Overview
ISO/IEC 18328-1:2015 - Identification cards - ICC-managed devices - Part 1: General framework - defines the general architecture for identification cards (ICCs) with integrated or externally connected ICC-managed devices. This international standard provides a foundational framework that ensures consistency and enables interoperability across various types of identification cards and supporting devices, regardless of the communication interface employed.
The primary principle detailed in ISO/IEC 18328-1:2015 is that all actions involving ICC-managed devices are governed by the card’s integrated circuit (card-IC), including management of devices outside the physical card. This part serves as the basis for the broader ISO/IEC 18328 series, clarifying content boundaries and setting the stage for detailed specifications in subsequent parts.
Key Topics
- General Architecture of ICC-Managed Devices: Establishes a standard structure for connecting and managing electronic devices on, or external to, an integrated circuit card.
- Device Categories: Covers input (keypad, biometric sensor), output (display, loudspeaker), input/output (touchscreen), communication (LED, microphone), and support devices (power supply).
- Interoperability: Provides guidelines to minimize technology-specific differences, supporting broad compatibility with card devices as technology evolves.
- Logical Control by Card-IC: Mandates that the card's operating system is responsible for all operations involving connected devices, regardless of physical location.
- Independence from Interface Technology: Ensures applicability across different physical and logical communication interfaces such as SPI, I²C, or contactless protocols.
- Security and Trust: Includes the logical framework for secure data exchange, supporting authentication, confidentiality, and integrity of managed data.
Applications
ISO/IEC 18328-1:2015 underpins a wide range of practical identification card uses. Its framework supports:
- Multi-Factor Authentication: Enables cards with biometric sensors, PIN entry, or combination devices for secure user verification in banking, government ID, or corporate access systems.
- Dynamic Data Display: Supports electronic displays on cards, allowing the presentation of temporary PINs, balances, transaction numbers, or consent information directly to the user.
- Secure User Input: Facilitates on-card keypads or touchscreens for sensitive data input, reducing reliance on potentially insecure external terminals.
- Transaction Security: Strengthens interactions such as PIN verification, one-time password generation, and cardholder approval using onboard or external devices managed by the ICC.
- Mobile and NFC Integration: Applies to use cases where Secure Elements (eSE) or Trusted Execution Environments (TEE) in mobile devices manage ICC peripherals for enhanced security in contactless payments, eID, and secure services.
Related Standards
The ISO/IEC 18328 series comprises several parts, each addressing specific aspects of ICC-managed devices:
- ISO/IEC 18328-2: Physical characteristics and test methods for cards with devices.
- ISO/IEC 18328-3: Organisation, security, and command protocols for interchange between cards and devices.
Related foundational standards include:
- ISO/IEC 7816 & ISO/IEC 14443: Defining physical, electrical, and protocol requirements for integrated circuit cards and their contact/contactless interfaces.
- ISO/IEC 17839: Providing guidelines on biometric capture devices.
- Open Mobile APIs and Global Platform TEE specifications: Relevant for implementations in mobile environments with Secure Elements and Trusted Execution Environments.
By harmonizing the integration and control of ICC-managed devices, ISO/IEC 18328-1:2015 helps manufacturers, service providers, and system architects achieve secure, future-ready, and interoperable identification card solutions across industries.
Keywords: ISO/IEC 18328-1, ICC-managed devices, identification cards, card-IC, interoperability, biometric sensor, secure element, TEE, multi-factor authentication, smart card standards.