1、BSI Standards Publication BS ISO/IEC 24787:2010 Information technology Identification cards On-card biometric comparison BS ISO/IEC 24787:2010 Incorporating corrigendum June 2013BS ISO/IEC 24787:2010 BRITISH STANDARD National foreword This British Standard is the UK implementation of ISO/IEC 24787:2
2、010, incorporating corrigendum June 2013. The start and finish of text introduced or altered by corrigendum is indicated in the text by tags. Text altered by ISO/IEC corrigendum June 2013 is indicated in the text by . The UK participation in its preparation was entrusted to Technical Committee IST/1
3、7, Cards and personal identification. A list of organizations represented on this committee can be obtained on request to its secretary. This publication does not purport to include all the necessary provisions of a contract. Users are responsible for its correct application. The British Standards I
4、nstitution 2013. Published by BSI Standards Limited 2013 ISBN 978 0 580 83488 2 ICS 35.240.15 Compliance with a British Standard cannot confer immunity from legal obligations. This British Standard was published under the authority of the Standards Policy and Strategy Committee on 28 February 2011.
5、Amendments/corrigenda issued since publication Date Text affected 31 July 2013 Implementation of ISO/IEC corrigendum June 2013BS ISO/IEC 24787:2010Reference number ISO/IEC 24787:2010(E) ISO/IEC 2010INTERNATIONAL STANDARD ISO/IEC 24787 First edition 2010-12-15 Information technology Identification ca
6、rds On-card biometric comparison Technologies de linformation Cartes didentification Comparaison biomtrique sur cartes BS ISO/IEC 24787:2010 ISO/IEC 24787:2010(E) PDF disclaimer This PDF file may contain embedded typefaces. In accordance with Adobes licensing policy, this file may be printed or view
7、ed but shall not be edited unless the typefaces which are embedded are licensed to and installed on the computer performing the editing. In downloading this file, parties accept therein the responsibility of not infringing Adobes licensing policy. The ISO Central Secretariat accepts no liability in
8、this area. Adobe is a trademark of Adobe Systems Incorporated. Details of the software products used to create this PDF file can be found in the General Info relative to the file; the PDF-creation parameters were optimized for printing. Every care has been taken to ensure that the file is suitable f
9、or use by ISO member bodies. In the unlikely event that a problem relating to it is found, please inform the Central Secretariat at the address given below. COPYRIGHT PROTECTED DOCUMENT ISO/IEC 2010 All rights reserved. Unless otherwise specified, no part of this publication may be reproduced or uti
10、lized in any form or by any means, electronic or mechanical, including photocopying and microfilm, without permission in writing from either ISO at the address below or ISOs member body in the country of the requester. ISO copyright office Case postale 56 CH-1211 Geneva 20 Tel. + 41 22 749 01 11 Fax
11、 + 41 22 749 09 47 E-mail copyrightiso.org Web www.iso.org Published in Switzerland ii ISO/IEC 2010 All rights reservedii ISO/IEC 2010 All rights reservedBS ISO/IEC 24787:2010 ISO/IEC 24787:2010(E) ISO/IEC 2010 All rights reserved iiiContents Page Foreword .v Introductionvi 1 Scope1 2 Conformance.1
12、3 Normative references2 4 Terms and definitions .2 5 Abbreviated terms.4 6 Architecture of biometric matching using an ICC .5 6.1 General.5 6.2 Off-card comparison .5 6.3 On-card comparison (sensor-off-card) .6 6.4 Work-sharing on-card comparison7 6.5 System-on-card comparison8 7 General framework f
13、or on-card comparison applications 8 7.1 Data for on-card comparison .8 7.1.1 General.8 7.1.2 Biometric reference object handling.8 7.1.3 Configuration data for biometric verification .9 7.1.4 Shared interface for multiple applications11 7.1.5 Retry counter management15 7.2 Standard processes for on
14、-card comparison 15 7.2.1 Application identifier (AID) for on-card biometric comparison 15 7.2.2 Read biometric reference data.15 7.2.3 Enrolment.15 7.2.4 Verification.16 7.2.5 Termination of on-card comparison application16 7.2.6 Comparison process and result output 16 7.2.7 Security requirements a
15、nd biometric reference management .16 7.2.8 Threshold management17 8 Work-sharing.17 8.1 Runtime work-sharing mechanism using WSR protocol17 8.2 Work-sharing management 18 8.2.1 General.18 8.2.2 Work-sharing procedure discovery.19 8.2.3 Work-sharing procedure operation .19 Annex A (normative) Common
16、 TLV-structure of the file control parameter 20 Annex B (normative) Security policies for on-card biometric comparison 21 B.1 Introduction21 B.2 Common security policies (CSP) for on-card biometric comparison22 B.3 Security policies (SP1) for global comparison configuration data 22 B.4 Security poli
17、cies (SP2) for local comparison configuration data 23 Annex C (informative) Sample APDU for on-card comparison 24 Annex D (informative) Software shareable interface for biometrics comparison27 D.1 General.27 D.2 Shareable Interface Mechanism.27 BS ISO/IEC 24787:2010 ISO/IEC 24787:2010(E) ISO/IEC 201
18、0 All rights reserved iiiContents Page Foreword .v Introductionvi 1 Scope1 2 Conformance.1 3 Normative references2 4 Terms and definitions .2 5 Abbreviated terms.4 6 Architecture of biometric matching using an ICC .5 6.1 General.5 6.2 Off-card comparison .5 6.3 On-card comparison (sensor-off-card) .
19、6 6.4 Work-sharing on-card comparison7 6.5 System-on-card comparison8 7 General framework for on-card comparison applications 8 7.1 Data for on-card comparison .8 7.1.1 General.8 7.1.2 Biometric reference object handling.8 7.1.3 Configuration data for biometric verification .9 7.1.4 Shared interface
20、 for multiple applications11 7.1.5 Retry counter management15 7.2 Standard processes for on-card comparison 15 7.2.1 Application identifier (AID) for on-card biometric comparison 15 7.2.2 Read biometric reference data.15 7.2.3 Enrolment.15 7.2.4 Verification.16 7.2.5 Termination of on-card compariso
21、n application16 7.2.6 Comparison process and result output 16 7.2.7 Security requirements and biometric reference management .16 7.2.8 Threshold management17 8 Work-sharing.17 8.1 Runtime work-sharing mechanism using WSR protocol17 8.2 Work-sharing management 18 8.2.1 General.18 8.2.2 Work-sharing p
22、rocedure discovery.19 8.2.3 Work-sharing procedure operation .19 Annex A (normative) Common TLV-structure of the file control parameter 20 Annex B (normative) Security policies for on-card biometric comparison 21 B.1 Introduction21 B.2 Common security policies (CSP) for on-card biometric comparison2
23、2 B.3 Security policies (SP1) for global comparison configuration data 22 B.4 Security policies (SP2) for local comparison configuration data 23 Annex C (informative) Sample APDU for on-card comparison 24 Annex D (informative) Software shareable interface for biometrics comparison27 D.1 General.27 D
24、.2 Shareable Interface Mechanism.27 BS ISO/IEC 24787:2010 ISO/IEC 24787:2010(E) ISO/IEC 2010 All rights reserved iiiContents Page Foreword .v Introductionvi 1 Scope1 2 Conformance.1 3 Normative references2 4 Terms and definitions .2 5 Abbreviated terms.4 6 Architecture of biometric matching using an
25、 ICC .5 6.1 General.5 6.2 Off-card comparison .5 6.3 On-card comparison (sensor-off-card) .6 6.4 Work-sharing on-card comparison7 6.5 System-on-card comparison8 7 General framework for on-card comparison applications 8 7.1 Data for on-card comparison .8 7.1.1 General.8 7.1.2 Biometric reference obje
26、ct handling.8 7.1.3 Configuration data for biometric verification .9 7.1.4 Shared interface for multiple applications11 7.1.5 Retry counter management15 7.2 Standard processes for on-card comparison 15 7.2.1 Application identifier (AID) for on-card biometric comparison 15 7.2.2 Read biometric refere
27、nce data.15 7.2.3 Enrolment.15 7.2.4 Verification.16 7.2.5 Termination of on-card comparison application16 7.2.6 Comparison process and result output 16 7.2.7 Security requirements and biometric reference management .16 7.2.8 Threshold management17 8 Work-sharing.17 8.1 Runtime work-sharing mechanis
28、m using WSR protocol17 8.2 Work-sharing management 18 8.2.1 General.18 8.2.2 Work-sharing procedure discovery.19 8.2.3 Work-sharing procedure operation .19 Annex A (normative) Common TLV-structure of the file control parameter 20 Annex B (normative) Security policies for on-card biometric comparison
29、 21 B.1 Introduction21 B.2 Common security policies (CSP) for on-card biometric comparison22 B.3 Security policies (SP1) for global comparison configuration data 22 B.4 Security policies (SP2) for local comparison configuration data 23 Annex C (informative) Sample APDU for on-card comparison 24 Anne
30、x D (informative) Software shareable interface for biometrics comparison27 D.1 General.27 D.2 Shareable Interface Mechanism.27 BS ISO/IEC 24787:2010 ISO/IEC 24787:2010(E) ISO/IEC 2010 All rights reserved iiiContents Page Foreword .v Introductionvi 1 Scope1 2 Conformance.1 3 Normative references2 4 T
31、erms and definitions .2 5 Abbreviated terms.4 6 Architecture of biometric matching using an ICC .5 6.1 General.5 6.2 Off-card comparison .5 6.3 On-card comparison (sensor-off-card) .6 6.4 Work-sharing on-card comparison7 6.5 System-on-card comparison8 7 General framework for on-card comparison appli
32、cations 8 7.1 Data for on-card comparison .8 7.1.1 General.8 7.1.2 Biometric reference object handling.8 7.1.3 Configuration data for biometric verification .9 7.1.4 Shared interface for multiple applications11 7.1.5 Retry counter management15 7.2 Standard processes for on-card comparison 15 7.2.1 A
33、pplication identifier (AID) for on-card biometric comparison 15 7.2.2 Read biometric reference data.15 7.2.3 Enrolment.15 7.2.4 Verification.16 7.2.5 Termination of on-card comparison application16 7.2.6 Comparison process and result output 16 7.2.7 Security requirements and biometric reference mana
34、gement .16 7.2.8 Threshold management17 8 Work-sharing.17 8.1 Runtime work-sharing mechanism using WSR protocol17 8.2 Work-sharing management 18 8.2.1 General.18 8.2.2 Work-sharing procedure discovery.19 8.2.3 Work-sharing procedure operation .19 Annex A (normative) Common TLV-structure of the file
35、control parameter 20 Annex B (normative) Security policies for on-card biometric comparison 21 B.1 Introduction21 B.2 Common security policies (CSP) for on-card biometric comparison22 B.3 Security policies (SP1) for global comparison configuration data 22 B.4 Security policies (SP2) for local compar
36、ison configuration data 23 Annex C (informative) Sample APDU for on-card comparison 24 Annex D (informative) Software shareable interface for biometrics comparison27 D.1 General.27 D.2 Shareable Interface Mechanism.27 BS ISO/IEC 24787:2010 ISO/IEC 24787:2010(E) ISO/IEC 2010 All rights reserved iiiCo
37、ntents Page Foreword .v Introductionvi 1 Scope1 2 Conformance.1 3 Normative references2 4 Terms and definitions .2 5 Abbreviated terms.4 6 Architecture of biometric matching using an ICC .5 6.1 General.5 6.2 Off-card comparison .5 6.3 On-card comparison (sensor-off-card) .6 6.4 Work-sharing on-card
38、comparison7 6.5 System-on-card comparison8 7 General framework for on-card comparison applications 8 7.1 Data for on-card comparison .8 7.1.1 General.8 7.1.2 Biometric reference object handling.8 7.1.3 Configuration data for biometric verification .9 7.1.4 Shared interface for multiple applications1
39、1 7.1.5 Retry counter management15 7.2 Standard processes for on-card comparison 15 7.2.1 Application identifier (AID) for on-card biometric comparison 15 7.2.2 Read biometric reference data.15 7.2.3 Enrolment.15 7.2.4 Verification.16 7.2.5 Termination of on-card comparison application16 7.2.6 Compa
40、rison process and result output 16 7.2.7 Security requirements and biometric reference management .16 7.2.8 Threshold management17 8 Work-sharing.17 8.1 Runtime work-sharing mechanism using WSR protocol17 8.2 Work-sharing management 18 8.2.1 General.18 8.2.2 Work-sharing procedure discovery.19 8.2.3
41、 Work-sharing procedure operation .19 Annex A (normative) Common TLV-structure of the file control parameter 20 Annex B (normative) Security policies for on-card biometric comparison 21 B.1 Introduction21 B.2 Common security policies (CSP) for on-card biometric comparison22 B.3 Security policies (SP
42、1) for global comparison configuration data 22 B.4 Security policies (SP2) for local comparison configuration data 23 Annex C (informative) Sample APDU for on-card comparison 24 Annex D (informative) Software shareable interface for biometrics comparison27 D.1 General.27 D.2 Shareable Interface Mech
43、anism.27 iii ISO/IEC 2010 All rights reserved 6.2 Off-card biometric comparison .5 6.3 On-card biometric comparison (sensor-off-card) .6 6.4 Work-sharing on-card biometric comparison 7 6.5 System-on-card biometric comparison 8 7 General framework for on-card biometric comparison applications 8 7.1 D
44、ata for on-card biometric comparison .8 7.2 Standard processes for on-card biometric comparison .15 7.2.5 Termination of on-card biometric comparison application 16 Annex C (informative) Sample APDU for on-card biometric comparison 24BS ISO/IEC 24787:2010 ISO/IEC 24787:2010(E) iv ISO/IEC 2010 All ri
45、ghts reservedAnnex E (informative) Recommendation for security mechanisms in on-card comparison . 29 E.1 General.29 E.2 Mutual authentication. 29 E.3 Message integrity 29 E.4 Confidentiality.29 E.5 Prevention of replay attack using MAC with secret key. 30 Annex F (informative) Architecture for work-
46、sharing on-card comparison. 31 F.1 General.31 F.2 Work-sharing architecture for on-card comparison . 31 F.3 Types of work-sharing strategy used for on-card comparison . 32 F.3.1 General.32 F.3.2 Pre-comparison computation 32 F.3.3 Work-sharing at runtime 32 F.4 Work-sharing computation protocol. 32
47、Annex G (informative) Examples of implementations of on-card biometric comparison mechanisms 34 G.1 Introduction.34 G.2 Single Application, Homogeneous Usage . 34 G.3 Single Application, Heterogeneous Usage 35 G.4 Multiple Applications 35 Annex H (informative) State diagram of a card performing a WS
48、R session when needed 37 Bibliography. 38 BS ISO/IEC 24787:2010 ISO/IEC 24787:2010(E) iv ISO/IEC 2010 All rights reservedAnnex E (informative) Recommendation for security mechanisms in on-card comparison . 29 E.1 General.29 E.2 Mutual authentication. 29 E.3 Message integrity 29 E.4 Confidentiality.2
49、9 E.5 Prevention of replay attack using MAC with secret key. 30 Annex F (informative) Architecture for work-sharing on-card comparison. 31 F.1 General.31 F.2 Work-sharing architecture for on-card comparison . 31 F.3 Types of work-sharing strategy used for on-card comparison . 32 F.3.1 General.32 F.3.2 Pre-comparison computation 32 F.3.3 Work-sharing at runtime 32 F.4 Work-sharing computation protocol. 32 Annex G (informative) Examples of implementations of on-card biometric comparison mechanisms 34 G.1 Introduction.34 G.2 Sing