Overview
ISO/IEC 18584-1:2025 - "Information technology - Test methods for on-card biometric comparison applications - Part 1: General principles and specifications" defines a conformance testing framework for on-card biometric comparison implementations. The standard specifies how to test that an integrated circuit card (ICC) or Biometric System-on-Card (BSoC) meets the requirements set out in ISO/IEC 24787-1, focusing on the framework and security policies for on-card comparison. It does not cover measurement of biometric algorithm performance (error rates or speed).
Key topics and technical requirements
- Scope and objective
- Establishes conformance tests against ISO/IEC 24787-1 requirements for sensor-off-card devices and BSoC.
- Emphasizes maintaining the biometric reference inside the ICC to enhance privacy and security.
- Test methodology
- Defines a test environment with a Device Under Test (DUT, the ICC) and a Test Apparatus (IFD).
- Distinguishes test flows for sensor-off-card devices (samples through IFD) versus BSoC (samples to ICC).
- Test case structure
- Each test case includes: ID, Version, Purpose, Reference, Profile, Precondition, Scenario, Expected result, Postcondition.
- Results recorded as Pass, Fail, or Not applicable in a test report.
- ICC configuration profile
- Test cases reference specific ICC feature profiles; tests may be out-of-scope if a DUT lacks required features.
- Data and process test areas
- Data formats and objects: CBEFF-3 BIDO (biometric information data object), biometric functionality information, and biometric comparison parameters.
- Process testing: enrolment, biometric verification, re‑enrolment, and termination behaviors.
- Security policies
- Tests cover retry counter management and specific security policy behaviors (labelled SP1, SP2 in the standard) with dedicated test cases.
Practical applications and who uses this standard
- Smart card and BSoC manufacturers-to validate conformance before product release.
- Testing and certification laboratories-to structure test plans, perform conformance evaluations, and produce standardized test reports.
- System integrators and solution architects-to ensure on-card biometric components meet required security and interoperability policies.
- Government ID and e‑passport programs-to specify compliant secure biometric verification for identity documents.
- Card OS and IFD vendors-to align implementations with ICC configuration profiles and command/response behaviors.
Related standards
Keywords: ISO/IEC 18584-1:2025, on-card biometric comparison, conformance testing, ICC, Biometric System-on-Card, sensor-off-card, security policy, CBEFF-3 BIDO, biometric verification, enrolment.