From aa12cc3fffe2d34602e1b3990ebbd5b430e78234 Mon Sep 17 00:00:00 2001 From: Brian Wood Date: Tue, 2 Sep 2025 16:58:53 -0400 Subject: [PATCH 1/3] Remove ATE_IND.1 reference To support EAL2 for TS 103 732 integration, should not specifically reference ATE_IND.1, but just ATE_IND in general. --- toolbox.adoc | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/toolbox.adoc b/toolbox.adoc index 93d1ae5..97e354f 100644 --- a/toolbox.adoc +++ b/toolbox.adoc @@ -240,7 +240,7 @@ The results of the presentation of artefacts is defined as: |=== -== Guidance for Independent Testing (ATE_IND.1) +== Guidance for Independent Testing (ATE_IND) For independent testing, this guidance is common for all toolboxes. More specific guidance for a specific biometric modality is provided in each toolbox. This is in addition to guidance in <>. @@ -379,4 +379,8 @@ ISO/IEC 19989 “Information security — Criteria and methodology for security |October 15, 2024 |Update to support new PAD test levels +|1.3 +|September 2, 2025 +|Remove specific reference to ATE_IND.1 to support EAL2 or higher evaluations + |=== From eb16f9bd3cd74d372d8670c3d1e5b497e73c8ba4 Mon Sep 17 00:00:00 2001 From: Brian Wood Date: Tue, 2 Sep 2025 17:00:18 -0400 Subject: [PATCH 2/3] Update toolbox.adoc --- toolbox.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/toolbox.adoc b/toolbox.adoc index 97e354f..2977b55 100644 --- a/toolbox.adoc +++ b/toolbox.adoc @@ -12,7 +12,7 @@ == Introduction The TOE may be vulnerable to presentation attacks where attackers attempt to subvert the biometric enrolment or verification by presenting the Presentation Attack Instruments (PAIs). There is a wide range of PAIs that can be used, including natural biometric characteristics, such as dead eyes, or artefacts created from copied or faked characteristics. Using natural biometric characteristics is out of scope of <> evaluation and the evaluator shall only use created artefacts to evaluate the TOE. -The toolbox defines the common artefacts for each biometric modality based on publicly available information (e.g. research papers), experiences and knowledge shared among the BIO-iTC members. The evaluator needs to read the <> Section 7 as it explains how the evaluator shall use the toolbox during the ATE_IND.1 (Independent testing) and AVA_VAN.1 (Penetration testing) evaluation for Presentation Attack Detection (PAD) in detail. In this evaluation, PAD is being measured using Imposter Attack Presentation Attack Rate (IAPAR), which is a full system review as opposed to a component level review which would evaluate the matching subsystem and PAD subsystem separately. +The toolbox defines the common artefacts for each biometric modality based on publicly available information (e.g. research papers), experiences and knowledge shared among the BIO-iTC members. The evaluator needs to read the <> Section 7 as it explains how the evaluator shall use the toolbox during the ATE_IND (Independent testing) and AVA_VAN (Penetration testing) evaluation for Presentation Attack Detection (PAD) in detail. In this evaluation, PAD is being measured using Imposter Attack Presentation Attack Rate (IAPAR), which is a full system review as opposed to a component level review which would evaluate the matching subsystem and PAD subsystem separately. This overview is originally developed for evaluation activities for FIA_MBV_EXT.3, however, the evaluator can apply the same principles to evaluation activities for FIA_MBE_EXT.3. From f3ec16c818b18366ad62633da385efeae00e969e Mon Sep 17 00:00:00 2001 From: Brian Wood Date: Wed, 7 Jan 2026 08:31:32 -0500 Subject: [PATCH 3/3] Update toolbox.adoc Co-authored-by: Greg Fiumara --- toolbox.adoc | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/toolbox.adoc b/toolbox.adoc index 2977b55..7756269 100644 --- a/toolbox.adoc +++ b/toolbox.adoc @@ -381,6 +381,6 @@ ISO/IEC 19989 “Information security — Criteria and methodology for security |1.3 |September 2, 2025 -|Remove specific reference to ATE_IND.1 to support EAL2 or higher evaluations +|Remove specific reference to ATE_IND.1 and AVA_VAN.1 to support EAL2 or higher evaluations |===