Overview
ISO/IEC 17839-3:2016 specifies the logical information interchange mechanism for a Biometric System‑on‑Card (BSoC). A BSoC is a card‑sized device that integrates biometric acquisition, signal/image processing, storage, comparison and decision making. This Part 3 standard focuses on the logical data structures, enrolment procedures, and the use of commands and data objects (APDUs) defined in other ISO standards for secure on‑card biometric processing. It does not define requirements for commands that apply to external devices or internal BSoC logical interfaces.
Key Topics
- Logical data structures: Defines biometric information templates and capability descriptors (e.g., DO ‘7F60’ for BSoC capability, DO ‘7F74’ for feature management).
- Enrolment procedures:
- Internal enrolment: On‑card sensor capture using PBO (perform biometric operation) commands such as capture-and-store or capture-and-update. Enrolment must implement feedback mechanisms and retry counters.
- External enrolment: Importing reference data captured off‑card; must comply with on‑card security policies.
- Biometric comparison:
- IFD‑initiated verification via standard verify or PBO commands.
- Self‑initiated verification triggered by an on‑card switch or automatic detection; BSoC must manage power, result validity (configurable, max ~1 minute), and expiration.
- Feedback and status reporting: Use of card‑originated byte strings and standard status words (SW1‑SW2), including success ‘90 00’, warnings (‘62 xx’, ‘63 xx’) and specific errors such as timeout (‘64 83’) or non‑matching sample (‘64 84’).
- Service discovery and device descriptors: DO ‘62’, DO ‘81’, DO ‘82’ and templates in EF.ATR/INFO or FCI indicate available on‑card services and sensors.
- Conformance: BSoC implementations must meet mandatory requirements in the standard.
Applications
ISO/IEC 17839-3 is practical for organizations building or certifying secure biometric smart cards and related systems:
- Smart card and secure element manufacturers implementing BSoC firmware and APDU handling.
- Biometric module vendors integrating on‑card sensors, templates and comparison engines.
- Card issuers and system integrators designing enrolment flows (internal vs external) and verification workflows.
- Security architects and certification bodies validating conformance, feedback mechanisms, and retry/power management policies.
Keywords: biometric system-on-card, BSoC, ISO/IEC 17839-3, logical information interchange mechanism, on-card biometric comparison, enrolment procedures, APDU, SW1-SW2.
Related Standards
Normative references used by ISO/IEC 17839-3 include:
Annexes in the standard provide sample APDUs, command comparisons and self‑activation examples for implementation guidance.