R. Donida Labati, Contactless Fingerprint Biometrics: Acquisition, Processing, and Privacy Protection, Ph.D. Dissertation, Universita' degli Studi di Milano, Italy, February 2013.
Biometric systems
Privacy in Biometrics

Privacy in Biometrics is a research activity focused on reconciling the reliability and convenience of biometric authentication with the protection of personal data. Unlike passwords or access tokens, biometric traits are permanently associated with their owners and cannot easily be changed after a compromise. Stolen templates may therefore enable long-term impersonation, unauthorised identification or the correlation of a person’s activities across different databases. The research consequently addresses privacy throughout the complete biometric-system lifecycle, including acquisition, template generation, storage, communication and matching.
One research direction developed privacy-aware multimodal verification methods that combine multiple biometric readings to derive secure identifiers without storing information from which the original traits can readily be reconstructed. Secure-sketch techniques compensate for the natural variability between successive biometric acquisitions and make it possible to obtain stable cryptographic information from noisy biometric data. Implementations combining iris and fingerprint traits, or multiple iris templates, demonstrated that multimodal recognition can improve reliability while keeping the stored representation protected. The resulting identifiers can also support offline verification and remain privacy-preserving even when a personal document or stored record is lost or stolen.
A complementary direction investigated distributed fingerprint recognition performed directly on encrypted data. Using Fingercode representations, multiparty computation and homomorphic encryption, the proposed protocols allow a server to compare a captured fingerprint against enrolled templates without learning the submitted biometric data, while the client obtains only the authorised matching result and no additional information about the database. A complete demonstrator confirmed the practical feasibility of encrypted-domain biometric matching, although with a trade-off between privacy protection, computational complexity and recognition performance.
The broader contribution of the project includes guidelines for designing privacy-protective biometric applications. These emphasise purpose limitation, informed user consent, data minimisation, restricted retention periods, auditing, encryption and the storage of protected templates rather than raw biometric samples. The research also identifies four essential properties for template-protection mechanisms: irreversibility, diversity across applications, revocability after compromise and limited degradation of recognition accuracy. Overall, the project provides methodological and technological foundations for biometric systems that deliver strong authentication while reducing identity theft, unauthorised surveillance and misuse of sensitive personal information.
One research direction developed privacy-aware multimodal verification methods that combine multiple biometric readings to derive secure identifiers without storing information from which the original traits can readily be reconstructed. Secure-sketch techniques compensate for the natural variability between successive biometric acquisitions and make it possible to obtain stable cryptographic information from noisy biometric data. Implementations combining iris and fingerprint traits, or multiple iris templates, demonstrated that multimodal recognition can improve reliability while keeping the stored representation protected. The resulting identifiers can also support offline verification and remain privacy-preserving even when a personal document or stored record is lost or stolen.
A complementary direction investigated distributed fingerprint recognition performed directly on encrypted data. Using Fingercode representations, multiparty computation and homomorphic encryption, the proposed protocols allow a server to compare a captured fingerprint against enrolled templates without learning the submitted biometric data, while the client obtains only the authorised matching result and no additional information about the database. A complete demonstrator confirmed the practical feasibility of encrypted-domain biometric matching, although with a trade-off between privacy protection, computational complexity and recognition performance.
The broader contribution of the project includes guidelines for designing privacy-protective biometric applications. These emphasise purpose limitation, informed user consent, data minimisation, restricted retention periods, auditing, encryption and the storage of protected templates rather than raw biometric samples. The research also identifies four essential properties for template-protection mechanisms: irreversibility, diversity across applications, revocability after compromise and limited degradation of recognition accuracy. Overall, the project provides methodological and technological foundations for biometric systems that deliver strong authentication while reducing identity theft, unauthorised surveillance and misuse of sensitive personal information.
Relevant publications
R. Donida Labati, V. Piuri, F. Scotti, Biometric privacy protection: guidelines and technologies, Communications in Computer and Information Science, vol. 314, pp. 3-19, Springer, 2012, ISSN 978-3-642-35754-1.
S. Cimato, R. Sassi, F. Scotti, Biometric Privacy, Encyclopedia of Cryptography and Security (2nd ed.), pp. 101-104, Springer, 2011, ISSN 978-1-4419-5905-8.
M. Barni, T. Bianchi, D. Catalano, M. Di Raimondo, R. Donida Labati, P. Failla, D. Fiore, R. Lazzeretti, V. Piuri, F. Scotti, A. Piva, A privacy-compliant fingerprint recognition system based on homomorphic encryption and FingerCode templates, Proc. of the 2010 IEEE Int. Conf. on Biometrics: Theory Applications and Systems (BTAS 2010), pp. 1-7, Washington, D.C., USA, September 2010, ISSN 978-1-4244-7580-3.
M. Barni, T. Bianchi, D. Catalano, M. Di Raimondo, R. Donida Labati, P. Failla, D. Fiore, R. Lazzeretti, V. Piuri, F. Scotti, A. Piva, Privacy-preserving fingercode authentication, Proc. of the 2010 ACM Workshop on Multimedia and Security, pp. 231-240, New York, NY, USA, September 2010, ISSN 978-1-4503-0286-9.
S. Cimato, M. Gamassi, V. Piuri, R. Sassi, F. Scotti, Privacy in biometrics, Biometrics: theory, methods, and applications, IEEE Press Series on Computational Intelligence, pp. 633-654, Wiley-IEEE Press, 2009, ISSN 978-0-470-24782-2.
S. Cimato, M. Gamassi, V. Piuri, R. Sassi, F. Scotti, Privacy-aware biometrics: design and implementation of a multimodal verification system, Proc. of the 2008 Annual Computer Security Applications Conf. (ACSAC 2008), pp. 130-139, Anaheim, CA, USA, December 2008, ISSN 978-0-7695-3447-3.
S. Cimato, M. Gamassi, V. Piuri, R. Sassi, F. Scotti, A multi-biometric verification system for the privacy protection of iris templates, Proc. of the Int. Workshop on Computational Intelligence in Security for Information Systems (CISIS 2008), Advances in Soft Computing, vol. 53, pp. 227-234, Genova, Italy, October 2008, ISSN 978-3-540-88180-3.
S. Cimato, R. Sassi, F. Scotti, Biometrics and privacy, Recent Patents on Computer Science, vol. 1, pp. 98-109, June 2008, ISSN 1874-4796.
S. Cimato, M. Gamassi, V. Piuri, R. Sassi, F. Scotti, A biometric verification system addressing privacy concerns, Proc. of the 2007 Int. Conf. on Computational Intelligence and Security (CIS 2007), pp. 594-598, Harbin, China, December 2007, ISSN 978-0-7695-2823-6.
S. Cimato, M. Gamassi, V. Piuri, R. Sassi, F. Scotti, Privacy issues in biometric identification, Touch Briefings, pp. 40-42, Business Briefings LtD, 2006, ISSN 1-905-05296-0.
