← Back to Blog
System Design

Fingerprint AFIS Architecture Diagram: Capture, Liveness PAD, Minutiae Match and On-Card Templates

A fingerprint AFIS architecture diagram is a capture path with a decision the matcher never gets to undo. The sensor takes an image. A presentation-attack check can stop a spoof before comparison. Minutiae are extracted. The system then either compares those minutiae off the card or compares an ISO minutiae template on the card. NIST SP 800-76-2 is the PIV specification for enrollment, for mandatory off-card minutiae, and for optional on-card comparison. It does not define a presentation-attack detector. The series-versus-parallel placement of that detector comes from a separate NIST-hosted example, not from the PIV card profile.

Fingerprint AFIS architecture cover: sensor capture, PAD gate, minutiae extraction, and on-card or off-card match
Listing cover: sensor capture, a presentation-attack gate, minutiae extraction, and a fork between an off-card match and on-card comparison of a minutiae template.
Fingerprint AFIS Architecture Diagram: Capture, Liveness PAD, Minutiae Match and On-Card Templates
Detail diagram: sensor to a PAD gate that can stop a spoof, then minutiae extraction, then either an off-card match or on-card comparison. A small inset contrasts series PAD with parallel fusion of liveness and the match score.

What this fingerprint AFIS architecture diagram shows

The CSRC publication page for SP 800-76-2 describes it as the companion to FIPS 201. It sets acquisition and formatting rules for the PIV system, including the card, and it adds on-card comparison as an alternative to PIN-mediated card activation as well as an additional authentication method. The PDF is where the fingerprint path is actually specified: how images are collected for enrollment and the background check, how minutiae are prepared for off-card authentication, and how a separate on-card template is prepared.

Off the card, the mandatory biometric is a minutiae template compared on a reader with a template from the authentication attempt. The cardholder enters a PIN to release those templates, and the authentication comparison the specification describes is one-to-one. On the card, comparison is optional. When an agency uses it, the on-card data is an ISO/IEC 19794-2:2011 minutiae template computed from the off-card template. The specification says FIPS 201 does not require a PIN before that on-card fingerprint transaction, and that on-card comparison can stand in for PIN entry when the card's security state changes.

The minutiae boxes in this diagram are not a claim that PIV ships one vendor's extractor. NIST Biometric Image Software (NBIS) is public-domain reference code. MINDTCT is its minutiae detector: it locates ridge endings and bifurcations and includes a local quality assessment. BOZORTH3 is its minutiae matcher: it performs both one-to-one and one-to-many matching, and it accepts minutiae generated by MINDTCT. They are the reference extractor and matcher in that distribution. The NBIS page does not say a PIV reader must call those binaries.

The problem this architecture is solving

Enrollment has to survive a background check and still produce a template a reader from another agency can compare. SP 800-76-2 therefore separates three records. A fingerprint image may be retained by the agency, in a standard image format, with integrity protection. A minutiae template is mandatory on the card for off-card comparison. A second minutiae template may be placed on the card for on-card comparison. Those are not the same object. The specification allows the fingers used on-card to be the same as the fingers used off-card, and it does not require a separate finger set.

A matcher that trusts every image the sensor emits will compare spoofs. The IBPC 2014 example from Johnson and Schuckers, hosted by NIST, draws two ways to attach presentation attack detection to a fingerprint system. In series, liveness is decided before matching and spoof samples are filtered out. In parallel, liveness runs alongside matching and the comparison subsystem fuses the liveness score with the match score. A series gate can fail closed: if the detector calls the presentation a spoof, comparison does not run. SP 800-76-2 does not require that gate. The diagram shows it because an AFIS path that skips it has no place to reject an artefact before minutiae are treated as a probe.

Main components and trust boundaries

Sensor and enrollment capture. For PIV registration the specification collects a full set of fingerprint images under one of three protocols: plain live scan, rolled live scan plus plain impressions, or rolled ink on a card that is then scanned. Live-scan and card scanners used for this enrollment have to meet the FBI electronic biometric transmission specification the document cites. An operator is present. The procedure uses the NIST Fingerprint Image Quality algorithm, NFIQ, and can repeat acquisition when the thumb and index fingers do not all have NFIQ values of 1, 2, or 3. NBIS distributes NFIQ and describes it as scoring an image from 1, highest quality, to 5, lowest. The enrollment client should show the image to the operator, who repeats capture when ridges are unclear, broken, or incomplete.

PAD gate. In the IBPC example, presentation attack detection is an automated decision that a presentation is an attack. The slides list liveness detection, artefact detection, and altered-biometric detection as examples of that decision. Series mode sits in front of the comparison subsystem and filters spoofs. Parallel mode passes a liveness score into the comparison subsystem, which applies a fusion function. The example's own summary says the series path reduced performance on live fingers relative to matching with no liveness check, and that a simple sum-rule fusion did not improve on the series result. This article does not copy the false-accept, false-reject, or spoof-accept rates off those slides. They belong to that example's data and thresholds, not to a PIV operating point.

Minutiae extraction. MINDTCT, in NBIS, records ridge endings and bifurcations. SP 800-76-2's off-card PIV template is an INCITS 378:2004 minutiae record, not a free-form image and not the on-card encoding. If an agency also retains images, those images use the INCITS 381-2004 finger-image format, including single-finger images segmented from the plain impressions, wrapped so the record's integrity is protected and encryption is allowed. Retained templates, if any, get the same wrapper. The specification says retention supports uses such as detecting duplicate identities. It also says the agency shall guard against faulty presentation, whether malicious or unintentional, during attended enrollment. That operator check is not the same component as the IBPC liveness module.

Off-card match. The mandatory transaction compares templates on a reader after the PIN releases them. SP 800-76-2 describes that comparison as one-to-one against the identity the card claims. It also describes a different pattern some other programs use: biometrics stored on a central server, or matched one-to-many without a card. It lists tradeoffs, including loss of the card as a "something you have" factor and a larger false-match exposure when one probe is compared with many enrollments, and then says those use cases are not addressed by the specification. BOZORTH3 can run either one-to-one or one-to-many as reference software. An off-card AFIS gallery in the diagram is that off-card matcher, including a 1:N search when the deployment is actually a gallery. It is not a second copy of the PIV on-card template, and it is not a mode SP 800-76-2 fully specifies.

On-card template. Optional on-card comparison uses the ISO/IEC 19794-2:2011 compact format. The specification says that record is computed from the off-card INCITS 378 template, with pruning, a change of coordinate resolution, a shorter angle code, and a sort. Data sent to the card for the comparison is minutiae only, without a proprietary extension. What the card stores internally is less constrained: the requirement is that the authentication instruction still works. The trust boundary is the card. The transaction the specification describes sends probe minutiae to the card. It does not describe exporting the enrolled on-card template into an external gallery as part of that comparison.

Request or data path, step by step

Enrollment. Capture the registration set with an attended operator and the NFIQ retry rule. Segment plain impressions into single fingers. Prepare the image record if the agency retains images. Prepare the record the specification uses for the FBI background check. Generate the mandatory off-card minutiae template. Optionally convert that template into the on-card ISO minutiae template and load it. SP 800-76-2 does not insert a PAD score into those enrollment records.

Probe. A later visit captures a plain impression on a single-finger sensor that meets the sensor specification the document points to for authentication capture. Those authentication sensors are not the enrollment sensors used for the background check. The document says it does not set a performance specification for four-finger segmentation algorithms.

PAD, series. Run liveness or artefact detection first. If the sample is filtered out as a spoof, stop. Minutiae extraction for a match does not start. That is the fail-closed reading of the IBPC series implementation: detection prior to matching. The example also shows that this ordering changes outcomes for live fingers, so a closed gate is not free.

PAD, parallel. Extract minutiae and compute a match score anyway, and compute a liveness score, then fuse the two in the comparison subsystem. The IBPC slides call the simplest fusion a sum of the match score and the liveness score. They do not present that sum as a universal threshold, and the published numbers on the slides are not repeated here.

Fork after minutiae. Off-card, compare on the reader to the template the PIN released, one-to-one, or search a gallery if the system really is an identification store of the kind the PIV specification says it does not cover. On-card, send the compact minutiae into the card and take back a comparison result. Do not send both paths the same byte layout. The on-card template is a conversion of the off-card template, not a rename of it.

The diagram: labeled boxes and failure or isolation edges

  • Sensor to PAD. The enrollment quality loop (operator review and NFIQ) is not drawn as if it were liveness detection. The PAD gate is the IBPC subsystem.
  • Series fail-closed edge. A sample the series detector treats as a spoof has no arrow into minutiae comparison. Parallel mode does not use that edge. It draws a liveness score into the matcher and fuses it there.
  • Minutiae to the fork. MINDTCT-style endings and bifurcations feed the reference matcher. The PIV off-card record is the INCITS 378 template. The on-card record is the ISO/IEC 19794-2 compact template derived from it.
  • Isolation of the on-card template. Off-card one-to-one comparison releases templates to a reader after the PIN. On-card comparison is specified as a transaction that sends probe minutiae to the card. The diagram does not add an arrow that copies the on-card template into an AFIS gallery.

What the source does not claim

SP 800-76-2 establishes minimum accuracy specifications for PIV biometric authentication and points at test programs for template generators and matchers. This article does not turn those tests into a false-match target for a deployment. The publication does not specify a presentation-attack detector, a liveness threshold, or a requirement to fail closed.

The IBPC deck is an example with its own sensors, algorithms, and decision boundaries. It shows that series filtering and parallel fusion behave differently. It does not certify a PAD product. NBIS documents MINDTCT and BOZORTH3 as reference implementations in a public-domain distribution. It does not report a false-accept rate for them on PIV data, and this article does not invent one. On-card comparison remains optional. A deployment that never loads an ISO minutiae template is still inside the specification. One that skips the mandatory off-card template is not.

FAQ

What is series PAD versus parallel PAD in the IBPC example?

Series detection checks fingerprint liveness before matching and filters out samples treated as spoofs, so those samples do not continue into comparison. Parallel detection runs liveness alongside matching and applies a fusion function to the liveness score and the match score inside the comparison subsystem. That example is not a PAD requirement in SP 800-76-2.

How does on-card fingerprint comparison differ from off-card comparison?

Off-card comparison is the mandatory PIV biometric. Minutiae templates are released after a PIN and compared on a reader in a one-to-one check. On-card comparison is optional. It uses an ISO/IEC 19794-2 minutiae template prepared from the off-card template, and the specification says a PIN is not required before that on-card transaction.

What do NBIS MINDTCT and BOZORTH3 do?

In the NIST Biometric Image Software distribution, MINDTCT is a minutiae detector that locates ridge endings and bifurcations, and BOZORTH3 is a minutiae matcher that performs one-to-one and one-to-many matching on minutiae produced by MINDTCT. They are reference software, not a requirement that every PIV system use them.

Conclusion

Draw fingerprint recognition as capture, a PAD gate that can fail closed when it is placed in series, minutiae extraction, and then a real fork: off-card comparison or gallery search on one side, on-card comparison of an ISO/IEC 19794-2 minutiae template on the other. Use SP 800-76-2 for enrollment, the background-check image path, the mandatory off-card template, and the optional on-card template. Use NBIS only to name the reference extractor and matcher. Use the IBPC example only for the series-versus-parallel distinction. Do not promote a slide threshold into an operational setting. More architecture diagrams are on the ByteDiagram blog.

Diagram the fingerprint fork before enrollment day

Sketch capture, the PAD gate, minutiae extraction, and the split between an off-card match and on-card comparison of an ISO minutiae template.

Open Diagram Editor