Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Biometric assurance

PAD: know
what was evaluated.

Do not publish L2/L3 labels or accuracy figures without a report for the specific configuration.

Required PAD evaluation record

FieldRequirement
ISO/IEC 30107-3:2023Reference for evaluation and reporting.
Evaluation schemeScheme, laboratory and report identifier required.
Attack scopeList attack instruments, conditions and configuration; do not infer coverage from a marketing label.
APCER / BPCERNo report supplied in the input package; no values published.
Injection attacksEvaluate the channel/API separately; do not assume PAD testing covers injection.

Liveness is
device-profile dependent.

Do not mark every possible technique as supported.

Technique to evaluatePublication condition
IR / NIR analysisRequires the corresponding sensor, algorithm and report.
Active challengeEvaluate usability and replay resistance.
Passive analysisNeeds defined attack scope and operating conditions.
Depth / multispectralMention only when supported by the model and profile.

Evidence before publication

Device & firmware
Confirmation required
Algorithm & threshold
Confirmation required
Report & laboratory
Not supplied
Status
Project-specific validation required
View ISO reference ↗

Mobile-ID module PAD evidence.

PCEB 26/04/06: ISO/IEC 30107-3:2017, Level 2 on Android and iPhone. Not automatically applicable to palm sensors/engines.

Search Trusted Palm ID

Selected interface