IDMETRIX
← Secure Identity
Stage 5 · Verification

IDmetrix® Document Verifier (DV)

Decides which border terminals may read fingerprints and iris — and proves it to the chip.

The Document Verifier manages the Extended Access Control infrastructure: it issues certificates to inspection systems, enables Terminal Authentication, and controls access to the sensitive data groups — DG3 fingerprints and DG4 iris. It is the middle level of the EAC chain, between the national CVCA root and the reader at the desk.

Access rights enforced by the chip itself
Capabilities

Key functions

DV certificate issuance
Generation and signing of DV certificates for organizations — police, border service, immigration, consulates — with the access rights each is granted.
Terminal certificate issuance
Issuance of Terminal Certificates to specific inspection systems, based on the DV certificate.
CVCA link certificate management
Signing and distribution of CVCA Link Certificates for mutual recognition between countries, so country A’s terminals can read country B’s passports.
Certificate revocation
Revocation of compromised DV and Terminal certificates through CRL or OCSP.
Policy enforcement
Which organizations have rights to which data, in which jurisdictions, for how long — privacy and national rules applied as certificate policy.
HSM integration
DV private key storage in an HSM at FIPS 140-2/3 Level 3, with certificate signing performed without key export.
Bilateral agreement management
Managing which DVs of which countries trust each other, through cross-certification.
Terminal enrollment
Terminal registration binding a Terminal Certificate to a specific device by serial number and public key.
Audit and logging
All certificate issuance, revocation and use logged for regulatory compliance.
Sequence

How Terminal Authentication works

  1. 1Certificate chain presentationThe terminal sends the chain to the chip: CVCA Link Certificate, DV Certificate, Terminal Certificate.
  2. 2Certificate validationThe chip verifies the CVCA Link Certificate against the CVCA public key written into EF.DG14, then the DV and Terminal certificates in turn.
  3. 3Challenge-responseThe chip generates a random challenge and the terminal signs it with its private key.
  4. 4Access grantOnly after successful authentication does the chip grant access to the data its certificate rights allow — DG3, or DG4, or neither.
In practice

The Document Verifier at the border

Where the DV sits in an ordinary passport check, from the day the book was issued to the moment the traveller’s fingerprint is compared against the chip.

  1. 1EnrolmentThe applicant is issued a passport whose chip carries the issuing country’s CVCA public key, written in at personalization as the trust anchor everything later is measured against.
  2. 2Border controlThe inspection terminal works through the chip in order:BAC / PACEBasic access to the chip, from a session key derived from the printed data page.Passive AuthenticationThe SOD signature written by the Document Signer is checked against the Master List.Chip AuthenticationThe chip proves it holds its own private key, ruling out a copy of the data on a blank chip.Terminal AuthenticationWhere the DV comes in. The terminal presents the certificates the DV issued it; the chip verifies the chain back to its own CVCA and releases DG3 and DG4 as far as those certificates allow.
  3. 3Biometric matchThe fingerprint, face or iris captured at the desk is compared against the sample the chip has just released from DG3 or DG4.
Keep reading

Where this fits

This is the only IDMS component at this stage — the rest of the picture is here.