Overview
ISO/IEC 18013-3:2017/Amd 1:2022 introduces an amendment to the existing standard for ISO-compliant driving licences, with a focus on enhancing access control, authentication, and integrity validation using the PACE protocol. The amendment aligns the driving licence application security processes with internationally recognized practices for electronic machine readable documents, as set by ICAO Doc 9303. By incorporating the PACE protocol (Password Authenticated Connection Establishment), this update improves the protection of personal information stored on electronic driver’s licences, ensuring data confidentiality and authenticity during electronic communication and access.
Key Topics
- PACE Protocol Integration: This amendment implements PACE as the foundational protocol for access control and secure messaging in ISO-compliant driving licences. PACE enables robust mutual authentication between the chip and the reader, ensuring that only authorized parties can access sensitive information.
- Alignment with ICAO Standards: The document references ICAO Doc 9303, Part 10 and Part 11, ensuring harmonized security specifications across various types of electronic identification documents, such as driving licences and electronic passports.
- Support for Secure Messaging: After successful authentication with PACE, secure messaging using AES or 3DES is mandated to further protect data exchanged between the chip and the terminal.
- Detailed Application Guidance: The amendment provides clarified guidance on input strings, data element references, and protocols for non-match alert parameters, as well as explicit cross-references to source ICAO documents for technical implementation.
- Worked Example: A comprehensive example is provided to demonstrate the PACE protocol’s application in a typical workflow, illustrating command sequences and data structures used in real-world implementations.
Applications
The adoption of the PACE protocol in ISO/IEC 18013-3:2017/Amd 1:2022 has several practical applications:
- Electronic Driving Licences (IDL/EDL): National issuing authorities and technology providers benefit from enhanced security measures for personal data stored on contactless driver's licence chips. PACE ensures that only legitimate terminals can access and read licence data.
- Cross-Border Verification: With harmonization to ICAO standards, driving licences using PACE can be more easily and securely verified internationally, facilitating reliable identity validation during travel, car rentals, and law enforcement checks.
- Identity Management Systems: The specification supports integration with broader national or regional identification schemes, providing a standard approach for mutual authentication and data protection.
- Machine-Readable Document Security: By leveraging the same core security mechanisms as ePassports, implementers of secure personal ID cards can unify their technology stack and operational procedures.
Related Standards
Implementers and stakeholders should consider the following related standards:
- ISO/IEC 18013 Series: Encompasses specifications for ISO-compliant driving licences, covering physical characteristics, data structures, and security features.
- ICAO Doc 9303, Part 10 & Part 11: Core references for the logical data structure and security mechanisms of machine readable travel documents, ensuring interoperability and compliance across international borders.
- ISO/IEC 8859-1:1998: Specifies character encoding used for certain data fields in the standard.
- Barcode Standards: Including ISO/IEC 16022 (Data Matrix), ISO/IEC 15417 (Code 128), and ISO/IEC 16388 (Code 39) for encoding visible data fields.
By following ISO/IEC 18013-3:2017/Amd 1:2022, authorities, manufacturers, and system integrators can significantly enhance the privacy, integrity, and global interoperability of electronic driving licence solutions. This amendment reinforces commitment to robust personal identification supported by international best practices in cryptographic access control and authentication.