IDmetrix® CSCA & CVCA & ICAO PKD
The two national roots of trust, and the global directory that makes them useful abroad.
Two separate roots of trust sit under an electronic document programme, answering two different questions. The CSCA answers “was this document really issued by this government, and has the data been tampered with?” The CVCA answers “who is actually allowed to read the protected biometric data from it?” The ICAO PKD is how the answer to the first question travels across borders.
The three elements
- CSCA — Country Signing Certificate Authority
- The national root of trust for electronic passports and ID documents. Each issuing country establishes a single CSCA. It signs Document Signer certificates, forms the trust chain the border reader follows, issues CRLs, and uploads its certificates to the ICAO PKD. CSCA certificates are typically valid for three to five years and are often also exchanged bilaterally between countries.
- CVCA — Country Verifying Certification Authority
- The root CA of the national Extended Access Control infrastructure. Unlike the CSCA it does not confirm document authenticity — it authorizes access to sensitive biometric data on the chip. It issues certificates to subordinate Document Verifiers, defines access rights for domestic and foreign DVs, and uses card-verifiable certificates of a special format rather than standard X.509. There is a single national CVCA.
- ICAO PKD — Public Key Directory
- A global repository where countries upload their CSCA certificates. Border services of all participating countries download these certificates to verify passports from any other country, without needing bilateral key exchange. Validation involves no exchange of personal data about the document holder — it is purely a check of the digital signature on the chip.
Chain of trust
- 1ICAO PKDThe global directory distributing CSCA certificates and Master Lists.
- 2CSCA certificateThe country root certificate, which signs…
- 3Document Signer certificate (CDS)The operational signing certificate, which signs…
- 4SOD on the chipThe Security Object Document, which contains…
- 5Data groups DG1–DG14The hashes of every data group written to the chip.
The reader reads the SOD from the chip, extracts the Document Signer certificate from it, compares that certificate with the Master List obtained from the ICAO PKD, and verifies the SOD signature with the public key from the certificate. If everything matches, the document is authentic.
For access to fingerprints and iris the second chain applies: the CVCA signs the Document Verifier certificate, which signs the Terminal Certificate, which the border terminal presents to the chip. The chip verifies the whole chain against the CVCA public key written into it, and only then grants access to DG3 and DG4.
Also in Data Preparation
The other IDMS components at this stage of the lifecycle.
