diff --git a/toolbox.adoc b/toolbox.adoc index 93d1ae5..7756269 100644 --- a/toolbox.adoc +++ b/toolbox.adoc @@ -12,7 +12,7 @@ == Introduction The TOE may be vulnerable to presentation attacks where attackers attempt to subvert the biometric enrolment or verification by presenting the Presentation Attack Instruments (PAIs). There is a wide range of PAIs that can be used, including natural biometric characteristics, such as dead eyes, or artefacts created from copied or faked characteristics. Using natural biometric characteristics is out of scope of <> evaluation and the evaluator shall only use created artefacts to evaluate the TOE. -The toolbox defines the common artefacts for each biometric modality based on publicly available information (e.g. research papers), experiences and knowledge shared among the BIO-iTC members. The evaluator needs to read the <> Section 7 as it explains how the evaluator shall use the toolbox during the ATE_IND.1 (Independent testing) and AVA_VAN.1 (Penetration testing) evaluation for Presentation Attack Detection (PAD) in detail. In this evaluation, PAD is being measured using Imposter Attack Presentation Attack Rate (IAPAR), which is a full system review as opposed to a component level review which would evaluate the matching subsystem and PAD subsystem separately. +The toolbox defines the common artefacts for each biometric modality based on publicly available information (e.g. research papers), experiences and knowledge shared among the BIO-iTC members. The evaluator needs to read the <> Section 7 as it explains how the evaluator shall use the toolbox during the ATE_IND (Independent testing) and AVA_VAN (Penetration testing) evaluation for Presentation Attack Detection (PAD) in detail. In this evaluation, PAD is being measured using Imposter Attack Presentation Attack Rate (IAPAR), which is a full system review as opposed to a component level review which would evaluate the matching subsystem and PAD subsystem separately. This overview is originally developed for evaluation activities for FIA_MBV_EXT.3, however, the evaluator can apply the same principles to evaluation activities for FIA_MBE_EXT.3. @@ -240,7 +240,7 @@ The results of the presentation of artefacts is defined as: |=== -== Guidance for Independent Testing (ATE_IND.1) +== Guidance for Independent Testing (ATE_IND) For independent testing, this guidance is common for all toolboxes. More specific guidance for a specific biometric modality is provided in each toolbox. This is in addition to guidance in <>. @@ -379,4 +379,8 @@ ISO/IEC 19989 “Information security — Criteria and methodology for security |October 15, 2024 |Update to support new PAD test levels +|1.3 +|September 2, 2025 +|Remove specific reference to ATE_IND.1 and AVA_VAN.1 to support EAL2 or higher evaluations + |===