ISO/IEC 19785-4:2025
Information technology — Common Biometric Exchange Formats Framework — Part 4: Security block format specifications
Information technology — Common Biometric Exchange Formats Framework — Part 4: Security block format specifications
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 20
- Дата публикации:
- 25 июля 2025 г.
- Издание:
- ISO/IEC IS 19785 edition 2 version 1
- ICS:
- 35.240.15
This document specifies security block (SB) formats (see ISO/IEC 19785-1) registered in accordance with ISO/IEC 19785-2 as formats defined by the Common Biometric Exchange Formats Framework (CBEFF) biometric organization ISO/IEC JTC 1/SC 37. This document also specifies registered SB format identifiers. NOTE The SB format identifier is recorded in the standard biometric header (SBH) of a patron format (or defined by that patron format as the only available SB format). The general-purpose SB format specifies whether the biometric data block (BDB) is encrypted or the SBH and BDB have integrity applied (or both). The general-purpose SB format can include ACBio instances (see ISO/IEC 24761). This SB provides all necessary security parameters, including those used for encryption or integrity. This document does not restrict the algorithms and parameters used for encryption or integrity, but it provides for the recording of such algorithms and parameter values. This document does not cover profiling to determine what algorithms and parameter ranges can be used by the generator of an SB for a particular application area, and hence what algorithms and parameter ranges have to be supported by the user of an SB. The second SB format is more limited but simpler. In particular, it cannot contain ACBio instances and does not support encryption of the BDB. The general-purpose SB format in XML provides for specification of whether the BDB is encrypted or the SBH and BDB have integrity applied (or both).
Abstract
Overview
ISO/IEC 19785-4:2025 specifies security block (SB) formats and registered SB format identifiers for the Common Biometric Exchange Formats Framework (CBEFF). It defines how biometric data blocks (BDBs) and the standard biometric header (SBH) can be protected for integrity and/or confidentiality, and records the security parameters needed to interpret those protections. The standard provides ASN.1 and XML SB formats and uses the Cryptographic Message Syntax (CMS, RFC 5652) as the basis for message protection, with specific adaptations for biometric exchange.
Key topics and technical requirements
- SB format registration and identifiers: Defines how SB formats are identified and recorded in the SBH of a CBEFF patron format.
- General-purpose SB format (ASN.1): An extensible format supporting encryption and/or integrity protection of the BDB and SBH; can include optional ACBio instances (see ISO/IEC 24761) to convey authentication context.
- Signature-only SB format (ASN.1): A simpler SB limited to integrity (signatures) and not supporting encryption or ACBio instances.
- XML general-purpose SB: Provides an XML schema alternative that indicates whether the BDB is encrypted and/or integrity-protected.
- Use of CMS (RFC 5652): Modifies EnvelopedData, EncryptedData, SignedData, and AuthenticatedData structures to meet biometric-specific needs while preserving CMS principles.
- Security parameters recording: The standard does not mandate specific cryptographic algorithms or parameter values, but it requires the recording of algorithm identifiers and parameter values so receivers can interpret protections.
- Conformance, versioning and domain of use: Includes provisions for format version identifiers, conformance statements, and domains of use defined by the SB owner.
- Scope exclusions: The document does not perform profiling (i.e., it does not prescribe which algorithms or parameter ranges must be used in specific application domains).
Applications and practical value
- Secure biometric interchange between systems (e.g., AFIS, border control, eID, mobile biometrics).
- Interoperability for vendors and integrators by standardizing how integrity and encryption metadata are packaged with biometric data.
- Telebiometric authentication deployments that require authentication context (ACBio) to assess security level of biometric assertions.
- Government and identity programs that must audit and verify the origin and integrity of biometric evidence.
Who should use this standard
- Biometric system architects and implementers
- Identity management and e-government solution providers
- Security architects defining biometric protection policies
- Vendors of biometric data exchange formats and SDKs
- Standards bodies and integrators working with CBEFF patron formats
Related standards
- ISO/IEC 19785-1 (CBEFF core framework)
- ISO/IEC 19785-2 (CBEFF registration procedures)
- ISO/IEC 24761 (Authentication Context for Biometrics - ACBio)
- RFC 5652 (Cryptographic Message Syntax - CMS)
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 37 - Biometrics
- SKU
- ISO/IEC 19785-4:2025
Похожие стандарты
Стандарты, упомянутые в описании