Overview
ISO/IEC 27553-2:2025 - "Information security, cybersecurity and privacy protection - Security and privacy requirements for authentication using biometrics on mobile devices - Part 2: Remote modes" defines high-level security and privacy requirements for biometric authentication when biometric samples or derived biometric data are transmitted between mobile devices and remote services. The standard focuses on remote modes (partial or full off‑device processing, remote presentation-attack detection, outsourced biometric references, or server-side comparison) and covers functional components, communication, storage and remote processing. Enrollment, purely local modes, and biometric identification are out of scope.
Key topics and requirements
- Scope and architecture: generic system architecture, entities (mobile biometric system, RP agent, authentication agent, authentication and RP servers) and workflow types for remote modes.
- Threat analysis: threats to biometric data at capture, in transit, in storage and during remote processing; risks from heterogeneous remote service security.
- Security requirements: high‑level controls for mobile‑side components, server‑side processing, storage protection and secure communication channels (confidentiality, integrity, replay protection).
- Privacy requirements: protections for biometric data lifecycle, minimization, and considerations for persistent biometric characteristics.
- Recommendations: mitigations tailored for remote operation (e.g., limiting shared biometric information, protecting against eavesdropping and replay, addressing AI-generated synthetic biometric risks).
- Supporting content: implementation example (Annex A) and guidance on authentication assurance levels (Annex B).
- Normative references: aligns with ISO/IEC 24745 (Biometric information protection), ISO/IEC 27002 (security controls), ISO/IEC 18031 (random bit generation) and ISO/IEC 29100 (privacy framework).
Practical applications
ISO/IEC 27553-2:2025 is applicable to systems that capture biometric samples on mobile devices and transmit biometric data or derived data to remote services. Typical use cases:
- Mobile banking and financial services using remote biometric verification
- Government eID and remote identity proofing where biometric comparison occurs on servers
- Cloud-based presentation-attack detection (PAD) or hybrid on-device/server PAD
- Outsourced biometric storage and server-side matching for enterprise access control
- Federated authentication services integrating mobile biometrics with remote relying parties
Who should use this standard
- Security architects and system designers implementing biometric authentication for mobile apps
- Mobile application developers integrating remote biometric flows
- Cloud and identity service providers offering server-side biometric processing or storage
- Risk managers, auditors and compliance officers evaluating biometric privacy and security posture
- Regulators and procurement teams specifying requirements for biometric remote modes
Related standards
Keywords: ISO/IEC 27553-2:2025, biometrics, mobile devices, remote modes, biometric authentication, privacy, security requirements, biometric data transmission, presentation-attack detection.