33]. A TLS handshake can be performed with the enclave so that external attackers or the server owner cannot understand the communicated data [35]. We show in Fig. 2 a TLS handshake performed between an enclave and a remote party. The remote party sends a “ClientHello” which includes a random nonce. The enclave answers with a “ServerHello”, which includes another nonce, and its X.509 certificate. The remote party encrypts a random secret with the public key (𝑇𝐿𝑆𝑝𝑘) inside the certificate and sends it back to the enclave. Both enclave and remote party compute the same session key (𝐾) from the nonces and secret. 8 F. Author and S. Author RA-TLS is a variation of a TLS protocol in which the X.509 certificate used for the public TLS key of the enclave includes the attestation quote. Inside the attestation quote, the public TLS key of the enclave is added, ensuring the other party that the secret key is saved inside the enclave. To verify an Intel SGX attestation report, Intel provides quote libraries [36]. The RA-TLS can be performed between two enclaves as well, sending both a X.509 certificate with their quote inside. Several vulnerabilities of Intel SGX enclaves have been discovered throughout the years. The most important type are side-channel attacks, which can extract private data from timing information, instruction counts, power consumption, etc. These attacks can be avoided by keeping Intel SGX microcode updated, disabling hyper-threading capabilities on the processors, implementing side-channel safe programming when possible and revising possible vulnerabilities on external libraries [37, 38]. 4 Security Model We define a scalable and usable multifactor authentication system using TEEs and HE to ensure correct computation and secure private data. 4.1 System Model Our system is formed by three different parties: • The User Device (UD). It is assumed to be an untrusted device (typically a mobile phone) controlled by the user. It is responsible for acquiring the authentication factors and sending them to the Biometric Server. • The Biometric Server (BS). It is assumed to be an untrusted server, possibly malicious, that hosts a secure enclave. The enclave is responsible of calculating the enrollment/verification data from the received authentication factors. It is also Fig. 2. TLS handshake performed between an enclave and a remote party. Contribution Title (shortened if too long) 9 responsible for generating and storing the Kyber keys and encrypting the authentication data. It acts as the prover in the authentication protocol. • The Authentication Server (AS). It is assumed to be an untrusted server, possibly malicious, that hosts another secure enclave. This enclave will be responsible for comparing the enrollment and verification data and making the authentication decision. The enrollment data is stored sealed outside the enclave, since the enclave memory space is limited. Fig. 3 shows the architecture of the system and how the different modules are organized. Feature extraction, post-quantum protection, comparison and decision modules are all secure inside the enclaves. All communication between the three parties is secured by encrypting it with ephemeral session keys obtained with TLS handshakes. The session keys are only available to the User Device and the two enclaves, not to the servers. 4.2 Threat Model We assume that all parties distrust each other. Both servers can be malicious, but we assume that they do not collude, as they act as prover and authenticator in the protocol. Acquisition attacks on the User Device are outside of the scope of our study. 4.3 Security Measures Feature extraction and comparison/decision module attacks are prevented by performing said operations inside attested secure enclaves. Storage attacks are prevented by encrypting the enrollment data with Kyber and then storing them sealed with the enclave sealing key. The system is secure against man-in-the-middle attacks by Fig. 3. Architecture of the authentication scheme proposed. 16 F. Author and S. Author Future lines of work include the introduction of acquisition attack detection systems in the user device [47] and the study of a distributed backup system to allow users to recover their multifactor authentication data if a user device is lost or a password is forgotten. Acknowledgements. This research was conducted thanks to Grants PDC2023– 145873-I00, CPP2022–009796, and PID2023-150809OB-I00 funded by MICIU/AEI/10.13039/ 501100011033 and the European Union NextGenerationEU/PRTR, thanks to the LICORICE Project with Grant Agreement No. 101168311 under the EU Horizon Europe, and thanks to the grant USECHIP (TSI-069100-2023001) funded by the Secretary of State for Telecommunications and Digital Infrastructure, Ministry for Digital Transformation and Civil Service and by the European Union – Next Generation EU/PRTR. References 1. Ometov A, Bezzateev S, Mäkitalo N, Andreev S, Mikkonen T, Koucheryavy Y. Multi-Factor Authentication: A Survey. Cryptography. 2(1), (2018). 2. ISO/IEC 24745:2022. Information security, cybersecurity and privacy protection - Biometric information protection. 3. Abdullahi, S. M., Sun, S., Wang, B., Wei, N., Wang, H.: Biometric template attacks and recent protection mechanisms: A survey. Information Fusion 103, 102-144 (2024) 4. Dodis, Y., Reyzin, L., Smith, A.: Fuzzy extractors, In: Tuyls, P., Skoric, B., Kevenaar, T. (eds) Security with Noisy Data. Springer, London, (2007). 5. Juels, A.: Fuzzy commitment, In: Tuyls, P., Skoric, B., Kevenaar, T. (eds) Security with Noisy Data. Springer, London, (2007) 6. Bauspieß, P.: Post-Quantum secure biometric systems, Norwegian University of Science and Technology (2024) 7. Rathgeb, C., Uhl, A.: A survey on biometric cryptosystems and cancelable biometrics, EURASIP Journal on Information Security 2011, 3 (2011) 8. Zhao, C., Zhao, S., Zhao, M., Chen, Z., Gao, C., Li, H., Tan, Y.: Secure multi-party computation: Theory, practice and applications, Information Sciences 476, 357-372 (2019) 9. Gomez-Barrero, M., Maiorana, E., Galbally, J., Campisi, P., Fierrez, J.:Multi-biometric template protection based on Homomorphic Encryption. Pattern Recognition 67, 149-163 (2017). 10. Román, R., Arjona, R., López-González, P., Baturone, I.: A Quantum-Resistant Face Template Protection Scheme using Kyber and Saber Public Key Encryption Algorithms. In: International Conference of the Biometrics Special Interest Group (BIOSIG), pp. 1-5 (2022). 11. Arjona, R., López-González, P., Román, R., Baturone, I.: Post-Quantum Biometric Authentication Based on Homomorphic Encryption and Classic McEliece. Applied Sciences. 13(2), 757 (2023) 12. Bos, J., Ducas, L., Kiltz, E., Lepoint, T., Lyubashevsky, V., Schanck, J.M.: CRYSTALS - Kyber: A CCA-secure module-latticebased KEM. In:2018 IEEE European Symposium on Security and Privacy (EuroS&P), pp. 353–367, (2018). Contribution Title (shortened if too long) 17 13. Kumar, M., Pattnaik, P.: Post quantum cryptography(PQC) – An overview: (Invited paper). In: 2020 IEEE High Performance Extreme Computing Conference (HPEC), pp. 1-9, Waltham, MA, USA, (2020). 14. GlobalPlatform: Introduction to trusted execution environments, (2018) https://globalplatform.org/wp-content/uploads/2018/05/Introduction-to-Trusted-Execution-Environment15May2018.pdf, last accessed: 2025/05/13 15. Muñoz, A., Ríos, R., Román, R., López, J.: A survey on the (in)security of trusted execution environment. Computers & Security 129, 103180, (2023). 16. Bauspieß, P., Silde, T., Poljuha, M., Tullot, A., Costache, A., Rathgeb, C., Kolberg, J., Busch, C.: Brake: Biometric resilient authenticated key exchange. IEEE Access 12, pp. 46 596–46 615 (2024). 17. Arjona, R., Franco, C., Román, R., Baturone, I.: Combining CRYSTALS-Kyber Homomorphic Encryption with Garbled Circuits for Biometric Authentication. In: International Conference of the Biometrics Special Interest Group (BIOSIG), pp. 1-5, (2024). 18. Guo, C., You, L., Li, X., Hu, G., Wang, S., Cao, C.: A novel biometric authentication scheme with privacy protection based on SVM and ZKP. Computers & Security 144, 103995 (2024). 19. Guo, C., You, L., Hu, G.: A Novel Biometric Identification Scheme Based on ZeroKnowledge Succinct Noninteractive Argument of Knowledge. Security and Communication Networks 2022(1), 2791058 (2022). 20. Bassit, A., Hahn, F., Peeters, J., Kevenaar, T., Veldhuis, R., Peter, A.: Fast and Accurate Likelihood Ratio-Based Biometric Verification Secure Against Malicious Adversaries. IEEE Transactions on Information Forensics and Security 16, 5045–5060 (2021). 21. Gunasinghe, H. and Bertino, E.: PrivBioMTAuth: Privacy Preserving Biometrics-Based and User Centric Protocol for User Authentication From Mobile Phones, IEEE Transactions on Information Forensics and Security 13(4), 1042-1057 (2018). 22. Sun, Q., Wu, J., Yu, W.: BioShare: An Open Framework for Trusted Biometric Authentication under User Control. Applied Sciences 12, 10782 (2022). 23. Han, Y., Xu, C., Jiang, C., Chen, K.: A Secure Two-factor Authentication Key Exchange Scheme. IEEE Transactions on Dependable and Secure Computing 21(6), 5681-5693 (2024). 24. Mann, Z. A., Weinert, C., Chabal, D., Bos, J. W.: Towards Practical Secure Neural Network Inference: The Journey So Far and the Road Ahead. ACM Computing Surveys 56(5), 117 (2023). 25. Wang, O., Zhou, L., Bai, J., Koh, Y. S., Cui, S., Russello, G.: HT2ML: An efficient hybrid framework for privacy-preserving Machine Learning using HE and TEE. Computers & Security 135, 103509 (2023). 26. Natarajan, D., Loveless, A., Dai, W., Dreslinski, R.: CHEX-MIX: Combining Homomorphic Encryption with Trusted Execution Environments for Oblivious Inference in the Cloud. In: 2023 IEEE 8th European Symposium on Security and Privacy (EuroS&P), pp. 73-91, (2023). 27. Prodomo, V., Gonzalez, R., Gramaglia, M.: SCIPER: Secure Collaborative Inference via Privacy-Enhancing Regularization. IEEE Transactions on Privacy 1, 57-68 (2024). 28. Shen, X., Luo, X., Yuan, F., Wang, B., Chen, Y., Tang, D., Gao, L.: Privacy-preserving multi-party deep learning based on homomorphic proxy re-encryption. Journal of Systems Architecture 144, 102983 (2023). 29. NIST announces first four Quantum-Resistant Cryptographic Algorithms — NIST. (2022). https://www.nist.gov/news-events/news/2022/07/nist-announces-first-four-quantum-resistant-cryptographic-algorithms, last accessed 2025/01/10 18 F. Author and S. Author 30. Sabt, M., Achemlal, M., Bouabdallah, A.: Trusted execution environment: What it is, and what it is not. In: 2015 IEEE Trustcom/BigDataSE/ISPA, pp. 57–64, (2015) 31. González, J.: Operating system support for run-time security with a trusted execution environment. Ph.D. dissertation, (2015). 32. McGillion, B., Dettenborn, T., Nyman, T., Asokan, N.: OpenTEE – An Open Virtual Trusted Execution Environment. In: 2015 IEEE Trustcom/BigDataSE/ISPA, pp. 400-407, (2015) 33. Costan, V., Devadas, S.: Intel SGX Explained. IACR Cryptol. ePrint Arch 2016(86) (2016). 34. Kollenda, K.: General overview of AMD SEV-SNP and Intel TDX. (2023). https://sys.cs.fau.de/extern/lehre/ws22/akss/material/amd-sev-intel-tdx.pdf, last accessed 2025/01/10 35. Knauth, T., Steiner, M., Chakrabarti, S., Lei, L., Xing, C., Vij, M.: Integrating Intel SGX Remote Attestation with Transport Layer Security, https://arxiv.org/pdf/1801.05863, last accessed 2025/04/25 36. Intel® Software Guard Extensions (Intel® SGX) Data Center Attestation Primitives: ECDSA Quote Library API, (2022) https://www.intel.com/content/www/us/en/content-details/734437/intel-software-guard-extensions-intel-sgx-data-center-attestation-primitivesecdsa-quote-library-api.html, last accessed: 2025/04/25 37. Kisand, A., Randmets, J.: An Overview of Vulnerabilities and Mitigations of Intel SGX and Intel TDX Applications. Cybernetica research report D-2-116 v1.4 (2025), https://cyber.ee/uploads/report_2025_sgx_19b89d79ed.pdf, last accessed: 2025/06/11 38. Van Schaik, S. et al.: SoK: SGX.Fail: How Stuff Gets eXposed. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 4143-4162 San Francisco, CA, USA, (2024). 39. Tsia, C., Porter, D. E., Vij, M.: Graphene-SGX: A Practical Library OS for Unmodified Applications on SGX. In: Proceedings of the 2017 USENIX Conference on Usenix Annual Technical Conference, pp. 645-658, USENIX Association, CA, USA, (2017). 40. CRYSTALS-Kyber, https://github.com/pq-crystals/kyber, last accessed 2025/01/10 41. FaceNet, https://github.com/davidsandberg/facenet, last accessed 2025/01/10 42. FIPS 186-4 Digital Signature Standard (DSS) (2013) https://doi.org/10.6028/NIST.FIPS.186-4, last accessed 2025/04/25 43. Jang, J., Kim, H.: Performance Measures. In: Li, S.Z., Jain, A.K. (eds) Encyclopedia of Biometrics. Springer, Boston, MA. (2015) 44. Phillips, P. J., Moon, H., Rizvi, S. A., Rauss, P. J.: The FERET evaluation methodology for face-recognition algorithms. IEEE Transactions on Pattern Analysis and Machine Intelligence 22(10), 1090-1104, (2000). 45. Huang, G., Mattar, M., Berg, T.,Learned-Miller, E.: Labeled Faces in the Wild: A Database for Studying Face Recognition in Unconstrained Environments. In: Workshop on Faces in ’Real-Life’ Images: Detection, Alignment, and Recognition, pp. 1-11, Marseille, France (2008). 46. Lim, M. H., Teoh, A. B. J.: A Novel Encoding Scheme for Effective Biometric Discretization: Linearly Separable Subcode. IEEE Transactions on Pattern Analysis and Machine Intelligence 35(2), 300-313 (2013). 47. Encina, M.: Study and realization of biometric systems implemented in smartphones and robust against presentation attacks. Computer Science Engineering Bachelor’s Thesis, University of Seville (2025).