Biometric assurancePAD: know
PAD: know
what was evaluated.
Do not publish L2/L3 labels or accuracy figures without a report for the specific configuration.
Required PAD evaluation record
| Field | Requirement |
|---|---|
| ISO/IEC 30107-3:2023 | Reference for evaluation and reporting. |
| Evaluation scheme | Scheme, laboratory and report identifier required. |
| Attack scope | List attack instruments, conditions and configuration; do not infer coverage from a marketing label. |
| APCER / BPCER | No report supplied in the input package; no values published. |
| Injection attacks | Evaluate the channel/API separately; do not assume PAD testing covers injection. |
Liveness is
device-profile dependent.
Do not mark every possible technique as supported.
| Technique to evaluate | Publication condition |
|---|---|
| IR / NIR analysis | Requires the corresponding sensor, algorithm and report. |
| Active challenge | Evaluate usability and replay resistance. |
| Passive analysis | Needs defined attack scope and operating conditions. |
| Depth / multispectral | Mention only when supported by the model and profile. |
Evidence before publication
Mobile-ID module PAD evidence.
PCEB 26/04/06: ISO/IEC 30107-3:2017, Level 2 on Android and iPhone. Not automatically applicable to palm sensors/engines.