ISO/IEC 19785-4:2010 pdf – Information technology — Common Biometric Exchange Formats Framework — Part 4: Security block format specifications.
1 Scope This part of ISO/IEC 19785 specifies security block formats (see ISO/IEC 19785-1) registered in accordance with ISO/IEC 19785-2 as formats defined by the CBEFF biometric organization ISO/IEC JTC 1/SC 37, and specifies their registered security block format identifiers. NOTE The security block format identifier is recorded in the standard biometric header (SBH) of a patron format (or defined by that patron format as the only available security block format). The general-purpose security block format provides for specification of whether the biometric data block (BDB) is encrypted or the SBH and BDB have integrity applied (or both), and can include ACBio instances (see ISO/IEC 24761). This security block provides all necessary security parameters, including those used for encryption or integrity. It does not restrict the algorithms and parameters used for encryption or integrity, but provides for the recording of such algorithms and parameter values. It is a matter for profiling to determine, for a particular application area, what algorithms and parameter ranges can be used by the generator of a security block, and hence what algorithms and parameter ranges have to be supported by the user of a security block. This is out of the scope of this part of ISO/IEC 19785. The second security block is more limited, but simpler (and in particular cannot contain ACBio instances, and does not support encryption of the BDB). 2 Normative references The following referenced documents are indispensable for the application of this document. For dated references, only the edition cited applies. For undated references, the latest edition of the referenced document (including any amendments) applies. ISO/IEC 8824 (all parts) | ITU-T Rec. X.680–683, Information technology — Abstract Syntax Notation One (ASN.1) ISO/IEC 8825 (all parts) | ITU-T Rec. X.690–693, Information technology — ASN.1 encoding rules
ISO/IEC 24761, Information technology — Security techniques — Authentication context for biometrics RFC 3852, Cryptographic Message Syntax (CMS), July 2004 RFC 5911, New ASN.1 Modules for Cryptographic Message Syntax (CMS) and S-MIME, June 2010 3 Terms and definitions 3.1 Terms defined in ISO/IEC 19785-1 For the purposes of this document, the following terms defined in ISO/IEC 19785-1 apply: biometric, biometrics, biometric data block (BDB), biometric information record (BIR), CBEFF biometric organization, security block (SB), security block format, security block format identifier, security block format owner, standard biometric header (SBH). 3.2 Terms defined in ISO/IEC 19784-1 For the purposes of this document, the following term defined in ISO/IEC 19784-1 applies: BioAPI Unit. 3.3 Terms defined in ISO/IEC 24761 For the purposes of this document, the following terms defined in ISO/IEC 24761 apply: ACBio instance, authentication context for biometrics (ACBio), biometric processing unit (BPU). 3.4 Terms defined in ISO/IEC 9798-6 For the purposes of this document, the following term defined in ISO/IEC 9798-6 applies: message authentication code. 4 Abbreviated terms 4.1 Abbreviated terms defined in ISO/IEC 19785-1 For the purposes of this document, the following abbreviated terms in ISO/IEC 19785-1 apply: BDB, BIR, CBEFF, SB, SBH. 4.2 Abbreviated terms defined in ISO/IEC 24761 For the purposes of this document, the following abbreviated terms in ISO/IEC 24761 apply: ACBio, BPU. 4.3 Abbreviated terms defined in ISO/IEC 9798-6 For the purposes of this document, the following abbreviated term in ISO/IEC 9798-6 applies: MAC.
4.4 Abbreviated terms defined in RFC 3852 For the purposes of this document, the following abbreviated term in RFC 3852 applies: CRL. 5 Security block format: general purpose 5.1 Security block format owner ISO/IEC JTC 1/SC 37 5.2 Security block format owner identifier 257 (0101Hex) . This identifier has been assigned in accordance with ISO/IEC 19785-2 to ISO/IEC JTC 1/SC 37 as a CBEFF biometric organization. 5.3 Security block format name ISO/IEC JTC 1/SC 37 CBEFF general-purpose security block format 5.4 Security block format identifier 1 (0001 Hex) . This has been registered in accordance with ISO/IEC 19785-2 when DER encodings (see ISO/IEC 8825-1) are applied. 2 (0002 Hex) . This has been registered in accordance with ISO/IEC 19785-2 when canonical PER encodings (see ISO/IEC 8825-2) are applied. 3 (0003 Hex) . This has been registered in accordance with ISO/IEC 19785-2 when canonical XER encodings (see ISO/IEC 8825-3) are applied. 5.5 ASN.1 object identifier for this security block format 5.5.1 The case of DER encodings {iso registration-authority cbeff(19785) organizations(0) jtc-sc37 (257) sb-formats(3) general-purpose(0) der-encoding(1) } or, in XML value notation, 1.1.19785.0.257.3.0.1 5.5.2 The case of canonical PER encodings {iso registration-authority cbeff(19785) organizations(0) jtc-sc37 (257) sb-formats(3) general-purpose(0) per-encoding(2) } or, in XML value notation, 1.1.19785.0.257.3.0.2
www.findfreestandards.com