Biometrics Standards Financial

You might also like

Download as ppt, pdf, or txt
Download as ppt, pdf, or txt
You are on page 1of 19


84 Biometric Management and Security for the Financial Services Industry

ANSI X9F4 Working Group

What is X9.84?
Standard of the American National Standards Institute (ANSI) Focuses on management of the biometric data across its life cycle Covers enrollment, verification, and identification Primary industry focus is financial services Developed in collaboration with other standards efforts

November 8, 2000

X9F4 Working Group

Where Does X9.84 Fit? ISO

Accredited Standards Committee Financial Services Industry

Identification Cards and Related Devices
November 8, 2000 X9F4 Working Group 3

Where Does X9.84 Fit? ANSI
X9A - Retail Banking Subcommittee X9B - Check Processing Subcommittee X9D - Securities Subcommittee

X9F - Information and Data Security Subcommittee

X9F1 - Cryptographic Tools X9F3 - Cryptographic Protocols

X9F4 - Cryptographic Applications

X9.84 Biometric Management and Security for the Financial Services Industry X9F5 - Certificate Policy and Procedures X9F6 - Cardholder Authentication and ICC
November 8, 2000 X9F4 Working Group 4

Interested ISO Committees

Technical Committee 68 - Financial Industry Subcommittee 2 - Information Security

Joint Technical Committee One (JTC1) ISO/IEC Subcommittee 17 - Passports and Identification Cards

November 8, 2000

X9F4 Working Group

Collaborative Standards Activities


Biometric API - Vendor, biometric, and operating system independent API. Version 1.0 released April, 2000. Participants from biometrics industry, software developers, and system integrators.

Common Biometric Exchange File Format - enable interoperability of biometric-based application programs and systems from different vendors

November 8, 2000

X9F4 Working Group


Biometric Service Provider (BSP) API



Common Biometric Exchange File Format

November 8, 2000 X9F4 Working Group 7

Other Standards Activities
Enterprise Computer-Telephony Forum (ECTF) Speaker Recognition Resource for the ECTFs S.100 Interface. They have an architecture for computertelephony. S.100 is the API of the architecture. BAPI Microsoft & I/O Software API API for computing devices

November 8, 2000

Speaker Verification API (SVAPI) disbanded

X9F4 Working Group

What is X9.84?
Security of biometric data across its life cycle Management of the biometric data across its life cycle Usage of biometric technology for identifying and authenticating banking customers and employees Application of biometric technology for physical and logical access controls Encapsulation of biometric data
Techniques for securely transmitting biometric data Security of the physical hardware used throughout the biometric life cycle
November 8, 2000 X9F4 Working Group 9

Security Services
protection of data against unauthorized disclosure

protection against unauthorized access / authorization to data

protection of data against unauthorized modification / substitution

Authentication and Integrity provable to a third party
Access Control = Authentication + Authorization
November 8, 2000 X9F4 10 Working Group

Security Requirements
1. The biometric system must prevent captured biometric data from being introduced into the system through fake, system-attached, biometric capture devices. 2. The biometric system must ensure that biometric data can be introduced into the system only through authorized interfaces using prescribed procedures

* Source: A Biometric Standard for Information Management and Security

November 8, 2000

X9F4 11 Working Group

Security Requirements
3. The biometric system must implement protection mechanisms (controls and procedures) to detect or deter the synthetic biometric feature attack 4. Where necessary, the biometric system must implement protection mechanisms (controls and procedures) to prevent the exposure or loss of biometric data

* Source: A Biometric Standard for Information Management and Security

November 8, 2000

X9F4 12 Working Group

Security Requirements
5. The biometric system must implement protection mechanisms (controls and procedures) to ensure that the enrollment process is a well-defined 6. The biometric system must restrict access to the templates;
it must restrict the ability of an attacker to reconstruct the template database from intercepted biometric data (samples or templates); it must restrict the ability of an attacker to issue verification requests against data in the template database
* Source: A Biometric Standard for Information Management and Security

November 8, 2000

X9F4 13 Working Group

X9.84 Approach
Biometric data should be managed so that integrity is highest security requirement unauthorized disclosure of biometric data should not compromise the system or the individual NOTE Biometric data are not inherently confidential or secret. Therefore, biometric data may still be encrypted to protect the system for reasons of individual privacy issues

* Source: X9.84 Biometric Information Management and Security

November 8, 2000

X9F4 14 Working Group

X9.84 Requirements
1. Mechanisms to maintain the integrity of biometric data and verification results between any two components:
Cryptographic mechanisms such as a digital signature, physical protection where no transmission is involved and all components reside within the same tamper resistant unit

2. Mechanisms to authenticate the source of the biometric data and verification results, between the sender and receiver component:
Cryptographic mechanisms such as a digital signature Using physical protection where no transmission is involved and all components reside within the same tamper resistant unit

3. If desired, mechanisms to ensure the confidentiality of the biometric data during transmission
* Source: X9.84 Biometric Information Management and Security

November 8, 2000

X9F4 15 Working Group

X9.84 Architecture
A is storage only, all other components are external B input device and application are external C includes all components and application

Data Collection

Matching Signal Processing







* Source: X9.84 Biometric Information Management and Security

November 8, 2000

X9F4 16 Working Group

What Is X9.84 Current Status?

Work started in 1998 Approved by X9F4 in April 2000 Sent to X9 for a vote 30 day public review ANSI is going to submit X9.84 for new ISO standard New ISO working group (WG10) created to review X9.84. US will chair it and UK, Germany, Japan, and (maybe) Canada are among the participants.

November 8, 2000

X9F4 17 Working Group

Contact Information
[1] X9F4 Judith Markowitz

Jeff Stapleton

[2] ANSI X9 [3] NCITS B10 [4] Common Biometric Exchange File Format (CBEFF) www.nist.gove/cbeff [5] BioAPI [6] Biometric Consortium [7] International Biometric Industry Association (IBIA) [8] Enterprise Computer-Telephony Forum (ECTF) [9] BAPI November 8, 2000 X9F4 18 Working Group

Contact Information
Biometrics Integrated

November 8, 2000

X9F4 19 Working Group

You might also like