plt-04029 b.3 - Hid Biometric Manager Administration Guide
plt-04029 b.3 - Hid Biometric Manager Administration Guide
plt-04029 b.3 - Hid Biometric Manager Administration Guide
PLT-04029, B.3
August 2022
Powering HID® Biometric Manager™
Trusted Identities Administration Guide
Copyright
© 2022 HID Global Corporation/ASSA ABLOY AB. All rights reserved.
This document may not be reproduced, disseminated or republished in any form without the prior written permission of
HID Global Corporation.
Trademarks
HID GLOBAL, HID, the HID Brick logo, the Chain Design, iCLASS SE, HID Signo, Seos, HID Mobile Access, HID Reader
Manager, HID Elite, HID Origo, and HID Biometric Manager are trademarks or registered trademarks of HID Global, ASSA
ABLOY AB, or its affiliate(s) in the US and other countries and may not be used without permission. All other trademarks,
service marks, and product or service names are trademarks or registered trademarks of their respective owners.
Contacts
For technical support, please visit: https://support.hidglobal.com.
What's new
Date Description Revision
August 2022 Updates to support HID Biometric Manager version 1.0.2000.00019. B.3
Introduction 6
1.1 Document purpose 7
1.2 Intended audience 7
1.3 Related material 7
1.4 Physical Access Control System overview 8
1.5 HID Biometric Manager server application 9
1.5.1 System requirements 9
1.5.2 Reader Service 9
1.6 HID Biometric Manager Web UI 9
1.7 Signo Biometric Reader 25B 10
1.8 Panels and Door Controllers 10
Enrollment 72
3.1 Enrollment 73
3.1.1 Enroll people 73
3.1.2 Enroll Cards 75
3.2 Install SIGNO-B-USB Module 79
3.2.1 SIGNO-B-USB Enrollment 79
3.2.2 Enroll Biometrics 81
3.2.3 Local enrollment 85
3.3 Preventing user fingerprint display during enrollment 87
3.3.1 Write fingerprint templates to a card 88
3.4 Bypass finger TOC 90
3.4.1 Enrollment without fingerprints 91
3.4.2 Enrollment with fingerprints 92
3.5 BioTemplate settings 92
3.5.1 Auto download template 93
Network 104
5.1 Network setups examples 105
5.2 Network usage 105
5.3 Device discovery 106
5.4 Secure device communication 106
5.5 Chain of trust 106
The iCLASS SE® RB25F has been rebranded as the HID Signo Biometric Reader 25B.
The Signo 25B is launched with HBM version 1.0.1212.60729 and is available as an update for RB25F customers.
Note: Unless specified, all HBM version 1.0.2000.00019 features are available for RB25F customers. The features
not compatible with the RB25F will be called out explicitly throughout the document.
For more information on the Signo 25B, refer to HID Signo Biometric Reader 25B User Guide (PLT-04900).
When a card holder presents their credential to a Signo 25B access point reader, it performs authentication functions to
establish whether the user is who they claim to be. If the authentication is successful the PACS panel or controller is
notified of the request for access. The panel then checks the access rights for the presented credential to see if the card
holder is authorized for access. If authorization is successful it opens the door.
The diagram below provides a high level view of the various system solution components deployed in a PACS. The
function of each component is described in the following sub sections. The components with HID Biometric Manager
service box are typically deployed on the same server as the PACS headend software.
Note: Multiple Signo 25B devices and PACS Panel/Door Controllers can be added. HID Biometric Manager can
control up to 2,000 Signo 25B devices.
The web server allows you to configure Signo 25B device settings via a web browser, register credential holders, and to
distribute this information to the devices. It also collects and stores logged events from the Signo 25B.
This interface is used to install and configure Signo 25B readers. It is also used to perform user registration including
fingerprint enrollment. Any connected Signo 25B device, or SIGNO-B-USB can be selected as the enrollment device from
the browser.
Other functions include the ability to view transactions on the device in real time, and to download and trigger updates
for both the HID Biometric Manager software and the Signo 25B device firmware.
See Authentication Mode (Signo 25B) for more information. When the credential holder is authenticated, the data is
output to a third party controller.
2.1 Overview
HID® Biometric Manager™ is a web application that streamlines the management and configuration of Signo Biometric
Reader 25B devices and allows application operators to manage people enrollment, credentials and fingerprint
templates. HBM uses the following operator roles to control access to management tasks:
l Super Administrator: The super administrator is the initial default user account (cannot be deleted). This operator
installs and initially configures HBM software, and creates/administers operator roles within the application see 2.2
HID Biometric Manager initial setup.
l Administrator: This operator role has full access to HBM web application with functions to install and manage Signo
25B devices see 2.3 Device installation and configuration and enroll people in the system, add credentials, collect
and store associated biometric data see 3.1 Enrollment.
l Device Administrator: This operator role is intended for HID partner technicians involved in the setup and
maintenance of the Biometric Management environment as well as configuration and update of the Signo 25B. This
operator role has limited access to user information.
l Enrollment: This operator role has full access to HBM web application. however is limited to the day-to-day activities
of enrolling people in the system, adding credentials, collecting and storing associated biometric data see 3.1
Enrollment.
Notes:
l The user installing the HBM software needs to be logged in on the server as a Windows Administrator.
l The host name must be set before installation. Changing this after installation can impact device
communications.
l When using a static IP, it must be set before installation. Changing this after installation can impact device
communications.
1. Download the HID Biometric Manager.exe file from the download site to your server:
https://www.hidglobal.com/signo25b
2. Double click on the downloaded .exe file to launch the installation wizard.
Note: If the server system language is configured to one of the supported languages then the install wizard
instructions and HID Biometric Manager will automatically default to the server system language.
Supported languages:
l English l Portuguese
l German l Russian
l Spanish l Simplified Chinese
l French l Japanese
l Italian l Korean
3. Select the required language and click OK.
5. Read the License Agreement. Select I accept the agreement, and click Next.
Note: If you do not accept the License Agreement, click Cancel to end the installation setup process.
6. Follow the installation wizard prompts until the setup has finished installing HID Biometric Manager.
For information on the HBM Server application, see HID Biometric Server Application
1. Double-click the HID Biometric Manager desktop shortcut or navigate to the installation folder (usually, C:\Program
Files (x86)\HID Global\Biometric Manager\bin) and double-click the HID Biometric Manager.exe file.
Note: The size of the database may impact how long it takes the HID Biometric Manager application to launch.
Start up feedback is indicated with an on screen progress bar.
2. On the HID Biometric Manager Server application screen, click the Open Client Connection link to access the HID
Biometric Manager application login screen. Record the Client Connection URL as this can be distributed and used
to access the HID Biometric Manager application from a client PC on the same network.
Note: If the Open Client Connection URL fails to connect to HID Biometric Manager due to a port issue,
change the default port number (443) in the URL
to:http://hostname:82/HIDBiometric/HIDBiometricManager.html
3. Enter the initial default admin User Name (admin) and Password (password) and click LOGIN.
Note: A pop-up window containing the EULA will open after the initial login, this needs to be accepted.
Important: For security reasons it is recommended that the default admin login credentials are changed
immediately.
Note: Users will be locked out for 30 minutes after seven failed login attempts.
4. Click System > Operators.
5. Click the Edit icon [ ] associated with the displayed system admin user.
7. Click to save this new password. A notification will appear confirming that all changes have been saved at the
bottom of the window.
8. Close the HBM browser window and login again using the default username (admin) and new password.
1. Click System.
2. Click Date/Time to access the system time zone settings.
3. Click the Time Zone arrow icon to access a list of selectable regions and countries.
Note: Use the Search field to narrow your search criteria for a listed time zone.
5. Click .
5. When the installation has completed the Devices screen displays the installed device.
Note: Installed devices are automatically added to the default device profile named Devices. The default
device profile can be edited or new profiles can be added to the system.
1. On the Devices screen, highlight a device entry from the displayed list. The Edit/Delete icons appear on the screen
for the highlighted device.
2. Click [ ] to access the device settings screen.
l Operation Modes: Select the required operation mode to enable/disable the Tap or Twist and Go gesture
operation.
l Range and Power Settings: Set the read range for Tap and Twist and Go and the setting for Transmit
Power.
l READ: Read mobile keys from the device.
l WRITE: Write mobile keys to the device. Before mobile keys can be written to the device they must be loaded
onto HBM, see HID Origo set up.
Note: The default range settings for Tap, Twist and Go and Transmit Power are displayed in HBM. It is
recommended that the default Transmit Power setting (-4 dBm) is not exceeded unless absolutely
necessary as range and transmit power settings work in tandem to increase/decrease effective read
range.
Full device firmware updates can take approximately 25 minutes per device, including updates of the reader board.
Updates may complete faster depending on the HID Origo™ connection and the number of uninterrupted updates.
Important: It is recommended that device firmware updates should be carefully scheduled as all devices are
updated and will be unavailable for use during the firmware update period.
2. Click CHECK FOR UPDATES. Review the displayed firmware update information and click Install to start the
firmware update process.
Note: The Progress Report bar indicates firmware update progress against total devices. For example, if two
devices are being updated then 50% progress indicates one device updated out of two devices. Devices
are updated in series with information displayed on the current device being updated.
l A partial update means that the system was not able to complete the secondary step of applying reader
firmware updates, for example, as a result of the connection to the HID Origo not being setup (see HID
Origo set up) or being interrupted.
l A partially updated device will run the installed level of firmware however features, such as mobile access,
and firmware fixes will not be available.
The firmware files are available for download from the HBM Developer Center .
4. Click CONFIRM in the pop-up window and then select the update file from your local file system to begin the
update.
Note: The firmware files are available for download from the HBM Developer Center .
5. Click OK when the update is complete.
Reinstall firmware
1. Click Advanced.
2. Select Reinstall Firmware.
3. Click UPDATE FIRMWARE.
4. Click CONFIRM in the pop-up window.
Note: This operation will take around 25 minutes to complete.
5. Click OK when the update is complete.
Important: The device will be offline while the firmware update is in progress.
1. On the Devices screen, highlight a device entry from the displayed list. The Edit/Delete icons appear on the screen
for the highlighted device.
2. Click [ ] to access the device settings screen.
4. Click CONFIRM.
Note: Where communication between HBM and the Signo 25B is not possible, factory default reset can be carried
out at the reader, see HID Signo Biometric Reader 25B User Guide (PLT-04900).
1. On the Devices screen, highlight a device entry from the displayed list. The Edit/Delete icons appear on the screen
for the highlighted device.
2. Click [ ] associated with the device you want to uninstall.
3. Click CONFIRM.
4. Click OK.
Note: If all devices have been uninstalled in HBM, you will have the option to install a devices on the Devices
screen, see 2.3 Device installation and configuration.
Note: This must be set before installing any devices. If this is changed after device installation, devices must be re-
installed.
For all network setting changes, make sure that the Signo 25B stays connected to the HBM server that it was configured
to.
3. Click SAVE.
5. Click .
3. Select the desired Unit of Expiry from the drop down list.
4. Enter an Expiry Value.
Note: All new templates will now inherit the Expiry Date set in the biometric template schedule. This is visible
alongside the template.
Note: The schedule applies to all Biometric Templates enrolled after the schedule is set.
3. Use the drop down arrow to enter the desired Schedule Unit of Time and enter a Schedule Value.
1. During enrollment the system template expiration can be overridden by selecting the tick box to Override System
Template Expiry.
2. Select the required Unit of Time and enter the required value.
3. Click DONE.
To provide uninterrupted operation when in use with an unreliable network and power supply, HBM gives the option to
adjust the template security on the devices.
Note: Only use this option if the Signo 25B is installed in an area with an unreliable network connection and
frequent power outages.
Configuring the device template encryption allows different levels of encryption for individual devices. Disabling the
device template encryption allows operation without connecting the device to the server.
1. To configure the template encryption go to the Devices page and select the required device. Under the Advanced
tab there is the option to REDUCE TEMPLATE SECURITY.
Important: Read the information given in the pop-up window before confirming the action.
Click System > Transaction Report to make sure disabling the template encryption appears on the transaction report.
Note: You must have HID Origo System account, and Reader Manager authorization to access the keys.
For information on how to create a system account with Reader Manager authorization, see A.2 Create an Origo system
account in HBM
1. In HBM, select the Devices option and click on the Edit icon [ ] associated with the required device.
2. On the Devices page, select the Key Management tab. Click READ to check for any previously loaded MOB keys on
the device. Click CLEAR to remove any displayed MOB keys that have been read from the device.
3. Click the drop down arrow for Mobile Key to Write to Device and select a MOB key from the list.
4. Click WRITE to load the selected MOB key onto the device.
Note: The device can only contain one MOB key at any given time.
Notes:
l Standard keys will not work on the Signo 25B once Elite keys have been loaded to the device.
l After a factory reset, the device cannot be checked for standard or Elite key configurations.
l You need to be fully enrolled in HID Elite with an ICE Key reference for Signo 25B to load your ICE Key in the field.
This may require contacting HID Credential Programs for confirmation of enrolment.
1. Select a device.
2. Open the Key Management tab.
3. Click the arrow to select Elite keys.
1. Only available with Signo 25B ordered from the factory after June 2022 with firmware version 1.5.1.56. (NOT available with RB25 or previous Signo
25B devices).
To configure how HID Biometric Manager software and device firmware are updated:
4. Click System.
5. Select the required update option and click APPLY.
6. Click CHECK FOR UPDATES to check if software/firmware updates are available. Update Status information is
displayed on the screen.
l If new HBM software is available and selected, the installation progress is displayed in your browser. Once the
installation is complete, the HBM Server application will automatically shut down and re-start. You will be
prompted to log back into the HBM.
l If new device firmware is available, see 2.4.1 Device firmware update.
3. Enter a Name and optional Description for the new device profile.
4. Click .
5. The created device profile is listed on the Device Profiles screen. To edit a profile, highlight a device profile from
the displayed list. The Edit/Delete icons appear on the screen for the highlighted device profile.
6. Click the Edit icon associated with the device profile to access the profile attributes. See 2.12.2 Edit a device
profile.
1. On the Device Profiles screen, highlight a device profile from the displayed list. The Edit/Delete icons appear on
the screen for the highlighted device profile.
2. Click the Edit icon [ ] associated with the device profile.
3. Click Audio/Visual.
4. Select an Event.
5. Click the on an Event type from the displayed list to choose the attributes for the selected event.
6. Click SAVE.
Note: Click USE DEFAULTS to revert back to the default settings for the selected event.
l Creating a schedule allows the device to operate in different authentication modes for different parameters
for example, day of the week or time of the day. If no schedule is created the default schedule of 24/7 will be
applied.
9. On the Device screen, select Devices to view the list of devices that belong to this device profile. Any changes
made to this device profile will be applied to these listed devices.
10. Click to add a device to this device profile.
13. Click .
1. On the Device Profiles screen, highlight a device profile from the displayed list. The Edit/Delete icons appear on
the screen for the highlighted device profile.
2. Click the Delete icon [ ] associated with the device profile.
Low level communications only and the The device has power and can be found through LAN or Ethernet but there is an
device can't be used. operating error.
No communications with device. Communication has been lost between the device and HBM. The device has lost
power or a tamper event has taken place.
High level communications in place but Communication between the connected devices and HBM is stable but the
device is busy. device is experiencing a high level of usage.
The Devices page displays the real-time status for all connected devices.
Note: The device debug is only accessible for 30 minutes after a device factory reset
To access the device debug page, search http://<Device IP>:8888 in a Web browser.
The Misc window gives device information such as the running time, serial number and firmware version.
The Digital Inputs reading of High indicates that the input is in use or has been triggered. A short across the terminals
on the rear of the device will result in the Factory Default input reading High.
When the DHCP option under the Network window is deselected, the Network window will expand. The details can be
manually entered as required.
Under the Control tab, a relay can be selected and activated to determine a connection through the device debug page.
This is useful during the installation of the device. If the door strike is wired to the internal relay, it can be activated to
confirm connection.
Note: This feature is not available for the RB25F. It is exclusive to the Signo 25B only.
Important: If maintenance to the power system has been scheduled, disable the Factory Default Tamper
Settings before maintenance begins, to avoid having to re-install the devices in the event of an
accidental tamper during maintenance.
1. To toggle the Factory Default setting on or off, navigate to the Device Profile page and select the Advanced tab.
2. Click .
In the case of an accidental tamper where the device keeps power, a Tamper event will appear in the Live! view. The
Device health will now be red. To restore communications between the Device and HBM, the Device must be uninstalled
from HBM and then re-installed.
1. The Enforce Seos PACS option can be toggled on or off in Device Profiles under the Advanced tab.
2. Click .
Note: If using Seos credentials without this option enabled, the PACS data read will not be consistent.
To filter displayed events, select the Filters option. Any current filters in use are displayed. Click ADD FILTER to create a
new filter based on a Name, Event, or Device. Click to save any added filters.
Note: If no filters are used then the default filter is applied. This displays events only for the calendar day.
2. Click RUN REPORT to create a report of HBM transactions. Once the report is created click the save report icon [ ]
to save the report to a PDF or CSV file.
3. To filter report content select the Filters option. Any current filters in use are displayed. Click ADD FILTER to create
a new filter based on a Device, Date/Time, Event, or Person. Click to save any added filters.
Note: If no filters are used then the default filter is applied. This displays events only for the calendar day.
Note: Only users with administrator access can create a diagnostic bundle.
3.1 Enrollment
Enrolling people in the system, adding credentials, and collecting associated biometric data can be carried out by an
Administrator operator or an Enrollment operator.
Note: Please make sure that the enrollment reader and all connected readers are at the same firmware level for
template compatibility.
Note: If people are already enrolled, click the Add icon [ ] to enroll additional people.
6. Click .
7. The enrolled person record is displayed on the People screen. To add additional people, click and enter the new
persons details.
Note: To display people that have an inactive status, click the filter icon [ ] and select the Show Inactive
People option.
3. Click .
Note: The credential recorded in HID Biometric Manager must also be present in the third party PACS
software running on the PACS Server.
The operator can now collect and add biometric data associated with this enrolled person, see 3.2.2 Enroll Biometrics.
1. On the Details screen, select the arrow icon [ ] associated with the Format field.
3. Enter a Credential Number (decimal) and if displayed, enter the Facility Code.
4. Click
The manually entered card details are displayed with the decimal Credential Number converted to hexadecimal in
the Credential Identifier field.
Note: The credential recorded in HBM must be present in the third party PACS software running on the PACS
Server.
Note: HBM defaults to the SIGNO-B-USB for enrollment when it is enabled and the device is connected, even if
there is a Signo 25B fingerprint reader connected.
Notes:
l If the SIGNO-B-USB is being used for enrollment, it must be authorized for the enrollment workstation and
1. Login in as Administrator
2. Click Security > Communications in the HBM Server application.
After enrollment, the user record containing the user information and biometrics are encrypted and stored in the HBM
server database by default, for distribution to the connected Signo 25B devices.
Notes:
l The templates are encrypted when stored in the server and device databases by default.
4. In the Enroll Biometric pop-up window select the fingers you wish to enroll and click NEXT.
Note: If you intend to make use of the Template on Card option as the authentication mode you will only be
able to copy two of these templates to the card. However the system can store all ten fingers, if needed.
6. For the highlighted finger you will be prompted to Place finger on sensor followed by Lift finger. It is
recommended that you follow the on-screen prompts, in the correct sequence, to ensure a successful finger scan.
Note: For information regarding the correct method of presenting fingers to the scanner during the biometric
enrollment process, see HID Signo Biometric Reader 25B User Guide (PLT-04900).
7. Continue to follow the on-screen prompts until you have successfully scanned the first finger three times. Click
NEXT.
Note: A score of at least one star per scan is needed. A poor score will require that you scan the finger another
three times.
8. You will be prompted to proceed onto the next finger scan. Follow the on-screen instructions until you have
successfully scanned the next finger three times.
9. If there is a problem when scanning a finger, a pop-up window will give the options to SKIP that finger, RETRY to
scan again, or ABORT to cancel enrollment.
10. When all of the selected fingers have been successfully scanned, click DONE. The enrolled fingerprints are
associated with the top credential in the credential list.
Note: If the top credential in the credential list is deleted then enrolled fingerprints are associated with the next
credential in the list. If all credentials are deleted then the biometrics are also deleted.
Notes:
l Only use local enrollment with the Template on Card authentication mode. If the authentication mode is changed
When presented, the credential will appear in the LIVE! feed as No User Name(Unknown). The fingerprint template is
stored locally in the memory of the Signo 25B reader and will not be added to the database.
1. Go to System > Enrollment Settings and select the Display fingerprints tick box for the fingerprints to be
displayed. Deselect the tick box to remove the fingerprint display.
4. Click DONE.
Notes:
l Template on Card supports SEOS® and MIFARE® DESFire® EV1/EV3 SIO credentials. 1
l There is no support for template on card with custom DESFire credentials or credentials with custom keys.
1. Only available with Signo 25B ordered from the factory with SP2.5 (NOT available with RB25F).
4. Select the fingers (maximum of two) you wish to be written to the card and click WRITE TO CARD.
5. You will have approximately five seconds to present the supported card to the Signo 25B device to write the profiles
to the card. The LED bar will flash while writing to the card. Keep the card close to the reader until the LED bar
returns to it’s default color. You will be notified when the card has been successfully written to.
6. For a Template on Card authentication mode, the enrolled person can now enter the door by presenting this card,
immediately followed by the correct finger scan on the Signo 25B.
Note: When presenting the card and fingerprint, there is a time window of one second between card and
fingerprint scan.
This allows an individual to be in Card Only mode if the Device Profile is set to Template on Card mode.
Before disabling the Automatic Download of Template On Device you must change your device profile Authentication
Mode to Template On Card, or Card Only. You will be prompted by HBM to change it if you have not.
1. Navigate to Devices > Device Profiles and choose the profile you want to edit.
2. Click the Advanced tab.
3. Scroll down to Template Location.
5. Read the Authentication Mode Change pop-up notice, then click CONFIRM.
6. Click .
You can verify this by going to the Details tab of the Device Profile, and selecting the Authentication Mode. There
should only be two modes of authentication, Template on Card and Card Only.
Note: If the option is disabled, the authentication modes that require a user template in the device database are not
available.
This method can be used to change the administrator password, as shown in 2.2.2 HID Biometric Manager initial login
People and credentials can be imported into the system using an Excel or CSV file. Each column needs a header row
containing the criteria that populates the Source column and the data for each criteria below in the data rows as shown:
After a file is imported, the Source column values need to be mapped to the Destination column values in the drop down
menu.
Database
- Initial state
- Ready
- Failed to start
4.2 Live!
The Live! server application displays a live feed of updates and events happening in HBM. It is also available in the HBM
explorer window.
HBM uses a local database as the default database during installation. HBM allows you to use your own SQL database,
running on the same, or a different server.
Note: You must have Microsoft SQL Server Management Studio or similar installed on your computer.
For a new install, copy the files from the Empty folder to the computer running the SQL server (This does not have to be
the same computer running HBM).
With HBM running, right click the system tray icon and click database. From there you can select SQL server and fill in
each field. Click Test Database Connection. If the test passes click Save & Restart.
This section explains how to backup the Microsoft SQL local Data Base (DB) used by HBM.
Note: The backup and recovery feature is only available with software version 1.0.2000.00015 or higher.
Note: A recovery key only needs to be generated once per database instance.
Before beginning the first database backup, a recovery key has to be generated as a single use key. To generate a
recovery key from the HID Biometric Manager server and copy this to a safe location.
1. Stop the SQL local database by opening a command prompt and type:
SQLLOCALDB STOP HID_BIOMANAGER.
3. Copy the HID_BIOMANAGER.mdf and HIDBIOMANAGER_log.ldf files from C:\Program Files (x86)\HID
Global\Biometric Manager\database to a secure location.
l Backup daily or weekly.
l Store backups on a secure machine separate to the HBM server.
The backup is now complete. It is now safe to start up HBM if no recovery procedure is needed.
Note: During the backup procedure, the readers will continue to operate but HBM will be unavailable.
1. Ensure that the original server is not on the network, or that HBM has been uninstalled and is no longer used on the
original server.
2. Ensure the SQL server version on the recovery machine is the same or a higher version than the original server. The
SQL local database version installed by HBM is based on the current version of SQL server installed.
Note: To check the SQL version on the recovery machine, connect to the server side Database and perform the
Select @@version command.
3. Install HBM but do not start up HBM.
4. Copy and paste the previously backed up .mdf and .ldf files to C:\Program Files (x86)\HID Global\Biometric
Manager\database.
6. Once started, check that the recovery process has created a new certificate with the recovery server information
and not the original server information. This can be verified through the HBM Server application.
7. Log into HBM and uninstall all connected devices. Do not Factory Default through the software.
8. Factory default all devices using the pins on the reverse of the unit, see HID Signo Biometric Reader 25B User Guide
(PLT-04900).
9. Wait one minute for devices to reboot after factory default.
10. Re-install all devices within HBM.
11. Test the communication between devices and HBM.
Note: Return to 4.4.1 Generate recovery key after completing the above steps.
Note: Switching between DHCP and Static IP will cause the certificates to no longer work. To resolve this, re-install
the unit with the target settings set in HBM.
Scenario 1 - DHCP network, Signo 25B devices have dynamic IP, Server has a static IP
In this system setup the server has a static IP or the DHCP server assigns an IP with a permanent lease.
Signo 25B devices have an Ethernet connection on the same LAN as the server running HID Biometric Manager. The
network is configured so that the DCHP server dynamically assigns IPs (which may have a limited lease time) to Signo
25B.
Scenario 2 - DHCP network, Signo 25B devices have dynamic IP, Server has a dynamic IP
In this system setup the server has a DHCP assigned IP.
Signo 25B devices have an Ethernet connection on the same LAN as the server running HID Biometric Manager. The
network is configured so that the DCHP server dynamically assigns IPs (which may or may not have limited lease time).
HID Biometric Manager is installed on the server using the setup install wizard. During installation of Signo 25B devices
in HID Biometric Manager, you must select and use the default server hostname. In the event where the server IP
address changes, the hostname will reflect back to the server hostname.
Note: Setting HID Biometric Manager to a static IP will cause issues on this network.
Scenario 3 - HID Biometric Manager installed on a Server and connects to DHCP network
This is the same as Scenario 2 except HID Biometric Manager is running on a Server. This means that it is likely that HID
Biometric Manager will not be running all the time. When HID Biometric Manager is not running, Signo 25B devices will
be in an off-line mode. In off-line mode they will run as configured and log events, however enrollment will not be
possible.
l https://prod-readermanager.hidglobal.com/
Note: The CA certificate is specific to the host that generated the certificate.
The certificate SAN fields show the IP/DNS name that is expected. Contact HID technical support to reset the software
to initial state. If the device is removed and connected to a different instance of the server, communication will be lost. In
this case, reset the Signo 25B to the factory default settings, and install to the new server.
This section provides details on the prerequisites that must be in place in order to setup a connection between HID
Biometric Manager™ and the HID Origo® Portal. The section also details how to verify HID Reader Manager™ Technician
account details in HID Biometric Manager and how to load HID Origo (MOB) keys onto the Signo Biometric Reader 25B.
https://portal.origo.hidglobal.com/mobile-identities/#/home
For information relating to the HID Mobile Access solution, including the HID Origo Portal, refer to the following:
l HID Mobile Access Solution Overview (PLT-02078).
l HID Mobile Access Frequently Asked Questions (PLT-02085).
2. Fill in the required information and follow the prompts to create your account.
To validate a Reader Manager Technician account (this should be the HID Origo Portal admin or a company employee) in
HID Biometric Manager:
3. On the HID Update Account Settings page enter the System or Individual account details User
account/Password) and click VERIFY ACCOUNT.
If the Reader Technician account has not been authorized for any MOB keys then no keys are listed under Keys
associated to Account. If MOB keys have been assigned to the account then these will be listed in.
1. Log into HBM and click the Live! option to view HBM events.
2. Present the mobile device to the Signo 25B and check the Live! screen to see events showing the mobile access
read and the associated credential identifier.
Note: Mobile Access read will only work if the Signo 25B is in one of the authentication modes that support
card read, i.e. Card Only, Card or Finger, or Card + Finger. Mobile Access will not work if the Signo 25B is
in finger mode.
l The device profile will sync to make sure all the reader configuration is downloaded to the Signo 25B device
after re-installation and once connection has been established with the HBM.
B.3 Additional information on the Signo Biometric Reader 25B template encryption
l All Signo 25B units have been shipped with Identrust x509 certificates which are used as part of the Biometric
template encryption feature.
l The HID Biometric Manager server application will generate an AES-256 encryption key to be used as part of the
template encryption feature.
l There is no need to enter any additional information or setup other than running the update.
After the Signo 25B has been updated to firmware version 1.5.0.86, and the Signo 25B has gone through a re-install
process, it must connect with the HBM in order for the encryption key to be sent to the Signo 25B. There are two
important points of note:
1. Once the update is complete, the device will only allow Template on Device Authentication until the AES-256
encryption keys are sent from the HBM. If the authentication mode was set to Finger Only or Finger + Card the
device will need to make a connection with the HBM to receive the decryption keys before it can become fully
operational.
2. As part of HBM version 1.0.886.57608 the AES-256 encryption keys are not backed up. If the computer that the
HBM is running on is destroyed, it is not possible to recover them.
Notes:
l You may need to create the sysdba user in SQL Server Management Studio first.
l A common problem during this step, is that the SQL server does not have permission to access the database
files. There are two options to resolve this.
a. Change the account that the SQL Server service uses. Open Services under Administrative Tools in Control
Panel. Find the SQL Server Service and open its properties. Change the “Log on As” account to “Local System
Account”.
b. Change the file permissions on the database folder in Windows Explorer. Right-click on the Database folder. On
the Security tab, edit the permissions to include the user account that the SQL Server service is running as.
1. Select Mixed Mode Authentication. You can now log on to SQL Server using Windows authentication, or as a
defined SQL Server user.
2. If you are using an existing SQL Server installation, you can change the server authentication options in SQL Server
Management Studio by right-clicking on the server in object explorer, and selecting Properties.
3. Select Security under the Properties tab. Change the Server Authentication to SQL Server and Windows
Authentication mode.
Note: Please contact your system database administrator or IT support for additional guidance.
Term Definition
Authentication Mode Template on Card: The Signo 25B is waiting for a Credential (Card) to be presented. It retrieves all the
(Signo 25B) biometric templates from the credential.
If the presented finger matches the biometric templates retrieved from the credential a Grant Access is
recommended. This is a 1:1 Verification match against Template on Card (TOC). The sensor is not armed
(blue light off) until the Credential is presented.
Card + Finger: The Signo 25B is waiting for a Credential (Card) to be presented. It looks up the user ID and
all associated biometric templates in it’s local device database. If the presented finger matches the
biometric templates retreated from the local database a Grant Access is recommended. This is a 1:1
Verification match against Template on Device (ToD). The sensor is not armed (blue light off) until the
Credential is presented.
Finger Only: The Signo 25B is waiting for a finger to be presented that is stored in its local device database.
If the presented finger matches one stored in the database a Grant Access is recommended. This is a 1:N
Identification match against Template on Device (ToD). The sensor is always armed (blue light on).
Card Only: The Signo 25B is waiting for a Credential (Card) to be presented. It reads the PACS data only and
always recommends a Grant Access. The sensor is never armed (blue light off).
Card Only (or) Finger Only: The Signo 25B is waiting for either a Credential (Card) to be presented or a
finger, stored in its local device database, to be presented. This authentication mode is particularly useful
during initial enrollment setup.
Biometric spoofing Biometric spoofing is a method of fooling a biometric identification management system. An
artificial object (for example, a fingerprint mold made of silicon) is presented to the biometric
scanner that imitates the unique biological properties of a person which the system is designed
to measure.
BLE Bluetooth Low Energy (formerly marketed as Bluetooth Smart) is a wireless personal area
network technology.
ERR The Equal Error Rate (EER) is the common value indicating that the proportion of false
acceptances (FAR) is equal to the proportion of false rejections (FRR). The lower the EER value,
the higher the accuracy of the biometric system.
False Accept Rate (FAR) The False Accept Rate (FAR) is the measure of the likelihood that the biometric security system
will incorrectly accept an access attempt by an unauthorized user.
False Reject Rate (FRR) The False Reject Rate (FRR) is the instance of a security system failing to verify or identify an
authorized person.
FTA Failure To Acquire. The biometric system failure to extract usable identification data from a
biometric sample.
Identification (of Identity) Typically finding a matching template in a large database of templates. 1:N matching.
LFD Live Finger Detection. This is used in some markets instead of Spoof. It is also used to refer to
insuring a severed finger is not being presented at the sensor.
MINEX Minutia Interoperability Exchange. The MINEX program is dedicated to the evaluation and
development of the capabilities of fingerprint minutia matchers running on ISO/IEC 7816 smart
cards.
M-Series Mercury Platform Series of Products.
MSI Multi-Spectral Imaging.
Term Definition
OSDP Open Supervised Device Protocol (OSDP) is an access control communications standard
developed by the Security Industry Association (SIA) to improve interoperability among access
control and security products.
PAD Pressure Attack Detection.
PD Presence Detection.
ROC Receiver Operating Characteristic.
SDK Software Development Kit.
SIA Structure Image Acquisition.
Tap The Tap gesture with a mobile device for door opening.
The Tap operation is typically used when the mobile device is in close proximity to the reader.
Approximately 12 inches (30 cm).
Twist and Go The Twist gesture with mobile device for door opening.
The Twist operation is typically used when the mobile device is at a longer distance from the reader.
Approximately 6 feet (2 meters).
TOC Template on Card. The PACS data is read from the card.
The users enrolled biometric template is written to a predetermined address in the application
area of the supported credentials.
ToD Template on Device. The PACS data is read from the device database.
vCOM V-Series Command Protocol.
Verification (of Identity) Typically a fingerprint template is stored on a card and checked against a finger presented to
the finger print sensor. 1:1 matching.
Idle - - Red
Revision history
Date Description Revision
August 2022 Updates to support HID Biometric Manager version 1.0.2000.00019. B.3
October 2021 Updates to support HID Biometric Manager version 1.0.1550.62511. B.2
March 2021 Updates to support Signo Biometric Reader 25B Reader version 1.5.1.44 and HID Biometric Manager B.1
version 1.0.1212.60729.
October 2020 Product rebrand from iCLASS SE® iCLASS SE RB25F to HID Signo® Biometric Reader 25B B.0
June 2020 Updates to support iCLASS SE iCLASS SE RB25F Reader version 1.5.1.22 and HID Biometric Manager A.4
version 1.0.1103.59811. Product rebrand from iCLASS SE RB25F to Signo Biometric Reader 25B.
December 2019 Updates to support HID Biometric Manager Signo Biometric Reader 25B Reader version 1.5.0.86 and A.3
HID Biometric Manager version 1.0.886.57608.
September 2019 Updates to support Signo Biometric Reader 25B reader version 1.5.0.82 and HID Biometric Manager A.2
version 1.0.774.56514.
June 2019 Minor update to Section 3.2.1 HID Biometric Manager software install. A.1
February 2019 Initial release. A.0
Dummy text.