Overview
ISO/IEC 30107-4:2024 - "Information technology - Biometric presentation attack detection - Part 4: Profile for testing of mobile devices" is an ISO profile that tailors PAD (presentation attack detection) testing requirements specifically for mobile devices. It specifies how to evaluate PAD mechanisms on mobile devices with local biometric recognition and on biometric modules integrated into mobile devices. The profile lists mobile-specific requirements drawn from ISO/IEC 30107-3 and adds mobile-focused requirements and test approaches. It applies to closed systems (no access to internal PAD results) and excludes devices that rely solely on remote biometric recognition. Only attacks at the capture device during presentation are considered.
Key topics and technical requirements
- Scope and applicability: Targets mobile devices (smartphones, tablets, wearables, laptops) and embedded biometric modules operating as closed systems. Not applicable to remote-only biometric systems.
- PAD evaluation profile: Defines a mobile-specific profile that maps ISO/IEC 30107-3 requirements to an “Approach in PAD Tests for Mobile Devices,” including numerical best-practices where appropriate.
- Attack types and attacker models: Requires specification of the presentation attacker type (e.g., biometric impostor or concealer) and the set or range of attack types under test.
- Item under test (IUT) description: Test reports must fully describe mobile device model, OS and version, sensor position (front/back), biometric module positioning, and user interaction method (touch, swipe, gaze, passphrase).
- Evaluation level: Emphasizes full-system evaluations for mobile devices; clarifies when subsystem or capture-level tests apply.
- PAI and bona fide samples: Requires a representative set of presentation attack instruments (PAIs) and bona fide test subjects; best-practice PAI species minimum has been updated (document notes change from minimum 3 to minimum 6).
- Artefact creation and usage: Test reports must document artefact creation, preparation difficulty, durability, presenter training level, and any oversight during usage.
- FIDO-specific profile: Clause dedicated to FIDO biometric PAD evaluation requirements for Fast IDentity Online implementations on mobile platforms.
Applications and who uses this standard
- Mobile device manufacturers and biometric module vendors - for implementing, testing and documenting PAD capability.
- Security evaluation laboratories and certification bodies - to plan and execute PAD tests and to produce compliant evaluation reports.
- Mobile OS and app developers integrating local biometric authentication - to understand testing expectations and ensure compatibility with PAD profiles.
- Procurement, compliance, and risk teams - to specify PAD testing requirements in contracts and regulatory submissions.
- FIDO implementers - to align mobile biometric PAD tests with FIDO-specific requirements.
Related standards
Keywords: ISO/IEC 30107-4:2024, biometric presentation attack detection, PAD testing, mobile devices, FIDO biometric, biometric module, presentation attack instruments, mobile biometrics.