Identity Cards are tokens that are used to verify the identity of the cardholder. Identity Cards that do not comply with ICAO’s standard for Machine Readable Travel Documents are, for example, food distribution cards, insurance cards, voter cards, driver’s licenses, permits etc. The purpose of the identity card card is to store key biographic information, possibly in combination with biometrics like facial or fingerprint information.
For applications in which the biometric identity verification takes place in a terminal, the identity card is used primarily for storage. This is attractive from a processing and cost perspective, because the terminal has more processing resources than any card, and when a card only needs to provide storage, low-cost solutions can be selected. However, a solid protection mechanism is then required to safeguard the storage of the biometric (fingerprint) information, the communication to the terminal and the biometric processing in the terminal.
Current security mechanisms are typically based on traditional encryption technology usually in the form of a Public Key Infrastructure. These mechanisms do not meet today’s requirements for availability, security and privacy that is associated with the personal and highly privacy sensitive biometric information, because in any traditional biometric match, the fingerprint images ultimately need to be available in-the-clear (for the matching process) making them very vulnerable for misuse.
Traditionally, the only solution to this has been Match-on-Card where the biometrics is stored inside a smart card and never leaves the card. With the intrinsic security of BioHASH®, MoC is no longer the only privacy-respecting and secure solution, and identity verification in a terminal becomes a very viable option.
Benefits
GenKey’s BioHASH® solution protects the biometric information using a cryptographic hash function. This offers the following benefits when used in combination with identity documents
- Low-complex security architecture with off-line deployment: The BioHASH® templates ensure intrinsic security, making it possible to perform verification without an on-line connection or exchange of certificates.
- Barcode or RFID templates: The small template size of 180 bytes gives the possibility to store the BioHASH® templates on contactless RFID or simple barcodes. Not only does this provide a cost benefit, it also introduces flexibility in the card design process. For example, in the case of barcodes, card personalization can be done with simple off-the-shelf card printers.
Markets & Product
GenKey’s BioHASH® SecureID SDK provides all the functionalities to deploy Biometric Identity Cards. The enrollment SDK can be integrated in an enrollment application and translates a fingerprint image into a BioHASH® template or a barcode. The extraction and verification SDK’s can be integrated in any terminal to read the BioHASH® template or barcode and compare it to a live measurement. The BioHASH® SecureID SDK is suited for any type of Identity Card.
