Overview
ISO/IEC 19286:2018 - Identification cards - Integrated circuit cards - Privacy-enhancing protocols and services defines a privacy-focused framework for smart cards and other integrated circuit cards (ICCs). The standard normalizes privacy-enhancing protocols and services at the card edge by re-using relevant mechanisms from ISO/IEC 7816 and ISO/IEC 18328, specifying discoverability of privacy attributes, defining requirements for attribute-based credential handling, and identifying the data objects and commands used by ICCs. It also adapts generic privacy protocols for distributed ICC systems and strengthens authentication protocols (e.g., secure channel establishment) with privacy protections. Annex B provides guidance for privacy impact assessments (PIA).
Key technical topics and requirements
- Privacy architecture & principles: data minimization, user control, data quality and categorization of user, ICC, issuer and service-provider data.
- Discoverability: means for external devices to detect privacy-enabling attributes on an ICC.
- Attribute-based credential handling: requirements for managing and presenting credentials and attribute statements while preserving privacy.
- Privacy-enhancing protocols: standardized descriptions of user verification, device authentication and attribute verification mechanisms tailored for ICCs. Examples covered include PACE, EACv2, ABC-based protocols, ERA and OPACITY (as adapted for ICC use).
- Pseudonymous mechanisms: support for domain-specific identifiers, pseudonymous signatures and credential-based signatures that reduce linkability.
- Data objects & commands: identification of ICC data structures and command sequences needed to implement privacy services and to interoperate with existing ISO/IEC 7816 commands.
- On-card device and secure channel considerations: secure communication between ICC and on-card or external devices, including enhancements to protect privacy during authentication.
- Privacy impact assessment: practical guidance (Annex B) for assessing privacy risks in electronic identification and trust services.
Practical applications
- Electronic passports, national eID and citizen cards
- Employee access badges, health insurance cards, and other identity tokens
- eVoting systems and privacy-sensitive IoT deployments that rely on ICC-based identity
- Payment and loyalty cards requiring pseudonymity or attribute-limited disclosure
Who should use this standard
- Smart card and ICC manufacturers and firmware developers
- Identity providers, issuers and service providers implementing eID/eAuth solutions
- System integrators, security architects and solution designers for identity systems
- Privacy officers, regulators and conformity assessment bodies performing PIAs and evaluations
Related standards (normative references)
- ISO/IEC 7816 series (card organization, security, commands, biometric verification)
- ISO/IEC 18328-3 (ICC-managed devices - organization/security/commands)
Keywords: ISO/IEC 19286, privacy-enhancing protocols, integrated circuit cards, ICC, smart card privacy, attribute-based credentials, PACE, EACv2, OPACITY, pseudonymous signatures, privacy architecture, data minimization.