eMRTD Creator is a complete hardware and software toolkit for teams developing, testing and debugging systems that read electronic Machine Readable Travel Documents (eMRTDs), including ePassports and ICAO-compatible electronic identity documents.
The toolkit combines the eMRTD Creator desktop application with a specially licensed NFC device running dedicated eMRTD emulation firmware. Together, they provide a configurable alternative to fixed physical specimen documents and a direct view of the protocol exchange from the document’s point of view.
Create controlled ICAO Doc 9303 LDS1 test configurations, present them to the reader through the supplied NFC emulation device, and inspect the complete document-side communication in real time.
Replace scarce physical specimens with configurable test documents
National issuing authorities produce specimen travel and identity documents in small numbers. Obtaining the specimen required for a project can be complex, take weeks or months, and sometimes be impossible.
Real passports do not solve the testing problem. They are personal documents, limited in variety and impractical for systematic test coverage. Each physical passport or specimen provides one identity, one photograph, one set of keys, one certificate configuration and one fixed combination of document data and protocol options.
With eMRTD Creator, teams can prepare or change a controlled test configuration in minutes rather than wait weeks or months for another physical specimen. Data, photographs, Machine Readable Zone (MRZ) content, Data Groups, test keys, certificates and protocol options can be adapted, saved and reproduced as the test plan changes.
Create. Emulate. Inspect.
1. Create the test document
Use the desktop application to configure an ICAO Doc 9303 Logical Data Structure 1 (LDS1) test document.
The application supports TD1, TD2 and TD3 document formats, including their corresponding MRZ structures. Configure biographical and document data, JPEG or JPEG 2000 holder photographs, the signed security object (SOD), and the complete standard Data Group range from DG1 through DG16.
All supported encodings and data structures within each Data Group are configurable. This allows a test configuration to represent the exact valid, unusual or boundary condition required by the test plan.
2. Present it through the reader’s normal NFC path
Connect the supplied NFC emulation device to the host computer over USB and select it in the eMRTD Creator desktop application. The device presents the configured test document to the system under test over NFC.
The target uses its existing electronic-document interface; no eMRTD Creator library, runtime or product-specific integration is required.
The desktop application must remain active and connected throughout emulation. The NFC emulator does not operate as a standalone eMRTD emulator without the application.
3. Inspect the document-side exchange
The desktop application automatically records every emulation session. It captures timestamped raw protocol traffic, including every command and response Application Protocol Data Unit (APDU), from the document’s point of view.
Developers can see which command reached the document, how it was processed and where an unsuccessful exchange stopped. One-click export saves the complete NFC conversation for analysis and reproducible issue reports.

Build repeatable positive, negative and edge-case tests
Negative test cases are nearly impossible to obtain as controlled physical documents. eMRTD Creator enables teams to create repeatable scenarios that exercise both expected behavior and failure handling.
Test configurations can include:
- valid reference documents for functional and regression testing
- mismatched or deliberately incorrect test keys
- unusual and boundary-value document formats
- uncommon combinations of LDS1 Data Groups
- controlled variations of identity data, credentials, certificates and protocol options
- repeatable failure conditions for integration and error-handling tests
Full protocol coverage on the document side
eMRTD Creator provides full protocol coverage on the document side for the supported eMRTD profiles listed below. It is designed for testing implementations based on ICAO Doc 9303 and BSI TR-03110.
- Basic Access Control (BAC): test MRZ-derived access and inspect protected-session establishment.
- Password Authenticated Connection Establishment (PACE): configure supported scenarios using MRZ, Card Access Number (CAN), Personal Identification Number (PIN) and Personal Unblocking Key (PUK) credentials.
- Secure Messaging: verify the reader’s handling of authentication and integrity protection, including CMAC- and Retail MAC-protected commands and responses.
- Active Authentication (AA): generate document-specific test keys and test the reader’s authentication workflow.
- Chip Authentication (CA): test the reader’s handling of document-specific Chip Authentication key material.
- Terminal Authentication and Extended Access Control (EAC): create and test the required keys, certificates and protocol structures. The toolkit validates the complete Country Verifying Certification Authority (CVCA), Document Verifier (DV) and Terminal certificate chain.
For the exact protocol versions, cipher suites, algorithms, key sizes and parameter sets, refer to the eMRTD Creator technical specification.
Test PKI and document security
The desktop application creates the test Public Key Infrastructure (PKI) material required by the scenario: test Country Signing Certification Authority (CSCA) and Document Signer certificates and keys; RSA, RSA-PSS and ECDSA material for applicable roles; Active Authentication and Chip Authentication keys; Terminal Authentication and EAC structures with complete CVCA–DV–Terminal chain validation; and signed security objects.
All generated material uses user-controlled test data, test keys and test certificates. It is not issued by a national authority and does not belong to a production national trust chain.
Debug the secure channel from the document side
Secure-channel establishment is often one of the most time-consuming parts of an eMRTD reader integration. A problem may occur during BAC or PACE session setup, Secure Messaging, MAC verification, Chip Authentication or Terminal Authentication.
Reader applications often report only the final error. eMRTD Creator exposes the complete document-side raw traffic for supported protocols, every command and response APDU, and the point at which communication stopped. This helps teams distinguish credential, certificate, protocol-state and message-protection errors and can save days of debugging time.
Exported logs can be attached to bug reports, shared with another team or retained with the test configuration for regression testing.
Test through the target’s real NFC interface
Software-only simulations can test application logic, but they do not exercise the NFC interface used by the finished reader. eMRTD Creator presents the configured document through a physical NFC emulation device, allowing the reader hardware and document-reading software to be tested together.
The host computer running eMRTD Creator can be a supported Windows system or a supported Mac with Apple Silicon (M1 or later).
The system under test is independent of the host platform. It can be an Android or iOS application, a Windows or Linux workstation, a border terminal, eGate or kiosk, an embedded Linux or RTOS device, or a bare-metal microcontroller design. The target only needs a compatible NFC interface and support for the eMRTD profiles being tested.
• Android • iOS • Windows • Linux
• Embedded RTOS • Bare-metal MCU

Built for document-reading teams
- ePassport and eID reader developers: integrate and debug inspection systems, eGates, airline systems and identity-based access-control readers.
- Mobile identity teams: test Android and iOS passport-reading, KYC and identity-verification applications through the device’s normal NFC path.
- Embedded-system teams: exercise readers running Linux, an RTOS or bare-metal firmware without adding an emulator library to the target.
- QA and regression teams: build repeatable positive, negative and edge-case configurations and reproduce reported issues.
- Pre-certification and compliance teams: prepare and debug implementations based on supported ICAO Doc 9303 and BSI TR-03110 structures before formal testing.
- Security researchers and trainers: observe and demonstrate eMRTD protocol behavior with controlled data and non-production credentials.
eMRTD Creator supports pre-certification engineering work but does not replace formal certification or an accredited RF conformance system.
eMRTD Creator package overview
| Desktop application | Self-contained application for Windows and macOS on Apple Silicon (M1 or later) |
|---|---|
| Emulation device | µFR Zero CS with dedicated eMRTD emulation firmware |
| License | Software license bound to the supplied µFR Zero CS device |
| USB connection | USB CDC virtual COM port using the supplied USB-A to USB-C cable |
| Device power | Fully USB-powered; no battery or external power supply required |
Designed for authorized development and testing
eMRTD Creator is purpose-built for authorized development, QA, pre-certification preparation, security research and training. It uses user-controlled, non-production test data, keys and certificates to create repeatable eMRTD test scenarios.
The toolkit does not create genuine travel or identity documents, reproduce national production credentials, or generate documents signed by a national issuing authority. It is designed specifically for eMRTD testing—not for payment, transport, access-control cards, arbitrary NFC tags or general-purpose NFC emulation.
eMRTD Creator focuses on application- and protocol-level testing. It supports preparation for formal testing but does not replace certification, analog RF measurement equipment or accredited conformance testing.
Turn an authentication failure into a reproducible test case
Configure the required document, present it through the target’s normal NFC path, inspect the complete document-side exchange, and save the configuration and raw session log for the next test run.

