ISO/IEC 18013-3:2017
Information technology — Personal identification — ISO-compliant driving licence — Part 3: Access control, authentication and integrity validation
Information technology — Personal identification — ISO-compliant driving licence — Part 3: Access control, authentication and integrity validation
- Статус документа:
- Действующий
- Формат:
- Электронный (PDF)
- Количество страниц:
- 80
- Дата публикации:
- 4 апреля 2017 г.
- Издание:
- ISO/IEC IS 18013 edition 2 version 1
- ICS:
- 35.240.15
ISO/IEC 18013 establishes guidelines for the design format and data content of an ISO-compliant driving licence (IDL) with regard to human-readable features (ISO/IEC 18013‑1), machine-readable technologies (ISO/IEC 18013‑2), and access control, authentication and integrity validation (ISO/IEC 18013‑3). It creates a common basis for international use and mutual recognition of the IDL without impeding individual countries/states to apply their privacy rules and national/community/regional motor vehicle authorities in taking care of their specific needs. ISO 18013-3:2017 - is based on the machine-readable data content specified in ISO/IEC 18013‑2; - specifies mechanisms and rules available to issuing authorities (IAs) for: - access control (i.e. limiting access to the machine-readable data recorded on the IDL), - document authentication (i.e. confirming that the document was issued by the claimed IA), and - data integrity validation (i.e. confirming that the data has not been changed since issuing). ISO 1813-3:2017 does not address issues related to the subsequent use of data obtained from the IDL, e.g. privacy issues.
Abstract
Overview
ISO/IEC 18013-3:2017 defines access control, authentication and integrity validation mechanisms for an ISO‑compliant driving licence (IDL). Building on the machine‑readable data model in ISO/IEC 18013‑2, this part gives issuing authorities (IAs) interoperable technical options to: limit access to on‑card data, verify that a driving licence was issued by the claimed authority, and confirm that on‑card data have not been altered since issuance. The standard supports international use and mutual recognition of IDLs while allowing jurisdictions to apply their own privacy and policy rules. Note: ISO/IEC 18013‑3:2017 does not address downstream privacy or data‑use policy.
Key topics and requirements
- Access control - Mechanisms to prevent unauthorized/remote reading of machine‑readable data (e.g., Basic Access Protection (BAP), PACE).
- Document authentication - Techniques to confirm the document origin (e.g., Passive Authentication, Active Authentication, EACv1).
- Data integrity validation - Methods to ensure recorded data have not been changed since issuance (e.g., digital signatures and the Document Security Object EF.SOD).
- Mechanisms covered (from normative clauses and annexes): Passive Authentication; Active Authentication; Basic Access Protection; PACE (Password Authenticated Key Exchange based on Diffie‑Hellman, restricted to ECDH generic mapping for IDL); Extended Access Control v1 (EACv1); scanning area identifiers; non‑match alerts.
- Security file structure - Logical data files and tags such as EF.SOD, EF.DG13 (Active Authentication), EF.DG14 (EACv1) and EF.CardAccess (PACE) are specified for interoperable implementations.
- PKI and conformance - Public Key Infrastructure considerations (Annex A) and conformance rules guide issuer trust models and verification workflows.
- Standard updates - The 2017 edition simplified authentication protocols for better interoperability: harmonized Active Authentication, removal of certain BAP/EAP configurations, and optional EACv1 and PACE support.
Applications and who uses it
ISO/IEC 18013‑3:2017 is aimed at:
- Issuing authorities (motor vehicle agencies) designing secure IDLs.
- Smartcard/secure element manufacturers implementing IDL integrated circuits and file systems.
- Border control, law enforcement and inspection terminals that read and authenticate driving licences.
- System integrators and software developers building verification apps and PKI solutions.
- Standards bodies and policymakers aligning national IDL programs for mutual recognition.
Practical benefits include improved cross‑border interoperability, standardized anti‑skimming/access controls, and robust document and data integrity checks.
Related standards
- ISO/IEC 18013‑1 (human‑readable features)
- ISO/IEC 18013‑2 (machine‑readable data content) - ISO/IEC 18013‑3 is explicitly based on this part.
Keywords: ISO/IEC 18013-3:2017, ISO-compliant driving licence, IDL, access control, authentication, data integrity, PACE, EACv1, Basic Access Protection, Passive Authentication, Active Authentication.
Технические детали
- Технический комитет
- ISO/IEC JTC 1/SC 17 - Cards and security devices for personal identification
- SKU
- ISO/IEC 18013-3:2017
Похожие стандарты
Упомянутые в описании и другие стандарты ISO
ISO/IEC 18013-2:2020
ДействующийPersonal identification — ISO-compliant driving licence — Part 2: Machine-readable technologies
Overview ISO/IEC 18013-2:2020 defines the machine‑readable technologies and data model for an ISO‑compliant driving licence (IDL). The standard specifies which data elements are mandatory or optional…
BS ISO/IEC 18013-1:2018
ДействующийInformation technology. Personal identification. ISO-compliant driving licence. Physical characteristics and…
ISO 8212:1986
ОтменёнSoaps and detergents — Techniques of sampling during manufacture
Overview Standard Reference: ISO 8212:1986 Title: Soaps and detergents - Techniques of sampling during manufacture ISO 8212:1986 defines standardized techniques for taking representative samples of s…
ISO 20662:2020
ДействующийShips and marine technology — Hopper dredger supervisory and control systems
Overview ISO 20662:2020 - Ships and marine technology: Hopper dredger supervisory and control systems (HD‑SCS) - specifies the components, structure, general requirements, and functional requirements…
ISO 3021:2023
ДействующийAdventure tourism — Hiking and trekking activities — Requirements and recommendations
Overview ISO 3021:2023 - Adventure tourism: Hiking and trekking activities - Requirements and recommendations defines safety-focused requirements and recommendations for hiking and trekking offered a…
ISO 3826-2:2008
ДействующийPlastics collapsible containers for human blood and blood components — Part 2: Graphical symbols for use on l…
Overview ISO 3826-2:2008 - "Plastics collapsible containers for human blood and blood components - Part 2: Graphical symbols for use on labels and instruction leaflets" defines a system of internatio…
ISO/IEC 24730-1:2014
ДействующийInformation technology — Real-time locating systems (RTLS) — Part 1: Application programming interface (API)
Overview ISO/IEC 24730-1:2014 specifies the Application Programming Interface (API) for Real‑Time Locating Systems (RTLS). The standard defines a minimal, interoperable boundary that lets application…
ISO 8668-5:1992
ДействующийAircraft — Terminal junction systems — Part 5: Detail specification for type 3 system
Overview - ISO 8668-5:1992 (Aircraft terminal junction systems, Type 3) ISO 8668-5:1992 defines the detail specification for Type 3 Terminal Junction Systems (TJS) used in aircraft electrical install…