SECURING AND AUTHENTICATION OF A PERSONAL IDENTITY DOCUMENT

DE502022008467D1Active Publication Date: 2026-08-27OESTERR STAATSDRUCKEREI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE502022008467
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Filing Date
2022-07-15
Publication Date
2026-08-27
Estimated Expiration
2042-07-15

AI Technical Summary

Technical Problem

Current identity documents, particularly those with embedded chips, face limitations such as wear and tear, connectivity issues, and vulnerability to quantum attacks, making them insecure and difficult to update, while existing cryptographic methods are not post-quantum secure.

Method used

Implement a machine-readable graphic code, like a QR code, with a control code generated using different hash functions and a digital key, ensuring post-quantum security by combining multiple hash algorithms and Message Authentication Codes (MACs) to create a robust security layer that can be updated independently.

Benefits of technology

Provides a secure, post-quantum resistant identity verification method that maintains security even if one hash function is compromised, allowing for easy updates and reducing reliance on electronic components.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The invention relates to a method for securing a personal identity document, wherein the identity document is equipped with a machine-readable graphic code representing data content, the data content comprising user data and control data, the user data comprising at least one field content of the identity document, and a hash function being applied at least to the user data to determine a control code. The invention further relates to an identity document for proving the identity of a person, wherein the identity document has a machine-readable graphic code representing data content, the data content comprising user data and control data, the user data comprising at least one field content of the identity document.The control code is generated from the user data using a hash function; for example, a result of the hash function is calculated from the user data. In this context, an identity document is understood to be a physical document. The method of production of the physical document is irrelevant. It can be printed, laser-cut, stamped, or embossed, for example.

[0002] Machine-readable travel documents (MRTDs) used for international travel require a high level of protection. Currently, these documents are protected by multiple security features, both physical and digital. Many of these measures are internationally specified in ICAO 9303. These documents are established sovereign trust anchors for legal matters concerning identity, thereby enabling citizens to participate in public life, the free market, and international border crossings. Furthermore, the development of e-government and the ongoing digitalization of society increase the need for securely verifiable identity documents.

[0003] Classic physical security features, and those that are publicly known, include security threads, guilloche patterns, DOVIDs, etc. These features protect an identity document (e.g., a passport) against physical manipulation, duplication, or outright forgery. In addition, digital security measures using cryptographic signatures serve as a further safeguard for personal data and are an important feature for ensuring the authenticity and integrity of the document. In Austria and many other countries, the so-called chip passport was therefore introduced starting in 2006. The chip also has several security layers, such as cloning protection, access control, and other physical features.

[0004] The verification of the chip and the personal data it contains offers a comprehensive, secure, machine-assisted, and proven identity verification process that has become an international standard. Nevertheless, the use of the chip has disadvantages in terms of usage and limitations when writing and reading chip data: Reading chip data via NFC is prone to errors in establishing a connection and in the application itself – contact-based chip interfaces are subject to wear and tear. With mobile readers, maintaining the document's position during the reading process is not comparable to that of stationary scanners. Due to its physical properties, the chip has performance limitations when reading and writing. For the identity document to be readable, it requires both a functioning chip and an undamaged antenna.Deliberate damage is not easily detectable and / or verifiable. According to current assessments, the cryptographic algorithms used are not post-quantum secure, meaning they cannot be attacked with a future quantum computer. At the same time, the algorithms used in the chip are not easily replaceable once the documents are in the field. The selection and availability of possible algorithms may be limited by the chip architecture. Changing the chip technology (e.g., updating the chip's operating system) involves enormous effort.

[0005] To address these disadvantages and achieve independence from electronic technologies, security features that can be printed and embedded in the document are a viable option. One such feature is the aforementioned machine-readable graphic code, which represents data content. This data content comprises user data and control data, with the user data including at least one field of the identity document. To determine a control code, a hash function is applied to at least the user data. The machine-readable graphic code can be, for example, a printed or laser-engraved two-dimensional (2D) code, such as a QR code or a Data Matrix code. The machine-readable graphic code contains, among other things, personal data that allows for the unambiguous identification of a person.The user data, in particular the personal data it contains, can, analogous to the data on the chip, be sufficient to ensure the identity of the document holder.

[0006] The machine-readable graphical code can, for example, create a complementary security layer to a chip in the identity document. Should the chip or antenna be damaged or unreadable for other reasons, valid personal identification can be carried out using the machine-readable graphical code. Reading a graphical code by machine is not subject to the aforementioned limitations of a chip. Therefore, the graphical code—with suitable security features—is, at best, an additional trust anchor alongside a chip and the identity document itself.

[0007] Since future developments in the field of quantum computers already suggest that asymmetric cryptographic methods will only be secure with very large key spaces, and therefore necessarily larger image spaces, it is particularly useful for use in machine-readable graphical codes on identity documents, due to their relatively long validity period, to implement an alternative to these methods.

[0008] Currently, there are two methods that make cryptography vulnerable to attack with a quantum computer. Shor's algorithm specifically breaks elliptic curve cryptography and allows for the reverse engineering of the signature, using the public key together, to the secret key in a very short time compared to the processing time of an identity document. This would mean that an attacker could sign arbitrary data in a way that is indistinguishable from the document's creator. Grover's algorithm attacks existing hash functions and can find a hash collision (a second input value produces the same hash value). Grover's algorithm does not necessarily lead to an immediate "breaking" of the hash function, but primarily provides an increase in efficiency compared to classical "exhaustive search" algorithms. To protect against Grover's algorithm, it is sufficient to increase the hash function's image space. From today's perspective, a 512-bit image space is considered sufficiently secure.

[0009] Against this background, the technical field of the aforementioned method and identity document, in which the disclosed invention lies, must be understood.

[0010] One method for securing identity documents with a machine-readable graphic code, specifically barcodes, is described in US 10,931,461 B. However, in that case, the identity document itself is not equipped with a machine-readable graphic code; rather, the code belongs to a digital copy of the document that can be used with a mobile application. Furthermore, the code does not contain any field content from the identity document, but merely a reference to the aforementioned digital copy, which can then be retrieved from an external database.

[0011] WO 2020 / 245024 A1 demonstrates – though not specifically for identity documents, but for general documents – the use of a machine-readable graphical code to secure a physical document. A hash function is applied to different sections of the document, resulting in multiple hash values ​​that differ due to the various payloads. The combined hash values ​​form a control code, which is stored in a database for later verification.

[0012] In another technical field, the search for digital data, US Patent 8,171,004 B proposes concatenating multiple hash values ​​from different hash functions to harden the result against collisions. This publication contains no indication of an application in identity documents, let alone in combination with machine-readable graphic codes (such as barcodes or QR codes).

[0013] Also in a different technical field, the error-free transmission of information using blockchain technology, US 2021 / 0099309 A1 describes the use of multiple different hash values, either based on an alternately inverted payload or on different hash functions, to increase security against collisions. However, this publication also contains no reference to applying the described technical measures to the content of a machine-readable graphic code (such as barcodes or QR codes) for securing printed identity documents.

[0014] As has been shown, the two documents mentioned last, US 8,171,004 B and US 2021 / 0099309 A1, are each in different technical fields than this disclosure and therefore naturally concern entirely different tasks. Consequently, a person skilled in the art looking for ways to securely exchange physical identity documents could not have hoped to find a solution in either of these publications.

[0015] One objective of the invention is to enable the secure revocation and exchange of identity documents, for example, if a weakness in the hash function used for the control code becomes known. At no point should user data be exposed, particularly not during such an exchange. Furthermore, the invention aims to ensure the highest possible level of post-quantum security at all times.

[0016] The method according to the invention provides that the control data includes a digital key, and that the control code has at least two code sections, wherein different hash functions based on different hash algorithms are applied to the data content (i.e., the combination or entirety of payload and control data) to determine each of the two code sections. Thus, the same data (the same "payload") is hashed with different hash functions.

[0017] Similarly, the identity document according to the invention provides that the control data comprises at least one digital key, wherein the digital key is independent of the user data, and that the identity document is assigned a control code comprising at least two code segments, which were determined by means of different hash functions based on different mathematical algorithms and applied to the data content. In particular, the digital key is not derived from the user data. The digital key can, for example, be newly generated for each document using a cryptographic random number generator.

[0018] Using a different second hash algorithm for the second code section (the one on which the first code section is based) means that both security features avoid the known potential weaknesses of asymmetric cryptography. At the same time, this increases security compared to using only one hash algorithm. Should a new attack on one hash algorithm become known, the security of the other hash algorithms remains unaffected. For example, the now less secure hash algorithm can be replaced by a third, different hash algorithm. The security of the identity document would therefore only be compromised if, by chance, new attacks on both (or all) of the different hash algorithms used were discovered simultaneously.Thanks to this invention, a window of opportunity is effectively created to replace the broken hash function with another, unbroken one, both during production and the testing process. Furthermore, regardless of new attacks, the search for hash collisions is significantly hampered, going beyond the mere increase in the image size of a single hash algorithm.

[0019] In the described identity document, the image space of the digital key can correspond to the image space of at least one hash function used (or employed) to secure the identity document. A larger image space for the digital key could facilitate attacks on the hash function. However, to optimally fulfill its function, the image space should not be too small. Among other things, the digital key serves to prevent a deterministic relationship between the user data and each of the code segments. This prevents the user data and field contents of the identity document—typically personal and sensitive—from being deduced from the code segments, which may be publicly accessible.The size of the image space can also be used as a requirement for choosing the hash functions to be used, whereby the cardinal numbers of the image spaces of all chosen hash functions should be the same.

[0020] In addition to the size of the image space, ease of replacement and available information about post-quantum security can be considered relevant parameters for selecting hash functions. For example, hash functions from the NIST-standardized Secure Hash Algorithm 2 (SHA-2) or Secure Hash Algorithm 3 (SHA-3) groups can be used.

[0021] Optionally, each individual code segment can be determined using a Message Authentication Code (MAC) method. In particular, at least two (or all) code segments can be determined using different MAC methods. Since the payload of an identity document can contain highly sensitive personal data, it should not be possible for an attacker to reverse-engineer or deduce the payload, even with broken hash functions. Message Authentication Codes inherently provide this protection because they are specifically designed for use with a digital key.

[0022] For example, in the disclosed method, at least one of the two code segments can be determined as a Keyed-Hash Message Authentication Code (HMAC). Similarly, in the disclosed identity document, at least one of the two code segments can be, for example, a Keyed-Hash Message Authentication Code (HMAC). HMAC is specified in RFC 2104 "HMAC: Keyed-Hashing for Message Authentication" of the Internet Engineering Task Force (IETF) and FIPS 198 "The Keyed-Hash Message Authentication Code (HMAC)" of the National Institute of Standards and Technology (NIST). If more than one code segment is determined as an HMAC, different HMACs, i.e., based on different hash functions, would be used.

[0023] Alternatively or additionally, within the disclosed method, at least one of the two code segments can be determined, for example, as a KECCAK Message Authentication Code (KMAC), or, within the disclosed identity document, can be a KECCAK Message Authentication Code (KMAC). KMAC is specified in NIST SP800-185 "SHA-3 Derived Functions: cSHAKE, KMAC, TupleHash, and ParallelHash". For clarity, KMAC is referred to as the second MAC algorithm in the following text.

[0024] In an application example, a data block can be created that includes the control code (with at least two code segments) and stored in a database. The database can then be used to verify the secured identity document. For this purpose, the database is operated by a trusted provider and is accessible to interested or authorized parties.

[0025] Additionally, the data blocks stored in the database can be concatenated using hash values. This has the advantage that a verifying authority only needs to trust that an authentic data block was stored at the time of creation. Since all subsequent data blocks are based on this, subsequent manipulation of one or more of the data blocks is practically impossible. For concatenation, analogous to the control code, at least two different hash functions can be applied to the (to be stored) control code and a reference to the preceding data block. A reference containing the results of both hash functions is then included in the new data block—along with at least the control code to be stored.

[0026] In this context, the database can, for example, be a central register, and saving the data block can involve uploading the data block to the central register via a computer network.

[0027] In general, the control data in the above-described procedure or identity document can optionally include at least one cryptographic signature of the issuer of the identity document. This signature is generated, for example, from the user data. This cryptographic signature is a supplementary security feature. The control code fulfills its security function independently of any additional cryptographic signature. Therefore, the cryptographic signature can generally be omitted, for example, to reduce the amount of control data. The amount of data is relevant, for example, for graphical representation (e.g., as a 1D or 2D barcode), whereby smaller data sets can be represented graphically more easily and robustly.

[0028] The use of a cryptographic signature (or digital signature) is similar to authentication using an electronic chip embedded in the identity document. For example, a digital signature via the Elliptic Curve Digital Signature Algorithm (ECDSA) can be used. The underlying certificates can be derived from a public key infrastructure (PKI) and have expiration dates for regular renewal. Even though Elliptic Curve Cryptography (ECC) is not, according to current knowledge, "post-quantum secure" without modifications (as discussed in the introduction), it can be advantageous to include such security features as an additional layer of protection for documents alongside the control code described above. In particular, the fundamentally different algorithm improves resilience, simply due to its redundancy.

[0029] According to a specific application example of the procedure or identity document described above, the user data can contain image data of a portrait of a person identified by the identity document. The security properties of the control code used and its code segments can thus be extended to the portrait, which is a crucial and often the only feature for the visual authentication of a person identified by the identity document. This allows the security of this function of the identity document to be improved accordingly through the measures described above.

[0030] The invention will be explained in more detail below with reference to a particularly preferred embodiment, to which it is not limited, and with reference to the drawings. The drawings show in detail: Fig. 1schematically, an identity document with a machine-readable graphic code; Fig. 2 schematically a system with three identity documents according to Fig. 1 , each represented as data content of the machine-readable graphical code, and with a central database containing data blocks associated with the identity documents; and Fig. 3 schematically a data block according to Fig. 2 .

[0031] Fig. 1 Figure 1 schematically shows an identity document 1 for proving a person's identity. The identity document 1 features a portrait 2 of the person identified by the identity document, several data fields 3-7 containing personal data of this person, and a machine-readable graphic code 9 in the form of a QR code 10. The QR code 10 represents a data content 11 (see Figure 10). Fig. 2 ) in a machine-readable form. The data content 11 comprises user data 12 and control data 13.

[0032] The payload 12 includes, for example, the field content of the fields "Document Type" 3, "Number" 4, "Last Name" 5 and "First Name" 6 (summarized as the so-called Machine Readable ZONE, "MRZ" 14) as well as the image data 15 of the portrait 2. The field content of the field "Date of Birth" 7 is not part of the payload 12 in this example. Other possible field contents are, for example, the gender of the identified person, a validity date of the identity document and a signature ID.

[0033] The signature ID serves to identify the type of document (e.g., identity card or passport), the document version (generation n identity cards may contain different security features than generation n+1), and the signature method used.

[0034] The Machine Readable Zone (MRZ), according to ICAO guidelines, summarizes all important data of the document or document owner. Standardization allows the MRZ to be read by machines worldwide; however, the MRZ is not represented as a graphical code, but as an alphanumeric text field.

[0035] The document owner's name may contain more information than is displayed in the MRZ (Multiple Reference Number). Long names can be truncated in the MRZ; furthermore, titles are not included in the MRZ, and special characters (e.g., letters with diacritics) are transliterated. By including the name in the QR code's data content, this information can be presented to the user of the scanning application in a clear and accurate manner. For example, user accounts can be created quickly, and the document owner's name is correctly entered. Depending on the application and (language) region, a wide variety of characters can be encoded. The more different characters that need to be supported, the closer the encoding must be to UTF-8; however, this increases the required file size. A trade-off may be necessary between the image quality of the portrait image data and the display of special characters (e.g., a smaller image for special characters in the name).

[0036] The image of the document holder (e.g. formatted as base64) is located in the data content 11 of the QR code 10 to enable a link between the document holder (who is standing in front of you), the image in the identity document (which is protected with classic security features) and the image in the QR code (which can be displayed to the verifier e.g. in an application).

[0037] The control data includes a digital key (also called an "initial vector," "IV") 16, which is independent of the user data as well as of field contents not included in the user data. The image space of the digital key 16 corresponds to the image space of each of the hash functions used to secure the identity document 1 and to determine a control code 18. In addition to the digital key 16, the control data includes a cryptographic signature 17 from an issuer of the identity document regarding the user data 12 and the digital key 16. Furthermore, the control data may also include, for example, a checksum and an identification of a signature certificate.

[0038] Until the post-quantum era, the data content of the QR code can be sealed with a classical signature. With the use of quantum computing, the signature can be omitted, and the QR code's authenticity can be verified using the address and a central address database. By retaining the signature in the barcode until it is superseded by the address method, backward compatibility with existing verification processes (using asymmetric methods) is ensured.

[0039] Fig. 2 schematically shows a system 19 comprising three identity documents 1, 20, 21 according to Fig. 1 and a database 22. The identity documents 1, 20, 21 are here through the one related to Fig. 1 The described data content 11 of their respective QR code 10 represents the data content. The database 22 stores, among other things, three data blocks 23, 24, 25 assigned to the displayed identity documents 1, 20, 21 (in Fig. 2(One row corresponds to one data block). Database 22 can, for example, be designed as a permissioned public (or private) ledger (possibly also distributed).

[0040] How more precisely in Fig. 3 As shown, each data block 23-25 ​​comprises a control code 18 ("address A_i") and a reference 26 ("H_i") to which the subsequent data block refers. The data blocks are thus linked via the references 26, but not via the control codes 18. In this example, the control codes 18 consist of two code segments 27 and 28. The two code segments 27 and 28 were determined using different hash functions based on different hash algorithms. For this purpose, the relevant hash functions were applied to the... Fig. 2The data content 11 of the identity document 1, 20, and 21 associated with the data block was applied, and the results, i.e., the two resulting hash values, were concatenated. The concatenation of the at least two code segments for the control code is also referred to as the "address." This expresses that the identity document can be uniquely identified using this address. The references 26 were also determined using two different hash functions, the results of which 29 and 30 were concatenated. The hash functions were applied to a concatenation of the control code 18 of the same data block and the reference 26 of the preceding data block (i.e., control code and reference).The data block 24 assigned to document 1 with the (virtual) counter n in database 22 thus contains the control code 18 determined from the data content 11 of document 1 in the form of the address A_n and the reference H_n, which was determined from hashes of the combination of A_n with the reference H_n-1 of the preceding data block 23. The counter and the reference of the preceding data block are in . Fig. 2 The dotted lines indicate that these columns are not, or at least not necessarily, part of the data blocks and therefore of database 22.

[0041] The following section explains in more detail the procedure for securing a personal identity document 1, according to which System 19 in Fig. 2was created and is being expanded. As part of this process, identity documents 1 are equipped with machine-readable graphic codes 9, in this example QR codes 10, and the corresponding data blocks 23-25 ​​are stored in the database 22.

[0042] To create the QR codes 10, the desired data content 11 is first entered. This includes the user data 12 and control data 13 already described above. That is, the field contents of the relevant fields of the identity document 1 (e.g., in the form of the MRZ 14, in ASCII format, whereby the name can be used in UTF-8 format) and the image data 15 of the portrait (in binary format) are entered, and a digital key 16 is generated. The digital key 16 is randomly generated and is unique for each identity document. The digital key is embedded in the QR code in base64 format. Optionally, the cryptographic signature 17 and possibly an associated certificate identifier can also be included with the data content 11. The QR code 10 is generated from this data content 11 and applied to the identity document 1, e.g., by printing or laser engraving.

[0043] The data size relevant for creating the QR code 10 can be composed as follows, for example: Data content Data size in bytes Control data: signature 184 Key 64 Usage data: Certificate ID 16 MRZ 123 Full name 120 Facial image 1413 sum 1800

[0044] The data size specifications refer to base64 encoding.

[0045] In parallel, the same data content 11 is hashed using two different hash functions based on different hash algorithms. Specifically, a Keyed-Hash Message Authentication Code (HMAC) is generated from the data content 11. The HMAC forms the first code segment 27 of the control code 31 assigned to the new identity document 1. Additionally, a KECCAK Message Authentication Code (KMAC) is generated from the data content 11. The KMAC forms the second code segment 28 of the control code 31 assigned to this identity document 1. In generating the HMAC and the KMAC, the same digital key 16 is used as the "secret key" K, and the same remaining data content 11 is used as the "message" m.The underlying hash functions H are hash functions with a matching image space of 512 bits, namely the SHA2-512 hash function for HMAC and the SHA3-512 hash function for KMAC (if HMAC is also used for the second part, the hash function used can also be SHA3-512). The two code sections 27 and 28, HMAC and KMAC, are then concatenated to form the new control code 31.

[0046] To create a new data block 32 in database 22, a new cryptographic reference 33 is created in addition to the new control code 31. Like the existing references 26, the new reference 33 consists of two concatenated hash values ​​29 and 30. These two hash values ​​29 and 30 are determined by applying two different hash functions to the new control code 31 and the last existing reference 26 in database 22 (i.e., the last added data block) as the "message" m. Specifically, the hash functions SHA2-512 and SHA3-512 are used in this example.

[0047] Subsequently, a new data block 32 is created using the newly determined address (i.e., the new control code 31) and the newly determined reference 33. This block is then uploaded to and stored in database 22, which serves as a central register, via a computer network. This new data block 32 is now the last data block in database 22. To ensure the verifiability of the data blocks in database 22, database 22 optionally also stores the order of the data blocks, for example, in the form of a counter 34. Database 22 accepts new data blocks only from authenticated and appropriately authorized participants, such as the authority responsible for issuing identity documents.

[0048] To initialize the chaining, a predefined constant "previous" reference ("H_genesis") 35 is used to determine the reference 26 of the first data block.

[0049] For the authentication of a personal identity document 1 according to Fig. 1 For example, the following steps are carried out during an identity check: Reading and determining a data content 11 of the QR code 10; calculating HMAC and KMAC based on the transmitted data content 11 analogous to the procedure described for issuing identity cards; establishing a connection to the database 22 and sending a query to search for a data block whose control code 18 matches the determined control code; confirming the authenticity of the identity document 1 if a corresponding data block is found.

Claims

1. Method for securing a personal identity document (1), wherein the identity document (1) is provided with a machine-readable graphic code (9) that represents a data content (11), wherein the data content (11) comprises payload data (12) and control data (13), wherein the payload data (12) comprises at least one field content of the identity document (1), wherein a hash function is applied at least to the payload data (12) for determining a control code (18), characterized in that the control data (13) comprises a digital key (16), and that the control code (18) has at least two code sections (27, 28), wherein for determining the two code sections (27, 28) respectively different hash functions based on different mathematical algorithms are applied to the data content (11).

2. Method according to claim 1, characterized in that at least one of the code sections (27, 28) is determined as a Keyed-Hash Message Authentication Code.

3. Method according to claim 1 or 2, characterized in that at least one of the two code sections (27, 28) is determined as a KECCAK Message Authentication Code.

4. Method according to any one of claims 1 to 3, characterized in that a data block (31) comprising the control code (18) is created and the data block (31) is stored in a database (22).

5. Method according to claim 4, characterized in that the data blocks (23, 24, 25) stored in the database (22) are chained to one another by utilizing hash values.

6. Method according to claim 4 or 5, characterized in that the database (22) is a central register and the storing of the data block (31) comprises an uploading of the data block (31) via a computer network into the central register.

7. Method according to any one of claims 1 to 6, characterized in that the control data (13) comprises at least one cryptographic signature (17) of an issuer of the identity document (1).

8. Method according to any one of claims 1 to 7, characterized in that the payload data (12) contains image data (15) of a portrait of a person identified by the identity document (1).

9. Identity document (1) for proving the identity of a person, wherein the identity document (1) has a machine-readable graphic code (9) that represents a data content (11), wherein the data content (11) comprises payload data (12) and control data (13), wherein the payload data (12) comprises at least one field content of the identity document (1), characterized in that the control data (13) comprises at least one digital key (16), wherein the digital key (16) is independent of the payload data (12), and that the identity document (1) is assigned a control code (18) that has at least two code sections (27, 28), which were determined by means of respectively different hash functions based on different mathematical algorithms and applied to the data content (11).

10. Identity document (1) according to claim 9, characterized in that the image space of the digital key (16) corresponds to the image space of at least one hash function usable for securing the identity document (1).

11. Identity document (1) according to any one of claims 9 to 10, characterized in that the control data (13) comprises at least one cryptographic signature (17) of an issuer of the identity document (1).

12. Identity document (1) according to any one of claims 9 to 11, characterized in that the payload data (12) contains image data (15) of a portrait of a person identified by the identity document (1).

13. System (19) comprising at least one identity document (1) according to any one of claims 9 to 12 and a database (22), wherein the database (22) stores a data block (24) assigned to the at least one identity document (1), wherein the data block (24) comprises the control code (18).

14. System (19) according to claim 13, characterized in that the data blocks (24, 25, 26) stored in the database (22) are chained to one another by utilizing hash values.

15. Method for authenticating a personal identity document (1), the method comprising the steps: - Reading out and determining a data content (11) of a machine-readable graphic code (9) of the identity document (1), wherein the data content (11) comprises payload data (12) and control data (13), wherein the payload data (12) comprises at least one field content of the identity document (1) and wherein the control data (13) comprises a digital key (16); - Determining a control code (18) with at least two code sections (27, 28), wherein for determining the two code sections (27, 28) respectively different hash functions based on different hash algorithms are applied to the data content (11); - Establishing the existence of the determined control code (18) in a database (22); - Confirming the authenticity of the identity document (1) on the basis of the established existence.