ISO/IEC DIS 19785-4.2
Information technology — Common biometric exchange formats framework — Part 4: Security block format specifications
| Organization: | ISO |
| Publication Date: | 25 October 2023 |
| Status: | pending |
| Page Count: | 25 |
| ICS Code (Identification cards. Chip cards. Biometrics): | 35.240.15 |
scope:
This document specifies security block formats (see ISO/IEC 19785-1) registered in accordance with ISO/IEC 19785-2 as formats defined by the CBEFF biometric organization ISO/IEC JTC 1/SC 37, and specifies their registered security block format identifiers.
NOTE The security block format identifier is recorded in the standard biometric header (SBH) of a patron format (or defined by that patron format as the only available security block format).
The general-purpose security block format provides for specification of whether the biometric data block (BDB) is encrypted or the SBH and BDB have integrity applied (or both), and can include ACBio instances (see ISO/IEC 24761). This security block provides all necessary security parameters, including those used for encryption or integrity.
It does not restrict the algorithms and parameters used for encryption or integrity, but provides for the recording of such algorithms and parameter values.
It is a matter for profiling to determine, for a particular application area, what algorithms and parameter ranges can be used by the generator of a security block, and hence what algorithms and parameter ranges have to be supported by the user of a security block. This is out of the scope of this document.
The second security block is more limited, but simpler (and in particular cannot contain ACBio instances, and does not support encryption of the BDB).
The general-purpose security block format in XML provides for specification of whether the BDB is encrypted or the SBH and BDB have integrity applied (or both).
Document History