FB pixel

Kantara lays out trust-building recommendations for mDLs

Kantara lays out trust-building recommendations for mDLs
 

A global digital ID association has published steps vendors and others need to take in order to build effective mobile driving license services that also put ID holders in control of their identity.

The Kantara Initiative’s report starts from the premise that trust in mobile driving licenses grows with the degree of control that license holders have over the documents, their privacy and their biometric identifiers.

Privacy and digital ID-related requirements and expectations identified in the report pertain to all ISO/IEC 18013-5-compliant credentials in the pursuit of “robust and privacy-protective” systems for stakeholders.

The organization notes that the interface between issuing authority infrastructure and the mobile driver’s license is out of scope of ISO 18013-5, while those between the mDL and mDL reader and the reader and issuer are covered by the standard

The report surveys other standards and guidance being formulated. The American Association of Motor Vehicle Administrators (AAMVA) has looked into public key collection and dissemination solutions, as it seeks to stand up a Verified Issuer Certificate Authority List (VICAL). The AAMVA has also issued guidelines for issuing authorities on how to administer mDLs. The Identity Council of the Secure Technology Alliance (STA), meanwhile, has published a set of educational materials and resources for participants within the mDL ecosystem.

Eleven categories of risk considerations are listed, including for establishing consent, purpose legitimacy, collection limitation, data minimization and use, retention and disclosure limitation. Data flows for various use cases are defined and mapped out. These considerations state the importance of “proof of presence” in online transactions with mDLs, likely in the form of biometrics.

The Kantara authors write that their requirements will enable relying parties — anyone relying on validity of a person’s or process’ authenticators and credentials — to give mobile license holders a significant and “potentially verifiable” assurance about how their private data is protected.

Related Posts

Article Topics

 |   |   |   |   |   |   |   |   |   |   | 

Latest Biometrics News

 

AI deepfakes push biometric industry toward measurable assurance

The rise of AI-generated deepfakes and injection attacks is reshaping how organizations evaluate biometric security systems, pushing the industry toward…

 

Security, ruggedness key for reliable biometric physical access control tools

A recent webinar from Biometric Update and Goode Intelligence opens up the hood on the 2026 Biometric Physical Access Control…

 

Trident pivots to multi‑vertical holding company focused on sovereign digital infrastructure

Trident Digital Tech Holdings Ltd. is overhauling its corporate structure to strengthen focus on its offerings for national digital economies….

 

South Africa Home Affairs seeks $828M budget for digital ID, biometric visa projects

South Africa’s Department of Home Affairs has tabled a budget of 13.8 billion Rand (about US$828 million) in parliament for…

 

NIST biometric age estimation update show demographic, accuracy gains

Demographic disparities and mean error rates are falling among the newest age estimation and verification algorithms submitted to the U.S.’…

 

Identity verification becomes core compliance infrastructure across regulated sectors

Identity verification is increasingly becoming embedded operational infrastructure across regulated industries as tighter AML, KYC and fraud-prevention requirements push organizations…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events