Information technology — Test methods for on-card biometric comparison applications — Part 1: General principles and specifications

This document establishes conformance testing for the requirements described in ISO/IEC 24787-1, which are: — framework for on-card biometric comparison, both in sensor-off-card systems and as part of Biometric System-on-Card; — security policies for on-card biometric comparison. Measuring the performance of on-card biometric comparison algorithms such as error rates or speed is not within the scope of this document.

Technologies de l'information — Méthodes d'essai pour les applications de comparaison biométrique sur carte — Partie 1: Principes généraux et spécifications

General Information

Status
Published
Publication Date
28-May-2025
Current Stage
6060 - International Standard published
Start Date
29-May-2025
Due Date
11-Jul-2025
Completion Date
29-May-2025
Ref Project

Relations

Standard
ISO/IEC 18584-1:2025 - Information technology — Test methods for on-card biometric comparison applications — Part 1: General principles and specifications Released:29. 05. 2025
English language
19 pages
sale 15% off
Preview
sale 15% off
Preview

Standards Content (Sample)


International
Standard
ISO/IEC 18584-1
First edition
Information technology — Test
2025-05
methods for on-card biometric
comparison applications —
Part 1:
General principles and
specifications
Technologies de l'information — Méthodes d'essai pour les
applications de comparaison biométrique sur carte —
Partie 1: Principes généraux et spécifications
Reference number
© ISO/IEC 2025
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting on
the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address below
or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
© ISO/IEC 2025 – All rights reserved
ii
Contents Page
Foreword .iv
Introduction .v
1 Scope . 1
2 Normative references . 1
3 Terms and definitions . 1
4 Abbreviated terms . 2
5 Test methodology . 2
5.1 Test environment .2
5.2 Test case .3
5.3 Test report .3
6 ICC configuration profile . 3
7 Summary of the test cases . 4
8 Common test requirement . 5
9 Test requirements related to framework for on-card biometric comparison . 6
9.1 Data for on-card biometric comparison — CBEFF-3 BIDO .6
9.1.1 General .6
9.1.2 Test case: CBF_001 .6
9.2 Data for on-card biometric comparison — Biometric functionality information .7
9.2.1 General .7
9.2.2 Test case: BFI_001 .7
9.3 Data for on-card biometric comparison — Biometric comparison parameters .9
9.3.1 General .9
9.3.2 Test case: BCP_001 .9
9.3.3 Test case: BCP_002 .11
9.4 Processes .11
9.4.1 Enrolment .11
9.4.2 Biometric verification . 12
9.4.3 Re-enrolment . 12
9.5 Termination .14
9.5.1 General .14
9.5.2 Test case: TMN_001 .14
9.5.3 Test case: TMN_002 . 15
10 Security policy .15
10.1 Retry counter management . 15
10.1.1 General . 15
10.1.2 Test case: RCM_001 .16
10.1.3 Test case: RCM_002 .16
10.1.4 Test case: RCM_003 .17
10.2 Security policy for SP1 .17
10.2.1 General .17
10.2.2 Test case: SP1_001 .17
10.3 Security policy for SP2 .18
10.3.1 General .18
10.3.2 Test case: SP2_001 .18

© ISO/IEC 2025 – All rights reserved
iii
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical activity.
ISO and IEC technical committees collaborate in fields of mutual interest. Other international organizations,
governmental and non-governmental, in liaison with ISO and IEC, also take part in the work.
The procedures used to develop this document and those intended for its further maintenance are described
in the ISO/IEC Directives, Part 1. In particular, the different approval criteria needed for the different types
of document should be noted. This document was drafted in accordance with the editorial rules of the ISO/
IEC Directives, Part 2 (see www.iso.org/directives or www.iec.ch/members_experts/refdocs).
ISO and IEC draw attention to the possibility that the implementation of this document may involve the
use of (a) patent(s). ISO and IEC take no position concerning the evidence, validity or applicability of any
claimed patent rights in respect thereof. As of the date of publication of this document, ISO and IEC had not
received notice of (a) patent(s) which may be required to implement this document. However, implementers
are cautioned that this may not represent the latest information, which may be obtained from the patent
database available at www.iso.org/patents and https://patents.iec.ch. ISO and IEC shall not be held
responsible for identifying any or all such patent rights.
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation of the voluntary nature of standards, the meaning of ISO specific terms and expressions
related to conformity assessment, as well as information about ISO's adherence to the World Trade
Organization (WTO) principles in the Technical Barriers to Trade (TBT) see www.iso.org/iso/foreword.html.
In the IEC, see www.iec.ch/understanding-standards.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 17, Cards and security devices for personal identification.
This first edition of ISO/IEC 18584-1, together with ISO/IEC 18584-2, cancels and replaces
ISO/IEC 18584:2015.
A list of all parts in the ISO/IEC 18584 series can be found on the ISO and IEC websites.
Any feedback or questions on this document should be directed to the user’s national standards
body. A complete listing of these bodies can be found at www.iso.org/members.html and
www.iec.ch/national-committees.

© ISO/IEC 2025 – All rights reserved
iv
Introduction
On-card biometric comparison provides a more secure biometric verification method than off-card biometric
comparison, as the comparison is executed inside the integrated circuit card (ICC) and the biometric
reference is never revealed outside the ICC. ISO/IEC 24787-1 specifies a set of requirements for implementing
biometric comparison inside the ICC. An ICC application that claims conformance to ISO/IEC 24787-1 fulfils
a set of requirements outlined in this document. The requirements are established for on-card biometric
comparison in both a sensor-off card and a Biometric System-on-Card, as defined in ISO/IEC 24787-1.

© ISO/IEC 2025 – All rights reserved
v
International Standard ISO/IEC 18584-1:2025(en)
Information technology — Test methods for on-card
biometric comparison applications —
Part 1:
General principles and specifications
1 Scope
This document establishes conformance testing for the requirements described in ISO/IEC 24787-1, which are:
— framework for on-card biometric comparison, both in sensor-off-card systems and as part of Biometric
System-on-Card;
— security policies for on-card biometric comparison.
Measuring the performance of on-card biometric comparison algorithms such as error rates or speed is not
within the scope of this document.
2 Normative references
The following documents are referred to in the text in such a way that some or all of their content constitutes
requirements of this document. For dated references, only the edition cited applies. For undated references,
the latest edition of the referenced document (including any amendments) applies.
ISO/IEC 2382-37, Information technology — Vocabulary — Part 37: Biometrics
ISO/IEC 7816-4, Identification cards — Integrated circuit cards — Part 4: Organization, security and commands
for interchange
ISO/IEC 7816-11, Identification cards — Integrated circuit cards — Part 11: Personal verification through
biometric methods
ISO/IEC 17839-3, Information technology — Identification cards — Biometric System-on-Card — Part 3: Logical
information interchange mechanism
ISO/IEC 19785-3:2020, Information technology — Common Biometric Exchange Formats Framework — Part 3:
Patron format specifications
ISO/IEC 19794 (all parts), Information technology — Biometric data interchange formats
ISO/IEC 24787-1:2024, Information technology — On-card biometric comparison — Part 1: General principles
and specifications
ISO/IEC 29794 (all parts), Information technology — Biometric sample quality
3 Terms and definitions
For the purposes of this document, the terms and definitions given in ISO/IEC 2382-37 and
ISO/IEC 24787-1 apply.
ISO and IEC maintain terminology databases for use in standardization at the following addresses:
— ISO Online browsing platform: available at https:// www .iso .org/ obp

© ISO/IEC 2025 – All rights reserved
— IEC Electropedia: available at https:// www .electropedia .org/
4 Abbreviated terms
For the purposes of this document, the abbreviated terms given in ISO/IEC 24787-1 and the following apply.
BSoC Biometric System-on-Card
DUT device under test
COS card operating system
IFD interface device
N/A not applicable
BIDO biometric information data object
CBEFF-3 Common Biometric Exchange Formats Framework — Part 3 — Patron format specification (ISO/
IEC 19785-3)
5 Test methodology
5.1 Test environment
Figure 1 and Figure 2 illustrate a typical test environment, which comprises a DUT and a test apparatus.
DUT is an ICC that is either a sensor-off-card device or a BSoC. Test apparatus is an IFD that sends command
messages to the DUT and receives response messages from the DUT. A DUT and a test apparatus are
connected by a physical interface that exchanges the messages. When a sensor-off-card device is evaluated
as a DUT, biometric samples are presented from a card holder to the test apparatus (see Figure 1). On the
other hand, when a BSoC is evaluated as a DUT, biometric samples are presented from a card holder to the
DUT (see Figure 2).
Figure 1 — Test environment for sensor-off-card device

© ISO/IEC 2025 – All rights reserved
Figure 2 — Test environment for BSoC
5.2 Test case
Each test case is introduced with the following information.
ID Introduces a unique test case identifier.
Version Specifies version number of the test case.
Purpose Specifies functionalities to be evaluated by this test.
Reference Introduces the references to the base requirements that bring this test case.
Introduces an ICC configuration profile to be tested, which is a set of specific features
Profile to be supported by the ICC. When the ICC does not support any of the features, this test
case is out of scope for evaluation of the ICC.
Precondition Specifies an internal state of the ICC to be transited before the scenario is performed.
Scenario Specifies test steps to be performed.
Expected result Specifies pass criteria for each test step of the test scenario.
Postcondition Specifies an internal state of the ICC to be transited after the scenario is performed.
An ID of each test case has a prefix label of test category which forms three digits of alphabet or number.
Test category is a set of test cases that is grouped by the same subject to be evaluated.
5.3 Test report
A test report shall be provided to analyse the detail of evaluation. The test report captures all test cases by
recording its ID. When a test case is applied to an evaluation, result of the test case is also recorded. Test
results are categorized into either "Pass" or "Fail". "Pass" is applied if the expected result of the test case
matches with all actual behaviours of the DUT and if the postcondition of the test case is fulfilled by the
actual internal state of the DUT after the scenario performed. "Fail" is applied if the expected result of the
test case does not match with any actual behaviour of the DUT or if the postcondition of the test case is not
fulfilled by the actual internal state of the DUT after the scenario is performed. The method to verify each
postcondition is not specified in this document since it depends on the specification of the DUT. If a test case
is not applied during evaluation because a DUT does not meet the profile of the test case, the test report will
record that the test case was not applicable.
6 ICC configuration profile
Each test case introduces an ICC configuration profile, which requires a specific feature list to be supported
by the ICC. All specific features to be used in this document are listed below:

© ISO/IEC 2025 – All rights reserved
(A) CBEFF-3 BIDOs are retrievable from ICC
(B) A biometric functionality information DO is retrievable from the ICC.
(C) A biometric comparison parameters DO is retrievable from the ICC.
(D) A biometric reference has already been stored.
(E) A biometric reference has not been stored yet.
(F) Work-sharing is not supported.
(G) Re-enrolment is supported.
(H) Re-enrolment is prohibited.
(I) A re-enrolment capability DO'83' is retrievable from the ICC.
(J) Termination of an on-card biometric comparison application is supported.
(K) Mechanism to reset a retry counter is supported to unblock the on-card biometric comparison.
(L) Global biometric comparison parameters and retry counter for the shared biometric reference (SP1)
(M) Independent biometric comparison parameters and retry counter for the shared biometric reference
(SP2)
(N) A biometric comparison parameters DO is updateable.
(O) Independent biometric comparison parameters and retry counter for application-specific biometric
reference (SP3)
7 Summary of the test cases
Table 1 introduces summary of test cases for framework defined in this clause.
Table 1 — Test case summary
Profile
ID Summary
A B C D E F G H I J K L M N
CBF_001 CBEFF-3 BIDO retrieval X X
BFI_001 Biometric functionality information retrieval X
BCP_001 Biometric comparison parameters retrieval X X
BCP_002 Biometric comparison parameters compatibility X X X
ENR_001 Enrolment capability  X
VER_001 Biometric verification functionality  X X
REN_001 Security rules applied to re-enrolment  X X
REN_002 Re-enrolment capability (supported) X X X X
REN_003 Re-enrolment capability (prohibited) X X  X X
TMN_001 Application termination (biometric verification denied)  X   X
TMN_002 Application termination (re-enrolment denied)  X X X
RCM_001 Retry counter reset by successful verification  X
Application blocked by retry counter reaching the maxi-
RCM_002  X
mum limit
NOTE SP3 is evaluated by applying the test categories other than SP1 and SP2 to each of multiple on-card biometric comparison
applications.
© ISO/IEC 2025 – All rights reserved
TTabablele 1 1 ((ccoonnttiinnueuedd))
Profile
ID Summary
A B C D E F G H I J K L M N
RCM_003 Application unblocked by resetting retry counter  X   X
A biometric comparison parameters DO is not updated by
SP1_001 X X    X X
any application independently in SP1
A biometric comparison parameters DO is updated by
SP2_001 X X    X X
only the associated application in SP2
NOTE SP3 is evaluated by applying the test categories other than SP1 and SP2 to each of multiple on-card biometric comparison
applications.
8 Common test requirement
To avoid redundancy of description in relevant tests, the common test requirements are listed as below.
These requirements are referenced from the following relevant sections:
(1) Value of a biometric data DO is in a format as defined in ISO/IEC 7816-11.
(See ISO/IEC 24787-1:2024, 8.3.2)
(2) If PBO command is used for enrolment, re-enrolment, or verification with externally-
captured biometric data, the command data field forms either DO'7F2E' (see
Table 4), DO'7F60' (see Table 3), or DO'7F61' (see Table 2) to transfer the biometric data.
(See ISO/IEC 24787-1:2024, 8.4.1, 8.4.2)
(3) Regardless of the command, the biometric data is encapsulated in either a DO'5F2E' or DO'7F2E' if the
biometric data is transferred in a biometric information template DO'7F60' (see Table 3).
(See ISO/IEC 24787-1:2024, 8.3.1 Table 2, 8.3.2)
(4) All biometric data are enciphered for transmission to the ICC unless the trusted environment is
established to keep confidentiality including guaranteeing cardholders' privacy.
(See ISO/IEC 24787-1:2024, 8.4.1, 9.1.2 Item d)
Table 2 — Biometric data transferred on DO'7F61'
T L V Presence
'7F61' Var. Biometric information template group template Mandatory
T L V —
'7F60' Var. Biometric information template (see Table 3) Mandatory
NOTE Any other DO can be included within this structure (see ISO/IEC 24787-1).
Table 3 — Biometric data transferred on DO'7F60'
T L V Presence
'7F60' Var. Biometric information template Mandatory
T L V —
Biometric data (Primitive/constructed) (see Table 4
'5F2E' or '7F2E' Var. Mandatory
for DO'7F2E')
NOTE Any other DO can be included within this structure (see ISO/IEC 24787-1).

© ISO/IEC 2025 – All rights reserved
Table 4 — Biometric data transferred on DO'7F2E'
T L V Presence
'7F2E' Var. Biometric data Mandatory
T L V —
Biometric data in standardized format
'81' or 'A1' Var. Mandatory
(Primitive/constructed)
NOTE Any other DO can be included within this structure (see ISO/IEC 24787-1).
9 Test requirements related to framework for on-card biometric comparison
9.1 Data for on-card biometric comparison — CBEFF-3 BIDO
9.1.1 General
This test category is applied if CBEFF-3 BIDOs are retrievable from ICC. The ICC is evaluated by the format
of CBEFF-3 BIDOs are structured properly. Also, general requirements regarding message integrity and
security are evaluated by this test category. When the ICC supports multiple applications hosted by multiple
DFs, this test category is also applied to multiple CBEFF-3 DOs associated with each application.
9.1.2 Test case: CBF_001
ID CBF_001
Version 1
Purpose To check that the following requirements are implemented.
— CBEFF-3 BIDOs are located within the required DO structure.
— ICC does not send out any biometric reference.
— Message integrity is assured in the retrieval of the DOs within a biometric information
template.
Reference ISO/IEC 24787-1:2024, 8.3.1, 9.1.2 Item a), 9.1.2 Item c)
Profile (A)  CBEFF-3 BIDOs are retrievable from ICC.
(D)  A biometric reference has already been stored.
Precondition — A DF including a CBEFF-3 BIDOs is selected.
— Security attributes associated with retrieval of CBEFF-3 BIDOs are satisfied.
— If necessary, a secure channel is established.
a, b
Scenario (1) Send a command(s) to retrieve CBEFF-3 BIDOs .
Expected result (1-1) The ICC returns SW1-SW2 as '9000'.
(1-2) The response data field includes a full or a part of the structure specified in Table 5
b
that contains CBEFF-3 BIDOs.
(1-3) Message integrity of any data objects in the response data field, which are found in
Table 5, is assured.
(1-4) Any biometric data is not included in the response data field.
Postcondition N/A
a
According to the implementation of the DUT, the scenario is composed of a command(s) to retrieve a whole structure
specified in Table 5 or to retrieve a part of the structure of Table 5 that includes CBEFF-3 BIDOs (e.g. by READ BINARY or GET
DATA command).
b
Each of the mandatory tags in Table 5 appears in a command(s) of Scenario (1) to indicate a path to retrieve the CBEFF-3
BIDOs or in a response data as a component of a template DO that stores CBEFF-3 BIDOs.

© ISO/IEC 2025 – All rights reserved
Table 5 — Container of CBEFF-3 BIDOs
T L V Presence
'7F60' Var. Biometric information template Mandatory
T L V —
'A1' Var. Biometric information DOs specified by other than ISO/IEC
Mandatory
7816-11
T L V —
'78' Var. Compatible tag allocation authority Mandatory
T L V —
Object identifier of the patron
'06' Var. format specified in ISO/IEC Mandatory
19785-3:2020, Clause 19
'70' Var. Biometric information DOs specified by the com-
Mandatory
patible tag allocation authority
T L V —
'XX' Var. CBEFF-3 BIDO Mandatory
: : : :
NOTE Any other DO can be included within this structure except for biometric data (see ISO/IEC 24787-1).
9.2 Data for on-card biometric comparison — Biometric functionality information
9.2.1 General
This test category is applied if a biometric functionality information DO is retrievable from the ICC. This
test category evaluates that the format of a biometric functionality information DO is structured properly.
Also, general requirements regarding message integrity and security are evaluated by this test category.
When the ICC supports multiple biometric modalities, this test category is also applied to multiple biometric
functionality information DOs associated with each biometric modality.
9.2.2 Test case: BFI_001
ID BFI_001
Version 1
Purpose To check that the following requirements are implemented.
— a biometric functionality information DO is located within the required DO structure.
— ICC does not send out any biometric reference.
— Message integrity is assured in the retrieval of the DOs within a biometric information
template.
Reference ISO/IEC 24787-1:2024, 8.3.1, 8.3.3.2 Table 7, 9.1.2 Item a), 9.1.2 Item c)
Profile (B)  A biometric functionality information DO is retrievable from ICC.
NOTE When this test case applied to an ICC with multiple biometric modalities, check that each biometric modality has its own
biometric
...

Questions, Comments and Discussion

Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.

Loading comments...