Title: Technical Report
1Technical Report
- PKI for
- Machine Readable Travel Documents offering ICC
read-only access
TAG_15 Montreal, 2004-05-18 Tom Kinneging
2Authenticity and Integrity
- Document Security Object
- Standardized data structure (RFC3369)
- Containing hash-representations of LDS data
groups - Digitally signed by issuing State
3Document Security Object
LDS
SOD
Data Group 1 (MRZ)
Hash DG_1
Data Group 2 (Encoded Face)
Hash DG_2
Data Group 3 (Encoded Finger)
Hash DG_3
Data Group 4 (Encoded Iris)
Hash DG_5
Data Group 5 (Displayed Face)
Digital Signature
Data Group 6 (Future use)
Data Group 7 - 15
Data Group 16 (Persons to notify)
4Key Management
- Document Signer Certificates
- Country Signing CA Certificates
- Certificate Revocation
- ICAO Public Key Directory
5Key Management
Country Signing CA
Document Signer
2
1
1
Issue sign
Issue Sign
Sign
SOD
Hash DG_1
2
1
Hash DG_2
Hash DG_3
Hash DG_5
Digital Signature
Document Security Object
Inspection system
MRTD chip
6Additional options
- Basic Access Control
- Active Authentication
- Securing additional biometrics
7Basic Access Control
- MRZ based key derivation
- Skimming
- Access to chip data
- Eavesdropping
- Secure communications chip / reader
8Basic Access Control
9Basic Access Control
10011101111001
Inspection system
10Active Authentication
- Chip Substitution
- Data Copying
- Documents Key pair
11Active Authentication
LDS
SOD
Data Group 1 (MRZ)
Hash DG_1
Data Group 2 (Encoded Face)
Hash DG_2
Data Group 3 (Encoded Finger)
Hash DG_3
Data Group 4 (Encoded Iris)
Hash DG_5
Data Group 5 (Displayed Face)
Hash DG_15
Data Group 6 (Future use)
Digital Signature
Data Group 7 - 14
Data Group 15 (AA Public Key)
AA Private Key
Data Group 16 (Persons to notify)
12Next steps
- Implementation experiences
- Further development
13Frequently Asked Questions
- TAG-MRTD-WP/10
- Keep up-to-date
14Action by the TAG/MRTD
- The TAG/MRTD is invited to endorse the Technical
Report, PKI for Machine Readable Travel
documents Offering ICC Read-only Access, Version
1.0.