NIST approval explained

profile picture Matt Prendergast 3 min read
Man working at laptop in office setting

Many companies in the identity space talk of NIST certification. What does this mean for you as a user of identity services and what does it mean for your customers?

 

Who is NIST?

NIST is the National Institute of Standards and Technology (NIST), a non-regulatory agency of the United States Department of Commerce. NIST’s remit is to create and certify measures, standards and technology to enhance trade and productivity. Formed in 1901, their remit is to provide standards and certification for businesses. At first this included clocks and thermometers, all kinds of ‘weights and measures’.  But over time the agency has grown to include tech, such as election technology and, of interest to us, cybersecurity.

 

What is NIST compliance?

Broadly, NIST certification means the product in question meets defined standards. Liveness is an anti-spoofing process that checks to ensure we are dealing with a real person. Not someone who is, for example, wearing a mask or using a photo or image of someone else. We use it across our suite of solutions including identity verification, digital ID and age verification

 

What does NIST certified liveness mean?

NIST provides a framework for testing performance levels of liveness. 

NIST Level 1 involves testing using things that could be found in a normal home or office. Materials used for testing should not cost more than $30. Masks are excluded. To pass NIST Level 1, you must detect every attack and limit false negatives to less than 15%. 

NIST Level 2. Involves testing against more specialist attacks, such as latex facemasks or 3D printers. Materials used for testing should not cost more than $300.To pass NIST Level 2, you must detect 99% of attacks and limit false negatives to less than 15%.

Once a liveness service has passed testing, they will be issued with a Presentation Attack Detection (PAD) Confirmation letter that provides results and methodology used and what product was tested. 

To learn more about our liveness products, please do get in touch.

Related stories

Yoti MyFace Match development and improvement

Yoti MyFace Match is what’s known as a 1:1 and 1:N face matching solution. The technology compares a single image with another image or set of images in real time to determine if it is the same person. Yoti licences this facial recognition technology to businesses wanting to be sure that, for example, the right person is accessing their online accounts. MyFace Match is also useful to businesses because they invite users to opt-in  to be ‘verified’ and then be required to provide consent whenever their image or content is published. In the case of live streaming, businesses can monitor

4 min read

Combatting deepfakes online

It’s concerning to see how innovative artificial intelligence (AI) is being used to create deepfakes that are spreading disingenuous information and explicit images online. Deepfakes are realistic videos or images created by generative AI. Fraudsters can now use advanced algorithms to manipulate visual and audio elements that mimic real people. This fake content shows people doing or saying things they never did. Two prominent individuals have recently been targets of deepfake scams. A video featuring Taylor Swift generated by artificial intelligence was used to promote a fraudulent cookware competition, and explicit AI-generated images of her were widely circulated online. Additionally,

6 min read

On the threat of detecting deepfakes

Learn how Yoti can help you defeat deepfakes As the threat of generative AI in identity and content integrity continues to build, Yoti has developed a comprehensive strategy focused on early detection by using tools to prevent AI-generated content or attacks at the point of source. Yoti’s strategy for detecting generative AI threats targets two attack vectors: presentation attacks (direct) and injection attacks (indirect), with a focus on early detection during the verification or authentication process.  Our proprietary and patented technology can work on: Deepfakes Illicit images Account takeovers Identity theft and fraud Content moderation Injection attacks Bot attacks

2 min read