ISO/IEC 30136:2018
Information technology — Performance testing of biometric template protection schemes
Information technology — Performance testing of biometric template protection schemes
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 23
- Дата публикации:
- 9 марта 2018 г.
- Издание:
- ISO/IEC IS 30136 edition 1 version 1
- ICS:
- 35.040
ISO/IEC 30136:2018 supports evaluation of the accuracy, secrecy, and privacy of biometric template protection schemes. It establishes definitions, terminology, and metrics for stating the performance of such schemes. Particularly, this document establishes requirements for the measurement and reporting of: - theoretical and empirical accuracy of biometric template protection schemes, - theoretical and empirical probability of a successful attack on biometric template protection schemes (single or multiple), and - the information leaked about the original biometric when one or more biometric template protection schemes are compromised. ISO/IEC 30136:2018 also gives guidance on measuring and reporting diversity and unlinkability of templates. ISO/IEC 30136:2018 does not: - establish template protection schemes; - address testing of traditional encryption schemes.
Abstract
Overview
ISO/IEC 30136:2018 - Information technology: Performance testing of biometric template protection schemes - defines a common framework and metrics to evaluate the accuracy, secrecy and privacy of biometric template protection. It sets out definitions, terminology and requirements for both theoretical and empirical performance measurement of template protection schemes (e.g., cancellable biometrics, fuzzy vaults, secure sketch approaches), and gives guidance on reporting diversity and unlinkability of protected templates. The standard does not define protection algorithms themselves or cover traditional encryption testing.
Key topics and technical requirements
- Performance metrics: Specifies metrics to describe enrolment and verification behaviour, including accuracy degradation (difference in FNMR/FMR with/without protection), and traditional recognition metrics (FNMR/FMR).
- Security and privacy metrics: Defines and requires measurement/reporting of irreversibility, unlinkability, diversity, storage requirements, and optional Successful Attack Rate (SAR) for single or multiple compromised templates.
- Theoretical vs empirical evaluation: Requires both analytical (theoretical) and test-based (empirical) approaches to quantify accuracy, probability of successful attacks, and information leakage.
- Threat models and attack methods: Describes threat models (naïve, collision, general) and methodologies for evaluating how adversaries may exploit compromised templates or multiple devices.
- Architectural guidance: Provides examples and considerations for common architectures - e.g., two-factor systems (smart card or password), multiple database deployment, and data separation strategies - to ensure testing reflects realistic deployments.
- Reporting requirements: Defines how to measure and report metrics consistently so different schemes can be compared.
Applications and users
ISO/IEC 30136:2018 is intended for:
- Biometric system designers and engineers evaluating template protection mechanisms.
- Conformity assessment and test laboratories performing performance and security testing.
- Security architects, privacy officers and risk assessors who need to quantify information leakage, revocability and unlinkability risks.
- Procurement teams and integrators comparing candidate biometric protection solutions for deployable systems (access control, identity systems).
- Researchers benchmarking new secure-biometric constructions against standardized metrics.
Practical uses include comparative testing of template protection schemes, documenting privacy guarantees for deployments, informing threat models for biometric systems, and supporting certification or procurement specifications.
Related standards
- ISO/IEC 24745:2011 - Biometric information protection (context and methods)
- ISO/IEC 19795-1 - Biometric performance testing and reporting (principles)
- ISO/IEC 2382-37 - Biometrics vocabulary
Adopting ISO/IEC 30136:2018 helps ensure consistent, reproducible assessment of biometric template protection performance across vendors and deployments.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 37 - Biometrics
- SKU
- ISO/IEC 30136:2018
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 19795-1:2021
ДействующийInformation technology. Biometric performance testing and reporting. Principles and framework.
BS EN 17054:2019
ДействующийBiometrics multilingual vocabulary based upon the English version of ISO/IEC 2382-37:2012.
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…