NIST iBeta". The name is wrong, the testing is real, and we have not been through it

No Solidus product has been submitted to iBeta or to any other accredited laboratory for presentation-attack-detection testing, and no Level 1 or Level 2 result exists.

The name conflates three organisations

The industry says "NIST iBeta certified" as though it were one thing. It is three, with three different roles:

  • NIST, the US National Institute of Standards and Technology, does not test or certify any company's liveness system. What it runs is NVLAP, a programme that accredits independent laboratories as competent to perform specified standardised tests.
  • iBeta Quality Assurance is one of those laboratories: a private commercial testing company, not a government agency, NVLAP-accredited to perform the testing and by far the most cited name when a vendor says its liveness is certified.
  • ISO/IEC JTC 1/SC 37 maintains ISO/IEC 30107-3, the standard the testing is performed against.

So "NIST certified" is not a thing that exists. Where you see it on a vendor's site, the vendor has either compressed the chain carelessly or is borrowing a federal agency's name for something it did not do. It is worth knowing before you compare vendors, including when you compare us.

What the testing actually measures

A laboratory runs a standardised battery of attacks against the system and reports whether it held:

  • Level 1, artefacts an attacker can produce cheaply: a printed photograph, a photograph displayed on a screen.
  • Level 2, more sophisticated artefacts, including masks, requiring materials and effort.

The value is that a stranger can check the result. iBeta publishes the vendors and products it has tested; a buyer reads the list rather than taking the vendor's word.

Where we are, which is two stages short

We have not been submitted. No laboratory, no battery, no result.

And there is an earlier stage we have also not completed: our own presentation-attack-detection model has not cleared an internal adversarial review. External laboratory testing is the step after that one.

So the honest position is not "we are working toward certification." It is that neither the internal nor the external assessment has happened, and stating only the second would imply the first was done.

You can check this yourself, and that is the point

Search iBeta's published list of certified vendors. Solidus will not appear, because no submission has been made.

That is unusual and worth naming: most of what we claim about our own gaps has to be taken on trust, but this one is independently checkable in the negative. Where we can hand you a way to verify a claim about us, we would rather do that than ask you to believe a sentence.

What this means for our liveness claims

Every statement we make about liveness and anti-spoofing is a claim about design, not a measured result. We can describe what the pipeline asks for, a document, an active liveness check, a face match, and we cannot tell you how it performs against a standardised attack battery, because nobody has run one.

And we will not publish a figure of our own. Any detection or spoof-resistance number we generated internally would describe our own test conditions, chosen by us, and would be exactly the kind of self-graded metric this testing exists to replace. If a Solidus page ever shows one, it is wrong.

Keep reading

Powered by the Protocol

Solidus Verify is one product on the Solidus Network.

Explore the consensus, the validator economics, and the other products on the same identity layer.

NIST iBeta". The name is wrong, the testing is real, and we have not been through it · Solidus — Solidus Verify