Overview
ISO/IEC TR 30117:2021 - "Information technology - Standards and applications for the integration of biometrics and integrated circuit cards (ICCs)" - is a technical report that summarizes how international standards and recommendations address personal identification and information security when combining biometrics with smartcards/ICCs. It maps relevant standards, describes integration architectures, data formats, privacy and security considerations, and provides implementation examples (e.g., ePassport and Spain’s DNIe). The report is aimed at designers, integrators and policymakers who need a pragmatic guide to standards selection and system design.
Key technical topics and requirements
- Architectures for integration: four primary approaches are defined and compared:
- Off-card biometric comparison (ICC stores reference; comparison performed externally)
- On-card biometric comparison (ICC stores reference and performs comparison)
- Work-sharing on-card comparison (processing split between ICC and external systems)
- Biometric System-on-Card (BSoC) (card contains capture, storage and comparison)
- Data formats and encapsulation: discussion of single-modality biometric data formats, multi-modality encapsulation, and ICC-specific data objects. Relevant frameworks include CBEFF, BIR/BDB and TLV/ASN.1 encodings used for interchange.
- Privacy and security controls: privacy-aware design, access controls, cryptographic protections, limiting unsuccessful comparisons, and secure operations aligned with ICC security mechanisms (e.g., PKI, BAC/EAC for travel documents).
- APIs and application interfaces: guidance on APIs and integration patterns for outside-ICC application development, including local and client‑server models and service interfaces.
- Use-case profiling and evaluation: templates for mapping standards to verification scenarios, technology evaluation criteria, and example implementations (Spanish DNIe, ePassport).
- Standards linkage: pointers to relevant committees (ISO/IEC JTC 1 SC 17, SC 27, SC 37) and related standards such as ISO/IEC 24787, ISO/IEC 19785 and ISO/IEC 7816.
Practical applications and who uses this standard
- Applications: national ID programs, ePassports, PIV and government credentials, secure access control, mobile and banking smartcard authentication.
- Users: system architects, security engineers, smartcard manufacturers, biometrics vendors, government program managers, and compliance officers who must align deployments with international standards and privacy/security best practices.
Related standards (select)
This report is a practical roadmap to selecting and combining international standards for secure, privacy-conscious biometric implementations on or with ICCs.