biometricITC / cPP-biometrics

Contains the development of a Collaborative Protection Profile for biometrics
MIT License
10 stars 2 forks source link

NIST 800-63B Biometric performance for different demographic #411

Closed n-kai closed 1 year ago

n-kai commented 1 year ago

Section - 5.2.3

Page - 34

Line - 1326-1327

Comment

Guidance created by the Biometrics Security iTC only recommends vendors to report test subject demographics (e.g., age, gender and ethnicity) in the performance test report because there is no best practice or standard (e.g., how many test subjects should be gathered for each ethnicity at minimum?) to estimate performance for different demographic types objectively.

However, ISO SC37 is developing ISO/IEC 19795-10 “Information technology — Biometric performance testing and reporting — Part 10: Quantifying biometric system performance variation across demographic groups” and we may see a clear standard in this area in the future. So, SHALL (requirement) should be replaced with SHOULD until we can see such standard and have a common understanding what “similar performance” exactly means.

Suggested Change

Biometric authentication technologies SHOULD provide similar performance for subscribers of different demographic types (racial background, gender, ethnicity, etc.).