Best Solutions for Biometrics and eid



Similar documents
Electronic machine-readable travel documents (emrtds) The importance of digital certificates

Modular biometric architecture with secunet biomiddle

ID Security Made in Germany Holistic Solutions for Biometric Systems and Identity Documents

SECURE IDENTITY MANAGEMENT. Globally recognised identity management expertise

Biometrics for Public Sector Applications

Preventing fraud in epassports and eids

Statewatch Briefing ID Cards in the EU: Current state of play

FAQs Electronic residence permit

Operational and Technical security of Electronic Passports

Biometrics for public sector applications

successstory Security for Diplomacy High Security for Embassy Networks

End-to-end security with advanced biometrics technology

End-to-end security with advanced biometrics technology

COMMON CERTIFICATE POLICY FOR THE EXTENDED ACCESS CONTROL INFRASTRUCTURE FOR PASSPORTS AND TRAVEL DOCUMENTS ISSUED BY EU MEMBER STATES

Company Overview. Iraq: Activities & Experience

Combatting Counterfeit Identities: The Power of Pairing Physical & Digital IDs

FIVE-MINUTES-TO-CONTRACT The DESKO over-all concept for digital contract management and ID verification.

SOLUTIONS FOR HEALTHCARE PROFESSIONALS AND GOVERNMENTS

Technical Guideline eid-server. Part 2: Security Framework

Case Studies. National Identity Management Commission (NIMC), Nigeria eid Consulting for national ID system

Intelligent Solutions for the Highest IT Security Demands

Conformance test specification for BSI-TR Biometrics for public sector applications

ON IDENTITY CARDS. Based on Article 65 (1) of the Constitution of the Republic of Kosovo, LAW ON IDENTITY CARDS CHAPTER I GENERAL PROVISIONS

PRIME IDENTITY MANAGEMENT CORE

D . A reliable and secure online communication platform. Armin Wappenschmidt (secunet) More information:

Implementation of biometrics, issues to be solved

Global eid Developments. Detlef Eckert Chief Security Advisor Microsoft Europe, Middle East, and Africa

Public Key Directory: What is the PKD and How to Make Best Use of It

Establishing and Managing the Schengen Masterlist of CSCAs

Smart Card- An Alternative to Password Authentication By Ahmad Ismadi Yazid B. Sukaimi

Transaction Security. Advisory Services

BALI MINISTERIAL CONFERENCE AD HOC EXPERTS' GROUP II REGIONAL WORKSHOP IDENTITY MANAGEMENT: CHALLENGES AND OPPORTUNITIES FOR COOPERATION

PKD Board ICAO PKD unclassified B-Tec/37. Procedures for the ICAO Public Key Directory

FAQs - New German ID Card. General

EMV-TT. Now available on Android. White Paper by

MOBILE IDENTIFICATION:

THE LEADING EDGE OF BORDER SECURITY

Full page passport/document reader Regula model 70X4M

Landscape of eid in Europe in 2013

Discover Germany s Electronic Passport

Complete. security. begins with 3M

Sub- Regional Workshop and Consulta;ons on Capacity- Building in Travel Document Security: Colombia, 2013

Facts about the new identity card

Introduction ICAO PKD

Proposed Framework for an Interoperable Electronic Identity Management System

DilRoom. Improving, accelerating and simplifying the sharing of sensitive information.

MegaMatcher Case Study

Mobile Driver s License Solution

European Electronic Identity Practices

How To Get Smart Cards From Atos

BoardNox. Secure file sharing solution for Executive Committees and Boards of Directors.

Intelligent Solutions for the Highest IT Security Requirements

PKD Board ICAO PKD unclassified B-Tec/36. Regulations for the ICAO Public Key Directory

Coesys Border Management

complexity data room is unique.

Border control using biometrics in Japan. September 2008 NEC Corporation/Daon

POSITION PAPER. The Application of Biometrics at Airports PUBLISHED BY ACI WORLD HEADQUARTERS GENEVA SWITZERLAND

Meeting the FDA s Requirements for Electronic Records and Electronic Signatures (21 CFR Part 11)

Kaba EACM The SAP module for efficient access organisation

Fighting product clones through digital signatures

OFTP 2 Secure Data Exchange Via the Internet

full ID MANAGEMENT

An introduction to EJBCA and SignServer

Security by Politics - Why it will never work. Lukas Grunwald DN-Systems GmbH Germany DefCon 15 Las Vegas USA

White Paper PalmSecure truedentity

eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke

esign FAQ 1. What is the online esign Electronic Signature Service? 2. Where the esign Online Electronic Signature Service can be used?

Common Criteria Protection Profile for Inspection Systems (IS) BSI-CC-PP Version 1.01 (15 th April 2010)

Information about the European Union is available on the Internet. It can be accessed through the Europa server (

SSLPost Electronic Document Signing

RF-Enabled Applications and Technology: Comparing and Contrasting RFID and RF-Enabled Smart Cards

W.A.R.N. Passive Biometric ID Card Solution

2. Is registration with PARAFES free? Yes.

GOALS (2) The goal of this training module is to increase your awareness of HSPD-12 and the corresponding technical standard FIPS 201.

TELSTRA RSS CA Subscriber Agreement (SA)

The Impact of 21 CFR Part 11 on Product Development

Secure egovernment Where convenience meets security.

Pretty Good Privacy (PGP)

START-UP. services DATACARD SM GLOBAL SERVICES. Prepare to streamline installation and optimize results

Control scanning, printing and copying effectively with uniflow Version 5. you can

- BIOMETRIC. Tel : Website : marketing@litestar.com.sg

SOFTWARE. CONSULTING. SOLUTIONS. Smart IT Solutions

2. Each server or domain controller requires its own server certificate, DoD Root Certificates and enterprise validator installed.

Contactless Smart Cards vs. EPC Gen 2 RFID Tags: Frequently Asked Questions. July, Developed by: Smart Card Alliance Identity Council

NOAA HSPD-12 PIV-II Implementation October 23, Who is responsible for implementation of HSPD-12 PIV-II?

OB10 - Digital Signing and Verification

Applying for a Passport

Oberthur Technologies. A Technology Leader

All you need to know about the electronic residence permit (eat)

CASE STUDY 3 Canada Border Services Agency (CBSA) Aéroport de Montréal Vancouver International Airport

Synergy between Registered Traveler Programs and Visa-Processing for frequent travelers

Advanced Authentication

Technical Description. DigitalSign 3.1. State of the art legally valid electronic signature. The best, most secure and complete software for

Transcription:

Best Solutions for Biometrics and eid

In times of virtual communication even a person s identity is converted into an electronic form with the help of biometrics and then organised through intricate technical processes. But unique and distinct components defining our identity such as our fingerprints, for example are only suited for authenticating an individual if they are secured from manipulation. And if only those persons have access to these data who are verifiably authorised to. Securing a person s identity is, thus, of utmost importance. Why is secunet the perfect partner for your projects in biometrics and eid? Guaranteeing secure identities is a permanent and global challenge for every nation worldwide. The challenge becomes even greater the more government documents are extended by biometric features. It is the aim of the current use cases to provide highly secure ID-documents, to simplify border control and to support governmental applications and procedures. Further scenarios of use will be added. For these we must develop solutions today. To live up to the globalised approach of our society, international institutions, nationally responsible governments and globally active companies have been cooperating for many years in the field of electronic ID-documents. secunet is the IT-security partner of the German Federal government and has for years been working with the German Federal Office for Information Security closely and trustfully in questions of biometrics.

This makes us the perfect partner secunet knows the entire process chain of eids secunet has hands-on experience in reliably and professionally operating the complete life cycle of government documents. For every stage of the process we have developed innovative solution modules and acquired extensive know-how. Our integrative knowledge is a key advantage for our clients: secunet s biometrics experts know the effects their projects cause on all sides better than anyone else. This guarantees our clients a smooth integration into the overall process. secunet is a first mover secunet s biometrics experts have been actively representing especially the practical dimensions in every important committees of standardisation worldwide since their beginnings. We take an active part in the continuous development of standards, technical specifications and interoperability-tests for ID-documents and -systems. Thus, we can offer our clients unique and nonetheless proven state of the art solutions sooner than other companies. secunet is a flexible partner Working on a biometrics or eid-project at secunet s can mean that we will take over the prime contractorship for the implementation of biometric security solutions. But we are also the right partner for you when it comes to providing completed solution modules or developing individual software components. Major system integrators, for example, use secunet s software packets for their eid-solutions which will later be applied by public authorities. secunet has substantial experience Internationally acclaimed specialists have been part of our team for many years. This fact alone is sufficient to count secunet as a first-class provider of solutions in the field of eid, playing in the highest league. Accompanying the initial implementation of the electronic passports and the preparation of introducing biometric visas in Germany and other European states has further enhanced our expertise and once more confirmed our pioneering task. That the quality of our ideas and solutions is top-level worldwide is verified through our current projects abroad.

The best solution for your needs Return Application Usage (Border Control) Production Issuance The stages of the eid-life cycle secunet offers you solutions and know-how for the complete life cycle of passports, ID cards, electronic residence permits, and visas. We support public authorities as well as organisations in the private industrial sector and system integrators in their projects concerning biometrics and eid. secunet represents a maximum of innovation, experience, trustworthiness and vision. secunet develops and implements solutions to master the constantly advancing requirements for security in the long term and exactly meeting our clients needs. We create the best solution for every eid-project. Whenever possible, we implement existing solution components following a modular design-philosophy: the modules can be combined and scaled flexibly and are platform independent. In combination with the adjustment to and integration in the existing system environment, our modules become a custom-fit solution.

Application Before the first citizen has the possibility to apply for an electronic ID-document, the government has set the course for this step. From the applicant s point of view, the application for a government document is fairly simple: The applicant hands in his photo, two fingerprints and his signature. The processing of the application is incomparably more complex. For example, a number of different technologies are used, all of which have to be supported: the photo is digitised with a scanner, the fingerprints are collected with a fingerprint-sensor and the signature is captured by a signature-pad. If the quality of the biometric features is sufficiently good, the data are compressed and coded for the production-process later. Finally, the application-data can be transmitted to the producer of the eid-document via a secure connection. The backbone of our solution-package is secunet biomiddle. Capture Compression QA Coding Scanner Digital camera FP-Scanner Signature-PAD biomiddle/bioapi JPG2000 WSQ JPG QA Provider QA Provider ISO + DG DG Production The production process includes both optic and electronic personalisation. The security mechanisms of the PKI are also the basis of the production process so that nobody will be able to change the data unauthorised later. For its subsequent use for example, when travelling internationally the electronic ID-document must be interoperable worldwide. This means: it must comply with the effective standards. To ensure this, passport-producers and governmental authorities rely on secunet s eid test suite as a proven testing mechanism. Issuance It is the citizens right to see his data stored in the eid. Just as well, in some states there is an obligation to ensure that the eid is picked up by the rightful owner of the document. This is done by biometric authentication. For these application-scenarios, secunet developed software components that facilitate the optic, electronic and biometric processing of the respective data. secunet biomiddle facilitates the modular use of biometric system components and passport-readers within the different biometric and eid-applications. Both functions are provided via an integrative interface. This means maximum flexibility and investment protection. Internationally standardised interfaces allow for easy replacement of individual components in the highly dynamic market of biometric technologies. secunet biomiddle communicates with clientapplications via a service-oriented interface which makes the middleware independent from system platforms and programming languages. Integration cannot be simpler or faster. A joint development by secunet and the German Federal Office for Information Security, secunet biomiddle is considered as the preferred architecture and reference implementation for using biometrics in the field of government documents.

Usage (Border Control) An electronic ID-document can be applied in private and governmental fields. In practice, the utilisation for sovereign purposes has prevailed so far. In times of continuously increasing numbers of flight-passengers, eids and biometric supported border controls will noticeably optimize international travelling soon: passengers will have shorter waiting periods at the control stations, and airports and airlines can increase their passenger-processing. With secunet biomiddle, secunet offers a platform that can be used in equal measure for the optic, electronic and biometric control of documents at the borders. This essentially sets the stage for further automation of the border control. Optical Processing Electronic Processing Biometric Processing Capture Comparsion Background Check biomiddle/bioapi opassport API epassport API on request INPOL eid-pki-suite EAC, ICAO Document reader Digital camera FP-Scanner Return Every government document has a validity period. Before the expiration of this period and upon a new application, the invalid document can be exchanged for a new version or can be made void. The passport-issuing authorities offer their citizens a physically secure disposal of the expired eid. Secure Infrastructure and Data Security Secure identity starts with protecting electronic data just like traditional optic data from manipulation and unauthorised access. The technological basis for this is a public-key-infrastructure (PKI). For electronic ID-documents, generally two PKIs are needed to protect data. The requirements for authenticity and integrity are represented by security mechanisms of the ICAO-PKI. The confidentiality of communication and the access to the data are regulated by the EAC-PKI. secunet has developed software products from previous eid-projects which are ready-to-implement for your projects, too. These products range from PKIcomponents to an epassportapi regulating the secure communication between the applications and the eids. ICAO-PKI CRL ICAO-PKD National Directory CSCA DS X.509-Certificates Passive Authentication Trust Anchor CV-Certificates IS Terminal Authentication CVCA DVCA HSM PKI- Server EAC-PKI

References eid-lifecycle secunet biomiddle used in German Embassies... The German Federal Foreign Office uses secunet biomiddle for passport- and visa-applications in its 200 embassies worldwide. Including biometric features into these eid-documents, the embassies must now check the applicants photos for their biometric suitability and capture their fingerprints directly. This means that every mission abroad needs the respective systems. Thus, the solution must be fast, reliable, compatible to Linux and flexible. secunet biomiddle meets every single one of these requirements....and soon in Austrian Missions as well The Austrian Foreign Office has assigned secunet to furnish every Austrian Mission abroad with hard- and software for biometric collection-systems for EU-visa applications. secunet won the bidding process against international competition. The solution is secunet biomiddle which once more convinced through its modular set-up and its independence from platforms and systems. secunet provides both the applications for capturing the application-data and biometric features and the hardware for collecting fingerprints. secunet s evaluation laboratory ensures security of the epassport NXP is the leading provider of chip-solutions for electronic passports. When testing the conformity of their products with international requirements to electronic passports, NXP trusts the No.1: secunet s Evaluation laboratory for IT conformity was the first laboratory officially accredited by the German Federal Office for Information Security in Germany to test documents according to layers 6 and 7. Thus, NXP ensures that the data stored on their epassport chips are readable at all borders worldwide and that the mechanisms for dataprotection are correctly implemented on the chip. secunet supports the Czech Republic in introducing electronic passports In the Czech Republic, the State printing works of securities (STC) is responsible for the introduction and issuance of electronic passports. A team of secunet s international experts has been accompanying the STC since the first days of this project in 2005 and assumes extensive tasks in various fields. Among these are, for example, ensuring the conformity with the effective standards of ICAO, ISO and the German Federal Office for Information Security or taking responsibility for the optimized capturing of biometric data. The aim is to provide highest quality for Czech passports in international travelling. Biometric border control with the epassport secunet supports the German Federal Office for Information Security in a pilot-project for biometric-based border control processes. The passengers walk through automated biometric control-gates which are supervised by border police officers. The advantages are obvious: the waiting periods at the border control counters are shortened and more passengers can be processed. Border officials can focus on checking suspicious persons. The German Federal Office for Information Security assigned secunet to take over the planning, implementation and evaluation of this pilot scheme. secunet also provides the software platform secunet biomiddle. secunet supports the EU in testing biometric visas In its project BIODEV II, the European Union tests the use of biometric technologies for visas. Eight member states are involved in collecting experiences with capturing, authenticating, and transmitting biometric data. The project partners each use different hard- and software. As a result, it is a further aim to test the interoperability of the different IT-systems. The partners from Germany and Belgium decided to use secunet biomiddle. Thus, smooth integration into the existing systems is best ensured.

secunet Security Networks AG Kronprinzenstraße 30 45128 Essen Germany Phone: +49-201 - 54 54-0 Fax: +49-201 - 54 54-13 24 E-mail: info@secunet.com www.secunet.com