Overview
ISO/IEC 18013-3:2017/Amd 2:2023 is an amendment to the international standard for ISO-compliant driving licences focusing on access control, authentication, and integrity validation. This amendment introduces significant updates to passive authentication methods used in personal identification driving licences, ensuring enhanced security and reliability. Developed by the ISO/IEC Joint Technical Committee 1 (JTC 1), Subcommittee 17 (SC 17), this standard is critical for governments, manufacturers, and authorities involved in issuing and verifying driving licences.
Key Topics
-
Passive Authentication Updates
The amendment revises passive authentication methods to reinforce data integrity and prevent unauthorized data modification. Version 02 of passive authentication supersedes version 01, introducing refined processes and updated cryptographic standards.
-
Digital Signature Standards
It updates references from FIPS 186-2 to FIPS 186-4 (2013) for digital signature standards (DSS), ensuring compliance with current cryptographic practices.
-
Hash Function Enhancements
The usage of hash functions has been updated. SHA-1 and SHA-224 have been deprecated in favor of stronger algorithms such as SHA-256, boosting security against vulnerabilities.
-
Data Group Signatures
The amendment specifies changes in how data groups within the driving licence are signed and validated, particularly for compact and standard encoding. It introduces new data groups DG.SOD.1 and DG.SOD.H for hashing and verifying public key certificates.
-
Public Key Infrastructure (PKI) Considerations
Although the standard does not mandate key management systems, it provides principles for establishing trust in public keys, vital for authentication during licence verification.
-
Cryptographic Curves and Encoding
The document details the elliptic curve cryptography (ECC) parameters recommended, harmonizing with FIPS standards and RFC 5639 curve identifiers for interoperability.
Applications
-
Driving Licence Issuance and Verification
Governments and authorized issuers can implement these updated passive authentication methods to ensure secure, verifiable, and tamper-proof driving licences.
-
Reader Device Manufacturers
Hardware developers designing card readers and authentication terminals will benefit from the specification changes that enhance compatibility and security when reading ISO-compliant driving licences.
-
Law Enforcement and Road Authorities
These entities can rely on passive authentication updates to verify the authenticity and integrity of driver identification documents more effectively during traffic stops, checkpoints, and other official processes.
-
Identity Verification Systems
Integration into wider identity management systems becomes more secure, supporting cross-border interoperability and reducing fraud risks in personal identification.
Related Standards
-
ISO/IEC 18013 Series
This part (Part 3) is one of a series defining requirements for ISO-compliant driving licences. Other parts cover physical characteristics, data structures, and application profiles.
-
ISO/IEC 7812-1
Related to issuer identification numbers used in authentication processes, referenced for ensuring accurate verification of the issuing authority.
-
FIPS 186-4
The Digital Signature Standard (DSS) referenced for cryptographic algorithms relevant to passive authentication signature processes.
-
ICAO Doc 9303
Provides guidelines for machine-readable travel documents, historically influencing hash function compatibility in driving licence standards.
-
RFC 3369 and RFC 4055
Define cryptographic message syntax and signature schemes applicable to the digital signature implementations within this standard.
By adopting ISO/IEC 18013-3:2017/Amd 2:2023, stakeholders ensure their driving licence systems stay aligned with the latest security enhancements and cryptographic standards, supporting robust personal identification and fraud prevention worldwide.