From Yellow Card to Cryptographic Proof

The paper-based International Certificate of Vaccination or Prophylaxis – the Yellow Card – long provided a portable record of vaccination, but its handwritten entries, stamps and signatures provided little resistance to alteration or counterfeiting.

In this technical feature we will review the progress made to move the health status paper certificate to a cryptographically verifiable 2D barcode.

The Yellow Card (source: CDC Yellow Book, public domain).

The COVID years

COVID-19 changed vaccination certification from a public-health record into a cross-border identity and trust problem. Governments needed to prove vaccination, test and recovery status at scale, often before common standards or international governance existed. National schemes therefore developed rapidly and unevenly, with bilateral recognition agreements used to make one country’s certificate acceptable in another 1.

Technically, the major change was the adoption of digitally signed health credentials. WHO’s 2021 DDCC:VS guidance defined a structured, software-agnostic model for recording vaccination events using HL7 FHIR data, digital signatures, health certificate identifiers and national trust architectures. It also required paper alternatives to reduce digital exclusion and made clear that a vaccination certificate was not itself an identity document 2.

ICAO addressed the issue for air travel through the Visible Digital Seal for Non-Constrained Environments. VDS-NC encoded essential health data, issuer information and a cryptographic signature within a 2D barcode readable from paper or a mobile screen. Verification systems could then use trusted public keys to confirm origin and detect alteration, even when inspected offline. Some travel systems strengthened the process through airline pre-travel identity checks.

These developments improved authenticity and interoperability, but they did not remove the need to bind the certificate to its bearer.

This was achieved through a combination of identity proofing at issuance and inspection against an identity document.

WHO’s DDCC:VS model assumed that the vaccinated person had first proved their identity under the issuing state’s rules. The certificate then carried identifying attributes – typically name and date of birth – within the digitally signed and encoded vaccination data. WHO member states could add a passport or national identity number where stronger binding was required.

At verification, the 2D barcode shifted the certificate from a handwritten claim to a signed data object. As Xiu-Ding Chen explains in ‘The Rise and Rise of the Barcode’ (IDN June 2026), the newer model is no longer a barcode that merely points to a database record; rather the code can carry the relevant health or identity attributes together with a tamper-evident issuer signature.

A scanner can then use the issuer’s published verification key to confirm who issued the certificate and whether the encoded data has been changed, even where the relying party has no live connection to the issuing health database.

This establishes data authenticity but not person verification. A copied barcode may still scan successfully, so the verification process must bind the signed data to the presenter. For COVID health certificates this was normally done by comparing the signed biographical details with the person and their passport or other identity document. WHO’s model allowed verification services to return such holder information for that purpose.

Adding an identity layer

COVID-era systems explored other ways to strengthen holder assurance by adding an identity layer around the health credential. In this model, the vaccination certificate remains a signed health record, but it is presented through an app, wallet or travel process that has already performed some form of identity verification.

CLEAR Health Pass was one example. It linked COVID-19 health information to a verified app-based identity, allowing users to add vaccination proof, test results or health declarations and present them through the CLEAR app. The relying party was therefore not looking only at a free-standing vaccination certificate, but at a health status assertion associated with an identity.

The IATA Travel Pass applied the same principle to air travel. It allowed passengers to create a digital passport and share relevant health status information with airlines or authorities. In airline trials, the identity layer could include passport data and a profile photo, connecting the health credential to the passenger’s travel identity.

The important distinction is that these systems did not make the vaccination barcode itself biometric. The barcode or digital certificate still proved the health event; the surrounding system provided additional assurance that the presenter was entitled to use it. Identity assurance was therefore added to the process, rather than embedded in the certificate.

Linking the person to the data

More advanced identity barcode schemes now take this logic further by embedding a portrait or biometrics inside the data contained in the barcode (the payload).

At Optical & Digital Document Security™ 2025, Geoff Slagle of FaceTec presented this approach in his paper ‘Cryptographically Signed Biometric Barcodes for In-Person and Remote Identification’. FaceTec’s UR Code (as it is termed) uses a QR-like symbol to carry not only identity attributes, but also a compact, digitally signed biometric representation of the holder.

This changes the role of the barcode. It is no longer just a machine-readable certificate or a pointer to a database record.

When scanned, the verifier can check the issuer’s digital signature, confirm that the encoded identity and biometric data have not been altered, and compare the live presenter with the biometric data contained in the code.

The important control is liveness. Without it, biometric binding risks becoming a static artefact that can be attacked with a printed face, replayed video or AI-generated presentation.

FaceTec’s model combines cryptographic issuer authentication with live biometric comparison, allowing verification to be performed locally using standard camera-based devices.

WHO’s next step

WHO’s current work in this field is through the Global Digital Health Certification Network (or GDHCN, see page 8), an open and interoperable trust network through which participating states can verify digitally signed health certificates issued by other recognised authorities 3.

The GDHCN does not operate as a central database of individual vaccination records. Instead, WHO acts as a trust anchor. Participating states submit public keys into a trusted directory, allowing verifiers to confirm that a digital health credential was issued by an authorised body and that the data has not been altered. WHO states that it does not hold or access the personal data inside individual certificates.

The first practical step has already appeared in the Americas. In November 2025, the Pan America Health Organisation (PAHO) announced that El Salvador and Costa Rica had issued the first digital yellow fever vaccination certificates aligned with WHO GDHCN standards. The same announcement noted that the paper-based international certificate remained a requirement while WHO completed consultation processes for implementation of digital certificates 4.

The technical direction for WHO seems to avoid turning vaccination certificates into identity verifying documents.

It is, rather, building the trust layer: common standards, public-key verification, governance and cross-border recognition. Once that layer exists, countries can decide how much additional identity assurance to add, whether by passport comparison, wallet-based identity, or future biometric binding.

1 - https://estore.reconnaissance.net/vaccination-certificate/

2 - https://www.who.int/publications/i/item/WHO-2019-nCoV-Digital_certificates-vaccination-2021.1

3 - https://smart.who.int/trust/

4 - https://www.paho.org/en/news/21-11-2025-salvador-and-costa-rica-issue-first-digital-yellow-fever-vaccination-certificates