ISO/IEC 19785-4:2010
Information technology — Common Biometric Exchange Formats Framework — Part 4: Security block format specifications
Information technology — Common Biometric Exchange Formats Framework — Part 4: Security block format specifications
- Статус документа:
- Отменён
- Формат:
- Электронный (PDF)
- Количество страниц:
- 18
- Дата публикации:
- 12 августа 2010 г.
- Издание:
- ISO/IEC IS 19785 edition 1 version 1
- ICS:
- 35.040
ISO/IEC 19785-4:2010 specifies security block formats (see ISO/IEC 19785-1) registered in accordance with ISO/IEC 19785-2 as formats defined by the CBEFF biometric organization ISO/IEC JTC 1/SC 37, and specifies their registered security block format identifiers. [The security block format identifier is recorded in the standard biometric header (SBH) of a patron format (or defined by that patron format as the only available security block format).] The general-purpose security block format provides for specification of whether the biometric data block (BDB) is encrypted or the SBH and BDB have integrity applied (or both), and can include ACBio instances (see ISO/IEC 24761). This security block provides all necessary security parameters, including those used for encryption or integrity. It does not restrict the algorithms and parameters used for encryption or integrity, but provides for the recording of such algorithms and parameter values. It is a matter for profiling to determine, for a particular application area, what algorithms and parameter ranges can be used by the generator of a security block, and hence what algorithms and parameter ranges have to be supported by the user of a security block. This is out of the scope of ISO/IEC 19785-4:2010. The second security block is more limited, but simpler (and in particular cannot contain ACBio instances, and does not support encryption of the BDB).
Abstract
Overview
ISO/IEC 19785-4:2010 defines security block format specifications for the Common Biometric Exchange Formats Framework (CBEFF). It registers two CBEFF security block formats (by ASN.1/Object Identifier and encoding) and specifies how security metadata is recorded in the Standard Biometric Header (SBH) to express integrity and/or encryption of biometric data blocks (BDBs). The document is intended to ensure interoperable protection of biometric information while allowing profiling for application-specific algorithm and parameter choices.
Key topics and technical requirements
- Two security block formats
- General-purpose security block: supports integrity and optional encryption of the BDB and SBH, may include ACBio instances (Authentication Context for Biometrics), and provides full security parameters. It uses RFC 3852 Cryptographic Message Syntax (CMS) with tailored handling of EnvelopedData, EncryptedData, SignedData and AuthenticatedData.
- Signature-only security block: simpler format that supports integrity (signatures) only; cannot contain ACBio instances and does not support BDB encryption.
- Registration and identifiers
- Registered format identifiers and ASN.1 object identifiers (OIDs) are defined for DER, PER and XER encodings so implementers can unambiguously reference the formats.
- Format encoding and structure
- Security blocks are defined using ASN.1 types (module provided in Annex A). The CBEFFSecurityBlock type is a sequence of elements (ContentInfoCBEFFSB, SubBlockForACBio, or ACBioInstances).
- Algorithm neutrality and profiling
- The standard records algorithm identifiers and parameters but does not mandate specific cryptographic algorithms or parameter ranges. Profiling for an application area determines permitted algorithms and required implementations (this profiling is out of scope of ISO/IEC 19785-4).
- Normative references
- References include ISO/IEC 19785-1/2, ISO/IEC 24761, RFC 3852 (CMS), RFC 5911, and ASN.1 encoding standards.
Applications and users
- Who uses it: biometric system architects, identity management vendors, government ID/visa/passport authorities, biometric device and software vendors, security integrators, and standards bodies creating CBEFF patron formats.
- Use cases:
- Securing biometric data in transit and at rest (ensuring integrity, optionally confidentiality).
- Embedding security metadata in CBEFF-compliant records for interoperable exchange between capture, storage, matching, and verification systems.
- Supporting telebiometric authentication infrastructures (TAI) by conveying authentication context via ACBio instances.
Related standards
- ISO/IEC 19785-1 (CBEFF data elements)
- ISO/IEC 19785-2 (registration procedures)
- ISO/IEC 19785-3 (patron formats)
- ISO/IEC 24761 (Authentication Context for Biometrics)
- RFC 3852 / RFC 5911 (Cryptographic Message Syntax)
- ISO/IEC 8824 / 8825 (ASN.1 and encodings)
Keywords: ISO/IEC 19785-4, CBEFF security block format, biometric security, SBH, BDB encryption, integrity, ACBio, RFC 3852, CMS, interoperability.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 37 - Biometrics
- SKU
- ISO/IEC 19785-4:2010
Похожие стандарты
Стандарты, упомянутые в описании
ISO/IEC 19785-4:2025
ДействующийInformation technology — Common Biometric Exchange Formats Framework — Part 4: Security block format specific…
Overview ISO/IEC 19785-4:2025 specifies security block (SB) formats and registered SB format identifiers for the Common Biometric Exchange Formats Framework (CBEFF). It defines how biometric data blo…