Biometric Test Center
Biometric Test Center
Independent biometric testing at NTNU
SAFE helps biometric technology providers, financial institutions and public-sector organisations evaluate whether biometric systems are secure, reliable and ready for real-world use. Our goal is to provide independent testing that makes performance, limitations and risks easier to understand.
What we test
- Presentation attack detection (PAD): resilience against masks, printed and replayed media, artificial fingerprints, voice replay and other presentation attack instruments.
- Injection attack detection (IAD): protection against manipulated, replayed or synthetic media injected into camera, microphone and sensor pipelines.
- Biometric performance: verification and identification accuracy, failure-to-acquire rates, non-response, operating thresholds and scenario effects.
- Modality-specific systems: face, fingerprint, finger-vein, voice and multimodal biometrics.
- Responsible deployment: demographic performance, explainability, privacy, usability and scenario-specific risk.
Standards and reference frameworks
| Standard or programme | How it applies |
|---|---|
| ISO/IEC 17025:2017 | Competence, impartiality and consistent operation of testing laboratories; the foundation of SAFE’s accreditation roadmap. |
| ISO/IEC 30107-1 | Framework and terminology for biometric presentation attack detection. |
| ISO/IEC 30107-2 | Data formats for communicating presentation-attack detection results. |
| ISO/IEC 30107-3 | Testing and reporting for presentation attack detection, including APCER, BPCER, IAPMR and relevant non-response rates. |
| ISO/IEC 30107-4 | Mobile-device presentation attack detection profiles and testing considerations. |
| ISO/IEC 19795-1 | General principles and framework for biometric performance testing and reporting. |
| ISO/IEC 19795-2 | Technology and scenario evaluation methods for biometric recognition systems. |
| ISO/IEC 19795-10 | Evaluation of biometric performance variation across demographic groups. |
| ISO/IEC 24745 | Protection of biometric information throughout its lifecycle. |
| ISO/IEC 39794 series | Extensible biometric data interchange formats for modalities including face, fingerprints and iris. |
| FIDO Alliance biometric requirements | Reference requirements for biometric component certification and authenticator ecosystems. |
Evaluation profiles
Every evaluation is tailored to the product and intended use. PAD work can progress through baseline, advanced and expert attack profiles, from readily available presentation attack instruments to attacks requiring specialist materials, equipment and expertise. The agreed plan defines the attack species, number of presentations, bona fide trials, metrics, decision thresholds, device configuration and retest conditions before testing begins.
How a test project works
- Scope: we review the product, biometric modality, threat model and intended deployment.
- Test plan: we agree methods, samples, metrics, acceptance criteria and handling of confidential material.
- Independent evaluation: trained researchers execute the agreed protocol in a controlled environment.
- Report and retest: you receive documented evidence, limitations and actionable findings, with a defined route to retesting.
Accreditation roadmap
SAFE is building documented procedures, validated methods, equipment controls, staff competence, impartiality safeguards and quality assurance in preparation for formal laboratory accreditation. Initial priorities include ISO/IEC 17025 and defined biometric performance and presentation-attack testing scopes. Any accredited scope or approved certification programme will be published here only after formal confirmation.