American Journal of Advanced Multidisciplinary Innovation and Research

E-ISSN: XXXX-XXXX     Impact Factor: -

A Widely Indexed Open Access Peer Reviewed Multidisciplinary Bi-monthly Scholarly International Journal

Call for Paper Volume 7, Issue 5 (September-October 2026) Submit your research before last 3 days of October to publish your research paper in the issue of September-October.

Privacy-Preserving Biometrics in Distributed Service Environments

Author(s) Dr. Laura M. Bennett
Country United States
Abstract Biometric authentication is increasingly incorporated into distributed digital-service environments in which users interact with multiple organizations, cloud platforms, identity providers, mobile applications, edge devices, and federated services. Although biometrics can improve convenience and strengthen user verification, conventional centralized architectures create substantial privacy risks because biometric characteristics cannot be replaced as easily as passwords and may enable cross-service linkage, identity inference, or reconstruction if inadequately protected. ISO/IEC 24745:2022 consequently addresses confidentiality, integrity, renewability, revocability, and privacy-compliant management of biometric information, while ISO/IEC 30136 provides metrics for evaluating the accuracy, secrecy, and privacy of biometric template-protection schemes. Current NIST authentication guidance similarly requires biometric information to be treated as sensitive personal information, limits biometric authentication to specified multifactor arrangements involving a physical authenticator, and requires an alternative non-biometric authentication option.
This study develops a privacy-preserving architecture for distributed biometric services that minimizes exposure of reusable biometric information across service boundaries. Four synthetic architectures were evaluated: centralized storage of raw biometric templates, centralized storage of encrypted protected templates, federated cancelable-biometric processing with secure aggregation, and a local-biometric verification architecture combining device-bound public-key credentials with encrypted remote biometric matching only when operationally necessary. The simulation modeled 480 distributed service nodes and 38,400 authentication transactions. Evaluation considered verification accuracy, privacy exposure, cross-service linkability, protected-template revocation capability, authentication latency, and distributed resilience. The simulated privacy-exposure index declined from 78.8 under centralized raw-template storage to 51.5 under encrypted centralized protection, 31.3 under federated cancelable biometrics, and 17.8 under the local-verification architecture. Verification accuracy remained between 94.1% and 95.2% across conditions, illustrating that stronger privacy controls need not necessarily imply unacceptable biometric utility loss when architectures are carefully designed.
The study argues that privacy-preserving biometrics should not be defined merely as encrypted storage. Contemporary research demonstrates practical progress in homomorphic-encryption-based biometric matching, cancelable templates, federated learning, and secure biometric fusion, but recent identity-leakage research also shows that transformed biometric representations may remain linkable even when original facial pixels cannot be directly reconstructed. The strongest distributed architecture therefore combines data minimization, local biometric comparison, cryptographic authentication, protected-template revocability, unlinkability across relying parties, secure aggregation, encrypted-domain matching, explicit retention limits, and non-biometric recovery. The paper concludes that biometric privacy is best preserved when distributed services authenticate a user through proof derived from biometric verification rather than distribution of the biometric identity itself.
Keywords privacy-preserving biometrics, distributed authentication, biometric template protection, cancelable biometrics, homomorphic encryption, federated learning, digital identity, WebAuthn, biometric privacy, secure authentication
Field Engineering
Published In Volume 3, Issue 3, May-June 2022
Published On 2022-06-12

Share this