Standard Details
Identity assertion, role gathering, multilevel access control, assurance, and auditing are provided by the Biometric Open Protocol Standard (BOPS). The BOPS implementation includes software running on a client device, a trusted BOPS server, and an intrusion detection system. The BOPS implementation allows pluggable components to replace existing components’ functionality, accepting integration into current operating environments in a short period of time. The BOPS implementation provides continuous protection to the resources and assurance of the placement and viability of adjudication and other key features. Accountability is the mechanism that proves a service-level guarantee of security. The BOPS implementation allows the systems to meet security needs by using the application programming interface. The BOPS implementation need not know whether the underlying system is a relational database management system or a search engine. The BOPS implementation functionality offers a “point-and-cut” mechanism to add the appropriate security to the production systems as well as to the systems in development. The architecture is language neutral, allowing Representational State Transfer (REST), JavaScript Object Notation (JSON), and Secure Sockets Layer (SSL) or Transport Layer Security (TLS) to provide the communication interface. The architecture is built on the servlet specification, open SSLs, Java, JSON, REST, and an open persistent store. All tools adhere to open standards, allowing maximum interoperability.
Sponsor Committee |
COM/EdgeCloud-SC - Edge, Fog, Cloud Communications with IOT and Big Data Standards Committee
|
Status |
Active
|
Board Approval |
2017-09-28
|
History |
Published Date:2017-10-20
|
Additional Resources Details
Pars | |
Redline | |
Historical Base Standard |
Working Group Details
Working Group |
BOP - Biometrics Open Protocol
|
Working Group Chair |
Scott Streit
|
Sponsor Committee |
COM/EdgeCloud-SC - Edge, Fog, Cloud Communications with IOT and Big Data Standards Committee
|
Society | |
IEEE Program Manager | |
Active Projects |
Identity assertion, role gathering, multilevel access control, assurance, and auditing are provided by the Biometric Open Protocol Standard (BOPS). The BOPS implementation includes software running on a client device and software running on a BOPS server. The BOPS implementation allows pluggable components to replace existing components? functionality, accepting integration into current operating environments in a short period of time. The BOPS implementation allows the systems to meet security needs by using the application programming interface. The BOPS implementation need not know whether the underlying system is a relational database management system or a search engine. The BOPS implementation functionality offers a ?point-and-cut? mechanism to add the appropriate security to the production systems as well as to the systems in development. The architecture is language neutral, allowing Representational State Transfer (REST), JavaScript Object Notation (JSON), and Secure Sockets Layer (SSL) or Transport Layer Security to provide the communication interface.
BOPS III enhances BOPS to include homomorphic encryption and a tremendous simplification of the API. The biometric payload is always one-way encrypted with no need for key management. A plaintext biometric is never received by the BOPS server and therefore privacy is guaranteed. BOPS assumes a greater security framework, whether it is Single Sign On (SSO) protocol (Active Directory, Google, Facebook) and BOPS supports the given framework with a simple 3 API interface.
This document describes the essential methodology to BOPS III
|
Existing Standards |
Identity assertion, role gathering, multilevel access control, assurance, and auditing are provided by the Biometric Open Protocol Standard (BOPS). The BOPS implementation includes software running on a client device (smartphone or mobile device), a trusted BOPS server, and an intrusion detection system. The BOPS implementation allows pluggable components to replace existing components? functionality, accepting integration into current operating environments in a short period of time. The BOPS implementation provides continuous protection to the resources and assurance of the placement and viability of adjudication and other key features. Accountability is the mechanism that proves a service-level guarantee of security. The BOPS implementation allows the systems to meet security needs by using the application programming interface. The BOPS implementation need not know whether the underlying system is a relational database management system or a search engine. The BOPS implementation functionality offers a ?point-and-cut? mechanism to add the appropriate security to the production systems as well as to the systems in development. The architecture is language neutral, allowing Representational State Transfer (REST), JavaScript Object Notation (JSON), and Secure Sockets Layer (SSL) or Transport Layer Security to provide the communication interface. The architecture is built on the servlet specification, open SSLs, Java, JSON, REST, and an open persistent store. All tools adhere to open standards, allowing maximum interoperability.
|