Best Solutions for Biometrics and eid
In times of virtual communication even a person s identity is converted into an electronic form with the help of biometrics and then organised through intricate technical processes. But unique and distinct components defining our identity such as our fingerprints, for example are only suited for authenticating an individual if they are secured from manipulation. And if only those persons have access to these data who are verifiably authorised to. Securing a person s identity is, thus, of utmost importance. Why is secunet the perfect partner for your projects in biometrics and eid? Guaranteeing secure identities is a permanent and global challenge for every nation worldwide. The challenge becomes even greater the more government documents are extended by biometric features. It is the aim of the current use cases to provide highly secure ID-documents, to simplify border control and to support governmental applications and procedures. Further scenarios of use will be added. For these we must develop solutions today. To live up to the globalised approach of our society, international institutions, nationally responsible governments and globally active companies have been cooperating for many years in the field of electronic ID-documents. secunet is the IT-security partner of the German Federal government and has for years been working with the German Federal Office for Information Security closely and trustfully in questions of biometrics.
This makes us the perfect partner secunet knows the entire process chain of eids secunet has hands-on experience in reliably and professionally operating the complete life cycle of government documents. For every stage of the process we have developed innovative solution modules and acquired extensive know-how. Our integrative knowledge is a key advantage for our clients: secunet s biometrics experts know the effects their projects cause on all sides better than anyone else. This guarantees our clients a smooth integration into the overall process. secunet is a first mover secunet s biometrics experts have been actively representing especially the practical dimensions in every important committees of standardisation worldwide since their beginnings. We take an active part in the continuous development of standards, technical specifications and interoperability-tests for ID-documents and -systems. Thus, we can offer our clients unique and nonetheless proven state of the art solutions sooner than other companies. secunet is a flexible partner Working on a biometrics or eid-project at secunet s can mean that we will take over the prime contractorship for the implementation of biometric security solutions. But we are also the right partner for you when it comes to providing completed solution modules or developing individual software components. Major system integrators, for example, use secunet s software packets for their eid-solutions which will later be applied by public authorities. secunet has substantial experience Internationally acclaimed specialists have been part of our team for many years. This fact alone is sufficient to count secunet as a first-class provider of solutions in the field of eid, playing in the highest league. Accompanying the initial implementation of the electronic passports and the preparation of introducing biometric visas in Germany and other European states has further enhanced our expertise and once more confirmed our pioneering task. That the quality of our ideas and solutions is top-level worldwide is verified through our current projects abroad.
The best solution for your needs Return Application Usage (Border Control) Production Issuance The stages of the eid-life cycle secunet offers you solutions and know-how for the complete life cycle of passports, ID cards, electronic residence permits, and visas. We support public authorities as well as organisations in the private industrial sector and system integrators in their projects concerning biometrics and eid. secunet represents a maximum of innovation, experience, trustworthiness and vision. secunet develops and implements solutions to master the constantly advancing requirements for security in the long term and exactly meeting our clients needs. We create the best solution for every eid-project. Whenever possible, we implement existing solution components following a modular design-philosophy: the modules can be combined and scaled flexibly and are platform independent. In combination with the adjustment to and integration in the existing system environment, our modules become a custom-fit solution.
Application Before the first citizen has the possibility to apply for an electronic ID-document, the government has set the course for this step. From the applicant s point of view, the application for a government document is fairly simple: The applicant hands in his photo, two fingerprints and his signature. The processing of the application is incomparably more complex. For example, a number of different technologies are used, all of which have to be supported: the photo is digitised with a scanner, the fingerprints are collected with a fingerprint-sensor and the signature is captured by a signature-pad. If the quality of the biometric features is sufficiently good, the data are compressed and coded for the production-process later. Finally, the application-data can be transmitted to the producer of the eid-document via a secure connection. The backbone of our solution-package is secunet biomiddle. Capture Compression QA Coding Scanner Digital camera FP-Scanner Signature-PAD biomiddle/bioapi JPG2000 WSQ JPG QA Provider QA Provider ISO + DG DG Production The production process includes both optic and electronic personalisation. The security mechanisms of the PKI are also the basis of the production process so that nobody will be able to change the data unauthorised later. For its subsequent use for example, when travelling internationally the electronic ID-document must be interoperable worldwide. This means: it must comply with the effective standards. To ensure this, passport-producers and governmental authorities rely on secunet s eid test suite as a proven testing mechanism. Issuance It is the citizens right to see his data stored in the eid. Just as well, in some states there is an obligation to ensure that the eid is picked up by the rightful owner of the document. This is done by biometric authentication. For these application-scenarios, secunet developed software components that facilitate the optic, electronic and biometric processing of the respective data. secunet biomiddle facilitates the modular use of biometric system components and passport-readers within the different biometric and eid-applications. Both functions are provided via an integrative interface. This means maximum flexibility and investment protection. Internationally standardised interfaces allow for easy replacement of individual components in the highly dynamic market of biometric technologies. secunet biomiddle communicates with clientapplications via a service-oriented interface which makes the middleware independent from system platforms and programming languages. Integration cannot be simpler or faster. A joint development by secunet and the German Federal Office for Information Security, secunet biomiddle is considered as the preferred architecture and reference implementation for using biometrics in the field of government documents.
Usage (Border Control) An electronic ID-document can be applied in private and governmental fields. In practice, the utilisation for sovereign purposes has prevailed so far. In times of continuously increasing numbers of flight-passengers, eids and biometric supported border controls will noticeably optimize international travelling soon: passengers will have shorter waiting periods at the control stations, and airports and airlines can increase their passenger-processing. With secunet biomiddle, secunet offers a platform that can be used in equal measure for the optic, electronic and biometric control of documents at the borders. This essentially sets the stage for further automation of the border control. Optical Processing Electronic Processing Biometric Processing Capture Comparsion Background Check biomiddle/bioapi opassport API epassport API on request INPOL eid-pki-suite EAC, ICAO Document reader Digital camera FP-Scanner Return Every government document has a validity period. Before the expiration of this period and upon a new application, the invalid document can be exchanged for a new version or can be made void. The passport-issuing authorities offer their citizens a physically secure disposal of the expired eid. Secure Infrastructure and Data Security Secure identity starts with protecting electronic data just like traditional optic data from manipulation and unauthorised access. The technological basis for this is a public-key-infrastructure (PKI). For electronic ID-documents, generally two PKIs are needed to protect data. The requirements for authenticity and integrity are represented by security mechanisms of the ICAO-PKI. The confidentiality of communication and the access to the data are regulated by the EAC-PKI. secunet has developed software products from previous eid-projects which are ready-to-implement for your projects, too. These products range from PKIcomponents to an epassportapi regulating the secure communication between the applications and the eids. ICAO-PKI CRL ICAO-PKD National Directory CSCA DS X.509-Certificates Passive Authentication Trust Anchor CV-Certificates IS Terminal Authentication CVCA DVCA HSM PKI- Server EAC-PKI
References eid-lifecycle secunet biomiddle used in German Embassies... The German Federal Foreign Office uses secunet biomiddle for passport- and visa-applications in its 200 embassies worldwide. Including biometric features into these eid-documents, the embassies must now check the applicants photos for their biometric suitability and capture their fingerprints directly. This means that every mission abroad needs the respective systems. Thus, the solution must be fast, reliable, compatible to Linux and flexible. secunet biomiddle meets every single one of these requirements....and soon in Austrian Missions as well The Austrian Foreign Office has assigned secunet to furnish every Austrian Mission abroad with hard- and software for biometric collection-systems for EU-visa applications. secunet won the bidding process against international competition. The solution is secunet biomiddle which once more convinced through its modular set-up and its independence from platforms and systems. secunet provides both the applications for capturing the application-data and biometric features and the hardware for collecting fingerprints. secunet s evaluation laboratory ensures security of the epassport NXP is the leading provider of chip-solutions for electronic passports. When testing the conformity of their products with international requirements to electronic passports, NXP trusts the No.1: secunet s Evaluation laboratory for IT conformity was the first laboratory officially accredited by the German Federal Office for Information Security in Germany to test documents according to layers 6 and 7. Thus, NXP ensures that the data stored on their epassport chips are readable at all borders worldwide and that the mechanisms for dataprotection are correctly implemented on the chip. secunet supports the Czech Republic in introducing electronic passports In the Czech Republic, the State printing works of securities (STC) is responsible for the introduction and issuance of electronic passports. A team of secunet s international experts has been accompanying the STC since the first days of this project in 2005 and assumes extensive tasks in various fields. Among these are, for example, ensuring the conformity with the effective standards of ICAO, ISO and the German Federal Office for Information Security or taking responsibility for the optimized capturing of biometric data. The aim is to provide highest quality for Czech passports in international travelling. Biometric border control with the epassport secunet supports the German Federal Office for Information Security in a pilot-project for biometric-based border control processes. The passengers walk through automated biometric control-gates which are supervised by border police officers. The advantages are obvious: the waiting periods at the border control counters are shortened and more passengers can be processed. Border officials can focus on checking suspicious persons. The German Federal Office for Information Security assigned secunet to take over the planning, implementation and evaluation of this pilot scheme. secunet also provides the software platform secunet biomiddle. secunet supports the EU in testing biometric visas In its project BIODEV II, the European Union tests the use of biometric technologies for visas. Eight member states are involved in collecting experiences with capturing, authenticating, and transmitting biometric data. The project partners each use different hard- and software. As a result, it is a further aim to test the interoperability of the different IT-systems. The partners from Germany and Belgium decided to use secunet biomiddle. Thus, smooth integration into the existing systems is best ensured.
secunet Security Networks AG Kronprinzenstraße 30 45128 Essen Germany Phone: +49-201 - 54 54-0 Fax: +49-201 - 54 54-13 24 E-mail: info@secunet.com www.secunet.com