Overview
ISO/IEC 30108-2:2023 - Biometrics - Identity attributes verification services - Part 2: RESTful specification defines how identity attributes verification services (IAVSs) are implemented using a RESTful API model. It translates the generic service and data model of ISO/IEC 30108-1 into concrete REST endpoints, data types and behaviors for remote (backend) biometric services. The standard focuses on server-side biometric and identity assurance functions and explicitly excludes client-side capture device protocols and embedding biometric services directly into authentication protocols.
Key technical topics and requirements
- RESTful service model: A full mapping of ISO/IEC 30108-1 functionality into REST semantics, including request/response formats and endpoint behaviors.
- Primitive and aggregated services: Detailed primitive operations (examples include Add Subject To Gallery, Identify Subject, Verify Subject, Create Subject, Delete Biometric Data, Check Quality, Perform Fusion) and higher-level aggregated workflows (Enrol, Identify, Verify, Delete, Update).
- Data elements and types: Standardized definitions for biographic data, biometric data (including CBEFF BIR support), document data, candidate lists, fusion information, and capability descriptions.
- Error handling and notifications: HTTP response mappings, error condition codes and guidance for REST error semantics.
- Security and conformance: Security considerations for backend biometric services and conformance rules for implementing compliant IAVSs.
- Normative machine-readable artifacts: Annexes include an OpenAPI™ (YAML) specification and CBEFF Patron Format (YAML) to accelerate implementation and interoperability.
Practical applications and target users
ISO/IEC 30108-2 is designed for organizations building server-side biometric identity services and APIs, such as:
- Biometric system architects and backend developers implementing identity verification and enrolment services
- Identity assurance and eKYC solution providers integrating biometric matching and document checks
- Government agencies and border control systems that require standardized biometric verification APIs
- Vendors offering biometric-as-a-service, galleries and candidate-matching services
- Integrators who need a standards-based REST API for interoperability between capture/front-end systems and backend matching engines
Practical use cases include identity verification for digital onboarding, multi-modal biometric fusion services, centralized biometric galleries, audit-able enrolment and deletion workflows, and scalable candidate identification.
Related standards
- ISO/IEC 30108-1 - conceptual service model and functional definitions (foundation for Part 2)
- CBEFF (Common Biometric Exchange Formats Framework) - referenced for biometric record formats and patrONs
ISO/IEC 30108-2:2023 provides a prescriptive, REST-focused roadmap to deploy interoperable backend biometric services-complete with data models, error handling, security guidance, and OpenAPI artifacts for rapid implementation. Keywords: ISO/IEC 30108-2, biometrics, RESTful specification, identity attributes verification, biometric APIs, identity assurance, OpenAPI, CBEFF.