Overview
ISO/IEC 17839-1:2025 - Information technology - Biometric System-on-Card (BSoC) - Part 1: Core requirements - defines the functional architecture and core requirements for integrating biometric capture, processing, storage, comparison, decision and action into a card-sized device. The standard covers two BSoC form-factors: Type ID-1 (conforming to ISO/IEC 7810 card dimensions) and Type ID-T (as specified in ISO/IEC 18328-2:2021, Annex A). It focuses on on-card biometric verification (the entire verification process executed on the card) and describes sensor types, discriminative power (biometric accuracy criteria), interfaces and power-supply options.
Key topics and requirements
- Functional architecture: Defines the end-to-end BSoC verification flow - capture, feature extraction, on-card comparison, decision and action - and how interfaces map to existing standards.
- Form factors:
- Type ID-1 BSoC - ISO/IEC 7810 dimensions, must pass torsion and bending tests; supports contact, USB, contactless and NFC interfaces.
- Type ID-T BSoC - deviates from some ISO/IEC 7810 constraints (thicker), supports contactless and NFC only.
- Sensor types: Area and swipe fingerprint sensors are explicitly addressed; other modalities (e.g., voice, dynamic signature) are allowed with appropriate sensors.
- Discriminative power: Biometric accuracy must follow FMR grading as defined in ISO/IEC 24787-1.
- Interfaces: Conformance to ISO/IEC 7816-3, ISO/IEC 7816-12, ISO/IEC 14443 series and ISO/IEC 18092 for contact/contactless/NFC operation.
- Power supply: Supports contact, contactless (ISO/IEC 14443-2 / ISO/IEC 18092) and internal power options (battery or capacitor). Battery-powered BSoC should support at least one full verification without recharge and may allow self-initiated verification.
- User feedback: On-card or reader-provided feedback (LED, display, buzzer, or IFD interpretation) to indicate verification status.
- Out of scope: Off-card comparison, storage-on-card architectures, sensor-off-card on-card comparison and detailed component specifications.
Applications
Practical uses of ISO/IEC 17839-1:2025 include designing and specifying secure, portable biometric verification solutions where the biometric match is performed entirely on the card. Typical applications:
- secure identity verification and authentication in constrained environments
- tamper-resistant personal ID and credential cards
- access control and verification systems requiring strong privacy protection (no biometric data leaves the card)
Who should use this standard
- card manufacturers and module designers
- biometric sensor vendors and system integrators
- government agencies and identity program architects
- test labs and conformity assessors
Related standards
Key references and interoperable standards: ISO/IEC 7810, ISO/IEC 7816-3, ISO/IEC 7816-12, ISO/IEC 14443 (all parts), ISO/IEC 18092, ISO/IEC 18328-2:2021 (Annex A), ISO/IEC 24787-1:2024, ISO/IEC 17839-3 and ISO/IEC 2382-37.