ISO/IEC 30136:2018 PDF
Information technology — Performance testing of biometric template protection schemes
Information technology — Performance testing of biometric template protection schemes
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 23
- Дата публикации:
- 9 марта 2018 г.
- Издание:
- ISO/IEC IS 30136 edition 1 version 1
- ICS:
- 35.040
ISO/IEC 30136:2018 supports evaluation of the accuracy, secrecy, and privacy of biometric template protection schemes. It establishes definitions, terminology, and metrics for stating the performance of such schemes. Particularly, this document establishes requirements for the measurement and reporting of: - theoretical and empirical accuracy of biometric template protection schemes, - theoretical and empirical probability of a successful attack on biometric template protection schemes (single or multiple), and - the information leaked about the original biometric when one or more biometric template protection schemes are compromised. ISO/IEC 30136:2018 also gives guidance on measuring and reporting diversity and unlinkability of templates. ISO/IEC 30136:2018 does not: - establish template protection schemes; - address testing of traditional encryption schemes.
Abstract
Overview
ISO/IEC 30136:2018 - Information technology: Performance testing of biometric template protection schemes - defines a common framework and metrics to evaluate the accuracy, secrecy and privacy of biometric template protection. It sets out definitions, terminology and requirements for both theoretical and empirical performance measurement of template protection schemes (e.g., cancellable biometrics, fuzzy vaults, secure sketch approaches), and gives guidance on reporting diversity and unlinkability of protected templates. The standard does not define protection algorithms themselves or cover traditional encryption testing.
Key topics and technical requirements
- Performance metrics: Specifies metrics to describe enrolment and verification behaviour, including accuracy degradation (difference in FNMR/FMR with/without protection), and traditional recognition metrics (FNMR/FMR).
- Security and privacy metrics: Defines and requires measurement/reporting of irreversibility, unlinkability, diversity, storage requirements, and optional Successful Attack Rate (SAR) for single or multiple compromised templates.
- Theoretical vs empirical evaluation: Requires both analytical (theoretical) and test-based (empirical) approaches to quantify accuracy, probability of successful attacks, and information leakage.
- Threat models and attack methods: Describes threat models (naïve, collision, general) and methodologies for evaluating how adversaries may exploit compromised templates or multiple devices.
- Architectural guidance: Provides examples and considerations for common architectures - e.g., two-factor systems (smart card or password), multiple database deployment, and data separation strategies - to ensure testing reflects realistic deployments.
- Reporting requirements: Defines how to measure and report metrics consistently so different schemes can be compared.
Applications and users
ISO/IEC 30136:2018 is intended for:
- Biometric system designers and engineers evaluating template protection mechanisms.
- Conformity assessment and test laboratories performing performance and security testing.
- Security architects, privacy officers and risk assessors who need to quantify information leakage, revocability and unlinkability risks.
- Procurement teams and integrators comparing candidate biometric protection solutions for deployable systems (access control, identity systems).
- Researchers benchmarking new secure-biometric constructions against standardized metrics.
Practical uses include comparative testing of template protection schemes, documenting privacy guarantees for deployments, informing threat models for biometric systems, and supporting certification or procurement specifications.
Related standards
- ISO/IEC 24745:2011 - Biometric information protection (context and methods)
- ISO/IEC 19795-1 - Biometric performance testing and reporting (principles)
- ISO/IEC 2382-37 - Biometrics vocabulary
Adopting ISO/IEC 30136:2018 helps ensure consistent, reproducible assessment of biometric template protection performance across vendors and deployments.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 37 - Biometrics
- SKU
- ISO/IEC 30136:2018
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
BS ISO/IEC 19795-10:2024
ДействующийInformation technology. Biometric performance testing and reporting. Quantifying biometric system performance…
SIST EN ISO/IEC 2382-37:2024
ДействующийInformation technology - Vocabulary - Part 37: Biometrics (ISO/IEC 2382-37:2022)
Overview SIST EN ISO/IEC 2382-37:2024 defines a standardized vocabulary for the field of biometrics concerning the recognition of human beings. Developed by CEN and based on ISO/IEC 2382-37:2022, thi…
ISO 8689-1:2000
ДействующийWater quality — Biological classification of rivers — Part 1: Guidance on the interpretation of biological qu…
Overview ISO 8689-1:2000, titled Water quality - Biological classification of rivers - Part 1: Guidance on the interpretation of biological quality data from surveys of benthic macroinvertebrates, is…
ISO/ASTM51540-04(2012)
ОтменёнStandard Practice for Use of a Radiochromic Liquid Dosimetry System (Withdrawn 2020)
Significance and Use4.1 The radiochromic liquid dosimetry system provides a means of measuring absorbed dose in materials (5-7). Under the influence of ionizing radiation, chemical reactions take pla…
ISO/ASTM51204-04
ДействующийStandard Practice for Dosimetry in Gamma Irradiation Facilities for Food Processing (Withdrawn 2013)
Significance and Use4.1 Food products may be treated with ionizing radiation, such as gamma-rays from 60Co or 137Cs sources, for numerous purposes, including control of parasites and pathogenic micro…
ISO/ASTM51431-05
ОтменёнStandard Practice for Dosimetry in Electron Beam and X-Ray (Bremsstrahlung) Irradiation Facilities for Food P…
Significance and Use4.1 Food products may be treated with acceleratorgenerated radiation (electrons and X-rays) for numerous purposes, including control of parasites and pathogenic microorganisms, in…
ISO/ASTM52628-20e1
ДействующийStandard Practice for Dosimetry in Radiation Processing
1.1 This practice describes the basic requirements that apply when making absorbed dose measurements in accordance with the ASTM E61 series of dosimetry standards. In addition, it provides guidance o…
ISO/ASTM52921-13(2019)
ДействующийStandard Terminology for Additive Manufacturing—Coordinate Systems and Test Methodologies
Significance and Use 3.1 Although many additive manufacturing systems are based heavily upon the principles of Computer Numerical Control (CNC), the coordinate systems and nomenclature specific to CN…