13.07.2015 Views

IBPC - ABC based on eMRTDs - NIST Visual Image Processing Group

IBPC - ABC based on eMRTDs - NIST Visual Image Processing Group

IBPC - ABC based on eMRTDs - NIST Visual Image Processing Group

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

OutlineUpdate <strong>on</strong> EasyPASSOperati<strong>on</strong>al experiences/figuresEasyPASS PLUS pilot projectSupport for the new German ID cardBackground infrastructure (EAC PKI)<str<strong>on</strong>g>ABC</str<strong>on</strong>g> in Europe<str<strong>on</strong>g>ABC</str<strong>on</strong>g> installati<strong>on</strong>sFr<strong>on</strong>tex <str<strong>on</strong>g>ABC</str<strong>on</strong>g> guidelinesMarkus NuppeneyGaithersburg, March 6. 2012 2


EasyPASS –overview<str<strong>on</strong>g>ABC</str<strong>on</strong>g> system operated by the German FederalPoliceLocated at Frankfurt Airport4 self-service eGates, 1 m<strong>on</strong>itoring stati<strong>on</strong>Open for citizens from 31 European countries(18+ years old)TimetableStart of operati<strong>on</strong> was in August 2009Pilot phase until March 2010Since April 2010 regular operati<strong>on</strong>Markus NuppeneyGaithersburg, March 6. 2012 3


EasyPASS –system architectureSoftware integrati<strong>on</strong> platform BioMiddleModular and platform independent architecture forbiometric applicati<strong>on</strong>sStandard interfaces and protocols(SOAP, BioAPI 2.0, ISO/IEC 19794-x, etc.)Allows for an easy integrati<strong>on</strong> of document readers,biometric comp<strong>on</strong>ents and background systems<strong>Image</strong> acquisiti<strong>on</strong>Integrati<strong>on</strong> of camera via BioAPI Capture BSPInternal pre-qualificati<strong>on</strong> regarding ISO19794-5Face verificati<strong>on</strong>Different face comparis<strong>on</strong> algorithms for the pilotphase, each integrated as BioAPI Verificati<strong>on</strong> BSPMarkus NuppeneyGaithersburg, March 6. 2012 4


EasyPASS –operati<strong>on</strong>al figures (2)≈ 18 sec. average time period to pass the eGateTime from presenting the ePassport <strong>on</strong> the DocReaderuntil the system is ready to process next travellerAverage time periods for main sub-processes5 - 6 sec. for Reading and checking ePassport data(optical and electr<strong>on</strong>ic checks)5 - 6 sec. for the traveller to enter the eGate1 sec. for biometrics (face capture and comparis<strong>on</strong>)5 - 6 sec. for the traveller to leave the eGateMarkus NuppeneyGaithersburg, March 6. 2012 6


EasyPASS –main less<strong>on</strong>s learnedVerificati<strong>on</strong> thresholds recommended by vendors didnot fit to the actual applicati<strong>on</strong> scenarioAppropriate thresholds have to be calculated <str<strong>on</strong>g>based</str<strong>on</strong>g> <strong>on</strong> thereal user group and the actual system setupElectr<strong>on</strong>ic document checks are reliable< 0,1% of the travellers are rejected due to failures of theelectr<strong>on</strong>ic document checksAvailability of CSCA certificates is a key issueTravellersdo not know if they carry an ePassportare not familiar with the document readerare happy with the fast and easy processMarkus NuppeneyGaithersburg, March 6. 2012 7


EasyPASS PLUS pilot projectPilot project of BSI and the German Federal PoliceMain goalsSupport for the new German nati<strong>on</strong>al ID card inEasyPASSDevelopment and implementati<strong>on</strong> of the backgroundinfrastructure (EAC-PKI)Terminal C<strong>on</strong>trol Center - TCCTimetablePilot operati<strong>on</strong> since August 2011Pilot phase until June 2012Markus NuppeneyGaithersburg, March 6. 2012 8


New German ID cardCard bodyElectr<strong>on</strong>ic functi<strong>on</strong>sAccess to all electr<strong>on</strong>ic functi<strong>on</strong>s/data viaExtended Access C<strong>on</strong>trol Versi<strong>on</strong> 2 (EAC 2)• access certificates are mandatory (EAC-PKI)1. eMRTD functi<strong>on</strong> incl. biometrics• digital photograph and (up<strong>on</strong> request) twofingerprints• <strong>on</strong>ly for entitled authorities, e.g. border c<strong>on</strong>trolSince Nov. 2010:credit-card-size ID 1 format2. Electr<strong>on</strong>ic ID functi<strong>on</strong>• for E-Business- and E-Government• access <strong>on</strong>ly to certain n<strong>on</strong>-biometric data fields3. Qualified electr<strong>on</strong>ic signature• up<strong>on</strong> requestMarkus NuppeneyGaithersburg, March 6. 2012 9


TCC –Terminal C<strong>on</strong>trol CenterTCC as central PKI comp<strong>on</strong>entManagement of certificates and cryptographic keysAuthenticati<strong>on</strong> of c<strong>on</strong>nected terminalsCommunicati<strong>on</strong> to DVCA and terminals via standardizedinterfacesICAO-PKI (TCC for Passive Authenticati<strong>on</strong>)Central storage of trusted CSCA certificatesCentralized checking of DS certificatesEAC-PKI (TCC as core of the Inspecti<strong>on</strong> System)Central storage of private keys in HSMEasy certificate management incl. renewalMarkus NuppeneyGaithersburg, March 6. 2012 11


eMRTD PKI landscape incl.Terminal C<strong>on</strong>trol CenterEasyPASS since Q4/2011Markus NuppeneyGaithersburg, March 6. 2012 12


EasyPASS –summing-upCombinati<strong>on</strong> of different checks to ensure a secure <str<strong>on</strong>g>ABC</str<strong>on</strong>g> processComplete checking of eMRTD electr<strong>on</strong>ic security features at ahigh reliability levelBiometrics are of no use, if not authenticated!Fast and easy process (approx. 18 sec)Innovative software architecture (BioMiddle)Detailed m<strong>on</strong>itoring of real life performanceSince Q4/2011 support for the German ID cardCentralized checking of DS certificates andEAC via Terminal C<strong>on</strong>trol Center (TCC)Future challenges in the <str<strong>on</strong>g>ABC</str<strong>on</strong>g> / eGate areaMultiapplicati<strong>on</strong> (eMRTD, Visa, RTP)Multibiometric (face, fingerprint, iris)Markus NuppeneyGaithersburg, March 6. 2012 13


<str<strong>on</strong>g>ABC</str<strong>on</strong>g> installati<strong>on</strong>s in EuropeCountrySystemStart ofOperati<strong>on</strong>Locati<strong>on</strong>sTokenBiometricsPTRAPID2007all int. airportsePassportfaceUKePassportGates2008all major int.airportsePassportfaceFI<str<strong>on</strong>g>ABC</str<strong>on</strong>g> lines2008Helsinki airportand Vaalimaa BCPePassportfaceFRPARAFES20092 airports (ParisCDG and Orly)RTP / ePassportfrom 2012 <strong>on</strong>fingerprintDEEasyPASS2010Frankfurt airportePassport /German ID cardfaceES<str<strong>on</strong>g>ABC</str<strong>on</strong>g>system20102 airports (Madridand Barcel<strong>on</strong>a)ePassport /Spanish ID cardface /fingerprintCZEasyGO2011Prague airportePassportfaceNLNo-Q2012Amsterdam airportePassportfaceMarkus NuppeneyGaithersburg, March 6. 2012 14


Fr<strong>on</strong>tex <str<strong>on</strong>g>ABC</str<strong>on</strong>g> Guidelines<str<strong>on</strong>g>ABC</str<strong>on</strong>g> Working <strong>Group</strong>NL, UK, FI, ES, PT, FR and DEWG started in Feb. 2010*Best Practice Guidelines <strong>on</strong> the Design,Deployment and Operati<strong>on</strong> of <str<strong>on</strong>g>ABC</str<strong>on</strong>g> SystemsVersi<strong>on</strong> 1.1, March 2011Biometrics: face verificati<strong>on</strong> <strong>on</strong>ly<str<strong>on</strong>g>ABC</str<strong>on</strong>g> Guidelines versi<strong>on</strong> 2.0 (coming in Q2/2012)Two separate documents (technical / operati<strong>on</strong>al)Biometrics: face and fingerprint*http://www.fr<strong>on</strong>tex.europa.eu/gfx/fr<strong>on</strong>tex/files/abc_best_practice_guidelines_v1.1.pdfMarkus NuppeneyGaithersburg, March 6. 2012 15


Thank you!Federal Office for Informati<strong>on</strong>Security (BSI)Inspecti<strong>on</strong> Infrastructures andArchitecturesMarkus Nuppeneymarkus.nuppeney@bsi.bund.dewww.bsi.deMarkus NuppeneyGaithersburg, March 6. 2012 16

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!