Overview
ISO/IEC 30107-1:2023 - "Information technology - Biometric presentation attack detection - Part 1: Framework" defines a common framework and vocabulary for Presentation Attack Detection (PAD) in biometric systems. It establishes terms, concepts and a structure for specifying, characterizing and evaluating PAD methods, focusing specifically on attacks that occur at the biometric capture device during presentation. This second edition (2023) harmonizes terms with other parts of the ISO/IEC 30107 series. The document does not standardize specific algorithms, sensors, countermeasures or system-level security assessments.
Key Topics
- Core definitions and vocabulary: PAD, liveness, bona‑fide presentation, biometric presentation attack, presentation attack instrument (PAI).
- Characterization of presentation attacks: taxonomy of attacks (artefact vs human-based vs other natural PAIs), impostor vs concealer attacks, and conformant vs non‑conformant presentations.
- PAD framework and process: types of PAD, the role and variants of challenge–response, liveness detection concepts, and how PAD integrates in biometric system architecture.
- Operational boundaries and scope: explicit focus on capture-device attacks; excludes sensor tampering, communications compromise, and broader system vulnerability assessments.
- Obstacles and trade-offs: recognition of PAD error types (false positives/negatives) and the balance between security and usability/performance.
Applications
ISO/IEC 30107-1 provides practical value across the biometric lifecycle:
- Design and specification: helps vendors and system architects describe PAD requirements and where PAD modules fit within the biometric pipeline.
- Test and evaluation: gives a consistent vocabulary and framework used by test labs and evaluators to characterize PAD behaviour and prepare datasets.
- Procurement and compliance: enables buyers and integrators to specify PAD capabilities and evaluate vendor claims.
- Policy and risk management: supports decision-making on suitable PAD strategies for remote authentication, unattended systems, and high‑security deployments.
Keywords for SEO: presentation attack detection, PAD, biometric security, liveness detection, presentation attack instrument (PAI), ISO/IEC 30107-1:2023, biometric capture device.
Who would use this standard
- Biometric system designers and integrators
- Security architects and risk assessors
- PAD algorithm developers and vendors
- Test laboratories and certification bodies
- Procurement teams and policy makers in identity, finance, government and mobile authentication contexts
Related Standards
This framework standard is the foundational reference for consistent communication, specification and evaluation of PAD across the biometric industry.