You are here: Resources > FIDIS Deliverables > HighTechID > D3.10: Biometrics in identity management > 

D3.10: Biometrics in identity management

The integration of biometrics in electronic documents issued by the government  Title:
INTEGRATING BIOMETRICS IN IDENTITY DOCUMENTS
 Match-on-card

 

Integrating biometrics in identity documents

Template-on-card

In order to increase the protection of the biometric reference template, it is possible to store it on a secure token like a smart card. This is called a template-on-card architecture, which avoids the use of databases containing large amounts of reference templates. These databases are considered to be worse than storage on a secure token because the latter rules out the possibility of using the biometric reference templates, which in fact should be regarded as unique identifiers, as keys in databases to increase linkability of personal data, from which different partial identities belonging to the same entity can be deduced (see also above, section ).

Irrespective to the discussion of linkability, implementing relations between personal data and biometric database keys should be avoided, because this would require extensive processing of biometric data. This is negatively assessed by Rodotà, who bases his argument on Directive 95/46/EC of the European Parliament, because “the data subjects will have no possibility to object to the processing of their biometric data”.

Database keys should be generated independently of biometric data so that it remains possible to use different keys for databases from distinct parts of a large organisation. For example, when government administrations store personal information electronically, it might be favoured not to use the same key for the linking of personal data stored by all authentic sources. This would allow the linking of pieces of information that is not justified by the presupposed purpose stated at the time of collection of the personal data. This purpose should be communicated clearly and not be violated afterwards.  

In this architecture, the only thing the token provides for the biometric recognition process is the template. It is communicated through a secure channel to the reader’s side where collection, extraction and matching takes place. The storage of the reference template on a secure token depends on the application and the identity document being used. When a user looses a card, a tamperproof smart card provides better protection of the reference template than a simple memory card. 

The biometric matching is performed off-card, by the card reader or by a software module or middleware, and therefore the reference template has to leave the card. To prevent identity fraud, the reference template should be digitally signed to ensure the integrity and authenticity of the template. At home, a user may trust her card reader or the system where the matching is performed, hence biometrics bring more convenience to the user (Convenience model - Type IV a). However this is not the case when the system is not under control of the user. This limits the use of biometrics to off-card recognition - in this system biometrics cannot be used to unlock the card’s functionality. 

 

The integration of biometrics in electronic documents issued by the government  20071228_fidis_deliverable_wp3_10_V1.0.final.sxw  Match-on-card
32 / 40