Government ID, Smart Cards, Identification and Authentication

New Extended Access Control technology to improve electronic passport security

Wednesday, December 26, 2007

Eric Skinner, Chief Technology Officer, Entrust

The next 12 months will witness a remarkable change. Specifically, 2008 will see the emergence of new and more sophisticated electronic passports across the globe, particularly in European Union (EU) countries. New information technology is emerging to better protect and verify the personal information contained in these documents.


The use of e-passports to more accurately ensure and verify the identities of travelers has gained momentum across the globe in recent years, with more than 40 countries currently issuing some type of electronic passport. And for good reason.

Security concerns, developing technologies and emerging standards have prompted national governments to pursue the issuance of machine readable travel documents containing a chip that stores information that can be verified against the data on the passport, thereby improving border control.

To facilitate interoperability across countries, the International Civil Aviation Organization (ICAO) has set global standards for e-passports. Since the e-passport contains sensitive personal information, security and integrity are critical. Therefore, the use of digital certificates and a public key infrastructure (PKI) have become integral to securing and verifying this data. In 2008, countries will begin to implement a new standard for digital certificates providing this functionality in preparation for a new generation of e-passport.

The initial generation of electronic passports in use today–throughout the EU and other countries–contain data protection under a scheme called Basic Access Control. In 2009, the EU countries will be required to add biometric data to the e-passport in the form of digital fingerprints. The strength of the security and verification around this data is evolving to protect this personal information through capabilities for Extended Access Control (EAC).

EAC is the process defined for ensuring that only authorized entities are able to access biometric data (such as an iris scan or fingerprint) stored on the contactless chip on an electronic passport. EAC also includes the authentication of a passport inspection station to the contactless chip, as well as the authorization of that inspection station to access the protected biometrics.

EAC provides a higher level of security during the verification process of e-passports. Not based on the X.509 standard, EAC will leverage a new type of certificate established by the ICAO known as a card verifiable (CV) certificate.

These next-generation passports will be required by all member EU nations by June 2009. The U.S. has yet to standardize on an EAC strategy.

While the remainder of the world has not yet established a timetable for implementing EAC, there is general agreement that the privacy of biometric data on electronic passports is critical; broad adoption of measures such as those provided by EAC can be reasonably expected over time.


About the AVISIAN Publishing Expert Panel At the close of each year, AVISIAN Publishing’s editorial team selects a group of key leaders from various sectors of the ID technology market to serve as Expert Panelists. Each individual is asked to share their unique insight into what lies ahead. During the month of December, these panelist’s predictions are published daily at the appropriate title within the AVISIAN suite of ID technology publications: SecureIDNews.com, ContactlessNews.com, CR80News.com, RFIDNews.org, FIPS201.com, NFCNews.com, ThirdFactor.com, and DigitalIDNews.com[end] 

After a nearly three-year delay, the Algerian government has finally launched its biometric passport program.

Magharebia reports that the biometric passports, which contain a contactless smart card chip that holds a digitized photo, fingerprints and signature, were supposed to be released in 2009. But the documents were delayed due to complexities with the operation of the project and the need to thoroughly research and analyze other countries’ experiences with biometric passports.

read more »

As part of the U.S. Department of State’s initiative to simplify and streamline customer service interactions and processes, the Office of Passport Services has started a 90-day pilot program for online passport card applications.

read more »

CBP denies report

A Canadian man uses a scanned image of his passport from his iPad to get past Customer and Border Protection officials, according to a report from the AP.

read more »

In an effort to streamline passenger security, Jakarta, Indonesia’s Soekarno-Hatta Airport has opened the country’s first biometric immigration gate.

Fingerprint biometric identification provider BIO-key International, Inc. and Oakwell Engineering Limited partnered to create the new gate, designed for use by passengers with electronic passports. Passengers submit their e-passports and authenticate with a fingerprint.

read more »

The BioP@ss project, a program funded through the EUREKA micro-electronics cluster MEDEA+, has been working on a way to speed up passport control at European airports. As reported on PhysOrg.com, digital security specialists, European electronics makers and biometrics experts have been working together on this new technology to meet the air travel security standards for 2014.

read more »

The Emirates Identity Authority (EIDA) announced that the registration of Emirati newborns is now mandatory for electronic passports (e-passport) and ID cards, according to ArabianBusiness.com.

read more »