What is ISO/IEC 18013-4 - Personal identification - ISO compliant driving licence about?
ISO/IEC 18013-4 is the fourth part of the multi-series standard that describes the test methods used for conformity testing, that is methods for determining whether a driving licence can be considered to comply with the requirements of the ISO/IEC 18013 series for:
- Machine readable technologies (ISO/IEC 18013-2), and
- Access control, authentication and integrity validation (ISO/IEC 18013-3).
The test methods described in ISO/IEC 18013-4 are based on specifications defined in ISO/IEC 18013-2 and ISO/IEC 18013-3 and underlying normative specifications.
ISO/IEC 18013-4 deals with test methods specific to IDL requirements.
Hence the purpose of ISO/IEC 18013-4 is to:
- Provide IDL implementers with requirements for conformity evaluation,
- Provide IDL issuing authorities with requirements for quality assurance, and
- Provide test laboratories and test tool providers with test suite requirements.
Note : Test methods applicable to (smart) cards in general (e.g., those specified in the ISO/IEC 10373 series) are outside the scope of ISO/IEC 18013-4.
Who is ISO/IEC 18013-4 - Personal identification - ISO compliant driving licence for?
ISO/IEC 18013-4 on Personal identification is useful for:
- IDL issuing authorities
- IDL implementers
- Test laboratories and test tool providers
Why should you use ISO/IEC 18013-4 - Personal identification - ISO compliant driving licence?
ISO/IEC 18013-4 establishes guidelines to users for the design format and data content of an ISO-compliant driving licence (IDL) with regard to human-readable features, machine-readable technologies and access control, authentication and integrity validation.
ISO/IEC 18013-4 creates a common basis for international use and mutual recognition of the IDL without impeding individual countries/states to apply their privacy rules and national/community/regional motor vehicle authorities in taking care of their specific needs.
ISO/IEC 18013-4 prescribes requirements for testing of the compliance of the machine-readable data content and mechanisms to control access to data recorded in the machine-readable technology on an IDL.
What’s changed since the last update?
BS ISO/IEC 18013-4:2019 supersedes BS ISO/IEC 18013‑4:2011. BS ISO/IEC 18013-4:2019 includes some technical changes with respect to BS ISO/IEC 18013‑4:2011. These include:
- In the interest of interoperability of cards used for personal identification, the authentication protocols for the IDL are simplified; Active Authentication is harmonised with other ISO standards and thus BAP configurations 2, 3 and 4, as well as EAP are no longer supported by ISO/IEC 18013-4
- Replacing EAP, the optional EACv1 protocol is defined for the IDL, enabling access control to sensitive biometric data stored on an integrated circuit; EACv1 may be used in conjunction with either BAP configuration 1 or PACE
- The optional PACE protocol enables access control to the data stored on an integrated circuit. The PACE protocol is a password-authenticated Diffie Hellman key agreement protocol based on a (short) input string that provides secure communication between a secure integrated circuit on an IDL and a terminal and allows various implementation options (mappings, input strings, algorithms)
- The PACE protocol implementation for the IDL has restricted to Elliptic Curve Diffie Hellman (ECDH) generic mapping and can be used as a stand-alone protocol or in combination with the EACv1 protocol.