Janus: Safe Biometric Deduplication for Humanitarian Aid Distribution
Kasra EdalatNejad, Wouter Lueks, Justinas Sukaitis, Vincent Graf Narbel, Massimo Marelli, Carmela Troncoso
IEEE Symposium on Security and Privacy 2024 · Day 1 · Continental Ballroom 4
Overview
This talk introduces Janus, a novel privacy-preserving biometric deduplication system designed specifically for humanitarian aid distribution. Presented by Kasra EdalatNejad, this collaborative project between EPFL, the International Committee of the Red Cross (ICRC), and CISPA addresses the critical challenge of preventing individuals from registering multiple times to receive aid, a practice that strains limited resources and reduces the number of people who can be helped. Traditional methods like phone numbers or government IDs often fail in conflict zones or areas lacking infrastructure, making biometrics a highly universal alternative. However, the creation of a centralized biometric database for vulnerable populations poses significant privacy and security risks, which Janus aims to mitigate.

Key moments
- 0:00 Introduction: The humanitarian aid deduplication problem
- 2:50 Red Cross's core challenge: Biometrics vs. privacy risk
- 3:10 Key requirements for the Janus system design
- 5:15 Designing Janus: Introducing a distributed trust model
- 6:00 Janus workflow for biometric deduplication
- 8:10 Introducing three different Janus system instantiations
- 8:50 Homomorphic encryption: The core of Hybrid Janus
Janus: Safe Biometric Deduplication for Humanitarian Aid Distribution
Speakers: Kasra EdalatNejad, Wouter Lueks, Justinas Sukaitis, Vincent Graf Narbel, Massimo Marelli, Carmela Troncoso
Conference: IEEE S&P
YouTube: https://www.youtube.com/watch?v=F-EO29depM4
Overview
This talk introduces Janus, a novel privacy-preserving biometric deduplication system designed specifically for humanitarian aid distribution. Presented by Kasra EdalatNejad, this collaborative project between EPFL, the International Committee of the Red Cross (ICRC), and CISPA addresses the critical challenge of preventing individuals from registering multiple times to receive aid, a practice that strains limited resources and reduces the number of people who can be helped. Traditional methods like phone numbers or government IDs often fail in conflict zones or areas lacking infrastructure, making biometrics a highly universal alternative. However, the creation of a centralized biometric database for vulnerable populations poses significant privacy and security risks, which Janus aims to mitigate.
The core innovation of Janus lies in its ability to perform biometric deduplication without creating a single point of privacy failure or a sensitive database that could be compromised. By leveraging advanced cryptographic techniques such as homomorphic encryption (HE), secure multiparty computation (SMC), and trusted execution environments (TEEs), Janus ensures that no single entity can access raw biometric data or templates, nor can the system be repurposed for unauthorized identification or authentication. This work is crucial for humanitarian organizations, enabling them to allocate aid strategically and efficiently while upholding the privacy and safety of the people they serve, particularly in high-risk environments.
The project not only provides a robust technical solution but also deeply considers the unique ethical and practical requirements of humanitarian operations. It emphasizes a low failure rate, especially concerning false accept rates (FAR), which in this context means denying aid to an eligible recipient—a mistake with severe human cost. Janus represents a significant step forward in applying cutting-edge privacy-enhancing technologies to real-world, high-stakes scenarios, demonstrating that effective aid distribution and robust privacy protection can coexist.
Background
▶ Watch: Introduction: The humanitarian aid deduplication problem (0:00)
Humanitarian organizations, such as the International Committee of the Red Cross (ICRC), operate under immense pressure, often in conflict zones or areas with limited infrastructure. Their primary goal is to provide aid to people in need, but this mission is frequently hampered by the challenge of deduplication: ensuring that each eligible recipient receives their fair share of assistance without double registration. Limited resources and budgets necessitate strategic allocation, making accurate deduplication critical for maximizing the number of people helped.
Traditional methods for deduplication face significant hurdles in these contexts. Relying on phone numbers, similar to how consumer applications like WhatsApp or Facebook operate, is often impractical. In many regions where humanitarian aid is distributed, acquiring multiple SIM cards is trivial, undermining the uniqueness of phone numbers. Furthermore, a substantial portion of the target population, particularly in remote or impoverished areas, may not even possess mobile phones. Similarly, using government-issued IDs is frequently unfeasible. People fleeing conflict often prioritize their lives over safeguarding documents, and in some areas, a functioning government capable of issuing IDs may not exist. These limitations render conventional approaches ineffective or unreliable for the ICRC's operational scope.
Biometrics emerge as a highly universal and promising alternative. Most individuals retain their hands and faces, making fingerprints, irises, and facial recognition viable options for identification. The concept is straightforward: a registration station captures a biometric sample, stores it in a database, and subsequently uses it to check for prior registrations. However, this simplicity introduces a grave risk: the creation of a centralized database containing highly sensitive biometric information of vulnerable populations. Such a database would be an attractive target for adversaries, including state actors or armed groups, who could exploit it for surveillance, tracking, or persecution, putting both the aid recipients and the humanitarian organization at severe risk. The ICRC's concern stemmed from this precise dilemma: how to leverage the functionality of biometrics without incurring these profound safety costs.
To address this, the project meticulously investigated the requirements for a safe biometric deduplication system in humanitarian aid. These requirements can be categorized as follows:
- Functionality: The system must accurately compute a binary membership status (new user or duplicate) with a low failure rate. Crucially, it must minimize false accept rate (FAR) errors, where an eligible person is mistakenly identified as a duplicate and denied aid, as this carries a "very high human cost."
- Safety: The system must have a single functionality and purpose, meaning it should only reveal the binary membership status. It must prevent access to raw biometric material or templates and resist repurposing for general biometric authentication or identification. Protection against both passive and active compromises is paramount, ensuring no single actor can learn sensitive information beyond their authorized output. Adversaries should only be able to query membership status with the explicit collaboration of the organization itself.
- Scalability: The system needs to support up to 10,000 users, a scale common for many humanitarian operations.
This comprehensive set of requirements laid the groundwork for the design of Janus, aiming to deliver robust deduplication while prioritizing the privacy and safety of the world's most vulnerable.
Key Findings
▶ Watch: Key requirements for the Janus system design (3:10)
Janus presents several groundbreaking contributions to the field of privacy-preserving biometric systems, particularly within the challenging context of humanitarian aid. One of its most significant findings is the successful development of the first privacy-preserving deduplication system capable of achieving acceptable error rates at scales exceeding 10,000 users. This addresses a critical gap, as previous systems often struggled with the trade-off between privacy and the practical accuracy required for large-scale deployments.
The system's versatility is another key finding. Janus provides support for all three major biometric modalities: fingerprint, iris, and face recognition. This adaptability is crucial for humanitarian operations, where the availability and quality of biometric samples can vary widely depending on the environment and the individual. Furthermore, Janus incorporates biometric fusion, a technique that combines multiple biometric samples (e.g., four fingers, two irises, or a combination of modalities) from a single user. This fusion dramatically improves the system's accuracy, effectively reducing both false reject rates (FRR) (failing to detect a duplicate) and, more critically, false accept rates (FAR) (mistakenly denying aid to an eligible new recipient). The talk highlights that with fusion, acceptable error rates can be maintained even for databases of 10,000 users, where single samples would almost always lead to failure.
Janus offers three distinct instantiations, each leveraging different privacy-enhancing technologies to provide varied trade-offs in terms of security guarantees, performance, and deployment complexity:
- SMC (Secure Multiparty Computation): Relies on distributed computation where parties jointly compute a function without revealing their individual inputs.
- Hybrid Janus: Combines homomorphic encryption (HE) with secure multiparty computation (SMC) to optimize for specific operations.
- TEE (Trusted Execution Environments): Utilizes hardware-based isolation, such as Intel SGX enclaves, to protect sensitive computations.
The evaluation of the Hybrid Janus instantiation demonstrates its practical feasibility. For a database of 8,000 users, performing a membership query with four fused finger samples—a configuration yielding an acceptable error rate—requires approximately 4 seconds of computation and 150 megabytes of data transfer. These performance metrics are a significant improvement over prior academic work, making privacy-preserving deduplication viable for real-world humanitarian scenarios. In conclusion, Janus successfully reconciles the critical need for efficient aid distribution with the paramount importance of protecting the privacy and safety of vulnerable populations, setting a new benchmark for scalable, secure biometric systems.
Technical Deep Dive
▶ Watch: Designing Janus: Introducing a distributed trust model (5:15)
The technical architecture of Janus is built upon the principle of distributed trust, ensuring that no single party ever has access to all the information required to compromise privacy. This is achieved by dividing responsibilities between two main entities: the registration station and the biometric provider. The registration station is the point of interaction with aid recipients, responsible for taking biometric samples. The biometric provider, which the paper argues can be securely deployed in a Red Cross headquarter or delegation, acts as an independent, trusted computational entity. Both parties are assumed to be "honest but curious," meaning they follow the protocol but may attempt to infer additional information.
The general workflow for deduplication with Janus is as follows:
- A recipient requests registration at the registration station.
- The registration station takes a biometric sample and initiates a membership request to Janus.
- Janus, involving both the registration station and biometric provider, computes a binary membership status.
- This status is revealed only to a human operator at the registration station, who makes the final decision.
- If the decision is positive (new member), both components collaborate to add the member to the database.
- Crucially, all plaintext and raw biometric material are immediately deleted from the registration station.
To understand the underlying mechanisms, it's essential to grasp how biometrics are processed. Biometric sensors capture images (e.g., fingerprint scans, iris images). These images are then processed into templates, which are fixed-size arrays of integers. Due to the probabilistic nature of this process, repeated captures from the same individual will yield slightly different templates. Therefore, direct equality checks are insufficient. Instead, biometric matching involves computing a distance (e.g., Euclidean or Hamming distance) between two templates and comparing it against a predefined threshold to determine if they originate from the same user.
Janus offers three instantiations, but the talk focuses on the Hybrid Janus version, which combines homomorphic encryption (HE) with secure multiparty computation (SMC).
Homomorphic Encryption is a powerful cryptographic primitive that allows computations on encrypted data without decrypting it first. It begins with a key generation phase, producing a secret key and a public key. The interesting property is that arithmetic operations like addition and multiplication can be performed directly on encrypted values (denoted by double brackets [[.]]), with all operations and decryption occurring modulo a prime number Q.
The Hybrid Janus protocol proceeds through distinct phases:
- Setup Phase:
- The registration station initializes its sensor and creates an empty database for storing encrypted templates.
- The biometric provider generates a homomorphic encryption key pair and sends the public key material to the registration station.
- Add Member Procedure:
- When a new user is registered, the registration station takes a biometric sample.
- This sample is encrypted using the public HE key, and the resulting encrypted template is stored in the registration station's database.
- Membership Procedure (Deduplication): This is the core of the privacy-preserving deduplication process and involves three main steps:
- Encrypted Distance Computation: The registration station takes a new biometric sample from the user and loads all existing encrypted templates from its database. It then leverages the homomorphic properties of the encryption scheme to compute the distance between the new sample's encrypted template and every encrypted template in the database. For Euclidean distance, this involves computing the square of pairwise differences and summing them up, all while the data remains encrypted. This results in
Nencrypted distances, whereNis the number of users in the database. - Secret Sharing of Distances: Performing a direct comparison against a threshold using HE is computationally expensive, and sending the encrypted distances to the biometric provider for decryption would reveal sensitive information. To overcome this, the registration station employs secret sharing. For each encrypted distance
[[D_i]], it chooses a random valuer_ifromZ_Q(integers modulo Q) and computes[[D_i - r_i]]. It then decrypts this value to getD_i - r_iand sendsr_ito the biometric provider. Since HE operations are performed moduloQ, the originalD_iand theD_i - r_iandr_ivalues form arithmetic secret shares of the distanceD_imoduloQ. - Garbled Circuit for Comparison and Combination: The biometric provider, having received the
r_ivalues and theD_i - r_ivalues (from the registration station decrypting its share), can reconstruct the actual distancesD_i. It then uses a garbled circuit to compare eachD_iagainst the biometric matching threshold. This comparison determines a matching status for every template in the database. Finally, these individual matching statuses are combined (e.g., if any match is found, the user is a duplicate) to compute a single, database-wide binary membership status. This final binary status—and only this status—is revealed to the registration station.
This intricate dance of encryption, secret sharing, and secure computation ensures that the biometric provider never sees the raw biometric samples or templates, nor does it learn the individual distances. Similarly, the registration station only receives the final binary decision, without learning which specific template matched or the raw biometric data of existing users. This distributed trust model, combined with these advanced cryptographic primitives, effectively achieves the "single functionality and purpose" requirement, preventing any single point of privacy failure or repurposing of the system.
Demo / Proof of Concept
▶ Watch: Introducing three different Janus system instantiations (8:10)
While the talk did not feature a live, interactive demonstration, it provided a robust evaluation of the implemented Janus system, serving as a strong proof of concept for its practical viability. The researchers implemented all three proposed instantiations of Janus:
- The SMC-based operations were implemented in C++ using the EMP framework.
- The homomorphic encryption (HE) operations for Hybrid Janus were implemented in Go, leveraging the Latigo library.
- The trusted execution environment (TEE)-based instantiation utilized Fortanix for operations within an SGX enclave, written in Rust.
A critical aspect of the evaluation focused on the system's error rates, particularly in the context of biometric matching. The talk clarifies that the underlying biometric matching operations in Janus closely mirror plaintext biometrics, meaning their inherent error rates (e.g., false positive rates of 0.01% to 5% for sensors) are adopted. However, the true challenge arises in deduplication across a database of N users, as this involves N matching operations. A single false positive in any of these N operations could lead to a false accept rate (FAR) error, where a new eligible recipient is wrongly denied aid. The presentation graphically illustrates that for a database of 10,000 users, relying on a single biometric sample would "almost always fail" due to the cumulative probability of errors.
To overcome this, the evaluation rigorously tested the impact of biometric fusion. This technique combines multiple samples from a single individual (e.g., four fingers, two irises, or multimodal combinations) to significantly enhance accuracy. By fusing samples, the system can achieve an acceptable error rate even for large databases. For instance, the evaluation showed that using four fingers or two irises with common sensor error rates can maintain an acceptable error rate for 10,000 users. This finding is crucial, as it marks Janus as the "first privacy-preserving deduplication system that can achieve error rates that scales beyond 10,000 users." The researchers also noted that further reductions in error rates are as simple as adding more samples per user.
The performance evaluation of Hybrid Janus specifically highlighted its efficiency:
- For a database of 8,000 users with four fused finger samples (a configuration providing an acceptable error rate), a membership query required approximately 4 seconds of computation.
- The associated data transfer was around 150 megabytes.
These figures represent a significant improvement over prior academic work, demonstrating that Janus is not just theoretically sound but also practically implementable and performant enough for real-world humanitarian aid scenarios. The comprehensive implementation and detailed performance analysis serve as a compelling proof of concept for the feasibility and efficacy of privacy-preserving biometric deduplication at scale.
Defensive Implications
▶ Watch: Homomorphic encryption: The core of Hybrid Janus (8:50)
The Janus system offers profound defensive implications for humanitarian organizations, and more broadly, for any entity handling sensitive personal data, particularly biometrics. The core lesson is the critical need to prioritize privacy by design when implementing biometric systems, especially for vulnerable populations.
For humanitarian organizations like the ICRC, the immediate defensive actions include:
- Adopt Privacy-Preserving Biometric Systems: The most direct implication is to move away from traditional centralized biometric databases. Janus provides a robust blueprint for implementing deduplication without creating a "honeypot" of sensitive data susceptible to compromise. Organizations should actively seek out or develop systems that incorporate homomorphic encryption, secure multiparty computation, or trusted execution environments to protect biometric templates and raw data.
- Implement Distributed Trust Architectures: The two-party model of a registration station and a biometric provider is fundamental. Defenders should ensure that no single entity holds sufficient information to compromise the privacy of individuals or to repurpose the system for unauthorized identification. This architectural separation mitigates risks from both internal collusion and external attacks.
- Leverage Biometric Fusion for Accuracy and Safety: The talk strongly emphasizes that biometric fusion is not just an enhancement but a necessity for achieving acceptable error rates at scale. For humanitarian aid, minimizing false accept rates (FAR)—denying aid to an eligible person—is paramount due to the "high human cost." Organizations must design systems that allow for multiple biometric samples per individual (e.g., four fingers, two irises) to significantly reduce errors and ensure aid reaches those who genuinely need it.
- Enforce Single Functionality: A key requirement for Janus is that it provides only a binary membership status and cannot be repurposed. Organizations must ensure that any deployed biometric system is strictly limited to its intended function (e.g., deduplication) and cannot be used for broader identification, authentication, or surveillance. This requires careful system design, strong access controls, and regular audits.
- Conduct Rigorous Threat Modeling: The ICRC's initial concerns, such as adversaries gaining control over devices in conflict zones, highlight the importance of comprehensive threat modeling. Defenders must consider sophisticated adversaries who might attempt to compromise components, collude, or exploit system vulnerabilities. The Janus design, with its protection against passive and active compromises, offers a model for addressing such threats.
- Regularly Evaluate Performance and Error Rates: Organizations must continually monitor the false reject rate (FRR) and false accept rate (FAR) of their biometric systems. The trade-offs between different modalities and fusion levels need to be understood in the specific context of their operations to ensure both efficiency and ethical compliance.
More broadly, for cybersecurity practitioners, Janus serves as a powerful case study in the practical application of Privacy-Enhancing Technologies (PETs). It demonstrates that advanced cryptography is not merely an academic exercise but can provide concrete, scalable solutions to real-world privacy challenges involving highly sensitive data. The lessons learned from Janus can be applied to other domains where sensitive personal information (e.g., healthcare records, financial data) needs to be processed or cross-referenced without compromising individual privacy.
Key Takeaways
- Biometric deduplication is essential for efficient humanitarian aid distribution, but traditional methods and centralized biometric databases pose significant privacy and security risks to vulnerable populations.
- Janus is a pioneering privacy-preserving biometric deduplication system that addresses these risks by distributing trust and leveraging advanced cryptographic techniques like homomorphic encryption, secure multiparty computation, and trusted execution environments.
- The system ensures single functionality, preventing access to raw biometric data or templates and making it impossible to repurpose for unauthorized identification or authentication.
- Biometric fusion, combining multiple samples (e.g., four fingers or two irises), is critical for achieving acceptable error rates at scale (beyond 10,000 users), significantly reducing the "high human cost" of denying aid to eligible recipients.
- The Hybrid Janus instantiation demonstrates practical performance, capable of processing membership queries for 8,000 users with acceptable error rates in approximately 4 seconds of computation and 150 MB of data transfer, making it feasible for real-world deployment.
- Janus offers a robust framework for humanitarian organizations to allocate aid strategically while upholding the paramount importance of protecting the privacy and safety of the individuals they serve.
About the Speaker(s)
The research presented in "Janus: Safe Biometric Deduplication for Humanitarian Aid Distribution" is a collaborative effort involving several distinguished researchers and institutions. The talk was delivered by Kasra EdalatNejad, who is affiliated with EPFL, the International Committee of the Red Cross (ICRC), and CISPA.
The co-authors of this significant work include Wouter Lueks, Justinas Sukaitis, Vincent Graf Narbel, Massimo Marelli, and Carmela Troncoso. Their collective expertise from EPFL, the ICRC, and CISPA underscores the interdisciplinary nature of this project, blending cutting-edge cryptography and security research with the practical and ethical considerations of humanitarian aid operations. This collaboration was crucial in identifying the unique requirements and developing a robust, privacy-preserving solution that addresses real-world challenges faced by organizations like the Red Cross.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
Janus presents a groundbreaking privacy-preserving biometric deduplication system for humanitarian aid, tackling the critical dilemma of efficient resource allocation versus protecting vulnerable populations. By ingeniously combining homomorphic encryption, SMC, and TEEs with biometric fusion, it achieves unprecedented scale and accuracy while ensuring no single entity can compromise sensitive data. This is real-world impact driven by sophisticated engineering.
Heather Calloway (CISO) — MUST SEE
This talk presents a critical breakthrough in deploying biometrics safely and ethically for humanitarian aid. Janus demonstrates how advanced privacy-enhancing technologies, coupled with distributed trust and biometric fusion, can address a profound governance and operational challenge without creating catastrophic risk for vulnerable populations. Every CISO contemplating biometric systems, especially in high-stakes environments, needs to understand this model.
→ Top-rated talks at IEEE Symposium on Security and Privacy 2024