Biometrics Evaluation and Testing. Dr Alain MERLE CEA-LETI

Size: px
Start display at page:

Download "Biometrics Evaluation and Testing. Dr Alain MERLE CEA-LETI"

Transcription

1 Biometrics Evaluation and Testing Dr Alain MERLE CEA-LETI

2 The BEAT project CC & Biometrics Towards a technical committee on Biometrics A. Merle 2

3 The BEAT project EU Funded project (FP7 SEC) grant agreement number: Area: Biometrics Evaluation & Testing Partners IDIAP CH Univ. Autonoma de MADRID ES Univ. of SURREY UK EPFL CH TUBITAK TR CEA-LETI F MORPHO F TUV-IT DE KUL BE Advisory Board Members BSI DE NPL UK ANSSI F CCN ES Biometrics Institutes AU Certification Bodies Evaluation labs A. Merle 3

4 BEAT: Status & Objectives Status No standards for evaluating Accuracy Resistance to attacks Privacy preservation strength Multi-modalities: Face, Fingerprints, Iris, Veins Objectives: Develop an On-Line open platform for performance evaluation Develop protocols & Tools for Vulnerability Analysis Propose a Common Criteria evaluation methodology A. Merle 4

5 BEAT: Structure of the project WP2: Specifications & Design WP3: Evaluation of biometric performance Protocols, databases, novel metrics WP4: Evaluation of vulnerabilities Direct (spoofing) and Indirect attacks WP5: Evaluation of Privacy Preservation Novel privacy preservation techniques WP6: Standards & Certification Common frameworks for the security evaluation of biometric systems (CC) WP7: Integration & Deployment WP9: Legal aspects of Privacy and IP A. Merle 5

6 BEAT: Biometrics performances Statistical by nature 2 major related factors FAR: False Accept Rate FRR: False Reject rate Dependent on the application Population characteristics Race, Blue/White collar, Need of huge data bases Privacy, National regulations A. Merle 6

7 BEAT: Spoofing Any modality is subject to spoofing A. Merle 7

8 BEAT: Indirect attacks Fake feature generation Ex: generating a fake fingerprint from a template «Hill Climbing» Using the matching score to optimize a generated feature list A. Merle 8

9 Notes A biometrics system is also an sensor/hardware/software system that could be subject to standard attacks towards this kind of system Tampering, Side channel analysis, fault injection, etc Ex: Access to matching score via Time analysis to implement a hill climbing attack. A CC specificity: Test strategies are adapted to the product Expertise & vulnerability analysis vs test list Ability to follow a fast evolving state of the art A. Merle 9

10 CC and Biometrics 2002: BEM: Biometrics evaluation methodology Focused on intrinsic performance evaluation (FAR & FRR) Dimensioning data bases 2007 Today Work on fingerprints (France, Germany, Spain) All kind of attacks specific to biometrics (spoofing, hill climbing, ) Document available: PPs from BSI Characterizing Attacks to Fingerprint Verification Mechanisms M-Jul2011.pdf EAL2, EAL2+ Max AVA_VAN.2, or even no AVA_VAN Definition of a dedicated SFR A. Merle 10

11 Open questions (among others) Extension to other modalities: Iris, veins, face Evaluation methodology FAR/FRR predefined or calculated by evaluator Databases for intrinsic performance evaluation (developer, evaluator, both, identical, different) Spoofing (methods, anything considered as standard ) Managing uncertainties in spoofing attacks Resistance rating Table, factors, numbers, 2 vs 1 phase (Identification & exploitation) Resistance Specific rating (biometrics, by modality) or «common rating» (which one, CEM, hardware, ) A. Merle 11

12 CC: the example of Smartcards Widely used for Smartcards But, heavy adaptations have been necessary to have an efficient process A. Merle 12

13 Resistance rating Alain MERLE A. Merle 13

14 In addition In the last 15 years, Common Criteria evaluations have been a very efficient process to enhance the security level of products Challenge conditions between developers & labs Safe and responsible environment No vulnerability critically transferred to the public A. Merle 14

15 BEAT: Intended production Evaluation methodology What is a biometrics systems What the developer has to produce What tasks the evaluator has to perform, requested competences, tools, etc PPs? Attacks description All the attacks methods an evaluation has to take into account «evaluators guide» Attack potential / Resistance rating With an agreement of the participants A. Merle 15

16 BEAT objectives Create a «technical committee» dedicated to Biometrics Open to all stakeholders participating or not to BEAT Based on an initial kernel participating to BEAT CBs (CCN, BSI, ANSSI), evaluation labs (LETI, TUV-IT, UAM), industry (MORPHO) SOG-IS MC Management Committee JIWG Joint Interpretation Library (JIL) Working Group JHAS JIL Hardware Attack Sub-group JTEMS JIL Terminal Evaluation Method Sub-group BIOMETRICS A. Merle 16

17 If interested, join us Contacts Beat project manager: Dr Sébastien MARCEL, IDIAP WP Leader for standardization & Certification: Dr Alain MERLE, CEA-LETI A. Merle 17

18 Questions?

BEAT - Project Overview Prof Julian Fierrez On behalf of Dr Sébastien Marcel Idiap Research Institute, CH http://www.idiap.ch/~marcel Biometrics Evaluation and Testing (BEAT) Research Projects Conference

More information

Rating Attack Potential for Smartcards

Rating Attack Potential for Smartcards Rating Attack Potential for Smartcards Alain MERLE, CEA-LETI Technical manager of CESTI LETI on behalf of ISCI (JHAS) group CESTI LETI 1 The ISCI group (International Security Certification Initiative)

More information

Supporting Document Guidance. Characterizing Attacks to Fingerprint Verification Mechanisms. Version 3.0 CCDB

Supporting Document Guidance. Characterizing Attacks to Fingerprint Verification Mechanisms. Version 3.0 CCDB Supporting Document Guidance Characterizing Attacks to Fingerprint Verification Mechanisms 2011 Version 3.0 CCDB-2008-09-002 Foreword This is a supporting document, intended to complement the Common Criteria

More information

IDENTIFICATION THINK EXCELLENCE, CHOOSE MULTIMODALITY

IDENTIFICATION THINK EXCELLENCE, CHOOSE MULTIMODALITY IDENTIFICATION THINK EXCELLENCE, CHOOSE MULTIMODALITY WHAT IS MULTIMODALITY? MULTIMODALITY: COMBINATION OF 2 OR SEVERAL COMPLEMENTARY BIOMETRICS Examples: Face and Iris, Hand and face, Finger vein & Fingerprint

More information

Mobile Felica on CX Virgo platform Version 5.0

Mobile Felica on CX Virgo platform Version 5.0 122 MAINTENANCE REPORT MR1 (supplementing Certification Report No. CRP298) Mobile Felica on Sm@rtSIM CX Virgo platform Version 5.0 Issue 1.0 September 2017 Crown Copyright 2017 All Rights Reserved Reproduction

More information

Indirect Attacks on Biometric Systems

Indirect Attacks on Biometric Systems Indirect Attacks on Biometric Systems Dr. Julian Fierrez (with contributions from Dr. Javier Galbally) Biometric Recognition Group - ATVS Escuela Politécnica Superior Universidad Autónoma de Madrid, SPAIN

More information

Legal Regulations and Vulnerability Analysis

Legal Regulations and Vulnerability Analysis Legal Regulations and Vulnerability Analysis Bundesamt für Sicherheit in der Informationstechnik (BSI) (Federal Office for Information Security) Germany Introduction of the BSI National Authority for Information

More information

Car2Car Forum Operational Security

Car2Car Forum Operational Security Car2Car Forum 2012 14.11.2012 Operational Security Stefan Goetz, Continental Hervé Seudié, Bosch Working Group Security Task Force: In-vehicle Security and Trust Assurance Level 15/11/2012 C2C-CC Security

More information

CC Part 3 and the CEM Security Assurance and Evaluation Methodology. Su-en Yek Australasian CC Scheme

CC Part 3 and the CEM Security Assurance and Evaluation Methodology. Su-en Yek Australasian CC Scheme CC Part 3 and the CEM Security Assurance and Evaluation Methodology Su-en Yek Australasian CC Scheme What This Tutorial Is An explanation of where Security Assurance Requirements fit in the CC evaluation

More information

Summary of the activities of the ERNCIP Applied Biometrics for security of CI Thematic Group

Summary of the activities of the ERNCIP Applied Biometrics for security of CI Thematic Group Summary of the activities of the ERNCIP Applied Biometrics for security of CI Thematic Group Sylvia Yang Danish Institute of Fire and Security Technology (DBI) March 2015 The research leading to these

More information

3D Face Project. Overview. Paul Welti. Sagem Défense Sécurité Technical coordinator. ! Background. ! Objectives. ! Workpackages

3D Face Project. Overview. Paul Welti. Sagem Défense Sécurité Technical coordinator. ! Background. ! Objectives. ! Workpackages 3D Face Project Paul Welti Sagem Défense Sécurité Technical coordinator Overview! Background! Objectives! Workpackages 2 1 ! Biometric epassport Biometrics and Border Control! EU-Council Regulation No

More information

Towards e-passport Duplicate Enrolment Check in the European Union

Towards e-passport Duplicate Enrolment Check in the European Union 2013 European Intelligence and Security Informatics Conference Towards e-passport Duplicate Enrolment Check in the European Union Moazzam Butt, Sandra Marti, Alexander Nouak,Jörg Köplin, R. Raghavendra

More information

An overview of research activities in Biometrics

An overview of research activities in Biometrics An overview of research activities in Biometrics at the Idiap Research Institute Dr Sébastien Marcel Senior research scientist www.idiap.ch/ marcel Idiap Research Institute Martigny, Switzerland www.idiap.ch

More information

CC withinthe Context of the EU Privacy Seal - EuroPriSe

CC withinthe Context of the EU Privacy Seal - EuroPriSe CC withinthe Context of the EU Privacy Seal - EuroPriSe TÜV Informationstechnik GmbH -TÜViT - Overview 1. Motivation 2. Data Privacy 3. European Privacy Seal EuroPriSe 4. CC and EuroPriSe 5. Conclusion

More information

IT Security Evaluation : Common Criteria

IT Security Evaluation : Common Criteria AfriNIC-9 MEETING Mauritius 22-28 November 2008 IT Security Evaluation : Common Criteria Ministry of Communication Technologies National Digital Certification Agency Mounir Ferjani November 2008 afrinic

More information

Visa Chip Security Program Security Testing Process

Visa Chip Security Program Security Testing Process Visa Chip Security Program Security Testing Process Visa Supplemental Requirements Version 2.1 January 2018 Visa Public Important Information on Confidentiality and Copyright Note: This document is a supplement

More information

Secure Access Control over Wide Area Network - IKTPLUSS Project SWAN

Secure Access Control over Wide Area Network - IKTPLUSS Project SWAN Secure Access Control over Wide Area Network - IKTPLUSS Project SWAN Raghu Ramachandra, Martin Stokkenes, Pankaj Wasnik, Norwegian University of Science and Technology - Gjøvik http://www.christoph-busch.de

More information

Biometrics. Overview of Authentication

Biometrics. Overview of Authentication May 2001 Biometrics The process of verifying that the person with whom a system is communicating or conducting a transaction is, in fact, that specific individual is called authentication. Authentication

More information

Joint Interpretation Library. Certification of "open" smart card products

Joint Interpretation Library. Certification of open smart card products Joint Interpretation Library Certification of "open" smart card products Version 1.1 (for trial use) 4 February 2013 Certification of "open" smart card products Joint Interpretation Library Acknowledgments:

More information

PROJECT FINAL REPORT. Tel: Fax:

PROJECT FINAL REPORT. Tel: Fax: PROJECT FINAL REPORT Grant Agreement number: 262023 Project acronym: EURO-BIOIMAGING Project title: Euro- BioImaging - Research infrastructure for imaging technologies in biological and biomedical sciences

More information

From the Iriscode to the Iris: A New Vulnerability Of Iris Recognition Systems

From the Iriscode to the Iris: A New Vulnerability Of Iris Recognition Systems From the Iriscode to the Iris: A New Vulnerability Of Iris Recognition Systems Javier Galbally Biometrics Recognition Group - ATVS Escuela Politécnica Superior Universidad Autónoma de Madrid, SPAIN http://atvs.ii.uam.es

More information

Biometric Spoofing and Anti-Spoofing

Biometric Spoofing and Anti-Spoofing Biometric Spoofing and Anti-Spoofing Presentation Attack Detection part 1 Sébastien Marcel Head of the Biometrics Security and Privacy group http://www.idiap.ch/~marcel IEEE Workshop on Information Forensics

More information

SECURITY FOR CONNECTED OBJECTS. Alain MERLE CEA-LETI

SECURITY FOR CONNECTED OBJECTS. Alain MERLE CEA-LETI SECURITY FOR CONNECTED OBJECTS Alain MERLE CEA-LETI Alain.merle@cea.fr Source: CISCO, AT&T IOT: SOME FIGURES Cisco predicts 50B of connected object by 2020 X-as-a-service a breakthrough for carrier s business

More information

1 Purpose of this document

1 Purpose of this document 1 Purpose of this document Many of the smartcard products or similar devices implement cryptographic operations that are subject to attacks such as fault injection and side-channel attacks at a high attack

More information

SECURITY OF CPS: SECURE EMBEDDED SYSTEMS AS A BASIS

SECURITY OF CPS: SECURE EMBEDDED SYSTEMS AS A BASIS SECURITY OF CPS: SECURE EMBEDDED SYSTEMS AS A BASIS Christoph Krauß, christoph.krauss@aisec.fraunhofer.de Dagstuhl Seminar 11441: Science and Engineering of CPS, November 2011 Overview Introduction Securing

More information

Certification Report

Certification Report TÜV Rheinland Nederland B.V. Version 2016-2 Certification Report Mercury epassport v1.16 Sponsor and developer: Infineon Technologies AG Am Campeon 5 D-85579 Neubiberg Germany Evaluation facility: Brightsight

More information

Juniper Networks EX3200 and EX4200 Switches running JUNOS 9.3R2

Juniper Networks EX3200 and EX4200 Switches running JUNOS 9.3R2 122 ASSURANCE MAINTENANCE REPORT MR2 (supplementing Certification Report No. CRP248 and Assurance Maintenance Report MR1) Juniper Networks EX3200 and EX4200 Switches running JUNOS 9.3R2 Version 9.3R2 Issue

More information

ASSURANCE MAINTENANCE REPORT MR3 (supplementing Certification Report No. CRP248) Version 9.3R1. Issue 1.0 April 2011

ASSURANCE MAINTENANCE REPORT MR3 (supplementing Certification Report No. CRP248) Version 9.3R1. Issue 1.0 April 2011 122 ASSURANCE MAINTENANCE REPORT MR3 (supplementing Certification Report No. CRP248) Juniper Networks M7i, M10i, M40e, M120, M320, T320, T640, T1600, MX240, MX480 and MX960 Services Routers and EX3200,

More information

Juniper Networks J2300, J2350, J4300, M7i and M10i Services Routers running JUNOS 8.5R3

Juniper Networks J2300, J2350, J4300, M7i and M10i Services Routers running JUNOS 8.5R3 122 ASSURANCE MAINTENANCE REPORT MR3 (supplementing Certification Report No. CRP237 and Assurance Maintenance Reports MR1 and MR2) Juniper Networks J2300, J2350, J4300, M7i and M10i Services Routers running

More information

Overview of ICT certification laboratories FINAL V1.1 JANUARY European Union Agency For Network and Information Security

Overview of ICT certification laboratories FINAL V1.1 JANUARY European Union Agency For Network and Information Security Overview of ICT certification laboratories FINAL V1.1 JANUARY 2018 www.enisa.europa.eu European Union Agency For Network and Information Security About ENISA The European Union Agency for Network and Information

More information

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006

ISO / IEC 27001:2005. A brief introduction. Dimitris Petropoulos Managing Director ENCODE Middle East September 2006 ISO / IEC 27001:2005 A brief introduction Dimitris Petropoulos Managing Director ENCODE Middle East September 2006 Information Information is an asset which, like other important business assets, has value

More information

Germany and The Netherlands Certification of cryptographic modules

Germany and The Netherlands Certification of cryptographic modules Germany and The Netherlands Certification of cryptographic modules Leo Kool (Msc), Brightsight 18 May 2016, kool@brightsight.com Outline CC and Schemes Evaluation Process and Reporting forms (NSCIB, BSI)

More information

Synergies of the Common Criteria with Other Standards

Synergies of the Common Criteria with Other Standards Synergies of the Common Criteria with Other Standards Mark Gauvreau EWA-Canada 26 September 2007 Presenter: Mark Gauvreau (mgauvreau@ewa-canada.com) Overview Purpose Acknowledgements Security Standards

More information

The exida. IEC Functional Safety and. IEC Cybersecurity. Certification Programs

The exida. IEC Functional Safety and. IEC Cybersecurity. Certification Programs The exida IEC 61508 - Functional Safety and IEC 62443- Cybersecurity Certification Programs V1 R1 November 10, 2017 exida Sellersville, PA 18960, USA, +1-215-453-1720 Munich, Germany, +49 89 4900 0547

More information

Quantitative Tests Supporting Standardized Biometric Data for Large Scale Identity Management

Quantitative Tests Supporting Standardized Biometric Data for Large Scale Identity Management Quantitative Tests Supporting Standardized Biometric Data for Large Scale Identity Management Patrick Grother Information Technology Laboratory National Institute of Standards and Technology (US), United

More information

Swedish Scheme Update Dag Ströman, Head of CSEC

Swedish Scheme Update Dag Ströman, Head of CSEC Swedish Scheme Update Dag Ströman, Head of CSEC 1 CSEC - The Legal Base Swedish Parliament approval of the Government bill in May 2002, which stated: The Swedish Defence Materiel Administration, FMV, is

More information

PVSITES project Dr. Maider Machado - Tecnalia

PVSITES project Dr. Maider Machado - Tecnalia PVSITES project Dr. Maider Machado - Tecnalia Acceleration of BIPV by international collaboration IEA PVPS Task 15 at 32 nd EU PVSEC - Munich 21 st June 2016 This project has received funding from the

More information

MIFARE Plus and DESFire

MIFARE Plus and DESFire Rev. 01 19 January 2015 Specification l Document information Info Content Keywords Security, Certification, MIFARE Abstract Document describing the NXP MIFARE Security Scheme Process Revision history Rev

More information

Figure 1. Example sample for fabric mask. In the second column, the mask is worn on the face. The picture is taken from [5].

Figure 1. Example sample for fabric mask. In the second column, the mask is worn on the face. The picture is taken from [5]. ON THE VULNERABILITY OF FACE RECOGNITION SYSTEMS TO SPOOFING MASK ATTACKS Neslihan Kose, Jean-Luc Dugelay Multimedia Department, EURECOM, Sophia-Antipolis, France {neslihan.kose, jean-luc.dugelay}@eurecom.fr

More information

Datasheet Fujitsu PalmSecure Contactless Biometrics Authentication

Datasheet Fujitsu PalmSecure Contactless Biometrics Authentication Datasheet Fujitsu PalmSecure Contactless Biometrics Authentication Award-winning Contactless Authentication Technology Verifies An Individual s Identity by Recognizing Palm Vein Patterns enabling dynamic

More information

Biometric Security Roles & Resources

Biometric Security Roles & Resources Biometric Security Roles & Resources Part 1 Biometric Systems Skip Linehan Biometrics Systems Architect, Raytheon Intelligence and Information Systems Outline Biometrics Overview Biometric Architectures

More information

Certification Report. EAL 4+ (ALC_DVS.2) Evaluation of TÜBİTAK BİLGEM UEKAE. AKİS v1.4i PASAPORT

Certification Report. EAL 4+ (ALC_DVS.2) Evaluation of TÜBİTAK BİLGEM UEKAE. AKİS v1.4i PASAPORT Certification Report EAL 4+ (ALC_DVS.2) Evaluation of TÜBİTAK BİLGEM UEKAE AKİS v1.4i PASAPORT issued by Turkish Standards Institution Common Criteria Certification Scheme SOFTWARE TEST and CERTIFICATION

More information

SECURITY CERTIFICATION

SECURITY CERTIFICATION ÉDITION 2018 SECURITY CERTIFICATION OF PRODUCTS BY THE FRENCH NATIONAL CYBERSECURITY AGENCY (ANSSI) PAR L AGENCE NATIONALE DE LA SÉCURITÉ DES SYSTÈMES D INFORMATION Security Visas provide a competitive

More information

C026 Certification Report

C026 Certification Report C026 Certification Report E-Jari v 4.0 File name: Version: v1a Date of document: 16 May 2011 Document classification: For general inquiry about us or our services, please email: mycc@cybersecurity.my C026

More information

Park, Jun Woo KISA / IT Security Evaluation Center

Park, Jun Woo KISA / IT Security Evaluation Center 2005. 9. 29 Park, Jun Woo (junupark@kisa.or.kr) KISA / IT Security Evaluation Center Contents Ⅰ Protection Profile Ⅱ Analysis of SOF Ⅲ Analysis Of Vulnerability I. Protection Profile 1. Protection Profile

More information

Information Security Identification and authentication. Advanced User Authentication II

Information Security Identification and authentication. Advanced User Authentication II Information Security Identification and authentication Advanced User Authentication II 2016-01-29 Amund Hunstad Guest Lecturer, amund@foi.se Agenda for lecture I within this part of the course Background

More information

Building an Assurance Foundation for 21 st Century Information Systems and Networks

Building an Assurance Foundation for 21 st Century Information Systems and Networks Building an Assurance Foundation for 21 st Century Information Systems and Networks The Role of IT Security Standards, Metrics, and Assessment Programs Dr. Ron Ross National Information Assurance Partnership

More information

Session objectives. Security Evaluation. Evaluation Standards. Can we trust a secure product/system? CSM27 Computer Security

Session objectives. Security Evaluation. Evaluation Standards. Can we trust a secure product/system? CSM27 Computer Security Overview Session objectives Security Evaluation CSM27 Computer Security Dr Hans Georg Schaathun University of Surrey Discuss advantages and limitations of security evaluations Clarify fundamental concepts

More information

Future role of DSO with large-scale DERs workshop

Future role of DSO with large-scale DERs workshop Future role of DSO with large-scale DERs workshop Aachen - 19/03/2015 ELECTRA presentation Mattia Marinelli The research leading to these results has received funding from the European Union Seventh Framework

More information

cryptovision s Government Solutions Adam Ross, Ben Drisch cryptovision GmbH

cryptovision s Government Solutions Adam Ross, Ben Drisch cryptovision GmbH cryptovision s Government Solutions Adam Ross, Ben Drisch cryptovision GmbH cv cryptovision GmbH T: +49 (0) 209.167-24 50 F: +49 (0) 209.167-24 61 info(at)cryptovision.com 1 cryptovision cryptovision Gelsenkirchen

More information

Dr Michaela Black, Prof. Jonathan Wallace.

Dr Michaela Black, Prof. Jonathan Wallace. Dr Michaela Black, Prof. Jonathan Wallace mm.black@ulster.ac.uk jg.wallace@ulster.ac.uk http://www.midasproject.eu http://www.midasproject.eu Outline MIDAS - Strengths MIDAS - Consortium Partners MIDAS

More information

Defining IT Security Requirements for Federal Systems and Networks

Defining IT Security Requirements for Federal Systems and Networks Defining IT Security Requirements for Federal Systems and Networks Employing Common Criteria Profiles in Key Technology Areas Dr. Ron Ross 1 The Fundamentals Building more secure systems depends on the

More information

Smart Meter Security. Martin Klimke, Principle of Technical Marketing Infineon Chip Card and Security

Smart Meter Security. Martin Klimke, Principle of Technical Marketing Infineon Chip Card and Security Smart Meter Security Martin Klimke, Principle of Technical Marketing Infineon Chip Card and Security Smart Grids: Advanced power control, intelligence and communications New Business models and Services

More information

Trustworthy ICT. FP7-ICT Objective 1.5 WP 2013

Trustworthy ICT. FP7-ICT Objective 1.5 WP 2013 Trustworthy ICT FP7-ICT-2013-10 Objective 1.5 WP 2013 1 General Overview Focused in a limited number of technologies in emerging application of high economic impact in the security area, Cloud Computing

More information

BSI-CC-PP for. Java Card Protection Profile - Open Configuration, Version December developed by. Oracle Corporation

BSI-CC-PP for. Java Card Protection Profile - Open Configuration, Version December developed by. Oracle Corporation BSI-CC-PP-0099-2017 for Java Card Protection Profile - Open Configuration, Version 3.0.5 December 2017 developed by Oracle Corporation Federal Office for Information Security (BSI), Postfach 20 03 63,

More information

Images can be regenerated from quantized biometric match score data

Images can be regenerated from quantized biometric match score data Images can be regenerated from quantized biometric match score data Andy Adler School of Information Technology and Engineering University of Ottawa 1 Problem: Biometrics security Biometric authentication:

More information

SOMA-c004 e-passport (BAC) Version 1.0

SOMA-c004 e-passport (BAC) Version 1.0 122 CERTIFICATION REPORT No. CRP278 SOMA-c004 e-passport (BAC) Version 1.0 running on Infineon M7892 Integrated Circuit Issue 1.0 December 2014 Crown Copyright 2014 All Rights Reserved Reproduction is

More information

Hill-Climbing Attack to an Eigenface-Based Face Verification System

Hill-Climbing Attack to an Eigenface-Based Face Verification System Hill-limbing Attack to an Eigenface-ased Face Verification System Javier Galbally, Julian Fierrez, and Javier Ortega-Garcia iometric Recognition Group ATVS, EPS, UAM / Francisco Tomas y Valiente 11, 2849

More information

Gurmeet Kaur 1, Parikshit 2, Dr. Chander Kant 3 1 M.tech Scholar, Assistant Professor 2, 3

Gurmeet Kaur 1, Parikshit 2, Dr. Chander Kant 3 1 M.tech Scholar, Assistant Professor 2, 3 Volume 8 Issue 2 March 2017 - Sept 2017 pp. 72-80 available online at www.csjournals.com A Novel Approach to Improve the Biometric Security using Liveness Detection Gurmeet Kaur 1, Parikshit 2, Dr. Chander

More information

FeliCa Approval for Security and Trust (FAST) Overview. Copyright 2018 FeliCa Networks, Inc.

FeliCa Approval for Security and Trust (FAST) Overview. Copyright 2018 FeliCa Networks, Inc. FeliCa Approval for Security and Trust (FAST) Overview Introduction The security certification scheme called FeliCa Approval for Security and Trust (FAST) has been set up to enable the evaluation and certification

More information

Australasian Information Security Evaluation Program

Australasian Information Security Evaluation Program Australasian Information Security Evaluation Program Certification Report 2012/78 2 May 2012 Version 1.0 Commonwealth of Australia 2012. Reproduction is authorised provided that the report is copied in

More information

6. Multimodal Biometrics

6. Multimodal Biometrics 6. Multimodal Biometrics Multimodal biometrics is based on combination of more than one type of biometric modalities or traits. The most compelling reason to combine different modalities is to improve

More information

Enhancing the Well-Defined and Successful ETR for Composition Approach

Enhancing the Well-Defined and Successful ETR for Composition Approach Enhancing the Well-Defined and Successful ETR for Composition Approach Monique Bakker, Olaf Tettero 11 September 2013; commoncriteria@brightsight.com Goal of this presentation 1. What should be the content

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 19795-5 First edition 2011-03-01 Information technology Biometric performance testing and reporting Part 5: Access control scenario and grading scheme Technologies de l'information

More information

Security System and COntrol 1

Security System and COntrol 1 Security System and COntrol 1 Security Management By: Joseph Ronald Canedo It is a Risky World Vulnerabilities Security objectives: Prevent attacks Detect attacks Recover from attacks Attacks: against

More information

Cybersecurity eit. Software. Certification. Industrial Security Embedded System

Cybersecurity eit. Software. Certification. Industrial Security Embedded System Statement Benefits and limitations of certifications and labels in the context of cyber security Arguments for a balance between customer information and industrial suitability Industrial Security Embedded

More information

TNO CERTIFICATION. NSCIB-CC Certification Report. Fort Fox Hardware Data Diode, version FFHDD2

TNO CERTIFICATION. NSCIB-CC Certification Report. Fort Fox Hardware Data Diode, version FFHDD2 TNO CERTIFICATION Laan van Westenenk 501 P.O. Box 541 7300 AM Apeldoorn The Netherlands Phone +31 55 5493468 Fax +31 55 5493288 E-mail: Certification@certi.tno.nl BTW/VAT NR NL8003.32.167.B01 Bank ING

More information

Security analysis and assessment of threats in European signalling systems?

Security analysis and assessment of threats in European signalling systems? Security analysis and assessment of threats in European signalling systems? New Challenges in Railway Operations Dr. Thomas Störtkuhl, Dr. Kai Wollenweber TÜV SÜD Rail Copenhagen, 20 November 2014 Slide

More information

BSI-CC-PP for. FIDO Universal Second Factor (U2F) Authenticator, Version 1.0. developed by. Federal Office for Information Security

BSI-CC-PP for. FIDO Universal Second Factor (U2F) Authenticator, Version 1.0. developed by. Federal Office for Information Security for FIDO Universal Second Factor (U2F) Authenticator, Version 1.0 developed by Federal Office for Information Security Federal Office for Information Security (BSI), Postfach 20 03 63, 53133 Bonn, Germany

More information

CSCE 548 Building Secure Software Biometrics (Something You Are) Professor Lisa Luo Spring 2018

CSCE 548 Building Secure Software Biometrics (Something You Are) Professor Lisa Luo Spring 2018 CSCE 548 Building Secure Software Biometrics (Something You Are) Professor Lisa Luo Spring 2018 Previous Class Credentials Something you know (Knowledge factors) Something you have (Possession factors)

More information

Security Standardization

Security Standardization ISO-ITU ITU Cooperation on Security Standardization Dr. Walter Fumy Chairman ISO/IEC JTC 1/SC 27 Chief Scientist, Bundesdruckerei GmbH, Germany 7th ETSI Security Workshop - Sophia Antipolis, January 2012

More information

Juniper Networks EX3200 and EX4200 Switches running JUNOS 9.3R2

Juniper Networks EX3200 and EX4200 Switches running JUNOS 9.3R2 122-B ASSURANCE MAINTENANCE REPORT MR1 (supplementing Certification Report No. CRP248) Juniper Networks EX3200 and EX4200 Switches running JUNOS 9.3R2 Version 9.3R2 Issue 1.0 February 2009 Crown Copyright

More information

Applying biometric authentication to physical access control systems

Applying biometric authentication to physical access control systems Applying biometric authentication to physical access control systems Published on 24 Jul 2018 Over the past few years, biometrics has rapidly expanded into consumer applications, like the financial market

More information

Athena IDProtect Duo (in BAC configuration) Version 10 running on Inside Secure AT90SC28880RCFV2

Athena IDProtect Duo (in BAC configuration) Version 10 running on Inside Secure AT90SC28880RCFV2 122 CERTIFICATION REPORT No. CRP283 Athena IDProtect Duo (in BAC configuration) Version 10 running on Inside Secure AT90SC28880RCFV2 Issue 1.0 July 2015 Crown Copyright 2015 All Rights Reserved Reproduction

More information

STORK Secure Identity Across Borders Linked

STORK Secure Identity Across Borders Linked STORK Secure Identity Across Borders Linked Projekt STORK Status und Ausblick 2011 BITKOM FA eid 20. Januar 2011 / Berlin Volker Reible / T-Systems Stork is an EU co-funded project INFSO-ICT-PSP-224993

More information

Trend Micro Professional Services Partner Program

Trend Micro Professional Services Partner Program Trend Micro Professional Services Partner Program PROGRAM OVERVIEW The Trend Micro Partner Program provides professional services companies with the certification, training, technical support and access

More information

Smart Card and Biometrics Used for Secured Personal Identification System Development

Smart Card and Biometrics Used for Secured Personal Identification System Development Smart Card and Biometrics Used for Secured Personal Identification System Development Mădălin Ştefan Vlad, Razvan Tatoiu, Valentin Sgârciu Faculty of Automatic Control and Computers, University Politehnica

More information

Put Identity at the Heart of Security

Put Identity at the Heart of Security Put Identity at the Heart of Security Strong Authentication via Hitachi Biometric Technology Tadeusz Woszczyński Country Manager Poland, Hitachi Europe Ltd. 20 September 2017 Financial security in the

More information

The European Union approach to Biometrics

The European Union approach to Biometrics The European Union approach to Biometrics gerald.santucci@cec.eu.int Head of Unit Trust & Security European Commission Directorate General Information Society The Biometric Consortium Conference 2003 1

More information

Fake Biometric System For Fingerprint, Iris, and face using QDA and SIFT

Fake Biometric System For Fingerprint, Iris, and face using QDA and SIFT Fake Biometric System For Fingerprint, Iris, and face using QDA and SIFT 1 Gummadidala Ravi Babu, 2 Nagandla Prasad 1 (M.Tech),DECS, Sai Thirumala NVR engineering College, Narasaraopeta, AP, INDIA. 2 Asst

More information

CIS 4360 Secure Computer Systems Biometrics (Something You Are)

CIS 4360 Secure Computer Systems Biometrics (Something You Are) CIS 4360 Secure Computer Systems Biometrics (Something You Are) Professor Qiang Zeng Spring 2017 Previous Class Credentials Something you know (Knowledge factors) Something you have (Possession factors)

More information

Access Control with Fingerprint Recognition

Access Control with Fingerprint Recognition Access Control with Fingerprint Recognition Christoph Busch Gjøvik University College http://www.christoph-busch.de/ Finse Winterschool May 7, 2014 Norwegian Biometrics Laboratory (NBL) A very international

More information

Hardening Fingerprint Authentication Systems Using Intel s SGX Enclave Technology. Interim Progress Report

Hardening Fingerprint Authentication Systems Using Intel s SGX Enclave Technology. Interim Progress Report Hardening Fingerprint Authentication Systems Using Intel s SGX Enclave Technology Interim Progress Report DELL-EMC Envision the Future Competition 2018 Table of Contents List of Figures... 3 List of tables...

More information

Ceri J Vincent. Chair of CO 2 GeoNet Executive Committee British Geological Survey. website:

Ceri J Vincent. Chair of CO 2 GeoNet Executive Committee British Geological Survey.   website: Ceri J Vincent Chair of CO 2 GeoNet Executive Committee British Geological Survey email: info@co2geonet.com website: www.co2geonet.eu CO 2 GeoNet: pan-european research association for advancing geological

More information

The emerging EU certification framework: A role for ENISA Dr. Andreas Mitrakas Head of Unit EU Certification Framework Conference Brussels 01/03/18

The emerging EU certification framework: A role for ENISA Dr. Andreas Mitrakas Head of Unit EU Certification Framework Conference Brussels 01/03/18 The emerging EU certification framework: A role for ENISA Dr. Andreas Mitrakas Head of Unit EU Certification Framework Conference Brussels 01/03/18 European Union Agency for Network and Information Security

More information

BSI-PP for. Protection Profile Waste Bin Identification Systems (WBIS-PP) Version developed by. Deutscher Städte- und Gemeindenbund

BSI-PP for. Protection Profile Waste Bin Identification Systems (WBIS-PP) Version developed by. Deutscher Städte- und Gemeindenbund Bundesamt für Sicherheit in der Informationstechnik BSI-PP-0010-2004 for Protection Profile Waste Bin Identification Systems (WBIS-PP) Version 1.04 developed by Deutscher Städte- und Gemeindenbund - Bundesamt

More information

Enhancing Critical Infrastructure Protection with innovative SECurity framework

Enhancing Critical Infrastructure Protection with innovative SECurity framework Enhancing Critical Infrastructure Protection with innovative SECurity framework Manos Athanatos FORTH-ICS, Distributed Computing Lab H2020 SAINT Project Workshop 20/03/2018 The research leading to these

More information

On the Vulnerability of Iris-Based Systems to a Software Attack Based on a Genetic Algorithm

On the Vulnerability of Iris-Based Systems to a Software Attack Based on a Genetic Algorithm On the Vulnerability of Iris-Based Systems to a Software Attack Based on a Genetic Algorithm Marta Gomez-Barrero, Javier Galbally, Pedro Tome, and Julian Fierrez Biometric Recognition Group-ATVS, EPS,

More information

ISO/IEC TR TECHNICAL REPORT. Information technology Security techniques Information security management guidelines for financial services

ISO/IEC TR TECHNICAL REPORT. Information technology Security techniques Information security management guidelines for financial services TECHNICAL REPORT ISO/IEC TR 27015 First edition 2012-12-01 Information technology Security techniques Information security management guidelines for financial services Technologies de l'information Techniques

More information

2018 HIPAA One All Rights Reserved. Beyond HIPAA Compliance to Certification

2018 HIPAA One All Rights Reserved. Beyond HIPAA Compliance to Certification 2018 HIPAA One All Rights Reserved. Beyond HIPAA Compliance to Certification Presenters Jared Hamilton CISSP CCSK, CCSFP, MCSE:S Healthcare Cybersecurity Leader, Crowe Horwath Erika Del Giudice CISA, CRISC,

More information

Guidance for Requirements for qualified trust service providers: trustworthy systems and products

Guidance for Requirements for qualified trust service providers: trustworthy systems and products Guidance for Requirements for qualified trust service providers: trustworthy systems and products Note on using the guidance: examples are used throughout they are not normative or exclusive, but there

More information

Digitising European industry

Digitising European industry Digitising European industry LETI Innovation Days 50 th Anniversary 28 June 2017 Dr. Max Lemke, European Commission, DG CONNECT Head of Unit Technologies & Systems for Digitising Industry #DigitiseEU CEA-LETI

More information

The SPARKS Project Motivation, Objectives and Results

The SPARKS Project Motivation, Objectives and Results The SPARKS Project Motivation, Objectives and Results Paul Smith paul.smith@ait.ac.at AIT Austrian Institute of Technology SEGRID Project Workshop 14 th November, 2016, Barcelona, Spain The SPARKS Project

More information

On security evaluation of fingerprint recognition systems

On security evaluation of fingerprint recognition systems On security evaluation of fingerprint recognition systems Olaf Henniger, Dirk Scheuermann, and Thomas Kniess Fraunhofer Institute for Secure Information Technology, Germany Abstract. This paper discusses

More information

Alain MERLE, PhD Strategic Marketing Manager CYBERSECURITY OF MEDICAL DEVICES

Alain MERLE, PhD Strategic Marketing Manager CYBERSECURITY OF MEDICAL DEVICES Alain MERLE, PhD Strategic Marketing Manager Alain.merle@cea.fr CYBERSECURITY OF MEDICAL DEVICES SECURITY OF MD: A BRIEF HISTORY 2 THE LAST PUBLICATIONS Security evaluation analysis Black box testing Covering

More information

ISO/IEC INTERNATIONAL STANDARD

ISO/IEC INTERNATIONAL STANDARD INTERNATIONAL STANDARD ISO/IEC 19795-7 First edition 2011-01-15 Information technology Biometric performance testing and reporting Part 7: Testing of on-card biometric comparison algorithms Technologies

More information

Face anti-spoofing using Image Quality Assessment

Face anti-spoofing using Image Quality Assessment Face anti-spoofing using Image Quality Assessment Speakers Prisme Polytech Orléans Aladine Chetouani R&D Trusted Services Emna Fourati Outline Face spoofing attacks Image Quality Assessment Proposed method

More information

Cybersecurity & Digital Privacy in the Energy sector

Cybersecurity & Digital Privacy in the Energy sector ENERGY INFO DAYS Brussels, 25 October 2017 Cybersecurity & Digital Privacy in the Energy sector CNECT.H1 Cybersecurity & Digital Privacy, DG CNECT ENER.B3 - Retail markets; coal & oil, DG ENER European

More information

BroadMap Brief Intro Final Stakeholders Workshop

BroadMap Brief Intro Final Stakeholders Workshop BroadMap Brief Intro Final Stakeholders Workshop 6 April 2017 Website: www.broadmap.eu PSCE Public Communications Europe Forum Member of the Board, BroadMap Project Coordinator www.broadmap.eu @BroadMap_H2020

More information