Overview of National and International Biometric Standards Activities

Overview of National and International Biometric Standards Activities Overview of National and International Biometric Standards Activities

biometrics.nist.gov
from biometrics.nist.gov More from this publisher
11.07.2015 Views

Overview ofNational and International BiometricStandards ActivitiesFernando PodioProgram Manager,NIST Biometric Standards ProgramComputer Security DivisionNIST/ITL1 (301) 975 - 2947fernando.podio@nist.govANSI/NIST ITL 1 2000 UpdateWorkshop, April 26 28, 20051

<strong>Overview</strong> <strong>of</strong><strong>National</strong> <strong>and</strong> <strong>International</strong> <strong>Biometric</strong>St<strong>and</strong>ards <strong>Activities</strong>Fern<strong>and</strong>o PodioProgram Manager,NIST <strong>Biometric</strong> St<strong>and</strong>ards ProgramComputer Security DivisionNIST/ITL1 (301) 975 - 2947fern<strong>and</strong>o.podio@nist.govANSI/NIST ITL 1 2000 UpdateWorkshop, April 26 28, 20051


<strong>Overview</strong>• <strong>National</strong> <strong>and</strong> <strong>International</strong> St<strong>and</strong>ardsOrganizations• Status <strong>of</strong> the INCITS M1 <strong>and</strong> JTC 1 SC 37<strong>Biometric</strong> St<strong>and</strong>ards Programs• Market Adoption Examples2


<strong>Biometric</strong>s St<strong>and</strong>ards <strong>Activities</strong> – Who is Doing What?<strong>International</strong>ISOIECICAOITU-TTC 68Banking,Securities <strong>and</strong>Other FinancialServicesISO/IEC JTC 1Information TechnologyNIST/BC<strong>Biometric</strong> WGBioAPIConsortiumSC 17Cards &PersonalIdentificationSC 27IT SecurityTechniquesSC 37<strong>Biometric</strong>sOASISOpen Group<strong>National</strong>ANSINIST/ITLX9(US TAG ISO TC 68)INCITSINCITS M1 isthe TAG toJTC 1 SC 37(ANSI/NIST ITL-1-2000)X9FData &InformationSecurityB10IdentificationCards & RelatedDevicesM1<strong>Biometric</strong>sT4SecurityTechniques


M1 <strong>Biometric</strong>s (US)• INCITS is the major st<strong>and</strong>ards organization in the USresponsible for the development <strong>of</strong> Information <strong>and</strong>Communication Technology (ICT) st<strong>and</strong>ards.• M1 is the INCITS committee for biometrics, establishedNovember 2001.• M1 represents the US in biometric international st<strong>and</strong>ardsdevelopment through Subcommittee 37 <strong>of</strong> Joint TechnicalCommittee 1 (JTC1).4


INCITS M1 St<strong>and</strong>ardsApproved DataInterchangeFormatsINCITS 377*Finger Pattern-BasedInterchange FormatINCITS 378*Finger Minutiae FormatFor Data InterchangeINCITS 379Iris Recognition Formatfor Data InterchangeINCITS 381Finger Image Formatfor Data InterchangeINCITS 385*Face Recognition Formatfor Data InterchangeConformance TestingMethodologies for theData InterchangeFormats (UnderDevelopment)Generalized TestingMethodology - Part 1Conformance TestingMethodology for INCITS 377Conformance TestingMethodology for INCITS 378Conformance TestingMethodology for INCITS 379Conformance TestingMethodology for INCITS 381Conformance TestingMethodology for INCITS 385Other DataInterchangeFormats <strong>and</strong>Related St<strong>and</strong>ards(UnderDevelopment)INCITS 395Signature/Sign DataINCITS 396H<strong>and</strong> Geometry InterchangeFormat<strong>Biometric</strong> Sample Quality(*) Currently amendments to these three st<strong>and</strong>ards areunder development5


INCITS M1 St<strong>and</strong>ardsApproved <strong>Biometric</strong>Application Pr<strong>of</strong>ilesINCITS 383Verification & Identification<strong>of</strong> Transportation WorkersINCITS 394<strong>Biometric</strong>-Based PersonalIdentification for BorderManagementOther <strong>Biometric</strong>Application Pr<strong>of</strong>iles(UnderDevelopment)Point <strong>of</strong> Sale <strong>Biometric</strong>IdentificationDoD ImplementationsCommercial <strong>Biometric</strong>Physical Access ControlPerformance Testing& ReportingSt<strong>and</strong>ards (UnderDevelopment)Part 1 – FrameworkPart 2 – Technology Testing<strong>and</strong> ReportingPart 3 – Scenario Testing<strong>and</strong> ReportingPart 4 – Operational Testing<strong>and</strong> ReportingPart 5 – Framework for<strong>Biometric</strong> DevicePerformance Evaluation forAccess ControlApproved InterfaceSt<strong>and</strong>ardsINCITS 358BioAPI Specification V1.1INCITS 398Common <strong>Biometric</strong> ExchangeFormats Framework (CBEFF)– NISTIR 6529-AConformance TestingMethodology (UnderDevelopment)Conformance TestingMethodology for INCITS 358(BioAPI Specification V1.1)6


The Role <strong>of</strong> St<strong>and</strong>ards in<strong>Biometric</strong> Interoperability & Data InterchangeApplication (Conforming to <strong>Biometric</strong> Application Pr<strong>of</strong>ile St<strong>and</strong>ards)Framework Conforming to the BioAPI St<strong>and</strong>ard<strong>Biometric</strong>Data StructureConforming to INCITS 398(NISTIR 6529-A)St<strong>and</strong>ardized biometricdata is embedded in theCBEFF structure<strong>Biometric</strong>ServiceProvider<strong>Biometric</strong>Device<strong>Biometric</strong>ServiceProvider<strong>Biometric</strong>Device<strong>Biometric</strong>ServiceProvider<strong>Biometric</strong>DeviceSt<strong>and</strong>ard Data DataInterchange Formats7


SC 37 - <strong>Biometric</strong>s• Responsible for the st<strong>and</strong>ardization <strong>of</strong> generic biometrictechnologies pertaining to human beings to supportinteroperability <strong>and</strong> data interchange among applications<strong>and</strong> systems.• Since SC 37 was established, it has maintained anaccelerated pace <strong>of</strong> biometric st<strong>and</strong>ards development(meetings approximately every 6 months)• Dem<strong>and</strong>ing schedule for technical editors, other <strong>of</strong>ficers,experts, national bodies <strong>and</strong> liaison organizations.• 21 Member countries – 6 Observers – 11 LiaisonOrganizations8


SC 37 - <strong>Biometric</strong>sISO/IEC JTC 1/SC 37 - <strong>Biometric</strong>sChair: Mr. Fern<strong>and</strong>o PodioSC 37 SecretariatANSIMs. Lisa RajchelWorking Group 1Harmonized <strong>Biometric</strong>VocabularyConvener:Ms. Rene McIverWorking Group 4<strong>Biometric</strong> FunctionalArchitecture <strong>and</strong>Related Pr<strong>of</strong>ilesConvener:Mr. Mike HoganWorking Group 2<strong>Biometric</strong> TechnicalInterfacesConvener:Dr. Young-Bin KwonWorking Group 5<strong>Biometric</strong> Testing <strong>and</strong>ReportingConvener:Mr. Bob CarterWorking Group 3<strong>Biometric</strong> DataInterchange FormatsConvener:Dr. Axel MundeWorking Group 6Cross-Jurisdictional<strong>and</strong> Societal AspectsConvener:Dr. Mario Savastano9


<strong>International</strong> St<strong>and</strong>ardDevelopment Stages<strong>International</strong> St<strong>and</strong>ardISFinal Draft<strong>International</strong> St<strong>and</strong>ardFDISFinal Committee DraftFCDCommittee DraftCDWorking DraftWDNew Work ItemProposalNP10


SC 37 - <strong>Biometric</strong>sISO FDIS 19794<strong>Biometric</strong> Data InterchangeFormat - Part 2, FingerMinutiae DataISO FDIS 19794<strong>Biometric</strong> Data InterchangeFormat - Part 4, FingerImage DataISO FDIS 19794<strong>Biometric</strong> Data InterchangeFormat - Part 5, Face ImageDataISO FDIS 19794<strong>Biometric</strong> Data InterchangeFormat - Part 6, Iris ImageDataFinal Draft<strong>International</strong> St<strong>and</strong>ardC<strong>and</strong>idates CD 24709-1Final Draft<strong>International</strong>St<strong>and</strong>ards Status FCD 19785Common <strong>Biometric</strong> ExchangeFormats Framework - Part 1,Data Element SpecificationFCD 19784BioAPI Specification – Part 1Final Committee DraftsFCD 19794-1<strong>Biometric</strong> Data InterchangeFormat – Part 1, FrameworkFCD 19794-3<strong>Biometric</strong> Data InterchangeFormat – Part 3, FingerPattern Spectral DataFCD 19795-1Performance Testing &Reporting – Principles <strong>and</strong>FrameworkCommittee DraftsBioAPI Conformance Testing– Part 1 – Methods &ProceduresCD 19794-7<strong>Biometric</strong> Data InterchangeFormat - Part 7,Signature/Sign Time SeriesCD 19794-8<strong>Biometric</strong> Data InterchangeFormat - Part 8, FingerPattern Skeletal DataCD 24713-1<strong>Biometric</strong> Pr<strong>of</strong>iles – Part 1,<strong>Biometric</strong> ReferenceArchitecture2 nd CD 24713-2<strong>Biometric</strong> Pr<strong>of</strong>iles – Part 2,<strong>Biometric</strong>-Based Verification& Identification <strong>of</strong> Employeesin a Token Based HighlySecure Environment11


SC 37 - <strong>Biometric</strong>sCommittee Drafts (Cont.)Working Drafts & Other DocumentsCD 19795-2<strong>Biometric</strong> PerformanceTesting & Reporting – Part 2,Testing MethodologiesCD 19795-4<strong>Biometric</strong> PerformanceTesting & Reporting – Part 4,Performance &Interoperability Testing <strong>of</strong>Interchange FormatsNew Projects• BioAPI “Lite”• Guidelines for DigitalCapture <strong>of</strong> Face Image Data• <strong>Biometric</strong> PerformanceTesting & Reporting – Part 5,Framework for <strong>Biometric</strong>Device PerformanceEvaluation for Access ControlWD 24709-2 ,BioAPI Conformance Testing, Part 2 – TestAssertionsWD2 19785-2, BioAPI, Part 2 – <strong>Biometric</strong> Archive FunctionProvider InterfaceWD 19785-3, CBEFF Part 3: Patron Format SpecificationsWD2 24722, Technical Report on Multi-Modal <strong>Biometric</strong> FusionWD3 24708, <strong>Biometric</strong> Interworking Protocol (BIP)WD 19794-9, <strong>Biometric</strong> Data Interchange Format – Part 9,Vascular Image DataWD 19794-10, <strong>Biometric</strong> Data Interchange Format – Part 10,H<strong>and</strong> Geometry Silhouette DataWD 19794-11, <strong>Biometric</strong> Data Interchange Format – Part 11,Signature/Sign Processed Dynamic Data2nd WD 24714, Technical Report on Cross Jurisdictional <strong>and</strong>Societal Aspects <strong>of</strong> Implementations <strong>of</strong> <strong>Biometric</strong> TechnologiesSD 2 - St<strong>and</strong>ing Document on <strong>Biometric</strong>Vocabulary12


JTC1 SC<strong>Activities</strong>Societal <strong>and</strong> Jurisdictional IssuesSC 37 WG6SC 37 WG1Harmonized <strong>Biometric</strong> Vocabulary<strong>Biometric</strong> InterfacesSC 17 7816-11Card basedSC 37 WG 2BioAPI<strong>Biometric</strong> System Properties<strong>Biometric</strong> DataSecurity AttributesSC 37 WG4<strong>Biometric</strong> Pr<strong>of</strong>ilesSC 27Security EvaluationSC 37 WG5Performance EvaluationLogical Data Structure/File FrameworkSC 27(e.g., ConfidentialityAvailability, Integrity)<strong>Biometric</strong> DataInterchangeFormatsSC 37 WG2CBEFFSC 37 WG313


Market Adoption Examples• <strong>International</strong> Civil Aviation Administration (ICAO):• Adopted a global, harmonized blueprint for theintegration <strong>of</strong> biometric identification information intopassports <strong>and</strong> other Machine Readable TravelDocuments (MRTD).• Requires conformance to JTC 1 SC 37 st<strong>and</strong>ards.• Facial recognition was selected as the globallyinteroperable biometric for machine-assisted identityconfirmation with MRTD.• Other requirements: CBEFF, Finger InterchangeFormats <strong>and</strong> Iris Interchange Format14


Market Adoption Examples• <strong>International</strong> Labor Office <strong>of</strong> the United Nations –Requirements for a Seafarer’s ID Card:• ISO <strong>and</strong> JTC 1 are assisting ILO regarding the use <strong>of</strong>biometrics for a Seafarer’s ID card.• Two fingerprint templates will be stored in a barcodewhich will be placed in the area indicated by ICAO 9303.• ILO Technical Report SID-002 (Approved March 2004)specifies the use <strong>of</strong> some <strong>of</strong> the st<strong>and</strong>ards underdevelopment in JTC 1 SC37 (finger minutiae, fingerimage <strong>and</strong> CBEFF).15


Market Adoption Examples• DHS / TSA - Transportation Worker IdentificationCredential (TWIC) Program :• System-wide common credential to be used for allpersonnel requiring unescorted physical <strong>and</strong>/or logicalaccess.• Phase III - Prototype Phase – <strong>Biometric</strong> Requirements:INCITS M1 biometric st<strong>and</strong>ards, as applicable, such asINCITS 383 Information technology - Application Pr<strong>of</strong>ile -Interoperability <strong>and</strong> Data Interchange - <strong>Biometric</strong> BasedVerification <strong>and</strong> Identification <strong>of</strong> Transportation Workers16


Market Adoption Examples• DHS – Facial Recognition St<strong>and</strong>ard:• Uses INCITS / M1 approved facial biometric st<strong>and</strong>ard (INCITS 385) as thebasis for the DHS st<strong>and</strong>ard.• Extract portions to provide guidelines for specific users:• Derivative 001: “Terms, Reference, <strong>and</strong> Guidelines for Project Managers”• Derivative 002: “Guidelines for S<strong>of</strong>tware <strong>and</strong> System Developers”• Derivative 003: “Guidelines for Photographers <strong>and</strong> Subjects”• Best practices for producing uniform photographs (posters)• References in the DoD IT St<strong>and</strong>ards Registry (DISR):• INCITS 358-2002, BioAPI Specification• CBEFF17

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!