Skip to content

EAC and Terminal Authentication ​

Some Data Groups on an eMRTD chip contain sensitive biometrics: fingerprints (Data Group 3) and iris images (Data Group 4). These are protected by Extended Access Control (EAC), defined in BSI TR-03110. This document explains what EAC is and why commercial inspection systems, including the KINEGRAM products, cannot read fingerprints. The standard is designed this way. It is not a product limitation.

What Is Extended Access Control? ​

EAC consists of two protocols:

  • Chip Authentication: the terminal verifies that the chip is genuine. It is already part of the regular verification procedure.
  • Terminal Authentication (TA): the chip verifies the terminal. The reading device must prove that it is authorized to access sensitive Data Groups before the chip releases them.

How Terminal Authentication Works ​

Terminal Authentication uses its own chain of card-verifiable certificates, separate from the CSCA chain used for Passive Authentication:

signs

signs

CVCA
(Country Verifying CA of the issuing country)

Document Verifier Certificate
(DV, one per receiving authority)

Inspection System Certificate
(IS, one per terminal)

signs

signs

CVCA
(Country Verifying CA of the issuing country)

Document Verifier Certificate
(DV, one per receiving authority)

Inspection System Certificate
(IS, one per terminal)

The terminal must present a certificate chain that leads back to the CVCA of the country that issued the document, together with proof of possession of the corresponding private key. Only then does the chip grant access to Data Groups 3 and 4.

Why Fingerprints Cannot Be Read ​

  • Inspection System certificates are issued only to government authorities (typically border control), based on bilateral agreements between states. A commercial party cannot obtain them.
  • The chip itself enforces the access rights. Without a successful Terminal Authentication it refuses to release Data Groups 3 and 4. The files cannot be read in any other way.
  • Terminal Authentication certificates are deliberately short-lived, so even authorized terminals must be re-provisioned frequently.

No system outside of government inspection infrastructure can read the fingerprints, regardless of the vendor.

What This Means in Practice ​

  • The MOBILE CHIP SDK and the DocVal Service read and verify the Data Groups that are accessible after BAC or PACE: MRZ info, photo of the face and the other relevant Data Groups.
  • The photo of the face (Data Group 2) is not protected by EAC and is the intended biometric for commercial identity verification.
  • A document whose fingerprints cannot be read is not defective or suspicious. The standard works as intended.