KeyOne ePassport Management

Safelayer’s ePassport PKI is a complete set of components that are part of the KeyOne product family. It supports implementing the public key infrastructure (PKI) related standards for electronic passports to ensure interoperability in the identification of people at border controls.

The International Civil Aviation Organization (ICAO) created an international standard for the first generation of ePassports that uses an RFID chip containing personal data together with simple biometric data. This standard, known as Basic Access Control (BAC), entails using digital signatures on the personal data to support the detection of cloned and modified ePassports.

This solution comprises the following entities:

  • The Country Signing Certification Authority (CSCA) which manages digital certificates of the national Document Signers (DS) and publication in the Public Key Directory (ICAO PKD)
  • The Document Signers (DS) which sign digitalized data on ePassport chip (Signed Object Document)
  • The National Public Key Directory (N-PKD) which replicates and complements ICAO PKD data at the national level

In addition, the Brussels Interoperability Group (BIG) is carrying out the coordination and standardization effort between the countries adopting the Extended Access Control (EAC) standard for the second generation of ePassports. These ePassports provide stronger security mechanisms against the fraudulent use of the personal identity information stored on the ePassport chip.

This solution comprises the following entities:

  • The Country Verifying Certification Authority (CVCA) which issues Card Verifiable (CV) certificates to the Document Verifiers (DV)
  • The Document Verifier (DV) which acts as a subordinate CA that issues CV certificates to the  national Inspection Systems (IS)
  • The Single Point of Contact (SPOC) which controls which domestic and foreign Document Verifiers can access the ePassport biometric information

(*) KeyOne CSCA/CVCA/DV v4.0 is in certification process to achieve CC EAL4+ (ALC_FLR.2).

For more information see:


Registering a foreign country in an e-Passport validation system.

Processing ICAO certificates with KeyOne e-Passport National PKD