KYC: NFC

Server-side verification of the document chip

The app with the SDK reads the passport chip, and the verkyc server performs the cryptographic checks: the data signature, the chain to the country certificate and signs of cloning. The result does not depend on what the device reported.

What is checked

  • Chip reading

    PACE or BAC access in the SDK, reading of data groups DG1 and DG2 and service files, a separate check of chip access.

  • Data signature

    The SOD signature and data group hashes are verified on the server: a change of any byte of the data is detected.

  • Chain of trust

    The signer certificate is checked against the country CSCA certificate from an approved trust source, with validity periods and revocation lists.

  • Signs of cloning

    Active authentication and chip authentication show that the answer came from the original chip rather than a copy of its data.

Trust source and limitations

  • CSCA certificates are loaded from an approved source (Master List) and refreshed on a schedule; the trust store version is written to the report.
  • For documents of Kazakhstan a chain signed with SHA-1 is accepted with an explicit mark in the report.
  • For documents of Kyrgyzstan and Armenia chip reading is not performed at launch: NFC checks in the case are marked as not performed with the reason.
  • For Russian passports the current CSCA certificates signed with SHA-1 are not accepted, so trust in the issuer is not established.

NFC in the browser

Browsers do not give access to the document chip. On the verification page the applicant gets a code and continues in the mobile app with the SDK, and the result returns to the same case.

Frequently asked questions

Which phones are supported?

iPhone 7 and newer with iOS 15 or later, and Android 8.0 or later devices with an NFC module.

Why is the check done on the server?

A device can be compromised. The server verifies the signatures and the chain to the country certificate itself, so the result does not depend on the app response.

What if the chip cannot be read?

NFC checks get an outcome with a reason, and your policy sets what happens next: another attempt, a photo-based document check or manual review.

See it on your own scenarios

Tell us who you need to verify and where. We will prepare a demo, test API access and a price estimate.