Biometrics/SmartCard Workshop

23
28 th International Traffic Records Forum Biometrics/ SmartCard Workshop 28 th International Traffic Records Forum August 4, 2002 Orlando, Florida

description

Biometrics/SmartCard Workshop. 28 th International Traffic Records Forum August 4, 2002 Orlando, Florida. Identification Technology. Verification of all three elements. X. Authentication Domains. Document- holder. Document. Data. General Principles. Document Authentication - PowerPoint PPT Presentation

Transcript of Biometrics/SmartCard Workshop

Page 1: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Biometrics/SmartCard Workshop

28th International Traffic Records

ForumAugust 4, 2002

Orlando, Florida

Page 2: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Document-holder

Document

Data

Identification Technology

Authentication Domains

Verification of all three elements

X

Page 3: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

General Principles

Document Authentication• Is this a genuine document?

• Addressed by anti-counterfeit technologies

• Was it issued legitimately• Unique personalization security• Authenicatable data

Page 4: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

General Principles

Data Authentication• Has data been altered?

• Classical card security techniques• Tamper evident features• Authenticatable data

Page 5: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

General Principles

• Data Authentication – Machine-readable data• Digital signatures/certificates

• Encryption

•Not covered, but not simple• Reliance upon machine authentication requires

high level of system control over data protection• Encryption• Keys

Page 6: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Data - Logical Security

• Highest security: chip-based Smart Card• PKI implementation• Crypto-processor cards

+ Increase security of off-line transaction+ Increase privacy+ Reduce paperwork+ Reduce the probability of:

• Data alteration• Data substitution

– Increased card & reader costs

Page 7: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

General Principles

Cardholder Authentication• Biometrics preferable

Page 8: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

General Principles

•Reader Authentication(Who authenticates the authenticator?)

Real device or,

A device to capture document, document holder information

Authentication requires logic within document

Cryptographic authentication best, but requires key infrastructure

Page 9: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

EnrollmentCapture Processing

ClientAccess Control

Card Issuance

Identification System Server(s)

HOST(S)CENTRAL SERVER ARRAYS

RDBMS

NetworkManagement

CommunicationNetwork

Point-of-UseVerification

CARD READER &PROCESSINGAPPLICATION

TELEPHONE

Identification System – Key Components

Page 10: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Smart Card Alliance – White Paper

“Smart Cards and Biometrics in Privacy-Smart Cards and Biometrics in Privacy-Sensitive Secure Identification Systems”Sensitive Secure Identification Systems”

Page 11: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

MatrixID Platform

Identification Card Applications:

•ICAO Travel Documents

•State / National Drivers License

•National ID

•Corporate ID

Page 12: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Range of Data Input Formats

Text

Digitized Images

Facial

Signature/usual Mark

Fingerprint Image

Biometric Templates

Fingerprint, Facial, Iris, Hand Geometry

Page 13: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Output Options

Data Structure - accommodates range of formats, including:• Visual Information (Visual Inspection Zone)

• OCR-B (Machine Readable Zone)

• 2-D Barcodes

• High density Magnetic Stripe

• Smart Cards (Contact and Non-Contact)

Page 14: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

MatrixID Interfaces

Designed for distributed system environments:

•Interface to Cryptographic facility

•Digital signatures

•Secure IC loading

•XML Data Structure

•Local Document Issuance

•Remote Document Issuance

Page 15: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Enrollment Screen

Page 16: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Verification

Page 17: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Page 18: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

After the card is read, the MatrixID display shows the following:1. The date/ time and method used to verify the cardholder.2. The date the card was issued and the Issuing Authority.3. That the document passes the integrity checks built into the MatrixID Data Structure4. The card holder’s photo, signature and fingerprint image. 5. The MatrixID will prompt the cardholder to verify their identity by comparing a live scan with the stored image.

Page 19: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

This page depicts the case where the presented fingerprints do not match. The cardholder is not validated.

Page 20: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

This page depicts the caThis page depicts the case where the presented fingerprints match and the cardholder is validated.rd matches the presenter and the cardholder identity is validated.

Page 21: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

•Better technology not sufficient without strategy

•Balance Risk, Privacy, Personal Convenience…

•And Cost

Page 22: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

Technology Changes

New Paradigms to create Transparent Trust

• Dynamically updateable ID

• Negotiated disclosure

• Virtual handshake

Page 23: Biometrics/SmartCard Workshop

28th International Traffic Records Forum

THANK YOU

Tate Preston

[email protected]