Overview
ISO/IEC 27553-1:2022 - "Information security, cybersecurity and privacy protection - Security and privacy requirements for authentication using biometrics on mobile devices - Part 1: Local modes" defines high‑level security and privacy requirements and recommendations for biometric authentication performed on mobile devices when biometric data and any derived biometric data do not leave the device (local modes). The standard targets the interaction between local biometric components and mobile applications or remote relying parties, and emphasizes threat analysis, secure component design, communication controls, and privacy safeguards.
Key topics and requirements
- Scope and applicability: Applies only to local modes where biometric data remain on the device; excludes identity proofing/enrolment and purely local applications with no remote service involvement.
- Security challenges: Discusses general biometric risks plus mobile‑specific issues such as device diversity, open computation environments, and unsupervised operation.
- System description: Provides an example architecture and defines entities/components including biometric system, biometric processing unit (BPU), authentication agent, relying party agent, and servers.
- Information assets & threat analysis: Identifies assets (biometric samples, templates, credentials) and enumerates threats to biometric systems and authentication agents.
- Security requirements & recommendations: High‑level controls for biometric subsystems, mobile device integration, and secure communication between agents and relying parties. (Detailed implementation requirements are left to implementers.)
- Privacy considerations: Guidance on privacy policies for biometric data, handling of derived data, and minimizing data exposure.
- Supporting content: Informative annexes include implementation examples, communication security issues, and authentication assurance/assurance levels.
Practical applications
- Secure mobile authentication for banking and payment apps where biometric templates remain on-device.
- Enterprise single sign-on and device‑binding scenarios that rely on local biometric verification.
- Mobile app developers and SDK providers implementing privacy‑aware biometric authentication flows.
- Evaluations of mobile biometric subsystems for product security reviews and risk assessments.
Who should use this standard
- Mobile device manufacturers and OS vendors
- Biometric hardware and SDK developers
- Security architects and product managers for mobile services
- Privacy officers and compliance teams assessing biometric data handling
- Certification bodies and auditors assessing high‑level security frameworks
Related standards
- ISO/IEC 24745 - Biometric information protection
- ISO/IEC 30107 series - Presentation attack detection (PAD)
- Part of the ISO/IEC 27553 series (other parts cover non‑local modes and related topics)
This standard is essential for organizations designing or assessing biometric authentication on mobile devices that require strong on‑device privacy and secure local verification.