E N D
1. Bruce WillinsSymbol TechnologiesSr Director R&D How many are piloting or considering biometrics.
How many are piloting or considering biometrics.
4. Mobile Security FIPS, HIPPA, Finance, TCPA, CRYSIS…
Terminal Firewall, Secure Policy Mgmt,
802.11 Black program
Describe Red/black interface of terminal
NY times article.
Mobile Security Architecture Document
FIPS, HIPPA, Finance, TCPA, CRYSIS…
Terminal Firewall, Secure Policy Mgmt,
802.11 Black program
Describe Red/black interface of terminal
NY times article.
Mobile Security Architecture Document
5. Security Encompasses Many Layers
6. Enterprise Synergy Is Critical Issue Is that Standard Radius Was not designed to meet the three necessary requirements for 802.11:
- Mutual Authentication
- Secure Key Generation & Distribution
- Facilitate Roaming
What is standard enterprise security ? LEAP?Issue Is that Standard Radius Was not designed to meet the three necessary requirements for 802.11:
- Mutual Authentication
- Secure Key Generation & Distribution
- Facilitate Roaming
What is standard enterprise security ? LEAP?
8. State of The Biometric Industry ~ 150 Biometric Companies
Veridicom dismantled in August
2001: 60%+ growth (post 9/11/01)
Harris Interactive (consulting) +9/11
“eighty-two percent of Americans are willing to have their fingerprints scanned for increased airport security”
“86 percent favor facial-recognition technology to scan for suspected terrorists”
(CNBC 9/19/01: Alan Dershowitz: “facial recognition is better than racial profiling”) Number of people surveyed?
Veridicom: spinoff from Lucent/Bell Labs in 1997, 1st commercial finger print sensor, Number of people surveyed?
Veridicom: spinoff from Lucent/Bell Labs in 1997, 1st commercial finger print sensor,
9. Biometrics Makes Famous Quotes List Wall Street Journal 11/13/01
“The Airport of The Future”“A special scanner scrapped in Charlotte, N.C., identified people by their iris but couldn’t detect guns.”
11. IBG-BioPrivacy25 Best Practices Protection of bio-data: storage, transmission…
Protection of Post Match Decisions
Explicit definition & disclosure of scope
Destruction of Dated Bio-Data
No Surreptitious Collection of Biometrics
Destruction of Raw bio-data (retention only of templates)
Right to unenroll
Active Matching Disclosure
Full Disclosure of Independent Audits
Disclosure of biometric alternatives Dollar Rental Dollar Rental
13. Bio-App Questionnaire Cooperative or Non-Cooperative ?
Overt or Covert ?
Habituated or Non-Habituated ?
Static or Dynamic Environment ?
Identification or Verification ?
Responsiveness (seconds) ?
Target Population ?
Enrollment Source ?
Attended or Unattended ?
Cost of FAR / FRR ?
Temporal Limits (template aging) Describe Cooperative or non-cooperativeDescribe Cooperative or non-cooperative
14. Obvious Applications For Biometrics-80/20 Rule To Expedite Airport Clearance
15. Change The Process
Expedited Passenger Processing System (EPPS)
By Brian Glancy,
The Government of Canada (GOC) portion of EPPS, is an automated primary inspection process at airports for pre-approved air travelers using automated kiosks and biometrics to confirm identity and verify admissibility. EPPS provides an alternative inspection process to “known risk” travelers allowing customs inspectors to concentrate their efforts on unknown travelers.
EPPS is a joint initiative between the GOC, namely the Canada Customs & Revenue Agency (CCRA), Citizenship & Immigration Canada (CIC), the Canadian Passport Office, and the Canadian Airports Council. The EPPS vision is to provide international air travelers with a host of ramp-to-curbside convenience services such as expedited luggage delivered to their hotel room, internet or other communications access, rental and valet services waiting at the curbside, and pre-arrival hotel check-in etc. The Government of Canada automated primary inspection process, is the first service being offered to EPPS participants.
EPPS is aimed at the frequent international business/frequent traveler. Initially, all citizens and permanent residents of Canada and the U.S. can participate in EPPS unless deemed inadmissible to Canada. Each participant will be security vetted using risk rating based on the results of background checks. Any applicant having previous criminal or border contravention history will not be accepted into the EPPS program. In subsequent phases, citizens of other countries will be offered membership based on visa requirements.
EPPS participants will enter Canada by accessing an automated kiosk located in the Customs primary area of the airport. During each passage, the participant’s biometrics will be verified using iris recognition technology in order to confirm identity, the participant will then make their Customs declaration electronically, and the individual’s risk rating will be taken into consideration in the referral determination.
Implementation of Phase I of EPPS, the automated primary inspection process is anticipated to begin by the beginning of next year at Vancouver, Calgary, Toronto, and Montreal International Airports. During the Fall of next year, phase II will expanded to include Edmonton, Winnipeg, Ottawa and Halifax airports.
Each airport of Phase I and II have a representative on the EPPS Regional Coordinators Committee consisting of CCRA and CIC officers. Meetings are being held on a regular basis with Phase I airports in order to document the requirements for design, development, and implementation.
Editors note:
Brian Glancy is a Senior Project Advisor for the Major Project Design & Development Directorate (MPDDD), Expedited Passenger Processing Systems Project, Canada Customs and Revenue Agency (CCRA) based in Ottawa, Canada.
Please refer any questions you have about this project to Brian Glancy, telephone: (613) 957-1209 or fax: (613) 954-7558.
Expedited Passenger Processing System (EPPS)
By Brian Glancy,
The Government of Canada (GOC) portion of EPPS, is an automated primary inspection process at airports for pre-approved air travelers using automated kiosks and biometrics to confirm identity and verify admissibility. EPPS provides an alternative inspection process to “known risk” travelers allowing customs inspectors to concentrate their efforts on unknown travelers.
EPPS is a joint initiative between the GOC, namely the Canada Customs & Revenue Agency (CCRA), Citizenship & Immigration Canada (CIC), the Canadian Passport Office, and the Canadian Airports Council. The EPPS vision is to provide international air travelers with a host of ramp-to-curbside convenience services such as expedited luggage delivered to their hotel room, internet or other communications access, rental and valet services waiting at the curbside, and pre-arrival hotel check-in etc. The Government of Canada automated primary inspection process, is the first service being offered to EPPS participants.
EPPS is aimed at the frequent international business/frequent traveler. Initially, all citizens and permanent residents of Canada and the U.S. can participate in EPPS unless deemed inadmissible to Canada. Each participant will be security vetted using risk rating based on the results of background checks. Any applicant having previous criminal or border contravention history will not be accepted into the EPPS program. In subsequent phases, citizens of other countries will be offered membership based on visa requirements.
EPPS participants will enter Canada by accessing an automated kiosk located in the Customs primary area of the airport. During each passage, the participant’s biometrics will be verified using iris recognition technology in order to confirm identity, the participant will then make their Customs declaration electronically, and the individual’s risk rating will be taken into consideration in the referral determination.
Implementation of Phase I of EPPS, the automated primary inspection process is anticipated to begin by the beginning of next year at Vancouver, Calgary, Toronto, and Montreal International Airports. During the Fall of next year, phase II will expanded to include Edmonton, Winnipeg, Ottawa and Halifax airports.
Each airport of Phase I and II have a representative on the EPPS Regional Coordinators Committee consisting of CCRA and CIC officers. Meetings are being held on a regular basis with Phase I airports in order to document the requirements for design, development, and implementation.
Editors note:
Brian Glancy is a Senior Project Advisor for the Major Project Design & Development Directorate (MPDDD), Expedited Passenger Processing Systems Project, Canada Customs and Revenue Agency (CCRA) based in Ottawa, Canada.
17. Anatomy of a Secure Boarding Pass RSA verification is about 10x faster than verification than DSS
RSA verification is about 10x faster than verification than DSS
18. Picture PDF – Simple Tokens JPEG 2000 – byte counts w/file headers stripped
Requires Human Intervention
Subversion
Error prone
Time consuming
19. Creating Biometric Secure Paper Tokens
20. Symbol Secure PDF Is A Temporal Paper Token That:
- Is Highly Difficult To Counterfeit
- Assures Issuer Authenticity Via Digital Signature
- Bound To The Individual Person via Biometrics
- Easily Generated: Mobile or Fixed Platforms
- Easily Verified: Mobile or Fixed Platforms
21. Authenticated Human Tracking System in place using phone over 1M calls/day.System in place using phone over 1M calls/day.
22. Taliban & Foreign National Prisoner Registration
23. Stability birth-to-slaughter
Scarring
RFID tagsStability birth-to-slaughter
Scarring
RFID tags
24. Tenets of User Authentication What You Know (i.e. Knowledge based)
25. Hand not much different between left & right very little change
Finger significant difference but can change dramatically
So we want is something with significant entropy and is little changed - irisHand not much different between left & right very little change
Finger significant difference but can change dramatically
So we want is something with significant entropy and is little changed - iris
27. Independent Bio-TestingCentre for Mathematics and Scientific Computing National Physical LaboratoryMiddlesex, UK Iris did not have a programmable threshold.
Iris had zero false matches (
Samples…?
Includes failure to acquire
200 subjects, 3 months of testing
Iris did not have a programmable threshold.
Iris had zero false matches (
Samples…?
Includes failure to acquire
200 subjects, 3 months of testing
28. AFIS 4 AFIS algorithms against standard database
29. "Everything should be made as simple as possible, but not simpler.“ – Albert Einstein Some of the parameter are more temporal than others. For example, cost is probably the most temporal and depends
On the biometrics ability to leverage other applications. Accuracy on the other hand is probably the least with some technologies
Inherently only containing some degree of entropy. Finally, performance is a function of so many other things; population,
Controls… so be careful Some of the parameter are more temporal than others. For example, cost is probably the most temporal and depends
On the biometrics ability to leverage other applications. Accuracy on the other hand is probably the least with some technologies
Inherently only containing some degree of entropy. Finally, performance is a function of so many other things; population,
Controls… so be careful
30. “Statistical Significance” How many samples must I take for my trial?
Binomial Approximation
Chose a confidence level, e.g. 95%
Determine the relationship of N & P such that the 95% of the time one or more failures, or more simply that 5% of the time 0 failures
150 samples
0 errors – 95% confident better than pe= .031
1 error - 95% confident better than pe = .02
Doddington’s “Rule of 30” (see [7]):
To be 90 percent confident that the true error rate
is within +/- 30 percent of the observed error
rate, there must be at least 30 errors.
150 samples
0 errors – 95% confident better than pe= .031
1 error - 95% confident better than pe = .02
Doddington’s “Rule of 30” (see [7]):
To be 90 percent confident that the true error rate
is within +/- 30 percent of the observed error
rate, there must be at least 30 errors.
31. Hybrid Systems: Knowledge based, Token, Physiology
Multipurpose Sensors For Biometrics
32. Multipurpose Biometric Terminal
33. Biometric Optical Issues Illumination
Filter ambient, Dominant source, Correct Wavelengthsreduce specula reflections
Issue: mobile device size, power constraints
Aperture
Open aperture to allow more light
Issue: large aperture reduces depth of focus
Pixel Density (pixels/inch)
Adequate Resolution To Extract Features: 150-200 Iris, 20 Face, 100 (10mil PDF)
Issue: narrow FoV for higher pixel density, but more difficult to acquire object
Focus
Short for Iris, long for face
FoV
Describe eyeglass experience and virtue of mobility in this case, e.g. eugene could not see dotDescribe eyeglass experience and virtue of mobility in this case, e.g. eugene could not see dot
34. The Iris: Rich in Features
35. Iris Issues Small target (~1 cm) to acquire from a distance (1 m)
Moving target within head, within moving target in eye socket
Jitter/Blur In 2 Non-Stationery Platforms
Located behind a curved, wet, reflecting surface (specular)
Obscured by eyelashes, lenses, reflections
Partially occluded by eyelids, often drooping
Deforms non-elastically as pupil changes size
Visible light dilation
Orwellian connotations
Aiming Mechanisms
Perceived Sensitivity Of Eye Intrusion
Drug Related Changes (e.g. Latanoprost 12% darkened iris)
*Single Company
External Factors
- voice person out of breath, background noise, sickness…
- Iris: lighting poor, person just came out of dark (pupils dilated)
- Finger: fingers wet, cold, sweaty, misalignmentExternal Factors
- voice person out of breath, background noise, sickness…
- Iris: lighting poor, person just came out of dark (pupils dilated)
- Finger: fingers wet, cold, sweaty, misalignment
36. “Liveness” & Challenge Considerations
37. Fingerprint Oldest Biometric
Latent Extraction Capability
AFIS Database (automated fingerprint identification systems)
Every State Has AFIS
FBI IAFIS – 227 Million+ Started in 1934
Issues:
Swipe vs full scan
Societal Connotation
Protection of solid state sensors (ESD, impact, grit, grime, de-naturing…)
Hygiene
Ethnic dependency – Asian women
Target variance: small cut can destroy 50% of minutia
Oil, dry, wet, cut, abrasions…
Sensor Types: Thermal, Optical, Capacitive, Pressure, Ultrasonic
38. Facial Biometrics
39. FRVT 2000 Test Overview Test Metrics
Compression - Media
Expression - Distance
Illumination - Temporal
Pose - Resolution Important point of ROC, not obvious that EER is best, need to determine operating point and then use ROC curveImportant point of ROC, not obvious that EER is best, need to determine operating point and then use ROC curve
40. Facial-In-A-CrowdProcessing False Accepts
41. Security Issues if going over wireless. May want to load flight profile from wired.Security Issues if going over wireless. May want to load flight profile from wired.
42. Define User Feedback For The Specific Application
43. Speech Recognition - Acoustic Processing: front-end filtering, noise cancellation, echo cancellation, gating- VAD
- Parametric representation of the sampled audio
- This diagram represents the Client Based recognition engine
- Most popular Feature Extraction is Mel-Frequency Capstral Coefficient
- Most popular Comparison is HMM
- Acoustic Processing: front-end filtering, noise cancellation, echo cancellation, gating- VAD
- Parametric representation of the sampled audio
- This diagram represents the Client Based recognition engine
- Most popular Feature Extraction is Mel-Frequency Capstral Coefficient
- Most popular Comparison is HMM
44. Futures Biometric Proliferation - Mobility
PDF Smart Tokens -> Smart Cards
Biometric Protection; platform, storage…
“Liveness”
Faster Less Obtrusive Biometrics:
3D Facial
Long Range Iris Scanning
Biometric Affinity Programs
“Unified” Standardization: Feature Extraction, file formats, API (BAPI), multi-bio databases
BAPI – bio API to BAPI – bio API to