Overview
ISO/IEC 24713-2:2008 defines a biometric profile for interoperability and data interchange specifically for physical access control for employees at airports. The standard specifies the application profile, required parameters, and interfaces between function modules (notably BioAPI-based modules and external interfaces) to support token-based biometric identification and verification at local access points (doors and controlled entrances) and across local boundaries within an airport’s defined area of control. It assumes an existing access control system and focuses on adding an interoperable biometric component rather than prescribing a complete access control solution.
Key Topics and Requirements
- Token-based biometric model: Tokens (smartcards or similar) are expected to contain one or more reference and/or operational biometrics for employee identification and verification.
- Inter-module interfaces: Defines interfaces between BioAPI modules and external systems to enable consistent biometric operations.
- Enrollment and lifecycle: Recommended practices for enrolment, proofing, registration, issuance, activation, and ongoing usage of biometric tokens.
- Operational safeguards: Guidance on watch-list checking, duplicate issuance prevention, and secure token management.
- Conformance & ICS: Systems must implement mandatory capabilities in the Requirements List and provide a profile-specific Implementation Conformance Statement (ICS) (Annex A).
- Security considerations: The standard includes security approaches and threat considerations (Annex C) and recommends safeguarding confidentiality, integrity, and availability of biometric data in line with local policy.
- Interchange formats: References and aligns with biometric data interchange formats for multiple modalities (fingerprint, face, iris, signature, vascular, hand geometry) and interface frameworks (CBEFF, BioAPI).
Applications and Who Uses It
- Airport operators and security teams: Implement interoperable biometric additions to existing access control for employee movement within secure zones.
- Access control system integrators: Integrate BioAPI-compliant biometric modules and ensure token compatibility across local boundaries.
- Biometric vendors and device manufacturers: Build modules and tokens that conform to the profile for interchange and interoperability.
- IT/security architects and consultants: Design token management, issuance workflows, and risk mitigation strategies consistent with the profile.
- Regulators and procurement teams: Specify interoperable biometric requirements when procuring airport access control solutions.
Related Standards
Key referenced standards for implementation include:
This profile is intended to enable secure, interoperable biometric access control deployments in airport employee environments while leaving system-wide access control policies and broader privacy regulations to local authorities.