Validate an eMRTD chip's Passive Authentication signature chain against the ICAO Public Key Directory (PKD) to establish issuer trust, not just internal signature consistency

domain: icao.int · 6 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. After reading the chip's Document Security Object (SOD) via NFC, extract the Document Signer Certificate (DSC) used to sign the SOD
  2. Fetch or maintain a synced copy of the issuing country's Country Signing CA (CSCA) certificates and Certificate Revocation Lists from the ICAO PKD
  3. Verify the DSC chains up to a trusted CSCA certificate for the document's issuing country, rather than accepting any internally-consistent signature
  4. Check the DSC and CSCA against current revocation lists to reject documents signed with a since-revoked certificate
  5. Recompute data group hashes from the chip and compare them to the hash values inside the signed SOD to detect any post-issuance tampering
  6. Reject or flag for manual review any document whose signer certificate cannot be chained to a known, non-revoked CSCA in the PKD

Known gotchas

Related routes

Verify an ePassport's NFC chip using Regula Document Reader's server-side re-verification to confirm eMRTD authenticity
docs.regulaforensics.com · 5 steps · unrated
Read and validate an NFC e-passport chip using ICAO 9303 standards and verify the MRZ
identity-general · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans