Skip to content

What reading an ePassport chip proves, and what it can't

Reading an ePassport chip can prove the data was signed by the issuing state and has not been altered, and with Active Authentication that the chip is not a copy. It cannot prove the person holding the passport is its owner; only a face match against the chip photo does that.

Charles Archibong

, Co-founder

· 5 min read

Headline "What a passport chip proves" beside an illustration of a passport booklet with a chip symbol and contactless waves, on a soft lavender gradient.

Key takeaways

  • Passive authentication proves the chip's data was signed by the issuing state and has not been changed.
  • Passive authentication alone does not stop an exact copy of a chip; Active Authentication addresses that.
  • An authentic, original chip can still be in the wrong hands, so match the live face to the chip photo.
  • A chip is only as trustworthy as the issuing country's certificate you check it against.

Reading an ePassport chip can prove two things no photograph of a passport can: that the personal data and portrait on the chip were digitally signed by the issuing state and have not been changed since, and, if the chip supports it, that the chip is the original rather than a copy. That is the strongest document evidence available anywhere a government database is out of reach.

It cannot prove that the person holding the passport is the person it was issued to. A genuine, original chip in a stolen passport passes every cryptographic check. Only a live face matched against the portrait stored on the chip connects the document to the applicant.

What is on the chip, and how does it get protected?

Modern passports, and some national ID cards, carry a contactless chip built to the International Civil Aviation Organization's standard, Doc 9303 (opens in a new tab). The chip holds the same details as the printed data page, a digital copy of the holder's portrait and, sometimes, extra details.

Three mechanisms from Doc 9303 Part 11 (opens in a new tab) (eighth edition, 2021) do most of the work:

Mechanism

What it does

What ICAO says it does not do

BAC or PACE (access control)

Opens the chip with a key derived from the printed machine-readable zone, and encrypts the conversation

Does not prevent an exact copy or chip substitution

Passive Authentication

Checks the chip's data against hashes signed by the issuing state

"Does not prevent exact copying of the contactless IC's content or chip substitution"

Active Authentication

The chip signs a fresh challenge with a private key it never reveals

Optional in the standard; not every chip has it

Part 11 states that at least one of BAC or PACE "SHALL be supported". It lists Active Authentication as optional, and credits it with proving that the data "has been read from the authentic contactless IC" and that the chip "has not been substituted".

What does passive authentication prove?

Passive authentication is the core check. The chip carries a security object: a list of hashes of every data group, signed by a Document Signer certificate, which is in turn issued by the country's signing authority (the CSCA). Verifying it proves the name, number, dates and portrait are exactly what the state wrote.

Two conditions make that proof real rather than decorative.

The signature must chain to a certificate you trust. The signer certificate travels inside the chip data the applicant submits. A signature that verifies against it proves only that some key signed the data. It proves the state signed it only if that certificate chains to the state's CSCA, which you obtain independently.

The check must run on your server. A phone app that reports "chip authentic" is making a claim, and an attacker controls the phone.

Myaza Trust Identity Verification runs passive authentication on the server and counts a chip as authentic only when its signer chains to a trusted issuing-state certificate. The list is built from certificate lists published by the German, Dutch and Italian governments and covers 138 countries, including Nigeria, Ghana, Kenya, Egypt, Ethiopia and Senegal. A chip from a country outside the list comes back inconclusive, and the verification falls back to the document and, where available, the government database. The NFC chip verification documentation keeps the current details.

Countries also cancel signing certificates, for example after a key is compromised. Not every country publishes a cancellation list, so the result says whether the signer's status was checked; a chip whose status is unknown is accepted by default, and a workflow rule can send it to review instead.

Why does copying matter?

Because passive authentication proves the data is genuine, not that the chip is. Someone with access to a real passport for a few seconds could, in principle, copy its chip data onto a blank chip. Every hash and signature would still verify.

Active Authentication closes that gap for chips that support it: the chip proves it holds the private key matching a public key the state signed. Myaza Trust reports how a copy was ruled out in a field called cloneCheck: active_auth (the chip answered a one-time challenge), face_bound (the chip has no such key, and the live selfie matched the chip portrait) or none. A chip reaches the top chip assurance level only when a copy is ruled out, and a chip that fails Active Authentication fails the verification outright as not_authentic.

What can't a chip prove?

These limits are worth stating plainly, because chip capabilities are often oversold.

  • That the holder is the owner. An original, authentic chip in a borrowed or stolen passport passes every chip check. Match a live selfie against the chip portrait.

  • That the passport is still valid for use. The chip tells you what the state wrote at issue. It does not tell you whether the passport has since been reported lost or stolen; that is a separate check against separate data.

  • Fingerprints or iris data. Data groups 3 and 4 sit behind Extended Access Control, and only government inspection systems holding the right certificates can read them. A vendor claiming to extract fingerprints from a passport chip for onboarding is claiming something the standard does not permit.

  • Anything, on some national ID cards. The South African smart ID, the Emirates ID and Malaysia's MyKad, among others, use proprietary chips that are not ICAO eMRTDs. They still verify by document capture; they cannot reach chip assurance.

  • Anything, in a browser. No browser API can talk to a passport chip. Myaza Trust reads chips in the React Native and Flutter SDKs only; web users who need chip assurance must be routed to a mobile app.

What happens when a chip cannot be read?

A lot of the time, it will not be. The phone may have no NFC radio, the user may hold the passport in the wrong place, or the passport may predate chips.

Design for that. In Myaza Trust a missing, unreadable or inconclusive chip never fails a verification; it simply does not contribute chip assurance, and the flow continues on the document and database checks. Only positive proof of tampering fails a verification. Workflows can let users skip the chip step manually, and phones without NFC skip it automatically.

An illustrative example: a remittance app onboards a Senegalese sender with a passport. On an NFC phone, the chip reads, authenticates against Senegal's certificate, answers the Active Authentication challenge, and the selfie matches the chip portrait: assurance level chip. The same sender on a phone without NFC verifies by document: assurance level document. The app gives both an account, and sets the first sender a higher limit.

A checklist for adding chip reading

  1. Offer it in a mobile flow; do not promise it on the web.

  2. Verify on the server, against issuing-state certificates, never on the device.

  3. Require a copy to be ruled out, by Active Authentication or a face match to the chip portrait, before treating the result as the highest tier.

  4. Always match the live face to the chip portrait.

  5. Never fail a customer for a chip that could not be read; fall back and adjust limits instead.

  6. Decide how to treat chips whose signer cancellation status is unknown.

Sources

Charles Archibong

About the author

Charles Archibong

Co-founder

Charles Archibong co-founded Myaza Trust. He writes about identity verification, financial technology, and the practical work of building trusted digital services.

  • Headline "Not every pass is equal" beside an illustration of three rising tiers, on a vivid purple gradient.

    Product Updates

    Not every pass is equal: using assurance levels in onboarding decisions

    A chip pass, a government database pass and a document-only pass are different strengths of evidence. Decide in advance what each tier may do, route on the tier together with the photo the face was matched against, and let customers move up a tier rather than failing them.

  • Headline "Don't trust the phone's verdict" beside an illustration of a shield with a check mark, on a soft lavender gradient.

    Identity Verification

    Why a liveness result from the phone is not enough

    A liveness result produced on the phone is a claim made by a device the attacker may control. Treat it as input, keep the recorded evidence, and re-check that evidence on the server before the result counts.

Build your product.We'll handle the rest.

Identity and compliance, end to end, built to global standards, priced for founders.

What NFC ePassport chip verification really proves · Myaza Trust