Extended Access Control (EAC)

Extended Access Control is the mechanism that keeps the most sensitive biometric data on an ePassport chip — fingerprints and iris images — away from any reader that cannot cryptographically prove it is authorized to see it. It is a mutual authentication scheme built on public key infrastructure, and it combines two protocols working in sequence.

Protects DG3 (fingerprints) and DG4 (iris images)
Two components Chip Authentication and Terminal Authentication
Specified in BSI TR-03110
Mandated by The European Union for second-generation ePassports
Trust model Public key infrastructure with country-issued terminal certificates
Terminal type Extended Inspection System
Does not protect DG1 and DG2 — the MRZ data and facial image

Why a second layer was needed

Basic Access Control and its successor PACE solve one problem: they stop a chip responding to a reader that does not physically hold the document. That is enough for the data already printed on the page — name, date of birth, document number — and for the facial photograph, which is visible to anyone looking at the passport anyway.

Fingerprints and iris images are different. They are not printed, not visible, and not revocable. If they leak, the holder cannot be issued new fingerprints. Possession of the document was judged insufficient justification for releasing them.

EAC raises the bar from “I am holding this passport” to “I am a border authority that a government has authorized, and I can prove it cryptographically.”

How the two halves work together

Chip Authentication runs first. The chip proves it holds a private key that never left the hardware, and the exchange produces session keys that encrypt everything afterward.

Terminal Authentication runs second. The reader presents a certificate chain proving a recognized authority granted it permission to request restricted data groups. Only then will the chip release DG3 or DG4.

The order matters. Chip Authentication establishes the secure channel first, so the terminal’s credentials and the biometric data that follows are never exposed in the clear.

Why EAC matters for identity verification

For most commercial verification, the practical consequence of EAC is a boundary: there is data on the chip you are not going to get, and the design intends it that way.

A bank onboarding a customer, a marketplace verifying a seller, a rental platform checking a driver — none of these will hold the terminal certificates required to read fingerprints. They will read DG1 and DG2, which is what identity document verification actually needs: the biographic data and a signed facial image to match a live selfie against.

That is not a limitation to work around. The facial image in DG2 is signed by the issuing state, which makes it a far stronger reference for biometric matching than a photograph lifted from the printed page. EAC simply marks where commercial access reasonably stops.

What EAC can’t do

It does not protect the basic data. DG1 and DG2 are outside its scope, secured by BAC or PACE instead. EAC is specifically about the restricted groups.

It depends on certificate management. The security rests on a PKI with expiring certificates distributed between countries. Operational failures in that chain, not cryptographic weaknesses, are the realistic risk.

Adoption is uneven. EAC is a European requirement. Many countries issue ePassports with no fingerprint data at all, in which case there is nothing for EAC to protect.

It authorizes readers, not people. A certified terminal in the wrong hands is still a certified terminal. EAC constrains which systems can ask, not who is operating them.

Frequently asked questions

What data does EAC protect?

Data group 3 and data group 4 on an ePassport chip — fingerprints and iris images. The MRZ data in DG1 and the facial image in DG2 are protected by Basic Access Control or PACE instead, not by EAC.

Can a private company read fingerprint data from a passport?

In practice, no. Reading DG3 requires terminal certificates issued through a government-controlled public key infrastructure, and those are granted to border and inspection authorities rather than commercial operators.

What are the two parts of EAC?

Chip Authentication, in which the chip proves it holds a private key that never left the hardware and establishes session encryption, and Terminal Authentication, in which the reader proves through a certificate chain that it is authorized to request restricted data.

Is EAC used outside Europe?

It originated as a European Union requirement and is specified in BSI TR-03110. Adoption elsewhere varies, and many countries issue ePassports containing no fingerprint or iris data, which removes the need for it entirely.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.