{"id":74892,"date":"2026-09-11T16:27:21","date_gmt":"2026-09-11T19:27:21","guid":{"rendered":"https:\/\/a3aengenharia.com\/?post_type=articles&#038;p=74892"},"modified":"2026-09-11T17:09:43","modified_gmt":"2026-09-11T20:09:43","slug":"liveness-anti-spoofing-biometrics-pad-presentation-attacks-access-control","status":"publish","type":"articles","link":"https:\/\/a3aengenharia.com\/en-us\/content\/technical-articles\/liveness-anti-spoofing-biometrics-pad-presentation-attacks-access-control\/","title":{"rendered":"Liveness and Anti-Spoofing in Biometrics: PAD, Presentation Attacks, and Design Criteria"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Liveness and anti-spoofing are mechanisms used to reduce the risk of a biometric system accepting an artificial, reproduced, or manipulated presentation as if it were a genuine characteristic of a person who is physically present. In standards terminology, the more precise concept is <strong>Presentation Attack Detection (PAD)<\/strong>: detecting attacks performed at the capture device during presentation and acquisition of the biometric characteristic.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In access control, PAD does not replace FAR\/FMR, FRR\/FNMR, 1:1 verification, 1:N identification, multifactor authentication, authorization, or the physical barrier itself. It addresses a different threat. A matcher may distinguish genuine users from zero-effort impostors very effectively and still be vulnerable to a photograph, screen replay, mask, fingerprint replica, or another artifact presented to the sensor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For that reason, specifying only \u201cbiometrics with liveness\u201d is insufficient. A technically verifiable design needs to define the threat model, biometric modality, capture conditions, performance criteria, test evidence, failure behavior, and how compliance will be demonstrated in FAT, SAT, and commissioning. The objective is not to promise invulnerability, but to control a measurable risk without unduly degrading the experience of legitimate users.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Liveness, anti-spoofing, and PAD are not the same thing<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cLiveness\u201d is the most widespread commercial and operational term for indicating that a sample appears to come from a living person who is present. \u201cAnti-spoofing\u201d is a broader expression used for mechanisms intended to hinder or detect forgery. The ISO\/IEC 30107 family uses <strong>Presentation Attack Detection<\/strong> because the standards problem is not limited to \u201cproving life\u201d: the focus is detecting presentations made to the capture device with the intent of interfering with operation of the biometric subsystem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This distinction prevents an imprecise specification. An algorithm may look for eye movement, texture, depth, spectral response, tissue properties, or other cues, but the design should not procure a technological \u201ctrick.\u201d It should procure <strong>verifiable performance against the presentation classes relevant to the risk<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Term<\/td><td>Typical use<\/td><td>Interpretation limitation<\/td><\/tr><tr><td>Liveness<\/td><td>Verify signals associated with live presence<\/td><td>May suggest a narrower scope than the actual risk<\/td><\/tr><tr><td>Anti-spoofing<\/td><td>Prevent or detect forgery<\/td><td>Broad term that does not by itself define a test and acceptance method<\/td><\/tr><tr><td>PAD<\/td><td>Detect presentation attacks at the capture point<\/td><td>Does not cover every threat to the biometric system<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">ISO\/IEC 30107-1:2023 limits PAD to attacks that occur at the capture device during presentation and acquisition of the biometric characteristic. Data injection after the sensor, API compromise, template theft, database tampering, administrative credential compromise, or controller bypass belong to other attack surfaces. This means that even a product with robust PAD still depends on appropriate architecture, cybersecurity, and access policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/guias-tecnicos\/guia-completo-sobre-controle-de-acesso\/\">complete guide to access control systems<\/a> places biometrics within the broader chain of identification, authentication, authorization, decision, and actuation. PAD is an additional layer in that chain, not a substitute for the others.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A presentation attack occurs at the capture point<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A presentation attack occurs when an attacker presents a characteristic or artifact to the sensor with the objective of producing an improper response. In facial recognition, the threat class may include two-dimensional or three-dimensional presentations. In fingerprint recognition, it may include materials capable of reproducing patterns relevant to the sensor. Other modalities have their own attack surfaces.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design requirement should not become a catalog of attack recipes. What matters is establishing, at an appropriate level of detail, <strong>which presentation families are plausible for the asset, how critical the access is, and what evidence will demonstrate compatible resistance<\/strong>.<\/p>\n\n\n\n<figure class=\"a3a-mermaid\"><svg id=\"a3a-diagram-1\" width=\"100%\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"flowchart\" style=\"max-width:min(700.26953125px, 100%);height:auto;display:block;margin:0 auto\" viewBox=\"0 0 700.26953125 1241\" role=\"graphics-document document\" aria-roledescription=\"flowchart-v2\" aria-labelledby=\"chart-title-a3a-diagram-1\"><title id=\"chart-title-a3a-diagram-1\">Posi\u00e7\u00e3o do PAD na cadeia de decis\u00e3o biom\u00e9trica de controle de acesso<\/title><style>#a3a-diagram-1{font-family:Roboto,sans-serif;font-size:15px;fill:var(--a3a-diag-text, #0a0a0a);}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#a3a-diagram-1 .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#a3a-diagram-1 .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#a3a-diagram-1 .error-icon{fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .error-text{fill:#000000;stroke:#000000;}#a3a-diagram-1 .edge-thickness-normal{stroke-width:1px;}#a3a-diagram-1 .edge-thickness-thick{stroke-width:3.5px;}#a3a-diagram-1 .edge-pattern-solid{stroke-dasharray:0;}#a3a-diagram-1 .edge-thickness-invisible{stroke-width:0;fill:none;}#a3a-diagram-1 .edge-pattern-dashed{stroke-dasharray:3;}#a3a-diagram-1 .edge-pattern-dotted{stroke-dasharray:2;}#a3a-diagram-1 .marker{fill:var(--a3a-diag-stroke, #2e42a2);stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 .marker.cross{stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 svg{font-family:Roboto,sans-serif;font-size:15px;}#a3a-diagram-1 p{margin:0;}#a3a-diagram-1 .label{font-family:Roboto,sans-serif;color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 .cluster-label text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster-label span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster-label span p{background-color:transparent;}#a3a-diagram-1 .label text,#a3a-diagram-1 span{fill:var(--a3a-diag-text, #0a0a0a);color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 .node rect,#a3a-diagram-1 .node circle,#a3a-diagram-1 .node ellipse,#a3a-diagram-1 .node polygon,#a3a-diagram-1 .node path{fill:var(--a3a-diag-fill, #eef2fd);stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:1px;}#a3a-diagram-1 .rough-node .label text,#a3a-diagram-1 .node .label text,#a3a-diagram-1 .image-shape .label,#a3a-diagram-1 .icon-shape .label{text-anchor:middle;}#a3a-diagram-1 .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#a3a-diagram-1 .rough-node .label,#a3a-diagram-1 .node .label,#a3a-diagram-1 .image-shape .label,#a3a-diagram-1 .icon-shape .label{text-align:center;}#a3a-diagram-1 .node.clickable{cursor:pointer;}#a3a-diagram-1 .root .anchor path{fill:var(--a3a-diag-stroke, #2e42a2)!important;stroke-width:0;stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-1 .arrowheadPath{fill:var(--a3a-diag-stroke, #0b0b0b);}#a3a-diagram-1 .edgePath .path{stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:2.0px;}#a3a-diagram-1 .flowchart-link{stroke:var(--a3a-diag-stroke, #2e42a2);fill:none;}#a3a-diagram-1 .edgeLabel{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-1 .edgeLabel p{background-color:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .edgeLabel rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .labelBkg{background-color:rgba(255, 255, 255, 0.5);}#a3a-diagram-1 .cluster rect{fill:var(--a3a-diag-surface, #f8f8f8);stroke:var(--a3a-diag-border, #e2e8f0);stroke-width:1px;}#a3a-diagram-1 .cluster text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 .cluster span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-1 div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:Roboto,sans-serif;font-size:12px;background:var(--a3a-diag-canvas, #ffffff);border:1px solid hsl(0, 0%, 90%);border-radius:2px;pointer-events:none;z-index:100;}#a3a-diagram-1 .flowchartTitleText{text-anchor:middle;font-size:18px;fill:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-1 rect.text{fill:none;stroke-width:0;}#a3a-diagram-1 .icon-shape,#a3a-diagram-1 .image-shape{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-1 .icon-shape p,#a3a-diagram-1 .image-shape p{background-color:var(--a3a-diag-canvas, #ffffff);padding:2px;}#a3a-diagram-1 .icon-shape rect,#a3a-diagram-1 .image-shape rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-1 .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#a3a-diagram-1 .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#a3a-diagram-1 :root{--mermaid-font-family:Roboto,sans-serif;}<\/style><g><marker id=\"a3a-diagram-1_flowchart-v2-pointEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 0 L 10 5 L 0 10 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-pointStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"4.5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 5 L 10 10 L 10 0 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-circleEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"11\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-circleStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"-1\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-crossEnd\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"12\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-1_flowchart-v2-crossStart\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"-1\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><g class=\"root\"><g class=\"clusters\"><\/g><g class=\"edgePaths\"><path d=\"M275.398,60.5L275.398,64.667C275.398,68.833,275.398,77.167,275.398,84.833C275.398,92.5,275.398,99.5,275.398,103L275.398,106.5\" id=\"L_A_B_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_A_B_0\" data-points=\"W3sieCI6Mjc1LjM5ODQzNzUsInkiOjYwLjV9LHsieCI6Mjc1LjM5ODQzNzUsInkiOjg1LjV9LHsieCI6Mjc1LjM5ODQzNzUsInkiOjExMC41fV0=\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M275.398,163L275.398,167.167C275.398,171.333,275.398,179.667,275.398,187.333C275.398,195,275.398,202,275.398,205.5L275.398,209\" id=\"L_B_C_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_B_C_0\" data-points=\"W3sieCI6Mjc1LjM5ODQzNzUsInkiOjE2M30seyJ4IjoyNzUuMzk4NDM3NSwieSI6MTg4fSx7IngiOjI3NS4zOTg0Mzc1LCJ5IjoyMTN9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M211.89,424.492L197.619,441.118C183.349,457.744,154.807,490.997,140.536,514.874C126.266,538.75,126.266,553.25,126.266,560.5L126.266,567.75\" id=\"L_C_D_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_C_D_0\" data-points=\"W3sieCI6MjExLjg5MDA2NTYxNDU2NDU4LCJ5Ijo0MjQuNDkxNjI4MTU0NTY0Nn0seyJ4IjoxMjYuMjY1NjI1LCJ5Ijo1MjQuMjV9LHsieCI6MTI2LjI2NTYyNSwieSI6NTcxLjc1fV0=\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M338.907,424.492L353.178,441.118C367.448,457.744,395.99,490.997,410.261,512.999C424.531,535,424.531,545.75,424.531,551.125L424.531,556.5\" id=\"L_C_E_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_C_E_0\" data-points=\"W3sieCI6MzM4LjkwNjgwOTM0NTQzNTQsInkiOjQyNC40OTE2MjgxNTQ1NjQ2fSx7IngiOjQyNC41MzEyNSwieSI6NTI0LjI1fSx7IngiOjQyNC41MzEyNSwieSI6NTYwLjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M424.531,635.5L424.531,639.667C424.531,643.833,424.531,652.167,424.531,659.833C424.531,667.5,424.531,674.5,424.531,678L424.531,681.5\" id=\"L_E_F_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_E_F_0\" data-points=\"W3sieCI6NDI0LjUzMTI1LCJ5Ijo2MzUuNX0seyJ4Ijo0MjQuNTMxMjUsInkiOjY2MC41fSx7IngiOjQyNC41MzEyNSwieSI6Njg1LjV9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M363.73,899.698L350.907,915.874C338.084,932.049,312.438,964.399,299.616,987.825C286.793,1011.25,286.793,1025.75,286.793,1033L286.793,1040.25\" id=\"L_F_G_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_F_G_0\" data-points=\"W3sieCI6MzYzLjcyOTU2MDc4MTE1Mzk2LCJ5Ijo4OTkuNjk4MzEwNzgxMTU0fSx7IngiOjI4Ni43OTI5Njg3NSwieSI6OTk2Ljc1fSx7IngiOjI4Ni43OTI5Njg3NSwieSI6MTA0NC4yNX1d\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M485.333,899.698L498.156,915.874C510.978,932.049,536.624,964.399,549.447,985.95C562.27,1007.5,562.27,1018.25,562.27,1023.625L562.27,1029\" id=\"L_F_H_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_F_H_0\" data-points=\"W3sieCI6NDg1LjMzMjkzOTIxODg0NjA0LCJ5Ijo4OTkuNjk4MzEwNzgxMTU0fSx7IngiOjU2Mi4yNjk1MzEyNSwieSI6OTk2Ljc1fSx7IngiOjU2Mi4yNjk1MzEyNSwieSI6MTAzM31d\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><path d=\"M562.27,1108L562.27,1112.167C562.27,1116.333,562.27,1124.667,562.27,1132.333C562.27,1140,562.27,1147,562.27,1150.5L562.27,1154\" id=\"L_H_I_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_H_I_0\" data-points=\"W3sieCI6NTYyLjI2OTUzMTI1LCJ5IjoxMTA4fSx7IngiOjU2Mi4yNjk1MzEyNSwieSI6MTEzM30seyJ4Ijo1NjIuMjY5NTMxMjUsInkiOjExNTh9XQ==\" marker-end=\"url(#a3a-diagram-1_flowchart-v2-pointEnd)\"><\/path><\/g><g class=\"edgeLabels\"><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_A_B_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_B_C_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\" transform=\"translate(126.265625, 524.25)\"><g class=\"label\" data-id=\"L_C_D_0\" transform=\"translate(-13.5859375, -11.25)\"><foreignObject width=\"27.171875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><p>No<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\" transform=\"translate(424.53125, 524.25)\"><g class=\"label\" data-id=\"L_C_E_0\" transform=\"translate(-12.6328125, -11.25)\"><foreignObject width=\"25.265625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><p>Yes<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_E_F_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\" transform=\"translate(286.79296875, 996.75)\"><g class=\"label\" data-id=\"L_F_G_0\" transform=\"translate(-13.5859375, -11.25)\"><foreignObject width=\"27.171875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><p>No<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\" transform=\"translate(562.26953125, 996.75)\"><g class=\"label\" data-id=\"L_F_H_0\" transform=\"translate(-12.6328125, -11.25)\"><foreignObject width=\"25.265625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><p>Yes<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_H_I_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><\/g><g class=\"nodes\"><g class=\"node default\" id=\"flowchart-A-0\" transform=\"translate(275.3984375, 34.25)\"><rect class=\"basic label-container\" style=\"\" x=\"-111.3984375\" y=\"-26.25\" width=\"222.796875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-81.3984375, -11.25)\"><rect><\/rect><foreignObject width=\"162.796875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Presentation to sensor<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-B-1\" transform=\"translate(275.3984375, 136.75)\"><rect class=\"basic label-container\" style=\"\" x=\"-95.2109375\" y=\"-26.25\" width=\"190.421875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-65.2109375, -11.25)\"><rect><\/rect><foreignObject width=\"130.421875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Biometric capture<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-C-3\" transform=\"translate(275.3984375, 350.5)\"><polygon points=\"137.5,0 275,-137.5 137.5,-275 0,-137.5\" class=\"label-container\" transform=\"translate(-137, 137.5)\"><\/polygon><g class=\"label\" style=\"\" transform=\"translate(-100, -22.5)\"><rect><\/rect><foreignObject width=\"200\" height=\"45\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table; white-space: break-spaces; line-height: 1.5; max-width: 200px; text-align: center; width: 200px;\"><span class=\"nodeLabel\"><p>PAD classifies as bona fide?<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-D-5\" transform=\"translate(126.265625, 598)\"><rect class=\"basic label-container\" style=\"\" x=\"-118.265625\" y=\"-26.25\" width=\"236.53125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-88.265625, -11.25)\"><rect><\/rect><foreignObject width=\"176.53125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Reject and log event<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-E-7\" transform=\"translate(424.53125, 598)\"><rect class=\"basic label-container\" style=\"\" x=\"-130\" y=\"-37.5\" width=\"260\" height=\"75\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-100, -22.5)\"><rect><\/rect><foreignObject width=\"200\" height=\"45\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table; white-space: break-spaces; line-height: 1.5; max-width: 200px; text-align: center; width: 200px;\"><span class=\"nodeLabel\"><p>Extract biometric representation<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-F-9\" transform=\"translate(424.53125, 823)\"><polygon points=\"137.5,0 275,-137.5 137.5,-275 0,-137.5\" class=\"label-container\" transform=\"translate(-137, 137.5)\"><\/polygon><g class=\"label\" style=\"\" transform=\"translate(-100, -22.5)\"><rect><\/rect><foreignObject width=\"200\" height=\"45\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table; white-space: break-spaces; line-height: 1.5; max-width: 200px; text-align: center; width: 200px;\"><span class=\"nodeLabel\"><p>Comparison meets threshold?<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-G-11\" transform=\"translate(286.79296875, 1070.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-95.4765625\" y=\"-26.25\" width=\"190.953125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-65.4765625, -11.25)\"><rect><\/rect><foreignObject width=\"130.953125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Reject identity<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-H-13\" transform=\"translate(562.26953125, 1070.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-130\" y=\"-37.5\" width=\"260\" height=\"75\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-100, -22.5)\"><rect><\/rect><foreignObject width=\"200\" height=\"45\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table; white-space: break-spaces; line-height: 1.5; max-width: 200px; text-align: center; width: 200px;\"><span class=\"nodeLabel\"><p>Apply authorization policy<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-I-15\" transform=\"translate(562.26953125, 1195.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-130\" y=\"-37.5\" width=\"260\" height=\"75\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-100, -22.5)\"><rect><\/rect><foreignObject width=\"200\" height=\"45\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table; white-space: break-spaces; line-height: 1.5; max-width: 200px; text-align: center; width: 200px;\"><span class=\"nodeLabel\"><p>Command or deny access point<\/p><\/span><\/div><\/foreignObject><\/g><\/g><\/g><\/g><\/g><\/svg><figcaption>Position of PAD in the biometric access-control decision chain<\/figcaption><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The figure shows why PAD and matching should not be confused. A presentation may be genuine and not match the template; it may reproduce enough characteristics for the matcher but be classified as an attack by PAD; or it may pass both layers and still be denied by the authorization policy.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Low FAR does not demonstrate spoofing resistance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">FMR\/FAR and FNMR\/FRR characterize comparison or biometric decision errors under defined conditions. A presentation attack is an adversarial problem: someone deliberately attempts to exploit the sensor and processing. A device with excellent FMR under artifact-free impostor attempts is not automatically protected against artificial presentations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Engineering documents should therefore separate at least three requirement families: <strong>capture quality<\/strong>, <strong>matching performance<\/strong>, and <strong>PAD performance<\/strong>. Combining everything into a phrase such as \u201chigh-accuracy biometrics with anti-spoofing\u201d makes acceptance subjective.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Passive and active PAD are architecture choices<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Solutions described as passive PAD attempt to classify the presentation without requesting an additional perceptible action from the user. Active solutions may introduce a challenge, interaction, or capture sequence. Neither approach is universally superior. The choice affects throughput, accessibility, training, ergonomics, rejection rate, and the ability to operate in contingency scenarios.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design should evaluate the technique as part of the system. At a low-throughput, high-criticality access point, an additional interaction may be acceptable. At an entrance with peak arrival periods, the same interaction may cause queues, operational pressure, and the creation of exceptions that weaken the control itself.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Threat model: what PAD really needs to detect<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The starting point should not be \u201cwhich biometric reader should we buy?\u201d but <strong>which threat needs to be controlled and what consequence exists if the mechanism fails<\/strong>. The same technology may be sufficient for an administrative area and inadequate for a critical room, laboratory, data center, industrial environment, or zone with reinforced segregation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A useful threat model considers asset value, attractiveness of the access point, user profile, possibility of obtaining biometric material, public exposure of characteristics, existing human supervision, presence of other credentials, and the consequence of an improper release.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The risk classification should then be converted into verifiable requirements in the <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/matriz-funcional-controle-de-acesso-como-especificar-cada-ponto\/\">access-control functional matrix<\/a>: modality, authentication mode, PAD requirement, additional factors, attempt policy, failure behavior, event logging, and test criteria by point or point class.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A printed photograph is only the most obvious attack<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Restricting the test to a single printed photograph can create a false sense of security. The evaluation needs to consider representative presentation classes compatible with the modality, capture technique, and threat scenario. ISO\/IEC 30107-3:2023 structures testing and reporting principles precisely to prevent a one-off demonstration from being mistaken for broad performance characterization.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This also means the specification should avoid absolute phrases such as \u201cimmune to photos, videos, and masks.\u201d Results depend on the presentation attack instrument, fabrication quality, environmental conditions, position, distance, sensor, algorithm, software version, and decision parameters. Engineering should procure evidence, not adjectives.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A deepfake may or may not be a presentation attack<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Deepfake is not synonymous with presentation attack. If synthetic content is physically presented or displayed on a screen to the capture sensor, it may form part of an adversarial presentation. If it is injected directly into a digital flow after capture, the threat is no longer in the same PAD domain defined by ISO\/IEC 30107.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design consequence is important: requiring PAD while ignoring channel integrity, device authentication, API protection, and server hardening leaves open an attack surface that the biometric mechanism was not designed to address.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1:1 and 1:N change the consequence of a bypass<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In <strong>1:1<\/strong> verification, the system compares the presented sample with a claimed or previously selected identity. In <strong>1:N<\/strong> identification, it searches for a match among a candidate database. The two architectures change risk, processing time, aggregate match probability, and consequences of a bypass.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The dedicated content on <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/biometria-1-1-1-n-verificacao-identificacao\/\">1:1 vs. 1:N biometrics<\/a> explores this difference in greater depth. For PAD, the rule is simple: protection against presentation must be analyzed together with the comparison mode that follows it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">MFA reduces dependence on a single layer<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When criticality requires greater robustness, biometrics can be combined with another factor, credential, or operational condition. Multifactor authentication does not make PAD unnecessary, but it reduces dependence on a single barrier. Likewise, strong PAD does not justify weakening authorization, anti-passback, dual custody, or physical segregation when those controls are part of the security concept.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A layered architecture is preferable to relying on a single proprietary \u201cliveness\u201d indicator. The residual risk of each layer should be understood and combined with the others.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">PAD metrics: APCER, BPCER, IAPAR, and legitimate-user performance<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">Laboratory metrics are useful only when they correspond to the product, version, configuration, and conditions relevant to the project. A technical review can identify gaps between claimed performance and what is actually specified for the project.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Independent validation is especially useful before freezing requirements, approving equivalents, or accepting threshold changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/revisao-validacao-tecnica-projetos-design-review\/\">Engineering Design Review<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">PAD introduces its own error matrix. A system may be aggressive in rejecting attacks and at the same time reject legitimate people at an unacceptable frequency. It may also preserve an excellent user experience while allowing a class of adversarial presentation to pass under relevant conditions. The design needs to see both sides.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">APCER and BPCER characterize classification errors<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In PAD evaluations, <strong>APCER<\/strong> is associated with the proportion of attack presentations improperly classified as bona fide for the evaluated class, while <strong>BPCER<\/strong> characterizes bona fide presentations improperly classified as attacks. They should not be mixed with FMR\/FNMR because they address a different decision stage.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table><tbody><tr><td>Indicator<\/td><td>Engineering question<\/td><td>Risk when high<\/td><\/tr><tr><td>APCER<\/td><td>Does PAD allow attack presentations from the tested class to pass?<\/td><td>Bypass of the detection layer<\/td><\/tr><tr><td>BPCER<\/td><td>Does PAD reject genuine users as if they were attacks?<\/td><td>Queues, exceptions, support burden, and operational bypass<\/td><\/tr><tr><td>FMR\/FNMR<\/td><td>How does the matcher behave in biometric comparison?<\/td><td>False match or rejection of a legitimate user<\/td><\/tr><tr><td>IAPAR<\/td><td>What is the acceptance rate of attack presentations in the evaluated authentication context?<\/td><td>Adversarial success under the adopted methodology<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The technical value lies less in seeking a \u201cmagic number\u201d and more in requiring methodology, population, conditions, presentation attack instruments, number of attempts, product version, configuration, and calculation method. Without this traceability, two percentages from different vendors may not be comparable.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">NIST is a useful reference, not a universal physical-access limit<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">NIST SP 800-63B-4, published in July 2025, addresses digital identity authentication in U.S. government networked systems. In that context, it requires PAD for facial recognition, recommends PAD for fingerprint and iris recognition, and indicates, for implementation testing, demonstration of IAPAR below 0.07.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These requirements are valuable as a contemporary engineering reference and demonstrate the separation between biometric performance and resistance to presentation attacks. However, they should not automatically be copied as a legal requirement or universal threshold for a Brazilian physical system. Acceptance criteria for access control should arise from risk analysis, the application, the technology, and the project&#8217;s specific obligations.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Matching and PAD thresholds require governance<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some solutions allow matching sensitivity, PAD sensitivity, or both to be adjusted. Changing a threshold simply to \u201ckeep the turnstile moving\u201d can reduce rejections while also changing risk. Critical parameters therefore need to be defined, documented, protected by administrative profiles, and subject to change management.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The commissioning Data Book should record the approved configuration, versions, relevant parameters, test evidence, and acceptance baseline. Without a baseline, a later change can degrade the system without the organization being able to demonstrate when or why performance changed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Physical and operational design: sensor, lighting, flow, and accessibility<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">When PAD is used in critical areas, the requirement needs to originate from the threat model, functional matrix, and actual conditions at each point. Specifying only \u201cterminal with liveness\u201d transfers security decisions to the vendor and makes acceptance subjective.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An independent design converts criticality, biometric modality, flow, contingency, and test criteria into verifiable requirements before procurement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">Access Control Design<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">PAD performance does not exist independently of the environment. Camera, lens, effective resolution, illuminators, distance, angle, installation height, scene background, solar exposure, reflections, temperature, dirt, humidity, vibration, and user position can change capture and classification. In fingerprint recognition, skin condition, contaminants, and sensor characteristics also affect the experience.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The specification should therefore connect the security requirement to the <strong>physical design of the access point<\/strong>. It is not enough to approve a terminal on a bench and assume its behavior will be identical when installed near a glazed fa\u00e7ade, outdoors, or in an industrial flow.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">PAD must be compatible with expected throughput<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Security that does not fit the operation tends to create exceptions. If every attempt requires repetition, repositioning, or guard intervention, peak-period queues may lead to doors being held open, authentication by third parties, shortcuts, or migration to a less secure mode.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The design should establish reference throughput, expected transaction time, retry rate, failure handling, and the procedure for users who cannot complete the flow. These criteria need to be tested with a representative population, not only with the technical team that installed the system.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Accessibility is part of the acceptance criterion<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Equipment height, capture field, required approach, gestures, response time, and interface instructions can create barriers for certain users. A biometric design needs to provide operational alternatives and authentication methods compatible with the environment and applicable accessibility requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The alternative should not become an ungoverned bypass. If a person cannot use the primary modality, the alternate flow must maintain identification, authorization, traceability, and a level of control consistent with the risk.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lighting and geometry need to be tested on site<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For facial recognition, lighting conditions can affect both matching and PAD. Backlighting, low illuminance, variable sunlight, or reflections can change characteristics extracted by the sensor. If PAD depends on multiple optical channels, the physical architecture and operating envelope must also be compatible.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SAT should reproduce foreseeable real situations: different times of day, users with varied characteristics, permitted accessories, approach distances, and flow conditions. The objective is not to \u201ctorture\u201d the product with impossible scenarios, but to demonstrate that the system operates within the contracted operating envelope.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Enrollment, templates, LGPD, and cybersecurity<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Enrollment and PAD solve different problems, but they meet at a critical point. If the identity or initial template is enrolled incorrectly, the rest of the lifecycle may operate exactly as designed and still protect a false identity or an improper association.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">PAD during enrollment may be more critical than during later use<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Enrollment should be governed with respect to identity, operator, authorized workstation, sample quality, duplicates, approval, and audit trail. When justified by the threat model, PAD mechanisms during enrollment help reduce the risk of registering an adversarial presentation as the legitimate reference.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Revocation and reenrollment also need to be defined. A biometric template is not a password whose physical characteristic can simply be changed; compromise and vendor changes require a lifecycle strategy.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Template protection remains essential<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">PAD operates before or during capture. After that, biometric representations are transmitted, processed, and may be stored. Encryption in transit and at rest, key segregation, administrative access control, hardening, logging, backup, retention, and disposal belong to another security layer and remain essential.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where integrations with enterprise systems are present, the article on <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/api-webhooks-middleware-controle-de-acesso\/\">APIs, webhooks, and middleware in access control<\/a> shows why service authentication, authorization, integrity, and event handling need to be designed beyond the biometric terminal.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">LGPD requires governance proportional to the sensitive nature of the data<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Biometric data linked to a natural person are sensitive personal data under Brazil&#8217;s LGPD. This increases the need for a defined purpose, applicable legal basis, necessity, security, access control, coherent retention, and processing governance. Brazil&#8217;s ANPD also highlights privacy, data-protection, and potential discriminatory risks associated with biometrics and facial recognition.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The decision to use biometrics should therefore not be made simply because equipment offers the feature. The function must be justified within access control, and collection and processing should be limited to what the use case requires.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Software- or AI-based PAD requires version management<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A firmware, model, library, or backend update can change classification without changing visible hardware. The contract and maintenance plan need to define how version changes will be evaluated, when regression testing is required, and how to return to the previous configuration if performance deteriorates.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">PAD events should also be differentiated from simple matching failures. This granularity improves investigation, makes trends visible, and prevents repeated adversarial attempts from being interpreted as merely \u201cpoor biometrics.\u201d Integration with VMS can enrich the investigation but does not by itself improve the algorithmic PAD capability.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Offline operation and failures require explicit behavior<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some terminals perform matching and PAD locally; others depend on central services for part of the analysis. The design should clarify what happens when the network, server, license, or analysis service is unavailable. Continuing to grant access with degraded functionality may reduce security; blocking everything may compromise operational continuity or emergency routes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This decision cannot remain hidden in the manufacturer&#8217;s default behavior. It should be specified by door class, aligned with the operating philosophy, and tested under contingency conditions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How to specify and procure PAD without relying on commercial claims<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">In procurement, commercial names such as \u201cAI liveness,\u201d \u201c3D anti-spoofing,\u201d or \u201cadvanced detection\u201d are not comparable by themselves. Technical equalization should compare requirements, reports, versions, test conditions, deviations, and acceptance criteria.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Technical procurement support preserves traceability between specification, proposal, clarifications, supply, and testing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/procurement\/\">Technical Procurement<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">A robust procurement process converts need into a verifiable requirement. \u201cHas liveness\u201d does not define what will be accepted, what evidence will be submitted, or how bidders will be compared. The specification should avoid both locking the design to a proprietary implementation and being so generic that any marketing statement is sufficient.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Engineering work begins by defining the object: a biometric system for a given set of points, with criticality classes, modalities, authentication policies, and integration. Functional and performance requirements follow, together with environmental conditions, prior evidence, supply testing, and acceptance criteria.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">What to require in the technical specification<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Where applicable, the documentation should establish:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>biometric modality and 1:1 or 1:N operating mode;<\/li><li>points or point classes where PAD is required;<\/li><li>threat model and presentation classes guiding the evaluation;<\/li><li>requested metrics and the conditions under which they will be reported;<\/li><li>laboratory evidence or test reports applicable to the offered version;<\/li><li>minimum capture and installation conditions;<\/li><li>capacity, latency, throughput, and retry handling;<\/li><li>behavior during unavailability, PAD failure, and offline operation;<\/li><li>logging, time synchronization, event export, and integration requirements;<\/li><li>template-protection and communication-security requirements;<\/li><li>FAT, SAT, regression testing, and acceptance documentation;<\/li><li>update, maintenance, and change-management policy.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The list should be calibrated to risk. Not every access point requires the same level of evidence, but critical points should not depend on a checkbox that nobody can test.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Certification and laboratory reports need critical review<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A declaration of conformity with ISO\/IEC 30107-3 should not be interpreted as a generic certification of invulnerability. Scope, modality, product, version, configuration, attack classes evaluated, conditions, laboratory, metrics, and reported results need to be checked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ISO\/IEC 30107-3:2023 establishes principles and methods for evaluating and reporting PAD mechanisms; it does not standardize a specific algorithm or provide a general security evaluation of the system. This limitation is essential in procurement: a valid report may answer only one part of the engineering question.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Technical equalization should compare evidence, not terminology<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Two vendors may call very different capabilities \u201cadvanced liveness.\u201d Technical equalization needs to place requirements, evidence, gaps, conditions, and deviations side by side. Where data are missing, the result should be \u201cnot demonstrated\u201d or \u201cclarification required,\u201d not approval by inference.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This reasoning connects with the <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/requisicao-tecnica-engenharia-procurement-pacote-tecnico\/\">technical requisition for Procurement<\/a>: PAD requirements need to enter the purchasing process in a format that supports proposal comparison and maintains traceability through acceptance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended contracting scope<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When contracting engineering support on this topic, the scope may include risk diagnosis, architecture definition, technical specification, functional matrix, review of vendor evidence, technical equalization, FAT, SAT, commissioning, and final documentation. Boundaries should be explicit: who provides test instruments and samples, who prepares the environment, who executes tests, who records evidence, and who has authority to accept deviations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Deliverables may include a design-criteria memorandum, requirements matrix, technical specification, point matrix, test protocol, FAT\/SAT report, punch list, configuration baseline, and Data Book. Measurement of the engineering service should be based on these products and milestones, not merely meeting attendance or hours without a verifiable result.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">FAT, SAT, commissioning, and acceptance criteria<\/h2>\n\n\n\n<div class=\"wp-block-a3a-destaque\">\n<p class=\"wp-block-paragraph\">PAD is demonstrated in the deployed system only when FAT, SAT, and field tests simultaneously verify rejection of the expected presentation classes, behavior of bona fide users, integrations, and contingencies.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Commissioning organizes protocols, evidence, nonconformities, retests, and the configuration baseline so acceptance is technical and traceable.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/comissionamento\/\">Engineering Commissioning<\/a><\/p>\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">PAD stops being a promise only when it is tested in a traceable manner. The test plan should distinguish what can be validated in a controlled environment from what depends on the final installation. FAT and SAT have complementary roles.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">FAT should demonstrate requirements before final mobilization<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">During FAT, the team can verify hardware and software versions, parameters, interfaces, logs, policies, expected presentation classes, bona fide-attempt behavior, and controlled failure scenarios. The protocol needs to clearly identify which results are objective and which observations require retesting on site.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The objective is not to reproduce every field risk in a laboratory, but to prevent basic problems from being discovered only after deployment. Evidence should identify the item tested, configuration, date, responsible parties, results, and nonconformities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">SAT validates the final environment<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">SAT brings in geometry, lighting, position, network, controller, lock or turnstile, integration, user database, flow, access policies, contingencies, and actual experience. A PAD mechanism that works on a bench may behave differently on site because of capture conditions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The article on <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/comissionamento-controle-de-acesso-iec-60839\/\">commissioning access control systems according to IEC 60839<\/a> details the testing, evidence, and acceptance discipline applied to the complete system.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Testing attacks without testing genuine users gives an incomplete view<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A campaign focused only on blocking artificial presentations can hide high BPCER, repeated attempts, and operational degradation. The protocol should also measure legitimate-user success, transaction time, retries, and behavior across groups and conditions relevant to actual use.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If threshold adjustments are required, the change should be recorded and relevant tests repeated. Accepting the system after \u201ctuning it until it works\u201d without preserving the final configuration makes future audits impossible.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Acceptance criteria should be defined before testing<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">The vendor should not discover on the day of SAT what the acceptance threshold will be. The protocol should state requirements, sampling, conditions, number of attempts where applicable, tolerances, treatment of inconclusive results, nonconformity classification, and retest rules in advance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It is also advisable to separate critical issues that prevent release from minor items that can be managed in a punch list with defined deadlines and responsibilities.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Assisted operation consolidates the baseline<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">After go-live, an assisted-operation period may reveal situations SAT did not capture: peak flow, seasonal lighting, accessories, behavior across user groups, intermittent unavailability, and exception procedures. The objective is not to reopen acceptance indefinitely, but to confirm stability and adjust parameters under governance.<\/p>\n\n\n\n<figure class=\"a3a-mermaid\"><svg id=\"a3a-diagram-2\" width=\"100%\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"flowchart\" style=\"max-width:min(2047.140625px, 100%);height:auto;display:block;margin:0 auto\" viewBox=\"0 0 2047.140625 91\" role=\"graphics-document document\" aria-roledescription=\"flowchart-v2\" aria-labelledby=\"chart-title-a3a-diagram-2\"><title id=\"chart-title-a3a-diagram-2\">Jornada de verifica\u00e7\u00e3o de PAD da especifica\u00e7\u00e3o ao aceite operacional<\/title><style>#a3a-diagram-2{font-family:Roboto,sans-serif;font-size:15px;fill:var(--a3a-diag-text, #0a0a0a);}@keyframes edge-animation-frame{from{stroke-dashoffset:0;}}@keyframes dash{to{stroke-dashoffset:0;}}#a3a-diagram-2 .edge-animation-slow{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 50s linear infinite;stroke-linecap:round;}#a3a-diagram-2 .edge-animation-fast{stroke-dasharray:9,5!important;stroke-dashoffset:900;animation:dash 20s linear infinite;stroke-linecap:round;}#a3a-diagram-2 .error-icon{fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-2 .error-text{fill:#000000;stroke:#000000;}#a3a-diagram-2 .edge-thickness-normal{stroke-width:1px;}#a3a-diagram-2 .edge-thickness-thick{stroke-width:3.5px;}#a3a-diagram-2 .edge-pattern-solid{stroke-dasharray:0;}#a3a-diagram-2 .edge-thickness-invisible{stroke-width:0;fill:none;}#a3a-diagram-2 .edge-pattern-dashed{stroke-dasharray:3;}#a3a-diagram-2 .edge-pattern-dotted{stroke-dasharray:2;}#a3a-diagram-2 .marker{fill:var(--a3a-diag-stroke, #2e42a2);stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-2 .marker.cross{stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-2 svg{font-family:Roboto,sans-serif;font-size:15px;}#a3a-diagram-2 p{margin:0;}#a3a-diagram-2 .label{font-family:Roboto,sans-serif;color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-2 .cluster-label text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-2 .cluster-label span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-2 .cluster-label span p{background-color:transparent;}#a3a-diagram-2 .label text,#a3a-diagram-2 span{fill:var(--a3a-diag-text, #0a0a0a);color:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-2 .node rect,#a3a-diagram-2 .node circle,#a3a-diagram-2 .node ellipse,#a3a-diagram-2 .node polygon,#a3a-diagram-2 .node path{fill:var(--a3a-diag-fill, #eef2fd);stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:1px;}#a3a-diagram-2 .rough-node .label text,#a3a-diagram-2 .node .label text,#a3a-diagram-2 .image-shape .label,#a3a-diagram-2 .icon-shape .label{text-anchor:middle;}#a3a-diagram-2 .node .katex path{fill:#000;stroke:#000;stroke-width:1px;}#a3a-diagram-2 .rough-node .label,#a3a-diagram-2 .node .label,#a3a-diagram-2 .image-shape .label,#a3a-diagram-2 .icon-shape .label{text-align:center;}#a3a-diagram-2 .node.clickable{cursor:pointer;}#a3a-diagram-2 .root .anchor path{fill:var(--a3a-diag-stroke, #2e42a2)!important;stroke-width:0;stroke:var(--a3a-diag-stroke, #2e42a2);}#a3a-diagram-2 .arrowheadPath{fill:var(--a3a-diag-stroke, #0b0b0b);}#a3a-diagram-2 .edgePath .path{stroke:var(--a3a-diag-stroke, #2e42a2);stroke-width:2.0px;}#a3a-diagram-2 .flowchart-link{stroke:var(--a3a-diag-stroke, #2e42a2);fill:none;}#a3a-diagram-2 .edgeLabel{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-2 .edgeLabel p{background-color:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-2 .edgeLabel rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-2 .labelBkg{background-color:rgba(255, 255, 255, 0.5);}#a3a-diagram-2 .cluster rect{fill:var(--a3a-diag-surface, #f8f8f8);stroke:var(--a3a-diag-border, #e2e8f0);stroke-width:1px;}#a3a-diagram-2 .cluster text{fill:var(--a3a-diag-title, #0124af);}#a3a-diagram-2 .cluster span{color:var(--a3a-diag-title, #0124af);}#a3a-diagram-2 div.mermaidTooltip{position:absolute;text-align:center;max-width:200px;padding:2px;font-family:Roboto,sans-serif;font-size:12px;background:var(--a3a-diag-canvas, #ffffff);border:1px solid hsl(0, 0%, 90%);border-radius:2px;pointer-events:none;z-index:100;}#a3a-diagram-2 .flowchartTitleText{text-anchor:middle;font-size:18px;fill:var(--a3a-diag-text, #0a0a0a);}#a3a-diagram-2 rect.text{fill:none;stroke-width:0;}#a3a-diagram-2 .icon-shape,#a3a-diagram-2 .image-shape{background-color:var(--a3a-diag-canvas, #ffffff);text-align:center;}#a3a-diagram-2 .icon-shape p,#a3a-diagram-2 .image-shape p{background-color:var(--a3a-diag-canvas, #ffffff);padding:2px;}#a3a-diagram-2 .icon-shape rect,#a3a-diagram-2 .image-shape rect{opacity:0.5;background-color:var(--a3a-diag-canvas, #ffffff);fill:var(--a3a-diag-canvas, #ffffff);}#a3a-diagram-2 .label-icon{display:inline-block;height:1em;overflow:visible;vertical-align:-0.125em;}#a3a-diagram-2 .node .label-icon path{fill:currentColor;stroke:revert;stroke-width:revert;}#a3a-diagram-2 :root{--mermaid-font-family:Roboto,sans-serif;}<\/style><g><marker id=\"a3a-diagram-2_flowchart-v2-pointEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 0 L 10 5 L 0 10 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-pointStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"4.5\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"8\" markerHeight=\"8\" orient=\"auto\"><path d=\"M 0 5 L 10 10 L 10 0 z\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-circleEnd\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"11\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-circleStart\" class=\"marker flowchart-v2\" viewBox=\"0 0 10 10\" refX=\"-1\" refY=\"5\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><circle cx=\"5\" cy=\"5\" r=\"5\" class=\"arrowMarkerPath\" style=\"stroke-width: 1; stroke-dasharray: 1, 0;\"><\/circle><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-crossEnd\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"12\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><marker id=\"a3a-diagram-2_flowchart-v2-crossStart\" class=\"marker cross flowchart-v2\" viewBox=\"0 0 11 11\" refX=\"-1\" refY=\"5.2\" markerUnits=\"userSpaceOnUse\" markerWidth=\"11\" markerHeight=\"11\" orient=\"auto\"><path d=\"M 1,1 l 9,9 M 10,1 l -9,9\" class=\"arrowMarkerPath\" style=\"stroke-width: 2; stroke-dasharray: 1, 0;\"><\/path><\/marker><g class=\"root\"><g class=\"clusters\"><\/g><g class=\"edgePaths\"><path d=\"M196.141,45.5L200.307,45.5C204.474,45.5,212.807,45.5,220.474,45.5C228.141,45.5,235.141,45.5,238.641,45.5L242.141,45.5\" id=\"L_A_B_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_A_B_0\" data-points=\"W3sieCI6MTk2LjE0MDYyNSwieSI6NDUuNX0seyJ4IjoyMjEuMTQwNjI1LCJ5Ijo0NS41fSx7IngiOjI0Ni4xNDA2MjUsInkiOjQ1LjV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M451.922,45.5L456.089,45.5C460.255,45.5,468.589,45.5,476.255,45.5C483.922,45.5,490.922,45.5,494.422,45.5L497.922,45.5\" id=\"L_B_C_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_B_C_0\" data-points=\"W3sieCI6NDUxLjkyMTg3NSwieSI6NDUuNX0seyJ4Ijo0NzYuOTIxODc1LCJ5Ijo0NS41fSx7IngiOjUwMS45MjE4NzUsInkiOjQ1LjV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M726.813,45.5L730.979,45.5C735.146,45.5,743.479,45.5,751.146,45.5C758.813,45.5,765.813,45.5,769.313,45.5L772.813,45.5\" id=\"L_C_D_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_C_D_0\" data-points=\"W3sieCI6NzI2LjgxMjUsInkiOjQ1LjV9LHsieCI6NzUxLjgxMjUsInkiOjQ1LjV9LHsieCI6Nzc2LjgxMjUsInkiOjQ1LjV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M859.031,45.5L863.198,45.5C867.365,45.5,875.698,45.5,883.365,45.5C891.031,45.5,898.031,45.5,901.531,45.5L905.031,45.5\" id=\"L_D_E_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_D_E_0\" data-points=\"W3sieCI6ODU5LjAzMTI1LCJ5Ijo0NS41fSx7IngiOjg4NC4wMzEyNSwieSI6NDUuNX0seyJ4Ijo5MDkuMDMxMjUsInkiOjQ1LjV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M1053.906,45.5L1058.073,45.5C1062.24,45.5,1070.573,45.5,1078.24,45.5C1085.906,45.5,1092.906,45.5,1096.406,45.5L1099.906,45.5\" id=\"L_E_F_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_E_F_0\" data-points=\"W3sieCI6MTA1My45MDYyNSwieSI6NDUuNX0seyJ4IjoxMDc4LjkwNjI1LCJ5Ijo0NS41fSx7IngiOjExMDMuOTA2MjUsInkiOjQ1LjV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M1187.609,45.5L1191.776,45.5C1195.943,45.5,1204.276,45.5,1211.943,45.5C1219.609,45.5,1226.609,45.5,1230.109,45.5L1233.609,45.5\" id=\"L_F_G_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_F_G_0\" data-points=\"W3sieCI6MTE4Ny42MDkzNzUsInkiOjQ1LjV9LHsieCI6MTIxMi42MDkzNzUsInkiOjQ1LjV9LHsieCI6MTIzNy42MDkzNzUsInkiOjQ1LjV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M1419.141,45.5L1423.307,45.5C1427.474,45.5,1435.807,45.5,1443.474,45.5C1451.141,45.5,1458.141,45.5,1461.641,45.5L1465.141,45.5\" id=\"L_G_H_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_G_H_0\" data-points=\"W3sieCI6MTQxOS4xNDA2MjUsInkiOjQ1LjV9LHsieCI6MTQ0NC4xNDA2MjUsInkiOjQ1LjV9LHsieCI6MTQ2OS4xNDA2MjUsInkiOjQ1LjV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><path d=\"M1729.141,45.5L1733.307,45.5C1737.474,45.5,1745.807,45.5,1753.474,45.5C1761.141,45.5,1768.141,45.5,1771.641,45.5L1775.141,45.5\" id=\"L_H_I_0\" class=\"edge-thickness-normal edge-pattern-solid edge-thickness-normal edge-pattern-solid flowchart-link\" style=\";\" data-edge=\"true\" data-et=\"edge\" data-id=\"L_H_I_0\" data-points=\"W3sieCI6MTcyOS4xNDA2MjUsInkiOjQ1LjV9LHsieCI6MTc1NC4xNDA2MjUsInkiOjQ1LjV9LHsieCI6MTc3OS4xNDA2MjUsInkiOjQ1LjV9XQ==\" marker-end=\"url(#a3a-diagram-2_flowchart-v2-pointEnd)\"><\/path><\/g><g class=\"edgeLabels\"><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_A_B_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_B_C_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_C_D_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_D_E_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_E_F_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_F_G_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_G_H_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"edgeLabel\"><g class=\"label\" data-id=\"L_H_I_0\" transform=\"translate(0, 0)\"><foreignObject width=\"0\" height=\"0\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" class=\"labelBkg\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"edgeLabel\"><\/span><\/div><\/foreignObject><\/g><\/g><\/g><g class=\"nodes\"><g class=\"node default\" id=\"flowchart-A-0\" transform=\"translate(102.0703125, 45.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-94.0703125\" y=\"-26.25\" width=\"188.140625\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-64.0703125, -11.25)\"><rect><\/rect><foreignObject width=\"128.140625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Threat model<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-B-1\" transform=\"translate(349.03125, 45.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-102.890625\" y=\"-26.25\" width=\"205.78125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-72.890625, -11.25)\"><rect><\/rect><foreignObject width=\"145.78125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Requirements and metrics<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-C-3\" transform=\"translate(614.3671875, 45.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-112.4453125\" y=\"-26.25\" width=\"224.890625\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-82.4453125, -11.25)\"><rect><\/rect><foreignObject width=\"164.890625\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Vendor evidence<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-D-5\" transform=\"translate(817.921875, 45.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-41.109375\" y=\"-26.25\" width=\"82.21875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-11.109375, -11.25)\"><rect><\/rect><foreignObject width=\"22.21875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>FAT<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-E-7\" transform=\"translate(981.46875, 45.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-72.4375\" y=\"-26.25\" width=\"144.875\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-42.4375, -11.25)\"><rect><\/rect><foreignObject width=\"84.875\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Deployment<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-F-9\" transform=\"translate(1145.7578125, 45.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-41.8515625\" y=\"-26.25\" width=\"83.703125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-11.8515625, -11.25)\"><rect><\/rect><foreignObject width=\"23.703125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>SAT<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-G-11\" transform=\"translate(1328.375, 45.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-90.765625\" y=\"-26.25\" width=\"181.53125\" height=\"52.5\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-60.765625, -11.25)\"><rect><\/rect><foreignObject width=\"121.53125\" height=\"22.5\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table-cell; white-space: nowrap; line-height: 1.5; max-width: 200px; text-align: center;\"><span class=\"nodeLabel\"><p>Commissioning<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-H-13\" transform=\"translate(1599.140625, 45.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-130\" y=\"-37.5\" width=\"260\" height=\"75\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-100, -22.5)\"><rect><\/rect><foreignObject width=\"200\" height=\"45\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table; white-space: break-spaces; line-height: 1.5; max-width: 200px; text-align: center; width: 200px;\"><span class=\"nodeLabel\"><p>Baseline and assisted operation<\/p><\/span><\/div><\/foreignObject><\/g><\/g><g class=\"node default\" id=\"flowchart-I-15\" transform=\"translate(1909.140625, 45.5)\"><rect class=\"basic label-container\" style=\"\" x=\"-130\" y=\"-37.5\" width=\"260\" height=\"75\"><\/rect><g class=\"label\" style=\"\" transform=\"translate(-100, -22.5)\"><rect><\/rect><foreignObject width=\"200\" height=\"45\"><div xmlns=\"http:\/\/www.w3.org\/1999\/xhtml\" style=\"display: table; white-space: break-spaces; line-height: 1.5; max-width: 200px; text-align: center; width: 200px;\"><span class=\"nodeLabel\"><p>Maintenance and change management<\/p><\/span><\/div><\/foreignObject><\/g><\/g><\/g><\/g><\/g><\/svg><figcaption>PAD verification journey from specification to operational acceptance<\/figcaption><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Operation, maintenance, and change<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">PAD security can degrade without an obvious physical failure. Firmware changes, terminal repositioning, lighting changes, camera replacement, improper cleaning, a new screen film, algorithm changes, or configuration changes can alter performance. Maintenance therefore needs to preserve the function, not merely verify that the equipment powers on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The maintenance plan for <a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/manutencao-sistemas-controle-de-acesso\/\">access control systems<\/a> should include inspections and tests proportional to criticality, together with records of interventions and configuration changes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Operational indicators help detect degradation<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Repeated-attempt rates, bona fide rejections, PAD events, support calls, passage times, and manual exceptions can reveal degradation before it becomes a permanent bypass. Trends need to be analyzed by point, period, and version while preserving applicable data-processing restrictions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An increase in rejections after a software update, for example, should trigger technical investigation. Likewise, a sudden drop in PAD events does not necessarily mean improvement: it may indicate the feature was disabled, logging failed, or a parameter changed.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Physical maintenance can change capture conditions<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Repositioning a terminal, replacing a mount, changing height, or installing new lighting may seem like a simple intervention, but it can alter the capture envelope. Critical points should have reinspection criteria and, when necessary, biometric-function retesting after relevant changes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Obsolescence should be addressed before support ends<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">PAD often depends on software, models, and libraries that evolve with threats and the manufacturer&#8217;s platform. The lifecycle plan needs to consider end of support, version compatibility, template migration, update availability, and a replacement strategy that preserves governance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Design checklist for liveness and anti-spoofing<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before approving a biometric solution with PAD, the team should be able to answer the following questions in documented form.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>What is the biometric modality and comparison mode, 1:1 or 1:N?<\/li><li>Which access points require PAD, and for what risk?<\/li><li>What threat model guides the presentation classes evaluated?<\/li><li>Is the offered feature measurable PAD or merely a commercial \u201cliveness\u201d label?<\/li><li>Which metrics are reported and under what test conditions?<\/li><li>Does the submitted evidence correspond to the offered product, version, and configuration?<\/li><li>How does the system balance rejection of attacks and rejection of bona fide users?<\/li><li>Which environmental and geometric conditions limit performance?<\/li><li>What throughput must be maintained, and how are retries handled?<\/li><li>Is there an accessible, governed flow for people who cannot use the primary modality?<\/li><li>How are enrollment, revocation, and reenrollment controlled?<\/li><li>How are templates and communications protected?<\/li><li>Which events are logged, and how are PAD, matching, and operational failures distinguished?<\/li><li>What happens during offline operation, server failure, or unavailability of the PAD feature?<\/li><li>Do FAT and SAT have predefined protocols and acceptance criteria?<\/li><li>Is the final configuration recorded in the Data Book?<\/li><li>Do version updates require analysis and regression testing?<\/li><li>Do maintenance and operations have indicators to detect degradation?<\/li><li>Does the contract define responsibilities, evidence, retests, and closure of punch-list items?<\/li><li>Is there an authentication alternative consistent with the risk for legitimate exceptions?<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">If several of these answers depend on \u201cwe will see during installation,\u201d the risk has not yet been converted into an engineering requirement. The best time to correct that gap is before procurement and deployment.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Final considerations<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Liveness and anti-spoofing should be treated as a <strong>Presentation Attack Detection<\/strong> problem, not a product checkbox. The objective is to reduce the probability that an artificial presentation is classified as bona fide without turning legitimate users into constant operational exceptions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Engineering needs to define the threat, metrics, conditions, failure behavior, evidence, and acceptance criteria, then demonstrate those requirements through FAT, SAT, commissioning, and assisted operation. The ISO\/IEC 30107 family provides the conceptual and testing framework for PAD, while references such as NIST SP 800-63B-4 show how presentation-attack metrics can be incorporated into contemporary authentication policies within their specific context.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Strong PAD is an important layer, but it still depends on appropriate matching, data protection, cybersecurity, authorization, the physical barrier, maintenance, and change management to form a robust and auditable access control system.<\/p>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Technical references<\/summary>\n<p class=\"wp-block-paragraph\">[1] ISO. ISO\/IEC 30107-1:2023 \u2014 Information technology \u2014 Biometric presentation attack detection \u2014 Part 1: Framework. Available at: <a href=\"https:\/\/www.iso.org\/standard\/83828.html\">https:\/\/www.iso.org\/standard\/83828.html<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[2] ISO. ISO\/IEC 30107-3:2023 \u2014 Information technology \u2014 Biometric presentation attack detection \u2014 Part 3: Testing and reporting. Available at: <a href=\"https:\/\/www.iso.org\/standard\/79520.html\">https:\/\/www.iso.org\/standard\/79520.html<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[3] NIST. SP 800-63B-4 \u2014 Digital Identity Guidelines: Authentication and Authenticator Management. July 2025. Available at: <a href=\"https:\/\/csrc.nist.gov\/pubs\/sp\/800\/63\/b\/4\/final\">https:\/\/csrc.nist.gov\/pubs\/sp\/800\/63\/b\/4\/final<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[4] ANPD. Technology Radar No. 2 \u2014 Biometrics and Facial Recognition. Bras\u00edlia, 2024. Available at: <a href=\"https:\/\/www.gov.br\/anpd\/pt-br\/centrais-de-conteudo\/documentos-tecnicos-orientativos\/radar-tecnologico-biometria-anpd.pdf\/@@display-file\/file\">https:\/\/www.gov.br\/anpd\/pt-br\/centrais-de-conteudo\/documentos-tecnicos-orientativos\/radar-tecnologico-biometria-anpd.pdf\/@@display-file\/file<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">[5] SUPREMA. Access Control and Biometrics Course. Sections on false-presentation detection, multispectral methods, and biometric authentication. Technical material consulted in the A3A Engenharia internal knowledge base.<\/p>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Frequently asked questions<\/summary>\n<div class=\"schema-faq wp-block-yoast-faq-block\"><div class=\"schema-faq-section\" id=\"faq-question-qual-a-diferen-a-entre-liveness-anti-spoofing-e--e37f6082\"><strong class=\"schema-faq-question\">What is the difference between liveness, anti-spoofing, and PAD?<\/strong> <p class=\"schema-faq-answer\">Liveness commonly refers to mechanisms that look for signals associated with a living, present person. Anti-spoofing is a broad term for techniques against forgery. PAD, or Presentation Attack Detection, is the standards concept used by ISO\/IEC 30107 to detect attacks presented to the capture device during biometric acquisition.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-um-far-ou-fmr-baixo-significa-que-a-biometria-re-e59915a7\"><strong class=\"schema-faq-question\">Does a low FAR or FMR mean the biometric system is resistant to spoofing?<\/strong> <p class=\"schema-faq-answer\">No. FAR\/FMR characterize biometric comparison or decision errors under defined conditions. Presentation attacks are adversarial attempts at the capture point and require a specific PAD evaluation.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-apcer-e-bpcer-s-o-as-mesmas-m-tricas-que-far-e-f-47b939c1\"><strong class=\"schema-faq-question\">Are APCER and BPCER the same metrics as FAR and FRR?<\/strong> <p class=\"schema-faq-answer\">No. APCER and BPCER characterize PAD classification errors for attack and bona fide presentations. FAR\/FMR and FRR\/FNMR belong to biometric comparison or decision performance. The two layers should be specified separately.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-pad-obrigat-rio-em-todo-sistema-de-reconheciment-7dc6a65c\"><strong class=\"schema-faq-question\">Is PAD mandatory in every facial-recognition system?<\/strong> <p class=\"schema-faq-answer\">There is no universal rule making PAD mandatory in every physical access control system. The need should be defined by risk, application, and applicable requirements. In the specific NIST SP 800-63B-4 context for digital identity authentication, PAD is required for facial recognition.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-como-avaliar-um-fornecedor-que-declara-possuir-l-01d0ace6\"><strong class=\"schema-faq-question\">How should a vendor claiming liveness be evaluated?<\/strong> <p class=\"schema-faq-answer\">Request evidence tied to the offered product, version, and configuration; verify methodology, presentation classes, metrics, test conditions, and report scope; then convert relevant requirements into traceable FAT, SAT, and acceptance criteria.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-o-sat-deve-testar-liveness-e-pad-no-ambiente-rea-506e49c9\"><strong class=\"schema-faq-question\">Should SAT test liveness and PAD in the real environment?<\/strong> <p class=\"schema-faq-answer\">Yes, when PAD is part of the system requirement. SAT should verify behavior in the final installation, including lighting, geometry, flow, bona fide users, integrations, contingencies, and the presentation classes defined in the protocol.<\/p><\/div><div class=\"schema-faq-section\" id=\"faq-question-a-lgpd-pro-be-o-uso-de-biometria-em-controle-de--9c17c957\"><strong class=\"schema-faq-question\">Does Brazil&#8217;s LGPD prohibit the use of biometrics in access control?<\/strong> <p class=\"schema-faq-answer\">Not generally. Biometric data linked to a natural person are sensitive personal data, and processing requires an appropriate legal basis, purpose, necessity, security, and governance consistent with the LGPD and the use case.<\/p><\/div><\/div>\n<\/details>\n\n\n\n<details class=\"wp-block-details is-layout-flow wp-block-details-is-layout-flow\"><summary>Complementary technical materials<\/summary>\n<h4 class=\"wp-block-heading\">Related services<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/projeto-de-controle-de-acesso\/\">Access Control Design: architecture, devices, integration, and specification<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/planejamento\/revisao-validacao-tecnica-projetos-design-review\/\">Engineering Design Review: technical review, interfaces, and design maturity<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/procurement\/\">Technical Procurement: specification, technical equalization, vendors, and procurement support<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/servicos\/implementacao\/comissionamento\/\">Engineering Commissioning: planning, testing, readiness, and handover<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Key content on this topic<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/guias-tecnicos\/guia-completo-sobre-controle-de-acesso\/\">Access Control System: types, technologies, standards, and design<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/abnt-nbr-iec-60839-controle-de-acesso-requisitos\/\">ABNT NBR IEC 60839: requirements for access control systems<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/matriz-funcional-controle-de-acesso-como-especificar-cada-ponto\/\">Access-control functional matrix: how to specify each point<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/comissionamento-controle-de-acesso-iec-60839\/\">Commissioning access control systems according to IEC 60839<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/biometria-1-1-1-n-verificacao-identificacao\/\">1:1 vs. 1:N biometrics: verification, identification, and design criteria<\/a><\/li><\/ul>\n\n<h4 class=\"wp-block-heading\">Related technical content<\/h4>\n\n<ul class=\"wp-block-list\"><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/api-webhooks-middleware-controle-de-acesso\/\">APIs, webhooks, and middleware in access control: integration, security, and architecture<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/manutencao-sistemas-controle-de-acesso\/\">Access control system maintenance: plan, inspections, tests, and evidence<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/dupla-custodia-regra-duas-pessoas-controle-de-acesso\/\">Dual custody in access control: two-person rule, dual access, and dual occupancy<\/a><\/li><li><a href=\"https:\/\/a3aengenharia.com.br\/conteudo\/artigos-tecnicos\/tailgating-anti-tailgating-controle-de-acesso\/\">Tailgating and anti-tailgating in access control: risks, detection, and design criteria<\/a><\/li><\/ul>\n<\/details>\n","protected":false},"excerpt":{"rendered":"<p>Understand liveness, anti-spoofing, and PAD in biometrics, metrics such as APCER\/BPCER\/IAPAR, and how to specify, test, and accept the capability in access control.<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"template":"","meta":{"_a3a_global_related_solutions":[],"_a3a_global_related_services":[],"_a3a_global_related_materials":[],"_a3a_post_lang":"en-us","_a3a_translation_group_id":"8683816c-c3dd-431b-98a8-e270e45e6447","_a3a_i18n_canonical_slug":"liveness-anti-spoofing-biometrics-pad-presentation-attacks-access-control","_a3a_lang_url_en-us":"","_a3a_lang_url_es-es":""},"categories":[],"segments":[],"mercados":[],"etapas":[],"class_list":["post-74892","articles","type-articles","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/74892","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles"}],"about":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/types\/articles"}],"author":[{"embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/74892\/revisions"}],"predecessor-version":[{"id":74893,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/articles\/74892\/revisions\/74893"}],"wp:attachment":[{"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/media?parent=74892"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/categories?post=74892"},{"taxonomy":"segments","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/segments?post=74892"},{"taxonomy":"mercados","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/mercados?post=74892"},{"taxonomy":"etapas","embeddable":true,"href":"https:\/\/a3aengenharia.com\/en-us\/wp-json\/wp\/v2\/etapas?post=74892"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}