Protecting Facial Biometric Templates with Threshold Secret Sharing: A Comparative Resource-Aware Study of a Non-Positional Polynomial Scheme and a Multivariable Verification Scheme

Facial biometric templates are permanent identifiers: once exposed, the underlying identity cannot be reissued, so single-copy storage is a critical single point of failure. This study protects facial templates by combining a non-invertible BioHashing transform and authenticated encryption with a threshold secret-sharing layer that distributes the protected record across independent storage nodes and reconstructs it only when a quorum of shares is collected. Two threshold schemes, previously proposed by our group for fingerprint and for general confidential data, are, for the first time, applied to facial templates and compared on a common platform as a resource-aware architecture: a non-positional polynomial notation scheme with the Chinese remainder theorem, and a verifiable multivariable-function scheme. Both reconstruct the template exactly and, across 2000 trials per attack, resist or detect every attack in our evaluation (for example, malicious-share tampering is detected in 100% of 2000 trials and stolen-token recovery succeeds in 0 of 2000), whereas a single read breach of one-copy storage discloses the template in full. Below the threshold they differ: the polynomial scheme is a compact, deterministic ramp scheme for edge and Internet-of-Things nodes that discloses only ciphertext bytes and, under separate key and token storage, neither the biometric nor the key; the multivariable scheme adds native share verification and, in its randomized single-secret mode, provides information-theoretic perfect secrecy for a single high-value secret, while for the packed record it is a verified ramp. Rather than ranking the schemes, we quantify this trade-off. Because the protection layer is lossless, recognition accuracy is inherited unchanged from the face encoder; on the LFW verification protocol, the complete pipeline attains an equal error rate of 2.12% ± 0.57% (95% CI [1.77%, 2.47%]) against a per-fold raw-embedding cosine baseline of 1.37% ± 0.62%.

Authors

Institutions

Publication Details

Journal
Computers
Published
2026-09-10
DOI
https://doi.org/10.3390/computers15090604
Primary Topic
Biometric Identification and Security
Type
article
Field-Weighted Citation Impact
0.00
Controls
|||
ALL TIME
JAN
FEB
MAR
APR
MAY
JUN
JUL
AUG
SEP
article

Protecting Facial Biometric Templates with Threshold Secret Sharing: A Comparative Resource-Aware Study of a Non-Positional Polynomial Scheme and a Multivariable Verification Scheme

Нурсулу Капалова, Nursultan Yergesh
Computers
Biometric Identification and Security
article

Protecting Facial Biometric Templates with Threshold Secret Sharing: A Comparative Resource-Aware Study of a Non-Positional Polynomial Scheme and a Multivariable Verification Scheme

Нурсулу Капалова, Nursultan Yergesh
article en

Abstract

Facial biometric templates are permanent identifiers: once exposed, the underlying identity cannot be reissued, so single-copy storage is a critical single point of failure. This study protects facial templates by combining a non-invertible BioHashing transform and authenticated encryption with a threshold secret-sharing layer that distributes the protected record across independent storage nodes and reconstructs it only when a quorum of shares is collected. Two threshold schemes, previously proposed by our group for fingerprint and for general confidential data, are, for the first time, applied to facial templates and compared on a common platform as a resource-aware architecture: a non-positional polynomial notation scheme with the Chinese remainder theorem, and a verifiable multivariable-function scheme. Both reconstruct the template exactly and, across 2000 trials per attack, resist or detect every attack in our evaluation (for example, malicious-share tampering is detected in 100% of 2000 trials and stolen-token recovery succeeds in 0 of 2000), whereas a single read breach of one-copy storage discloses the template in full. Below the threshold they differ: the polynomial scheme is a compact, deterministic ramp scheme for edge and Internet-of-Things nodes that discloses only ciphertext bytes and, under separate key and token storage, neither the biometric nor the key; the multivariable scheme adds native share verification and, in its randomized single-secret mode, provides information-theoretic perfect secrecy for a single high-value secret, while for the packed record it is a verified ramp. Rather than ranking the schemes, we quantify this trade-off. Because the protection layer is lossless, recognition accuracy is inherited unchanged from the face encoder; on the LFW verification protocol, the complete pipeline attains an equal error rate of 2.12% ± 0.57% (95% CI [1.77%, 2.47%]) against a per-fold raw-embedding cosine baseline of 1.37% ± 0.62%.

ComputersVol. 15(9)
Al-Farabi Kazakh National University (KZ), Institute of Information and Computational Technologies (KZ)
Openalex Percentile: Top 9%
Biometric Identification and Security
AI Navigator

Ask Laika to Summarize, Analyze, and Connect papers live on the map.

Summarize Papers & Methodologies

Extract key findings, datasets, and comparative methods across publications.

Benchmark Rankings & Visual Analytics

Rank top research institutions, authors, funders, topics, and journals by Field-Weighted Citation Impact (FWCI) and paper volume with instant charts.

Connect Distant Disciplines

Bridge topological clusters on the map to find hidden collaborative intersections.