Park, Jun Woo KISA / IT Security Evaluation Center

Size: px
Start display at page:

Download "Park, Jun Woo KISA / IT Security Evaluation Center"

Transcription

1 Park, Jun Woo KISA / IT Security Evaluation Center

2 Contents Ⅰ Protection Profile Ⅱ Analysis of SOF Ⅲ Analysis Of Vulnerability

3 I. Protection Profile

4 1. Protection Profile Fingerprint Authentication System Protection Profile Developed on February in 2004 for Government by KISA Evaluation Assurance Level : EAL2+ Some features related with Fingerprint -Threats Threats based on impersonation are added - TOE Security Functional Requirements Proper FAR/FRR are required Liveness Detection is required 3

5 1. Protection Profile Threats T.CASUAL The threat agent may make a zero effort forgery attempt to impersonate an authorized user The attacked identity is randomly chosen. The impostor makes no attempt to modify his/her own fingerprint characteristics to appear closer to the attacked identity. The chance of such an attack being successful is measured by the False Acceptance Rate (FAR). 4

6 1. Protection Profile Threats T. EVILTWIN The threat agent may attack a similar or twinned biometric template. In some cases an imposter s s fingerprint characteristics are very similar to those of an enrollee, and attack that identity. The greater the number of enrollees the more likely it is that the impostor resembles one of them. 5

7 1. Protection Profile Threats T. ARTIFACT The threat agent may use an artifact (e.g., artificial fingerprint, or other synthetic means) to gain unauthorized authentication. If an impostor can access a fingerprint image or template, he/she may be able to produce an artifact with an equivalent biometric template. Systems unable to detect the difference between a live sample and an artifact may be fooled by the use of such an artifact. 6

8 1. Protection Profile Threats T. RESIDUAL_IMAGE The residual fingerprint image from a previous user may be sufficient to allow access to an imposter. If an enrolled user leaves a residual fingerprint on a capture device, an impostor may be able to gain access subsequently. This vulnerability may be exploited separately or in conjunction with another vulnerability such as the use of an artifact. 7

9 1. Protection Profile TOE Boundary IT Environment TOE Boundary BIR Storage Enrollment Capture Extraction BIR Assurance BIR Creation BIR Validation reference template User presents Biometric PIN image capture Liveness transmission Security Management Functions Cryptographic service Compare (match) A SS E T S Verification Extraction request template 8

10 1. Protection Profile TOE Security Functional Requirements FIA_SOS.2 TSF Generation of secrets - FAR : < , FRR : < 0.05 FIA_UAU.5 Multiple authentication mechanisms - Liveness Detection 9

11 1. Protection Profile Rationale Threats T.CASUAL T.EVILTWIN T.ARTIFACT T.RESIDUAL_IMAGE Security Objectives O.Identification_and _Authentication Security Functional Requirements FIA_SOS.2 FIA_UAU.5 10

12 II. Analysis of SOF 11

13 2. Analysis of SOF Strength Of Function (SOF) on Fingerprint Authentication System SOF is an important part of the evaluation of a biometric device - It is related to FAR in Fingerprint Authentication System - It is needed proper test data to estimate FAR 12

14 2. Analysis of SOF Fingerprint Database for analyzing SOF The important characteristics of the test data - data is representative of the normal or expected operating conditions of the TOE (environmental conditions including lighting, weather, movement, surroundings, etc). - data is of sufficient size that an accurate estimate of the FAR/FRR can be determined. - data is representative of the type of samples collected (e.g., gender, age, occupation). 13

15 2. Analysis of SOF Fingerprint Database for analyzing SOF Fingerprint Database as the test data - Period of Collection 2002(1rd) 2003(2rd) 2004(3rd) Consideration Characteristic Age, Sex, Occupation, etc Temperature, Aging, etc Rolling scan, Aging, etc Population 2,000 persons 1,000 persons 600 persons Resolution 500dpi 500dpi 500dpi 14

16 2. Analysis of SOF Fingerprint Database for analyzing SOF Fingerprint Database as the test data - Sensors : 11 Types 15

17 2. Analysis of SOF Fingerprint Database for analyzing SOF Fingerprint Database as the test data - Program for fingerprint collection 16

18 2. Analysis of SOF Fingerprint Database for analyzing SOF Samples of Fingerprint Database EyeD Hamster MagicSecure2500 U.are.U Authentec Atmel 17

19 2. Analysis of SOF Fingerprint Database for analyzing SOF Population of Fingerprint Database - About 570,000 Fingerprint Images from 36,000 persons Composition -Male : 50%, Female : 50% -Age : 7 classes (~6,7~11,12~17,18~35,36~50,51~65,65~) -Occupation (6 classes) (student, officer, manufacturer, labor, housekeeper, etc.) Method Consideration -About 150 fingerprints per person -6 fingers (left, right : thumb, index, middle) -Repeat 5 times per finger Occupation, Sex, Temperature, Humidity, Aging, etc. 18

20 2. Analysis of SOF Fingerprint Database for analyzing SOF FAR/FRR Analysis - Display Fingerprint Database information 19

21 2. Analysis of SOF Fingerprint Database for analyzing SOF FAR/FRR Analysis - Creating Template Process Add Creating Template Module Set the Enrollee Select Information Set the Finger Select Information Select the Sensor Type Select the Multiple Impression 20

22 2. Analysis of SOF Fingerprint Database for analyzing SOF FAR/FRR Analysis - Matching Process Matching Module Path Configuration Path Set the Genuine Matching Information Set the Imposter Matching Information : Finger Type 21

23 III. Vulnerability of Fingerprint Authentication System 22

24 3. Vulnerability of Fingerprint Authentication System General Vulnerabilities Transmission Protocol Impostor intercepts or inserts authorized fingerprint sample or template as it is being transmitted between subsystems or components Operating Environment Impostor exploits vulnerabilities of OS or bypasses fingerprint authentication systems 23

25 3. Vulnerability of Fingerprint Authentication System Technology Specific Vulnerabilities Fake Fingerprint Impostor presents an artificial fingerprint sample Residual fingerprint image Impostor utilizes a residual fingerprint image left on the sensor Zero effort forgery attempt Impostor makes no attempt to modify his/her own fingerprint characteristics to appear closer to the attacked identity 24

26 3. Vulnerability of Fingerprint Authentication System Artificial Fingerprint Mold for Artificial Fingerprint using plaster or gummy clay 25

27 3. Vulnerability of Fingerprint Authentication System Artificial Fingerprint Artificial Fingerprint using Gelatine 26

28 3. Vulnerability of Fingerprint Authentication System Artificial Fingerprint Artificial Fingerprint using Gelatine 27

29 3. Vulnerability of Fingerprint Authentication System Vulnerability on Fingerprint Authentication System Comparison of Live and fake Live Finger Silicone Finger Gelatine Finger 28

30 3. Vulnerability of Fingerprint Authentication System Vulnerability on Fingerprint Authentication System Types of Experiments Experiment Type 1 Type 2 Type 3 Type 4 Enrollment Live Live Fake Fake Verification Live Fake Live Fake 29

31

CHAPTER 6 EFFICIENT TECHNIQUE TOWARDS THE AVOIDANCE OF REPLAY ATTACK USING LOW DISTORTION TRANSFORM

CHAPTER 6 EFFICIENT TECHNIQUE TOWARDS THE AVOIDANCE OF REPLAY ATTACK USING LOW DISTORTION TRANSFORM 109 CHAPTER 6 EFFICIENT TECHNIQUE TOWARDS THE AVOIDANCE OF REPLAY ATTACK USING LOW DISTORTION TRANSFORM Security is considered to be the most critical factor in many applications. The main issues of such

More information

On security evaluation of fingerprint recognition systems

On security evaluation of fingerprint recognition systems On security evaluation of fingerprint recognition systems Olaf Henniger, Dirk Scheuermann, and Thomas Kniess Fraunhofer Institute for Secure Information Technology, Germany Abstract. This paper discusses

More information

EpsonNet ID Print Authentication Print Module Security Target Ver1.11

EpsonNet ID Print Authentication Print Module Security Target Ver1.11 EpsonNet ID Print Print Module Security Target Version 1.11 2008-06-24 SEIKO EPSON CORPORATION This document is a translation of the evaluated and certified security target written in Japanese. SEIKO EPSON

More information

A Novel Approach for Detecting Fingerprint Liveness

A Novel Approach for Detecting Fingerprint Liveness A Novel Approach for Detecting Fingerprint Liveness Sonal Girdhar 1, Dr. Chander Kant 2 1 Research Scholar, DCSA, Kurukshetra University, Kurukshetra, India 2 Assistant Professor, DCSA, Kurukshetra University,

More information

BIOMET: A Multimodal Biometric Authentication System for Person Identification and Verification using Fingerprint and Face Recognition

BIOMET: A Multimodal Biometric Authentication System for Person Identification and Verification using Fingerprint and Face Recognition BIOMET: A Multimodal Biometric Authentication System for Person Identification and Verification using Fingerprint and Face Recognition Hiren D. Joshi Phd, Dept. of Computer Science Rollwala Computer Centre

More information

Bio-FactsFigures.docx Page 1

Bio-FactsFigures.docx Page 1 Above shows the G6-BIO-B (Beige case) and the G6-BIO-G (Grey case). Bio-FactsFigures.docx Page 1 Table of Contents 1. Biometric Concepts... 3 1.1. Is it possible to trick the sensor?... 3 1.2. Would a

More information

Supporting Document Guidance. Characterizing Attacks to Fingerprint Verification Mechanisms. Version 3.0 CCDB

Supporting Document Guidance. Characterizing Attacks to Fingerprint Verification Mechanisms. Version 3.0 CCDB Supporting Document Guidance Characterizing Attacks to Fingerprint Verification Mechanisms 2011 Version 3.0 CCDB-2008-09-002 Foreword This is a supporting document, intended to complement the Common Criteria

More information

FVC2004: Third Fingerprint Verification Competition

FVC2004: Third Fingerprint Verification Competition FVC2004: Third Fingerprint Verification Competition D. Maio 1, D. Maltoni 1, R. Cappelli 1, J.L. Wayman 2, A.K. Jain 3 1 Biometric System Lab - DEIS, University of Bologna, via Sacchi 3, 47023 Cesena -

More information

U.S. Government Biometric Verification Mode Protection Profile for. Medium Robustness Environments

U.S. Government Biometric Verification Mode Protection Profile for. Medium Robustness Environments U.S. Government Biometric Verification Mode Protection Profile for Medium Robustness Environments Information Assurance Directorate Version 1.0 November 15, 2003 Protection Profile Title: U.S. Government

More information

Computer Associates. Security Target V2.0

Computer Associates. Security Target V2.0 Computer Associates etrust Single Sign-On V7.0 Security Target V2.0 October 20, 2005 Suite 5200 West 7925 Jones Branch Drive McLean, VA 22102-3321 703 848-0883 Fax 703 848-0985 SECTION TABLE OF CONTENTS

More information

Biometric Security Roles & Resources

Biometric Security Roles & Resources Biometric Security Roles & Resources Part 1 Biometric Systems Skip Linehan Biometrics Systems Architect, Raytheon Intelligence and Information Systems Outline Biometrics Overview Biometric Architectures

More information

BIOMETRIC TECHNOLOGY: A REVIEW

BIOMETRIC TECHNOLOGY: A REVIEW International Journal of Computer Science and Communication Vol. 2, No. 2, July-December 2011, pp. 287-291 BIOMETRIC TECHNOLOGY: A REVIEW Mohmad Kashif Qureshi Research Scholar, Department of Computer

More information

Chapter 3: User Authentication

Chapter 3: User Authentication Chapter 3: User Authentication Comp Sci 3600 Security Outline 1 2 3 4 Outline 1 2 3 4 User Authentication NIST SP 800-63-3 (Digital Authentication Guideline, October 2016) defines user as: The process

More information

Smart Card and Biometrics Used for Secured Personal Identification System Development

Smart Card and Biometrics Used for Secured Personal Identification System Development Smart Card and Biometrics Used for Secured Personal Identification System Development Mădălin Ştefan Vlad, Razvan Tatoiu, Valentin Sgârciu Faculty of Automatic Control and Computers, University Politehnica

More information

National Information Assurance Partnership. Common Criteria Evaluation and Validation Scheme Validation Report

National Information Assurance Partnership. Common Criteria Evaluation and Validation Scheme Validation Report National Information Assurance Partnership Common Criteria Evaluation and Validation Scheme Validation Report TM QRadar V5.1.2 Report Number: Dated: January 26, 2007 Version: 1.1 National Institute of

More information

INTERPRETING FINGERPRINT AUTHENTICATION PERFORMANCE TECHNICAL WHITE PAPER

INTERPRETING FINGERPRINT AUTHENTICATION PERFORMANCE TECHNICAL WHITE PAPER INTERPRETING FINGERPRINT AUTHENTICATION PERFORMANCE TECHNICAL WHITE PAPER Fidelica Microsystems, Inc. 423 Dixon Landing Rd. Milpitas, CA 95035 1 INTRODUCTION The fingerprint-imaging segment of the biometrics

More information

AET60 BioCARDKey. Application Programming Interface. Subject to change without prior notice

AET60 BioCARDKey. Application Programming Interface.  Subject to change without prior notice AET60 BioCARDKey Application Programming Interface Subject to change without prior notice Table of Contents 1.0. Introduction... 3 2.0. Application Programming Interface... 4 2.1. Overview...4 2.2. Data

More information

Tutorial 1. Jun Xu, Teaching Asistant January 26, COMP4134 Biometrics Authentication

Tutorial 1. Jun Xu, Teaching Asistant January 26, COMP4134 Biometrics Authentication Tutorial 1 Jun Xu, Teaching Asistant csjunxu@comp.polyu.edu.hk COMP4134 Biometrics Authentication January 26, 2017 Table of Contents Problems Problem 1: Answer the following questions Problem 2: Biometric

More information

Zodiac Max OPERATOR GUIDE

Zodiac Max OPERATOR GUIDE Zodiac Max OPERATOR GUIDE February 2015 Table of Contents INTRODUCTION... 5 PC Requirements... 6 USB Driver Installation... 7 ZODIAC SINGLE-STATION SOFTWARE... 8 Software Installation... 8 Communications

More information

Lecture 11: Human Authentication CS /12/2018

Lecture 11: Human Authentication CS /12/2018 Lecture 11: Human Authentication CS 5430 3/12/2018 Classes of Countermeasures Authentication: mechanisms that bind principals to actions Authorization: mechanisms that govern whether actions are permitted

More information

Information Security Identification and authentication. Advanced User Authentication II

Information Security Identification and authentication. Advanced User Authentication II Information Security Identification and authentication Advanced User Authentication II 2016-01-29 Amund Hunstad Guest Lecturer, amund@foi.se Agenda for lecture I within this part of the course Background

More information

Multimodal Anti-Spoofing in Biometric Recognition Systems

Multimodal Anti-Spoofing in Biometric Recognition Systems Multimodal Anti-Spoofing in Biometric Recognition Systems Giorgio Fumera, Gian Luca Marcialis, Battista Biggio, Fabio Roli and Stephanie Caswell Schuckers Abstract While multimodal biometric systems were

More information

C026 Certification Report

C026 Certification Report C026 Certification Report E-Jari v 4.0 File name: Version: v1a Date of document: 16 May 2011 Document classification: For general inquiry about us or our services, please email: mycc@cybersecurity.my C026

More information

Certification Report

Certification Report Certification Report Koji Nishigaki, Chairman Information-technology Promotion Agency, Japan Target of Evaluation Application date/id 2009-09-30 (ITC-9272) Certification No. C0250 Sponsor Fuji Xerox Co.,

More information

AET60 API version 1.4 February Introduction...3 Features...3 Application Programming Interface...4

AET60 API version 1.4 February Introduction...3 Features...3 Application Programming Interface...4 Version 1.4 02-2007 Unit 1008, 10th Floor, Hongkong International Trade and Exhibition Centre 1 Trademart Drive, Kowloon Bay, Hong Kong Tel: +852 2796 7873 Fax: +852 2796 1286 Email: info@acs.com.hk Website:

More information

Biometric Fingerprint Reader Unit OZD-ABC-OA99 Technical Specification Data Sheet

Biometric Fingerprint Reader Unit OZD-ABC-OA99 Technical Specification Data Sheet BIOMETRIC FINGERPRINT TIME & ATTENDANCE FINGERPRINT READER UNIT Item Code: OZD-ABC-OA99 OZD-ABC-OA99 is one of the most cost effective Biometric Fingerprint Readers on the market today. OZD-ABC-OA99 incorporates

More information

RedCastle v3.0 for Asianux Server 3 Certification Report

RedCastle v3.0 for Asianux Server 3 Certification Report KECS-CR-08-21 RedCastle v3.0 for Asianux Server 3 Certification Report Certification No.: KECS-CISS-0104-2008 April 2008 IT Security Certification Center National Intelligence Service This document is

More information

Applying biometric authentication to physical access control systems

Applying biometric authentication to physical access control systems Applying biometric authentication to physical access control systems Published on 24 Jul 2018 Over the past few years, biometrics has rapidly expanded into consumer applications, like the financial market

More information

An Overview of Biometric Image Processing

An Overview of Biometric Image Processing An Overview of Biometric Image Processing CHAPTER 2 AN OVERVIEW OF BIOMETRIC IMAGE PROCESSING The recognition of persons on the basis of biometric features is an emerging phenomenon in our society. Traditional

More information

SECURITY ENHANCEMENT OF E-VOTING SYSTEM

SECURITY ENHANCEMENT OF E-VOTING SYSTEM SECURITY ENHANCEMENT OF E-VOTING SYSTEM CHAPTER-4 Security is one of the most important issues for a reliable and trusted Electronic Voting system. The term E-Voting is used in different ways and it encompasses

More information

Biometric Device Assistant Tool: Intelligent Agent for Intrusion Detection at Biometric Device using JESS

Biometric Device Assistant Tool: Intelligent Agent for Intrusion Detection at Biometric Device using JESS www.ijcsi.org 366 Biometric Device Assistant Tool: Intelligent Agent for Intrusion Detection at Biometric Device using JESS Prof. Maithili Arjunwadkar 1, Prof. Dr. R. V. Kulkarni 2 1 Assistant Professor,

More information

Robustness of Multi-modal Biometric Systems under Realistic Spoof Attacks against All Traits

Robustness of Multi-modal Biometric Systems under Realistic Spoof Attacks against All Traits Robustness of Multi-modal Biometric Systems under Realistic Spoof Attacks against All Traits Zahid Akhtar, Battista Biggio, Giorgio Fumera, and Gian Luca Marcialis Department of Electrical and Electronical

More information

Biometrics. Overview of Authentication

Biometrics. Overview of Authentication May 2001 Biometrics The process of verifying that the person with whom a system is communicating or conducting a transaction is, in fact, that specific individual is called authentication. Authentication

More information

Fuji Xerox ApeosPort-II 5010/4000/3000 Series Controller Software for Asia Pacific. Security Target

Fuji Xerox ApeosPort-II 5010/4000/3000 Series Controller Software for Asia Pacific. Security Target Fuji Xerox ApeosPort-II 5010/4000/3000 Series Controller Software for Asia Pacific Security Target Version 1.0.5 This document is a translation of the evaluated and certified security target written in

More information

Multimodal Fusion Vulnerability to Non-Zero Effort (Spoof) Imposters

Multimodal Fusion Vulnerability to Non-Zero Effort (Spoof) Imposters Multimodal Fusion Vulnerability to Non-Zero Effort (Spoof) mposters P. A. Johnson, B. Tan, S. Schuckers 3 ECE Department, Clarkson University Potsdam, NY 3699, USA johnsopa@clarkson.edu tanb@clarkson.edu

More information

LA GARD Smart Series. SmartLinc SmartLinc II SmartPoint. Programmable Multi-User, Multi-Compartment Safe Locks

LA GARD Smart Series. SmartLinc SmartLinc II SmartPoint. Programmable Multi-User, Multi-Compartment Safe Locks LA GARD Smart Series SmartLinc SmartLinc II SmartPoint Programmable Multi-User, Multi-Compartment Safe Locks LA GARD Smart Series at a Glance. The Smart Series products offer advanced features for controlling

More information

XSmart e-passport V1.2

XSmart e-passport V1.2 KECS-CR-11-27 XSmart e-passport V1.2 LG CNS Certification Report Certification No : KECS-ISIS-0319-2011 National Intelligence Service IT Security Certification Center Revision Number Establishment & Revision

More information

2 Electronic Passports and Identity Cards

2 Electronic Passports and Identity Cards 2 Picture source: www.bundesdruckerei.de Paper based Passport Radio Frequency (RF) Chip Electronic Passport (E Pass) Biographic data Human readable Partially machine readable (optically) Conventional

More information

Xerox WorkCentre 5222/5225/5230. Security Target

Xerox WorkCentre 5222/5225/5230. Security Target Xerox WorkCentre 5222/5225/5230 Security Target Version 1.0.2 This document is a translation of the evaluated and certified security target written in Japanese - Table of Contents - 1. ST INTRDUCTIN...

More information

Firewall Protection Profile V2.0 Certification Report

Firewall Protection Profile V2.0 Certification Report KECS-CR-08-10 Firewall Protection Profile V2.0 Certification Report Certification No. : KECS-PP-0093-2008 Apr, 2008 National Intelligence Service IT Security Certification Center This document is the certification

More information

Certification Report

Certification Report Certification Report McAfee File and Removable Media Protection 4.3.1 and epolicy Orchestrator 5.1.2 Issued by: Communications Security Establishment Certification Body Canadian Common Criteria Evaluation

More information

ThinkVantage Fingerprint Software

ThinkVantage Fingerprint Software ThinkVantage Fingerprint Software 12 2 1First Edition (February 2006) Copyright Lenovo 2006. Portions Copyright International Business Machines Corporation 2006. All rights reserved. U.S. GOVERNMENT

More information

COMMON CRITERIA CERTIFICATION REPORT

COMMON CRITERIA CERTIFICATION REPORT COMMON CRITERIA CERTIFICATION REPORT CA Privileged Access Manager Version 2.5.5 v1.2 8 August 2016 FOREWORD This certification report is an UNCLASSIFIED publication, issued under the authority of the Chief,

More information

Biometric Use Case Models for Personal Identity Verification

Biometric Use Case Models for Personal Identity Verification Biometric Use Case Models for Personal Identity Verification Walter Hamilton International Biometric Industry Association & Saflink Corporation Smart Cards in Government Conference Arlington, VA April

More information

Common Criteria Protection Profile. Machine Readable Travel Document with ICAO Application, Extended Access Control BSI-CC-PP-0056

Common Criteria Protection Profile. Machine Readable Travel Document with ICAO Application, Extended Access Control BSI-CC-PP-0056 Common Criteria Protection Profile Machine Readable Travel Document with ICAO Application, Extended Access Control BSI-CC-PP-0056 Foreword This Protection Profile Machine Readable Travel Document with

More information

Start Here. Quick Installation Guide. Verifi. IMPORTANT. Always install the Software prior to Hardware Installation ENTERPRISE

Start Here. Quick Installation Guide. Verifi. IMPORTANT. Always install the Software prior to Hardware Installation ENTERPRISE Verifi ENTERPRISE Start Here IMPORTANT. Always install the Software prior to Hardware Installation Quick Installation Guide Windows XP Fast User Switching Compatible QAS 097 022505 PG1 RA About the Reader

More information

CSCE 548 Building Secure Software Biometrics (Something You Are) Professor Lisa Luo Spring 2018

CSCE 548 Building Secure Software Biometrics (Something You Are) Professor Lisa Luo Spring 2018 CSCE 548 Building Secure Software Biometrics (Something You Are) Professor Lisa Luo Spring 2018 Previous Class Credentials Something you know (Knowledge factors) Something you have (Possession factors)

More information

DESIGNING A BIOMETRIC STRATEGY (FINGERPRINT) MEASURE FOR ENHANCING ATM SECURITY IN INDIAN E-BANKING SYSTEM

DESIGNING A BIOMETRIC STRATEGY (FINGERPRINT) MEASURE FOR ENHANCING ATM SECURITY IN INDIAN E-BANKING SYSTEM DESIGNING A BIOMETRIC STRATEGY (FINGERPRINT) MEASURE FOR ENHANCING ATM SECURITY IN INDIAN E-BANKING SYSTEM PROJECT REFERENCE NO. : 37S0270 COLLEGE : MANGALORE INSTITUTE OF TECHNOLOGY & ENGINEERING MANGALORE

More information

Protection Profile Encrypted Storage Device

Protection Profile Encrypted Storage Device Protection Profile 1 (37) Protection Profile Encrypted Storage Device In Cooperation between MSB-51.1 Protection Profile 2 (37) Table of content 1 INTRODUCTION... 3 1.1 PP REFERENCE... 3 1.2 TOE OVERVIEW...

More information

2016 Global Identity Summit Pre-Conference Paper Hardening Authentication Technologies

2016 Global Identity Summit Pre-Conference Paper Hardening Authentication Technologies 2016 Global Identity Summit Pre-Conference Paper Hardening Authentication Technologies Paper development coordinated by Cathy Tilton, CSRA This is a community-developed document. Information and viewpoints

More information

National Information Assurance Partnership. Common Criteria Evaluation and Validation Scheme Validation Report

National Information Assurance Partnership. Common Criteria Evaluation and Validation Scheme Validation Report National Information Assurance Partnership Common Criteria Evaluation and Validation Scheme Validation Report TM Trusted Computing Group (TCG) Personal Computer (PC) Specific Trusted Building Block (TBB)

More information

ISSN: ISO 9001:2008 Certified International Journal of Engineering and Innovative Technology (IJEIT) Volume 3, Issue 10, April 2014

ISSN: ISO 9001:2008 Certified International Journal of Engineering and Innovative Technology (IJEIT) Volume 3, Issue 10, April 2014 Two Way User Authentication Using Biometric Based Scheme for Wireless Sensor Networks Srikanth S P (Assistant professor, CSE Department, MVJCE, Bangalore) Deepika S Haliyal (PG Student, CSE Department,

More information

Common Criteria Protection Profile. for USB Storage Media BSI-PP Version 1.4,

Common Criteria Protection Profile. for USB Storage Media BSI-PP Version 1.4, Common Criteria Protection Profile for USB Storage Media BSI-PP-0025 Version 1.4, 27.03.06 Disclaimer: This report is the English translation of the document Common Criteria Schutzprofil für USB-Datenträger,

More information

Demographic Update through Update Client Lite (UCL)

Demographic Update through Update Client Lite (UCL) CSC e-governance Services India Limited, Ministry of Communications & Information Technology, Electronics Niketan, 3rd Floor, DeitY, 6 CGO Complex, Lodhi Road, New Delhi 110003 Phone : - 011-24301349 Operator

More information

Symantec Data Loss Prevention 14.5

Symantec Data Loss Prevention 14.5 Symantec Data Loss Prevention 14.5 Evaluation Assurance Level (EAL): EAL2+ Doc No: 1943-000-D102 Version: 1.2 15 November 2016 Symantec Corporation 303 2 nd Street 1000N San Francisco, CA 94107 United

More information

Machine Readable Travel Document with ICAO Application", Basic Access Control

Machine Readable Travel Document with ICAO Application, Basic Access Control Common Criteria Protection Profile Machine Readable Travel Document with ICAO Application", Basic Access Control BSI-PP-0017 Approved by the Federal Ministry of the Interior Version 1.0, 18 August 2005

More information

Security Target. Version 1.21

Security Target. Version 1.21 MQAssure /AppShield v1.2 integrated with MQAssure /IAM v1.0 Security Target 03 January, 2011 Prepared for MagnaQuest Solutions Sdn Bhd A-2-07 & A-2-09 SME Technopreneur Centre Cyberjaya 2270, Jalan Usahawan

More information

Are Spoof-Proof Biometrics Really Possible?

Are Spoof-Proof Biometrics Really Possible? SESSION ID: IDY-F03 Are Spoof-Proof Biometrics Really Possible? Dr. Stephanie Schuckers Director, Center for Identification Technology Research (CITeR) Paynter-Krigman Professor in Engineering Science,

More information

VIDEO CALLING SYSTEM USING BIOMETRIC REMOTE AUTHENTICATION

VIDEO CALLING SYSTEM USING BIOMETRIC REMOTE AUTHENTICATION International Journal of Electronics and Communication Engineering and Technology (IJECET) Volume 7, Issue 5, Sep-Oct 2016, pp. 47 57, Article ID: IJECET_07_05_006 Available online at http://www.iaeme.com/ijecet/issues.asp?jtype=ijecet&vtype=7&itype=5

More information

Presentations and Attacks, and Spoofs, Oh My Stephanie Schuckers, Clarkson University 2/3/2016

Presentations and Attacks, and Spoofs, Oh My Stephanie Schuckers, Clarkson University 2/3/2016 Publishation citation: Schuckers, Stephanie. "Presentations and attacks, and spoofs, oh my." Image and Vision Computing 55 (2016): 26 30. Presentations and Attacks, and Spoofs, Oh My Stephanie Schuckers,

More information

Security of the Lin-Lai smart card based user authentication scheme

Security of the Lin-Lai smart card based user authentication scheme Security of the Lin-Lai smart card based user authentication scheme Chris J. Mitchell and Qiang Tang Technical Report RHUL MA 2005 1 27 January 2005 Royal Holloway University of London Department of Mathematics

More information

Assessing Vulnerabilities of Biometric Readers Using an Applied Defeat Evaluation Methodology

Assessing Vulnerabilities of Biometric Readers Using an Applied Defeat Evaluation Methodology Edith Cowan University Research Online Australian Security and Intelligence Conference Conferences, Symposia and Campus Events 2010 Assessing Vulnerabilities of Biometric Readers Using an Applied Defeat

More information

1TouchXL & 1TouchXLS

1TouchXL & 1TouchXLS Manual 1TouchXL & 1TouchXLS Fingerprint Lock Operator s Manual Intelligent Biometric Controls, Inc. - www.fingerprintdoorlocks.com Rev. 2.2 Introduction I II III IV V VI VII Table Of Contents Introduction

More information

COMMON CRITERIA CERTIFICATION REPORT

COMMON CRITERIA CERTIFICATION REPORT COMMON CRITERIA CERTIFICATION REPORT McAfee Policy Auditor 6.4 with epolicy Orchestrator 5.10 5 November 2018 383-4-455 V1.0 Government of Canada. This document is the property of the Government of Canada.

More information

Biometrics Evaluation and Testing. Dr Alain MERLE CEA-LETI

Biometrics Evaluation and Testing. Dr Alain MERLE CEA-LETI Biometrics Evaluation and Testing Dr Alain MERLE CEA-LETI The BEAT project CC & Biometrics Towards a technical committee on Biometrics A. Merle 2 The BEAT project EU Funded project (FP7 SEC) grant agreement

More information

Fractional biometrics: safeguarding privacy in biometric applications

Fractional biometrics: safeguarding privacy in biometric applications Int. J. Inf. Secur. (2010) 9:69 82 DOI 10.1007/s10207-009-0096-z REGULAR CONTRIBUTION ractional biometrics: safeguarding privacy in biometric applications Duncan Bayly Maurice Castro Arathi Arakala Jason

More information

Fingerprint Authentication for SIS-based Healthcare Systems

Fingerprint Authentication for SIS-based Healthcare Systems Fingerprint Authentication for SIS-based Healthcare Systems Project Report Introduction In many applications there is need for access control on certain sensitive data. This is especially true when it

More information

Biometric authorization of Internet services users Online demo

Biometric authorization of Internet services users Online demo Biometric authorization of Internet services users Online demo Offline demo of the project IT A system for biometric authentication of Internet users based on the fusion of facial and palmprint features

More information

Certification Report

Certification Report Certification Report Koji Nishigaki, Chairman Information-technology Promotion Agency, Japan Target of Evaluation Application date/id 2008-03-28 (ITC-8219) Certification No. C0212 Sponsor Konica Minolta

More information

Stegano-CryptoSystem for Enhancing Biometric-Feature Security with RSA

Stegano-CryptoSystem for Enhancing Biometric-Feature Security with RSA 2011 International Conference on Information and Network Technology IPCSIT vol.4 (2011) (2011) IACSIT Press, Singapore Stegano-CryptoSystem for Enhancing Biometric-Feature Security with RSA Pravin M.Sonsare

More information

Hash-based Encryption Algorithm to Protect Biometric Data in e-passport

Hash-based Encryption Algorithm to Protect Biometric Data in e-passport Hash-based Encryption Algorithm to Protect Biometric Data in e-passport 1 SungsooKim, 2 Hanna You, 3 Jungho Kang, 4 Moonseog Jun 1, First Author Soongsil University, Republic of Korea, indielazy@ssu.ac.kr

More information

VeriFinger 6.4/MegaMatcher 4.2 Algorithm Demo

VeriFinger 6.4/MegaMatcher 4.2 Algorithm Demo VeriFinger 6.4/MegaMatcher 4.2 Algorithm Demo User's guide Copyright 1998-2012. All rights reserved. User's guide version: 6.4.0.0 Publish date: 3/1/2012 VeriFinger 6.4/MegaMatcher 4.2 Table of Contents

More information

Security Target Lite SK e-pass V1.0

Security Target Lite SK e-pass V1.0 Ref.: Security Target Lite SK e-pass V1.0 Table of Contents 1 INTRODUCTION... 6 1.1 ST AND ST-LITE IDENTIFICATION... 6 1.2 TOE IDENTIFICATION... 6 1.3 CC AND PP CONFORMANCE... 6 1.4 CONVENTIONS... 7 1.5

More information

MQAssure TM NetSignOn Secure Desktop Login

MQAssure TM NetSignOn Secure Desktop Login MQAssure TM NetSignOn Secure Desktop Login EAL 1 Security Target Version 1.7 Date: 08 February 2012 MAGNAQUEST SOLUTIONS SDN. BHD. Document History Version No. Date Revision Description 1.0 31 July 2010

More information

Network Intrusion Prevention System Protection Profile V1.1 Certification Report

Network Intrusion Prevention System Protection Profile V1.1 Certification Report KECS-CR-2005-04 Network Intrusion Prevention System Protection Profile V1.1 Certification Report Certification No. : CC-20-2005.12 12, 2005 National Intelligence Service This document is the certification

More information

Threat Assessment Summary. e-voting, Admin, and pvoting TOE s

Threat Assessment Summary. e-voting, Admin, and pvoting TOE s Threat Assessment Summary e-voting, Admin, and pvoting TOE s, 2011 Page 1 of 22 Source Code, High Level Architecture Documentation and Common Criteria Documentation Copyright (C) 2010-2011 and ownership

More information

etrust Admin V8.0 Security Target V2.3 Computer Associates 6150 Oak Tree Blvd, Suite 100 Park Center Plaza II Independence, OH 44131

etrust Admin V8.0 Security Target V2.3 Computer Associates 6150 Oak Tree Blvd, Suite 100 Park Center Plaza II Independence, OH 44131 etrust Admin V8.0 Security Target V2.3 February 2, 2006 Prepared for: Computer Associates 6150 Oak Tree Blvd, Suite 100 Park Center Plaza II Independence, OH 44131 Suite 5200 7925 Jones Branch Drive McLean,

More information

Certification Report

Certification Report Certification Report Target of Evaluation Application date/id Certification No. Sponsor Name of TOE Version of TOE PP Conformance Conformed Claim TOE Developer Evaluation Facility January 5, 2004 (ITC-4021)

More information

Palm Vein Technology

Palm Vein Technology Technical Paper Presentation On Palm Vein Technology (Security Issue) Hyderabad Institute of Technology And Management ABSTRACT Identity verification has become increasingly important in many areas of

More information

AWARD TOP PERFORMER. Minex III FpVTE PFT II FRVT PRODUCT SHEET. Match on Card. Secure fingerprint verification directly on the card

AWARD TOP PERFORMER. Minex III FpVTE PFT II FRVT PRODUCT SHEET. Match on Card. Secure fingerprint verification directly on the card AWARD Speed Accuracy Interoperability TOP PERFORMER PRODUCT SHEET Minex III FpVTE PFT II FRVT Match on Card Secure fingerprint verification directly on the card WWW.INNOVATRICS.COM MATCH ON CARD Our solution

More information

Certification Report

Certification Report Certification Report Target of Evaluation Application date/id Certification No. Sponsor Buheita Fujiwara, Chairman Information- echnology Promotion Agency, Japan 2007-06-26 (ITC-7159) C0137 Fuji Xerox

More information

Certification Report

Certification Report Certification Report Target of Evaluation Application date/id Certification No. Sponsor Koji Nishigaki, Chairman Information-technology Promotion Agency, Japan 2008-02-22 (ITC-8202) C0169 Fuji Xerox Co.,

More information

Applied IT Security. Device Security. Dr. Stephan Spitz 10 Development Security. Applied IT Security, Dr.

Applied IT Security. Device Security. Dr. Stephan Spitz 10 Development Security. Applied IT Security, Dr. Applied IT Security Device Security Dr. Stephan Spitz Stephan.Spitz@gi-de.com Overview & Basics System Security Network Protocols and the Internet Operating Systems and Applications Operating System Security

More information

Command Center Access Control Software

Command Center Access Control Software Command Center Access Control Software NextgenID BioAxs System Family: Member Enrollment Primer Mailing Address: NextgenID, Ltd. 10226 San Pedro Suite 100 San Antonio, TX 78216 USA Contacts: Phone: (210)

More information

A Study on Attacks and Security Against Fingerprint Template Database

A Study on Attacks and Security Against Fingerprint Template Database A Study on Attacks and Security Against Fingerprint Template Database Abstract: Biometric based authentication, the science of using physical or behavioral characteristics for identity verification is

More information

COMMON CRITERIA CERTIFICATION REPORT

COMMON CRITERIA CERTIFICATION REPORT COMMON CRITERIA CERTIFICATION REPORT Dell EMC Unity OE 4.2 383-4-421 22 September 2017 Version 1.0 Government of Canada. This document is the property of the Government of Canada. It shall not be altered,

More information

Security Flaws of Cheng et al. s Biometric-based Remote User Authentication Scheme Using Quadratic Residues

Security Flaws of Cheng et al. s Biometric-based Remote User Authentication Scheme Using Quadratic Residues Contemporary Engineering Sciences, Vol. 7, 2014, no. 26, 1467-1473 HIKARI Ltd, www.m-hikari.com http://dx.doi.org/10.12988/ces.2014.49118 Security Flaws of Cheng et al. s Biometric-based Remote User Authentication

More information

CSE 565 Computer Security Fall 2018

CSE 565 Computer Security Fall 2018 CSE 565 Computer Security Fall 2018 Lecture 9: Authentication Department of Computer Science and Engineering University at Buffalo 1 Lecture Outline Definition of entity authentication Solutions password-based

More information

Mobile ID, the Size Compromise

Mobile ID, the Size Compromise Mobile ID, the Size Compromise Carl Gohringer, Strategic Business Development E-MOBIDIG Meeting, Bern, 25/26 September 1 Presentation Plan The quest for increased matching accuracy. Increased adoption

More information

PERFORMANCE IMPACT OF THE USER ATTEMPTS ON FINGERPRINT RECOGNITION SYSTEM (FRS)

PERFORMANCE IMPACT OF THE USER ATTEMPTS ON FINGERPRINT RECOGNITION SYSTEM (FRS) PERFORMANCE IMPACT OF THE USER ATTEMPTS ON FINGERPRINT RECOGNITION SYSTEM (FRS) 1 DR. NEERAJBHARGAVA, 2 DR. RITUBHARGAVA, 3 MANISH MATHURIA, 4 MINAXI COTIA 1 Associate Professor, Department of Computer

More information

Security Vulnerabilities of Apple iphone Fingerprint Authentication. Suruchi Devanahalli

Security Vulnerabilities of Apple iphone Fingerprint Authentication. Suruchi Devanahalli 1 Security Vulnerabilities of Apple iphone Fingerprint Authentication Suruchi Devanahalli 2 Contents 1. Abstract 2. Introduction 2.1 The Touch ID sensor and the Secure Enclave 2.2 Fingerprint scan analysis

More information

Spoof Detection of Fingerprint Biometrics using PHOG Descriptor

Spoof Detection of Fingerprint Biometrics using PHOG Descriptor I J C T A, 9(3), 2016, pp. 269-275 International Science Press Spoof Detection of Fingerprint Biometrics using PHOG Descriptor Arunalatha G.* and M. Ezhilarasan** Abstract: Biometrics are used for authentication.

More information

Certification Report

Certification Report Certification Report Security Intelligence Platform 4.0.5 Issued by: Communications Security Establishment Certification Body Canadian Common Criteria Evaluation and Certification Scheme Government of

More information

VIRDI-4000 Fingerprint Access Control Terminal. High Security & Convenient Use

VIRDI-4000 Fingerprint Access Control Terminal. High Security & Convenient Use VIRDI-4000 Fingerprint Access Control Terminal 1 1. COMPANY OVERVIEW A. Our businesses Union Community is a leading biometrics company for access control, time & attendance, door lock, PC peripherals,

More information

Voice, Face and Behavioural Biometrics

Voice, Face and Behavioural Biometrics Voice, Face and Behavioural Biometrics Authentication & Fraud Prevention in the age of Virtual Assistants Brett Beranek, Director Product Strategy, Biometrics, Security & Fraud 2016 Nuance Communications,

More information

Multimodal Biometric System by Feature Level Fusion of Palmprint and Fingerprint

Multimodal Biometric System by Feature Level Fusion of Palmprint and Fingerprint Multimodal Biometric System by Feature Level Fusion of Palmprint and Fingerprint Navdeep Bajwa M.Tech (Student) Computer Science GIMET, PTU Regional Center Amritsar, India Er. Gaurav Kumar M.Tech (Supervisor)

More information

Tivoli Access Manager for Operating Systems 5.1 Security Target

Tivoli Access Manager for Operating Systems 5.1 Security Target Tivoli Access Manager for Operating Systems 5.1 Security Target Document Version Number 1.6.5 Document Creation Date: 2004-10-21 Document Update Date: 2006-02-01 Authors: Clemens Wittinger, David Ochel

More information

Canon MFP Security Chip Security Target

Canon MFP Security Chip Security Target Canon MFP Security Chip Security Target Version 1.06 April 7, 2008 Canon Inc. This document is a translation of the evaluated and certified security target written in Japanese Revision History Version

More information

National Information Assurance Partnership. Validation Report

National Information Assurance Partnership. Validation Report National Information Assurance Partnership TM Common Criteria Evaluation and Validation Scheme Validation Report Xerox Corporation Xerox CopyCentre C2128/C2636/C3545 Copier and WorkCentre Pro C2128/C2636/C3545

More information

CIS 4360 Introduction to Computer Security Fall WITH ANSWERS in bold. First Midterm

CIS 4360 Introduction to Computer Security Fall WITH ANSWERS in bold. First Midterm CIS 4360 Introduction to Computer Security Fall 2010 WITH ANSWERS in bold Name:.................................... Number:............ First Midterm Instructions This is a closed-book examination. Maximum

More information