Overview
ISO/IEC 30136:2018 - Information technology: Performance testing of biometric template protection schemes - defines a common framework and metrics to evaluate the accuracy, secrecy and privacy of biometric template protection. It sets out definitions, terminology and requirements for both theoretical and empirical performance measurement of template protection schemes (e.g., cancellable biometrics, fuzzy vaults, secure sketch approaches), and gives guidance on reporting diversity and unlinkability of protected templates. The standard does not define protection algorithms themselves or cover traditional encryption testing.
Key topics and technical requirements
- Performance metrics: Specifies metrics to describe enrolment and verification behaviour, including accuracy degradation (difference in FNMR/FMR with/without protection), and traditional recognition metrics (FNMR/FMR).
- Security and privacy metrics: Defines and requires measurement/reporting of irreversibility, unlinkability, diversity, storage requirements, and optional Successful Attack Rate (SAR) for single or multiple compromised templates.
- Theoretical vs empirical evaluation: Requires both analytical (theoretical) and test-based (empirical) approaches to quantify accuracy, probability of successful attacks, and information leakage.
- Threat models and attack methods: Describes threat models (naïve, collision, general) and methodologies for evaluating how adversaries may exploit compromised templates or multiple devices.
- Architectural guidance: Provides examples and considerations for common architectures - e.g., two-factor systems (smart card or password), multiple database deployment, and data separation strategies - to ensure testing reflects realistic deployments.
- Reporting requirements: Defines how to measure and report metrics consistently so different schemes can be compared.
Applications and users
ISO/IEC 30136:2018 is intended for:
- Biometric system designers and engineers evaluating template protection mechanisms.
- Conformity assessment and test laboratories performing performance and security testing.
- Security architects, privacy officers and risk assessors who need to quantify information leakage, revocability and unlinkability risks.
- Procurement teams and integrators comparing candidate biometric protection solutions for deployable systems (access control, identity systems).
- Researchers benchmarking new secure-biometric constructions against standardized metrics.
Practical uses include comparative testing of template protection schemes, documenting privacy guarantees for deployments, informing threat models for biometric systems, and supporting certification or procurement specifications.
Related standards
Adopting ISO/IEC 30136:2018 helps ensure consistent, reproducible assessment of biometric template protection performance across vendors and deployments.