FB pixel

NZ fills in digital credential portal details in response to vendor questions

NZ fills in digital credential portal details in response to vendor questions
 

Details about the digital credential issuance platform New Zealand’s Department of Internal Affairs is currently running an RFP for have emerged from the questions and answers posted to the procurement page.

The chosen vendor or consortium needs not just to be able to supply the PKI solution, but also manage it. The DIA expects the full platform to be run as a managed service, which should be reflected in the hosting and environment fees submitted in response to the RFP.

The department expects two to four DIA administrative staff to use the platform, along with two or three per issuer, assuming tenant admins are supported. The portal is not expected to handle double-digit concurrent users at any time.

DIA responds to several questions on certificate authentication by emphasizing that the goal is to prevent “impersonation and replay attacks.”

“That might be that the responder uses OAuth2.0 with short-lived tokens which is then hardened via sender-constraints such as mTLS,” DIA Procurement explains. “However, mTLS may not be possible for some agencies, in which case DPoP (demonstrable proof of possession per RFC9449), would be acceptable in those situations. It will come down to what the responder’s auth API for the scenario is though. We would want short-lived access tokens with replay protection, key rotation, scopes and audience restrictions over TLS. In regards to Public APIs, TLS is expected to be used following the OID4VCI Standard.”

DIA believes there is a “possibility of one or two issuers on or near day one” of the portal’s launch, and while it notes that the number of agencies that will eventually issue credentials through the platform is unknown, there will be time to scale ahead of time as each agency is onboarded.

The successful bidder will be expected to work with the project team to complete security accreditation for the platform under the country’s new Digital Identity Trust Framework.

DIA also addresses how issuers will know if a user deletes a credential from their digital wallet and how public keys will be verified through a VICAL in the responses.

The question and answer portal closes August 21 at 5pm New Zealand time, and the RFP closes August 27.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

ICE smart glasses plan points to broader DHS push to make biometrics mobile and routine

The Department of Homeland Security (DHS) is moving toward a broader biometric enforcement architecture that would extend facial recognition and…

 

FTC reminds tech platforms of deadline to comply with Take It Down Act

The Federal Trade Commission (FTC) is warning major technology companies that they must comply with the Take It Down Act…

 

World Bank unveils DPI procurement guide for more integrated digital services

The World Bank Group has published a guidance note that aims to assist countries in selecting the most appropriate procurement…

 

Privacy-preserving age assurance has arrived; now, it has to keep its promises

The Final Communiqué from the 2026 Global Age Assurance Standards Summit is now available. Summarizing learnings and takeaways from the…

 

MainMoney palm biometrics platform to support DRC’s financial inclusion drive

The Democratic Republic of Congo (DRC) is looking to strengthen its financial inclusion push with MainMoney, a digital payment platform…

 

Idex’ $1.75M deal with ID Centric for biometric payment cards back on

Singapore and Malaysia-based ID Centric will build fingerprint sensors from Idex Biometrics into its biometric payment cards through a $1.75…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events