GB/T 38671-2020 in English
VALIDInformation security technology -- Technical requirements for remote face recognition system
- Issued on:2020-04-28
- Implemented on:2020-11-01
- File Format:PDF
- Delivery:Via email within 1~3 business days
$379.00
《GB/T 38671-2020信息安全技术 远程人脸识别系统技术要求》由TC260(全国网络安全标准化技术委员会)归口,主管部门为国家标准化管理委员会。
Introduction
Analysis of the Standard Core Framework
| Technical Dimensions | Basic Level Requirements | Enhanced Level Requirements |
|---|---|---|
| Liveness Detection Capability | Defense against static attacks (photos/paper masks) | Increase defense against dynamic attacks (3D masks/video forgeries) |
| False Acceptance Rate (FAR) | FRR≤5% when ≤0.1% | FRR≤5% when ≤0.01% |
| Security Audit | Record 10 types of security events | Add data integrity check |
Key technology implementation points
1. Liveness detection dual mode
The standard requires that the system must support both:
- Active detection: Verification through command actions (nodding/blinking, etc.)
- Passive detection: Use near-infrared/3D sensing and other technologies to achieve non-sensing verification
Typical application scenarios: Financial remote account opening needs to meet enhanced level requirements and needs to defend against resin masks and AI face-changing attacks.
2. Data protection throughout the entire life cycle
The standard proposes three levels of protection for data processing:
- Transmission encryption: Establish a TLS1.2+ secure channel
- Storage desensitization: Feature templates must be encrypted and stored, and plain text retention is prohibited
- Residual removal: Memory data is destroyed immediately after use
Implementation suggestions
1. System classification strategy
Select a security level based on the application scenario:
- Basic level: Applicable to low-risk scenarios such as internal attendance
- Enhanced level: Mandatory for highly sensitive scenarios such as payment/government affairs
2. Security assurance system construction
Need to be built simultaneously:
- Secure development process that complies with EAL3/EAL4
- Multi-factor authentication fusion solution (face + SMS/token)
- Regular penetration testing mechanism

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

GB/T 45240-2025 in English
General requirements for device-independent quantum random number generators
2025-01-24 -

GB/T 20009-2019 in English
Information security technology—Security evaluation criteria for database management system
2019-08-30 -

GB/Z 24294.1-2018 in English
Information security technology—Guide of implementation for internet-basede-government information security—Part 1:General
2018-03-15 -

GB/T 15278-1994 in English
Information processing-Data encipherment-Physical layer interoperability requirements
1994-01-02 -

GB/T 20979-2019 in English
Information security technology—Technical requirements for iris recognition system
2019-08-30 -

GB/T 39276-2020 in English
Information security technology—General security requirements of network products and services
2020-11-19 -

GB/T 27422-2019 in English
Conformity assessment -- Requirements for bodies providing audit and certification of business continuity management systems
2019-12-10