Biometric authentication systems store the biometric data of users in order to verify their identity for access to systems or spaces. ISO/IEC 24761 defines the structure and the data elements of authentication context for biometrics (ACBio), which is used for checking the validity of the result of a biometric enrolment and verification process executed at a remote site.
ISO/IEC 24761 specifies the authentication context for biometrics usage to accompany any biometric processes related to enrolment and verification. The specification of authentication context for biometrics is applicable not only to single modal biometric enrolment and verification but also to multimodal fusion.
ISO/IEC 24761 specifies the cryptographic syntax of an authentication context for biometric usage. The cryptographic syntax of an authentication context for biometrics instance is defined in this document applying a data structure specified in cryptographic message syntax (CMS) schema whose concrete values can be represented using a compact binary encoding.
Note: ISO/IEC 24761 does not define protocols to be used between entities such as BPUs, claimants, and validators. Its concern is entirely with the content and encoding of the ACBio instances for the various processing activities.
ISO/IEC 24761 on the authentication context for biometrics is useful for:
While biometric systems allow recognition using mathematical algorithms and biometric data, they require upstream enrolment of users.
The authentication context for biometrics defines data formats for evidence data generated by biometric processing units (BPUs), such as a sensor, smartcard or comparison device, which are carried in data structures called authentication context for biometrics instances.
Conforming to ISO/IEC 24761, authentication context for biometrics specifies a trust and assurance mechanism based on digital signature technology to provide assured information about the biometric processing unit and its execution of the biometric enrolment and verification processes where the assured information about the biometric processing units is provided as biometric processing units report issued by the vendor of the biometric processing units.
In ISO/IEC 24761, the authentication context for biometrics recognizes that privacy requirements concerned with the storage of biometric data must comply with local laws and legislation on data privacy.
Authentication context for biometrics ensures that the validator can validate the result of the biometric verification process without receiving private data, such as the biometric sample acquired from the claimant, or the biometric reference used for comparison.
BS ISO/IEC 24761:2019 supersedes BS ISO/IEC 24761:2009, which has been technically revised. BS ISO/IEC 24761:2019 includes some technical changes with respect to BS ISO/IEC 24761:2009. These include:
ISO/IEC 24761