ISO/IEC 24761:2019 PDF
Information technology — Security techniques — Authentication context for biometrics
Information technology — Security techniques — Authentication context for biometrics
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 75
- Дата публикации:
- 14 октября 2019 г.
- Издание:
- ISO/IEC IS 24761 edition 2 version 1
- ICS:
- 35.030
This document defines the structure and the data elements of Authentication Context for Biometrics (ACBio), which is used for checking the validity of the result of a biometric enrolment and verification process executed at a remote site. This document allows any ACBio instance to accompany any biometric processes related to enrolment and verification. The specification of ACBio is applicable not only to single modal biometric enrolment and verification but also to multimodal fusion. The real-time information of presentation attack detection is not provided in this document. Only the assurance information of presentation attack detection (PAD) mechanism can be contained in the BPU report. Biometric identification is out of the scope of this document. This document specifies the cryptographic syntax of an ACBio instance. The cryptographic syntax of an ACBio instance is defined in this document applying a data structure specified in Cryptographic Message Syntax (CMS) schema whose concrete values can be represented using a compact binary encoding. This document does not define protocols to be used between entities such as BPUs, claimant, and validator. Its concern is entirely with the content and encoding of the ACBio instances for the various processing activities.
Abstract
Overview - ISO/IEC 24761:2019 (ACBio)
ISO/IEC 24761:2019, titled Information technology - Security techniques - Authentication context for biometrics (ACBio), defines the structure and data elements used to represent assurance about biometric enrolment and verification performed at a remote site. An ACBio instance is a signed report (encoded using ASN.1/BER) that carries information about the biometric processing units (BPUs), biometric references, verification results, and associated certificates so a remote validator can check the integrity and trustworthiness of a biometric transaction without receiving private biometric data.
Key aspects:
- Specifies the cryptographic syntax of ACBio instances using the Cryptographic Message Syntax (CMS) schema and compact binary encoding.
- Focuses on content and encoding of ACBio instances; it does not define protocols between BPUs, claimants, and validators.
- Applicable to single-modal and multimodal fusion biometric processes; biometric identification is out of scope.
- Real-time presentation attack detection (PAD) data is not provided; only PAD assurance information can appear in BPU reports.
Key Topics and Requirements
- ACBio instance structure: data blocks for BPU information, biometric processing details, and certificates.
- BPU (Biometric Processing Unit) reports and BPU certificates: provide assurance of device identity, capability, and execution integrity.
- Biometric capability classes: model for grouping how enrolment/verification functions map to BPU roles (e.g., sensor, comparator, storage).
- Cryptographic assurances: digital signatures and X.509 certificates (PKI/PKIX) to ensure data origin and integrity.
- Encoding and syntax: ASN.1 module and BER encoding for interoperable, compact binary representation.
- Privacy-preserving validation: design enables validators to assess results without receiving raw biometric samples.
Practical Applications and Who Uses It
ACBio is intended for organizations and professionals building or auditing biometric authentication systems that require verifiable, privacy-preserving evidence about remote biometric transactions:
- Biometric device vendors producing BPU firmware and BPU reports
- System integrators implementing remote verification or enrolment workflows
- Security architects and engineers defining assurance and trust frameworks
- Certification authorities issuing BPU and BRT certificates
- Service providers offering mobile authentication, e‑government or remote identity-proofing solutions that need tamper-evident transaction evidence
Related Standards
- ISO/IEC 24745 - Biometric information protection
- ISO/IEC 9594-8 / PKIX - Public-key and attribute certificate frameworks
- ISO/IEC 2382-37 - Biometrics vocabulary
- RFC/CMS and ASN.1/BER standards (for encoding and cryptographic message structures)
ISO/IEC 24761:2019 is essential when you need standardized, signed authentication context for biometric enrolment and verification, enabling trusted remote validation while preserving biometric privacy.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 27 - Information security, cybersecurity and privacy protection
- SKU
- ISO/IEC 24761:2019
Похожие стандарты
Стандарты, упомянутые в описании
BS ISO/IEC 24745:2022
ДействующийInformation security, cybersecurity and privacy protection. Biometric information protection.
ISO/IEC 9594-8:2020/Cor 2:2024
ДействующийInformation technology — Open systems interconnection — Part 8: The Directory: Public-key and attribute certi…
Overview ISO/IEC 9594-8:2020/Cor 2:2024 is a technical corrigendum to the international standard for Information Technology-Open Systems Interconnection (OSI)-The Directory: Public-key and Attribute…
SIST EN ISO/IEC 2382-37:2024
ДействующийInformation technology - Vocabulary - Part 37: Biometrics (ISO/IEC 2382-37:2022)
Overview SIST EN ISO/IEC 2382-37:2024 defines a standardized vocabulary for the field of biometrics concerning the recognition of human beings. Developed by CEN and based on ISO/IEC 2382-37:2022, thi…