ISO/IEC 24713-2:2008
Information technology — Biometric profiles for interoperability and data interchange — Part 2: Physical access control for employees at airports
Information technology — Biometric profiles for interoperability and data interchange — Part 2: Physical access control for employees at airports
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 46
- Дата публикации:
- 22 мая 2008 г.
- Издание:
- ISO/IEC IS 24713 edition 1 version 1
- ICS:
- 35.040
ISO/IEC 24713-2:2008 specifies the application profile including necessary parameters and interfaces between function modules (i.e. BioAPI based modules and an external interface) in support of token-based biometric identification and verification of employees, at local access points (i.e. doors or other controlled entrances) and across local boundaries within the defined area of control in an airport. The token is expected to contain one or more reference biometrics, one or more operational biometrics, or both.
Abstract
Overview
ISO/IEC 24713-2:2008 defines a biometric profile for interoperability and data interchange specifically for physical access control for employees at airports. The standard specifies the application profile, required parameters, and interfaces between function modules (notably BioAPI-based modules and external interfaces) to support token-based biometric identification and verification at local access points (doors and controlled entrances) and across local boundaries within an airport’s defined area of control. It assumes an existing access control system and focuses on adding an interoperable biometric component rather than prescribing a complete access control solution.
Key Topics and Requirements
- Token-based biometric model: Tokens (smartcards or similar) are expected to contain one or more reference and/or operational biometrics for employee identification and verification.
- Inter-module interfaces: Defines interfaces between BioAPI modules and external systems to enable consistent biometric operations.
- Enrollment and lifecycle: Recommended practices for enrolment, proofing, registration, issuance, activation, and ongoing usage of biometric tokens.
- Operational safeguards: Guidance on watch-list checking, duplicate issuance prevention, and secure token management.
- Conformance & ICS: Systems must implement mandatory capabilities in the Requirements List and provide a profile-specific Implementation Conformance Statement (ICS) (Annex A).
- Security considerations: The standard includes security approaches and threat considerations (Annex C) and recommends safeguarding confidentiality, integrity, and availability of biometric data in line with local policy.
- Interchange formats: References and aligns with biometric data interchange formats for multiple modalities (fingerprint, face, iris, signature, vascular, hand geometry) and interface frameworks (CBEFF, BioAPI).
Applications and Who Uses It
- Airport operators and security teams: Implement interoperable biometric additions to existing access control for employee movement within secure zones.
- Access control system integrators: Integrate BioAPI-compliant biometric modules and ensure token compatibility across local boundaries.
- Biometric vendors and device manufacturers: Build modules and tokens that conform to the profile for interchange and interoperability.
- IT/security architects and consultants: Design token management, issuance workflows, and risk mitigation strategies consistent with the profile.
- Regulators and procurement teams: Specify interoperable biometric requirements when procuring airport access control solutions.
Related Standards
Key referenced standards for implementation include:
- ISO/IEC 19784-1 (BioAPI)
- ISO/IEC 19785 (CBEFF)
- ISO/IEC 19794 series (biometric data interchange formats for fingers, face, iris, etc.)
- ISO/IEC 19795 series (performance testing)
This profile is intended to enable secure, interoperable biometric access control deployments in airport employee environments while leaving system-wide access control policies and broader privacy regulations to local authorities.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 37 - Biometrics
- SKU
- ISO/IEC 24713-2:2008
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 19784-1:2018
ДействующийInformation technology. Biometric application programming interface. BioAPI specification.
ISO/IEC 19785-4:2025
ДействующийInformation technology — Common Biometric Exchange Formats Framework — Part 4: Security block format specific…
Overview ISO/IEC 19785-4:2025 specifies security block (SB) formats and registered SB format identifiers for the Common Biometric Exchange Formats Framework (CBEFF). It defines how biometric data blo…
ISO/IEC 29109-9:2011
ДействующийInformation technology — Conformance testing methodology for biometric data interchange formats defined in IS…
Overview ISO/IEC 29109-9:2011 specifies a conformance testing methodology for vascular image data records defined in ISO/IEC 19794-9:2007. Its purpose is to establish repeatable, objective tests that…