{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T21:05:50Z","timestamp":1776373550737,"version":"3.51.2"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319192482","type":"print"},{"value":"9783319192499","type":"electronic"}],"license":[{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2015,1,1]],"date-time":"2015-01-01T00:00:00Z","timestamp":1420070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2015]]},"DOI":"10.1007\/978-3-319-19249-9_7","type":"book-chapter","created":{"date-parts":[[2015,5,23]],"date-time":"2015-05-23T07:55:31Z","timestamp":1432367731000},"page":"90-107","source":"Crossref","is-referenced-by-count":8,"title":["Privacy by Design in Practice: Reasoning about Privacy Properties of Biometric System Architectures"],"prefix":"10.1007","author":[{"given":"Julien","family":"Bringer","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Herv\u00e9","family":"Chabanne","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Daniel","family":"Le M\u00e9tayer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Roch","family":"Lescuyer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"key":"7_CR1","doi-asserted-by":"crossref","unstructured":"Abadi, M., Fournet, C.: Mobile values, new names, and secure communication. In: ACM Symposium on Principles of Programming Languages, POPL 2001, pp. 104\u2013115. ACM Press (2001)","DOI":"10.1145\/373243.360213"},{"key":"7_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1007\/978-3-319-11851-2_2","volume-title":"Security and Trust Management","author":"T. Antignac","year":"2014","unstructured":"Antignac, T., Le M\u00e9tayer, D.: Privacy architectures: Reasoning about data minimisation and integrity. In: Mauw, S., Jensen, C.D. (eds.) STM 2014. LNCS, vol.\u00a08743, pp. 17\u201332. Springer, Heidelberg (2014)"},{"key":"7_CR3","series-title":"IFIP AICT","doi-asserted-by":"publisher","first-page":"60","DOI":"10.1007\/978-3-319-18491-3_5","volume-title":"Trust Management IX","author":"T. Antignac","year":"2015","unstructured":"Antignac, T., Le M\u00e9tayer, D.: Trust driven strategies for privacy by design. In: Damsgaard Jensen, C., Marsh, S., Dimitrakos, T., Murayama, Y. (eds.) IFIPTM 2015. IFIP AICT, vol.\u00a0454, pp. 60\u201375. Springer, Heidelberg (2015)"},{"key":"7_CR4","doi-asserted-by":"crossref","unstructured":"Barth, A., Datta, A., Mitchell, J.C., Nissenbaum, H.: Privacy and contextual integrity: Framework and applications. In: IEEE Symposium on Security and Privacy, S&P 2006, pp. 184\u2013198. IEEE Computer Society (2006)","DOI":"10.1109\/SP.2006.32"},{"key":"7_CR5","unstructured":"Becker, M.Y., Malkis, A., Bussard, L.: S4P: A generic language for specifying privacy preferences and policies. Technical report, Microsoft Research \/ IMDEA Software \/ EMIC (2010)"},{"key":"7_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"190","DOI":"10.1007\/978-3-642-23822-2_11","volume-title":"Computer Security \u2013 ESORICS 2011","author":"M. Blanton","year":"2011","unstructured":"Blanton, M., Gasti, P.: Secure and efficient protocols for iris and fingerprint identification. In: Atluri, V., Diaz, C. (eds.) ESORICS 2011. LNCS, vol.\u00a06879, pp. 190\u2013209. Springer, Heidelberg (2011)"},{"key":"7_CR7","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1007\/978-3-540-73458-1_8","volume-title":"Information Security and Privacy","author":"J. Bringer","year":"2007","unstructured":"Bringer, J., Chabanne, H., Izabach\u00e8ne, M., Pointcheval, D., Tang, Q., Zimmer, S.: An application of the Goldwasser\u2013Micali cryptosystem to biometric authentication. In: Pieprzyk, J., Ghodosi, H., Dawson, E. (eds.) ACISP 2007. LNCS, vol.\u00a04586, pp. 96\u2013106. Springer, Heidelberg (2007)"},{"key":"7_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"289","DOI":"10.1007\/978-3-642-12980-3_18","volume-title":"Towards Trustworthy Elections","author":"S. Delaune","year":"2010","unstructured":"Delaune, S., Kremer, S., Ryan, M.: Verifying privacy-type properties of electronic voting protocols: A taster. In: Chaum, D., Jakobsson, M., Rivest, R.L., Ryan, P.Y.A., Benaloh, J., Kutylowski, M., Adida, B. (eds.) Towards Trustworthy Elections. LNCS, vol.\u00a06000, pp. 289\u2013309. Springer, Heidelberg (2010)"},{"key":"7_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"523","DOI":"10.1007\/978-3-540-24676-3_31","volume-title":"Advances in Cryptology - EUROCRYPT 2004","author":"Y. Dodis","year":"2004","unstructured":"Dodis, Y., Reyzin, L., Smith, A.: Fuzzy extractors: How to generate strong keys from biometrics and other noisy data. In: Cachin, C., Camenisch, J.L. (eds.) EUROCRYPT 2004. LNCS, vol.\u00a03027, pp. 523\u2013540. Springer, Heidelberg (2004)"},{"key":"7_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/11787006_1","volume-title":"Automata, Languages and Programming","author":"C. Dwork","year":"2006","unstructured":"Dwork, C.: Differential privacy. In: Bugliesi, M., Preneel, B., Sassone, V., Wegener, I. (eds.) ICALP 2006. LNCS, vol.\u00a04052, pp. 1\u201312. Springer, Heidelberg (2006)"},{"key":"7_CR11","unstructured":"European Parliament. European Parliament legislative resolution of 12 March 2014 on the proposal for a regulation of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data. General Data Protection Regulation, Ordinary legislative procedure: first reading (2014)"},{"key":"7_CR12","doi-asserted-by":"crossref","unstructured":"Fagin, R., Halpern, J., Moses, Y., Vardi, M.: Reasoning About Knowledge. MIT Press (2004)","DOI":"10.7551\/mitpress\/5803.001.0001"},{"key":"7_CR13","unstructured":"Fournet, C., Kohlweiss, M., Danezis, G., Luo, Z.: ZQL: A compiler for privacy-preserving data processing. In: USENIX 2013 Security Symposium, pp. 163\u2013178. USENIX Association (2013)"},{"key":"7_CR14","doi-asserted-by":"crossref","unstructured":"Gentry, C.: Fully homomorphic encryption using ideal lattices. In: ACM Symposium on Theory of Computing, STOC 2009, pp. 169\u2013178. ACM Press (2009)","DOI":"10.1145\/1536414.1536440"},{"key":"7_CR15","doi-asserted-by":"crossref","unstructured":"Govan, M., Buggy, T.: A computationally efficient fingerprint matching algorithm for implementation on smartcards. In: Biometrics: Theory, Applications, and Systems, BTAS 2007, pp. 1\u20136. IEEE Computer Society (2007)","DOI":"10.1109\/BTAS.2007.4401959"},{"key":"7_CR16","unstructured":"G\u00fcrses, S., Troncoso, C., D\u00edaz, C.: Engineering Privacy by Design. Presented at the Computers, Privacy & Data Protection Conference (2011)"},{"key":"7_CR17","doi-asserted-by":"crossref","unstructured":"Halpern, J.Y., Pucella, R.: Dealing with logical omniscience. In: Conference on Theoretical Aspects of Rationality and Knowledge, TARK 2007, pp. 169\u2013176 (2007)","DOI":"10.1145\/1324249.1324273"},{"key":"7_CR18","unstructured":"Huang, Y., Malka, L., Evans, D., Katz, J.: Efficient privacy\u2013preserving biometric identification. In: Network and Distributed System Security Symposium, NDSS 2011. The Internet Society (2011)"},{"issue":"1","key":"7_CR19","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1109\/TCSVT.2003.818349","volume":"14","author":"A.K. Jain","year":"2004","unstructured":"Jain, A.K., Ross, A., Prabhakar, S.: An introduction to biometric recognition. IEEE Trans. Circuits Syst. Video Techn.\u00a014(1), 4\u201320 (2004)","journal-title":"IEEE Trans. Circuits Syst. Video Techn."},{"issue":"2","key":"7_CR20","doi-asserted-by":"publisher","first-page":"237","DOI":"10.1007\/s10623-005-6343-z","volume":"38","author":"A. Juels","year":"2006","unstructured":"Juels, A., Sudan, M.: A fuzzy vault scheme. Des. Codes Cryptography\u00a038(2), 237\u2013257 (2006)","journal-title":"Des. Codes Cryptography"},{"issue":"1","key":"7_CR21","doi-asserted-by":"publisher","first-page":"123","DOI":"10.1002\/sec.626","volume":"7","author":"A. Kanak","year":"2014","unstructured":"Kanak, A., Sogukpinar, I.: BioPSTM: a formal model for privacy, security, and trust in template-protecting biometric authentication. Security and Communication Networks\u00a07(1), 123\u2013138 (2014)","journal-title":"Security and Communication Networks"},{"key":"7_CR22","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1007\/978-3-642-54069-1_3","volume-title":"Privacy Technologies and Policy","author":"F. Kerschbaum","year":"2014","unstructured":"Kerschbaum, F.: Privacy-preserving computation (position paper). In: Preneel, B., Ikonomou, D. (eds.) APF 2012. LNCS, vol.\u00a08319, pp. 41\u201354. Springer, Heidelberg (2014)"},{"issue":"1","key":"7_CR23","doi-asserted-by":"publisher","first-page":"122","DOI":"10.1109\/TIFS.2010.2098872","volume":"6","author":"L. Lai","year":"2011","unstructured":"Lai, L., Ho, S.-W., Poor, H.V.: Privacy-security trade-offs in biometric security systems \u2013 Part I: single use case. IEEE Transactions on Information Forensics and Security\u00a06(1), 122\u2013139 (2011)","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"1","key":"7_CR24","doi-asserted-by":"publisher","first-page":"140","DOI":"10.1109\/TIFS.2010.2098873","volume":"6","author":"L. Lai","year":"2011","unstructured":"Lai, L., Ho, S.-W., Poor, H.V.: Privacy-security trade-offs in biometric security systems \u2013 Part II: multiple use case. IEEE Transactions on Information Forensics and Security\u00a06(1), 140\u2013151 (2011)","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"7_CR25","doi-asserted-by":"crossref","unstructured":"Li, H., Pang, L.: A novel biometric\u2013based authentication scheme with privacy protection. In: Conference on Information Assurance and Security, IAS 2009, pp. 295\u2013298. IEEE Computer Society (2009)","DOI":"10.1109\/IAS.2009.304"},{"key":"7_CR26","doi-asserted-by":"crossref","unstructured":"Maffei, M., Pecina, K., Reinert, M.: Security and privacy by declarative design. In: IEEE Symposium on Computer Security Foundations, CSF 2013, pp. 81\u201396. IEEE Computer Society (2013)","DOI":"10.1109\/CSF.2013.13"},{"key":"7_CR27","doi-asserted-by":"crossref","unstructured":"McSherry, F.: Privacy integrated queries: an extensible platform for privacy-preserving data analysis. In: ACM Conference on Management of Data, SIGMOD 2009, pp. 19\u201330. ACM Press (2009)","DOI":"10.1145\/1559845.1559850"},{"key":"7_CR28","doi-asserted-by":"crossref","unstructured":"Le M\u00e9tayer, D.: Privacy by design: A formal framework for the analysis of architectural choices. In: ACM Conference on Data and Application Security and Privacy, CODASPY 2013, pp. 95\u2013104. ACM Press (2013)","DOI":"10.1145\/2435349.2435361"},{"key":"7_CR29","first-page":"989","volume":"14","author":"D.K. Mulligan","year":"2012","unstructured":"Mulligan, D.K., King, J.: Bridging the gap between privacy and design. University of Pennsylvania Journal of Constitutional Law\u00a014, 989\u20131034 (2012)","journal-title":"University of Pennsylvania Journal of Constitutional Law"},{"key":"7_CR30","unstructured":"National\u00a0Institute of\u00a0Standards and Technology (NIST). MINEXII \u2013 an assessment of Match\u2013On\u2013Card technology (2011), http:\/\/www.nist.gov\/itl\/iad\/ig\/minexii.cfm"},{"key":"7_CR31","unstructured":"International\u00a0Standard Organization. International standard iso\/iec 24787:2010, information technology \u2013 identification cards \u2013 on-card biometric comparison (2010)"},{"key":"7_CR32","doi-asserted-by":"crossref","unstructured":"Osadchy, M., Pinkas, B., Jarrous, A., Moskovich, B.: SCiFI \u2013 A system for secure face identification. In: IEEE Symposium on Security and Privacy, S&P 2010, pp. 239\u2013254. IEEE Computer Society (2010)","DOI":"10.1109\/SP.2010.39"},{"issue":"2","key":"7_CR33","doi-asserted-by":"publisher","first-page":"287","DOI":"10.1093\/logcom\/exi078","volume":"16","author":"R. Pucella","year":"2006","unstructured":"Pucella, R.: Deductive algorithmic knowledge. J. Log. Comput.\u00a016(2), 287\u2013309 (2006)","journal-title":"J. Log. Comput."},{"issue":"1","key":"7_CR34","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1109\/TSE.2008.88","volume":"35","author":"S. Spiekermann","year":"2009","unstructured":"Spiekermann, S., Cranor, L.F.: Engineering privacy. IEEE Trans. Software Eng.\u00a035(1), 67\u201382 (2009)","journal-title":"IEEE Trans. Software Eng."},{"key":"7_CR35","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"65","DOI":"10.1007\/978-3-319-17040-4_5","volume-title":"Foundations and Practice of Security","author":"V.-T. Ta","year":"2015","unstructured":"Ta, V.-T., Antignac, T.: Privacy by design: On the conformance between protocols and architectures. In: Cuppens, F., Garcia-Alfaro, J., Zincir Heywood, N., Fong, P.W.L. (eds.) FPS 2014. LNCS, vol.\u00a08930, pp. 65\u201381. Springer, Heidelberg (2015)"},{"key":"7_CR36","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"56","DOI":"10.1007\/978-3-540-79104-1_5","volume-title":"Information Security Practice and Experience","author":"Q. Tang","year":"2008","unstructured":"Tang, Q., Bringer, J., Chabanne, H., Pointcheval, D.: A formal study of the privacy concerns in biometric-based remote authentication schemes. In: Chen, L., Mu, Y., Susilo, W. (eds.) ISPEC 2008. LNCS, vol.\u00a04991, pp. 56\u201370. Springer, Heidelberg (2008)"},{"key":"7_CR37","doi-asserted-by":"crossref","unstructured":"Troncoso-Pastoriza, J.R., P\u00e9rez-Gonz\u00e1lez, F.: Fully homomorphic faces. In: International Conference on Image Processing, ICIP 2012, pp. 2657\u20132660. IEEE Computer Society (2012)","DOI":"10.1109\/ICIP.2012.6467445"},{"key":"7_CR38","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"310","DOI":"10.1007\/11527923_32","volume-title":"Audio- and Video-Based Biometric Person Authentication","author":"U. Uludag","year":"2005","unstructured":"Uludag, U., Pankanti, S., Jain, A.K.: Fuzzy vault for fingerprints. In: Kanade, T., Jain, A., Ratha, N.K. (eds.) AVBPA 2005. LNCS, vol.\u00a03546, pp. 310\u2013319. Springer, Heidelberg (2005)"}],"container-title":["Lecture Notes in Computer Science","FM 2015: Formal Methods"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-19249-9_7","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,28]],"date-time":"2025-05-28T02:43:09Z","timestamp":1748400189000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-319-19249-9_7"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015]]},"ISBN":["9783319192482","9783319192499"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-19249-9_7","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015]]}}}