FB pixel

NZ fills in digital credential portal details in response to vendor questions

NZ fills in digital credential portal details in response to vendor questions
 

Details about the digital credential issuance platform New Zealand’s Department of Internal Affairs is currently running an RFP for have emerged from the questions and answers posted to the procurement page.

The chosen vendor or consortium needs not just to be able to supply the PKI solution, but also manage it. The DIA expects the full platform to be run as a managed service, which should be reflected in the hosting and environment fees submitted in response to the RFP.

The department expects two to four DIA administrative staff to use the platform, along with two or three per issuer, assuming tenant admins are supported. The portal is not expected to handle double-digit concurrent users at any time.

DIA responds to several questions on certificate authentication by emphasizing that the goal is to prevent “impersonation and replay attacks.”

“That might be that the responder uses OAuth2.0 with short-lived tokens which is then hardened via sender-constraints such as mTLS,” DIA Procurement explains. “However, mTLS may not be possible for some agencies, in which case DPoP (demonstrable proof of possession per RFC9449), would be acceptable in those situations. It will come down to what the responder’s auth API for the scenario is though. We would want short-lived access tokens with replay protection, key rotation, scopes and audience restrictions over TLS. In regards to Public APIs, TLS is expected to be used following the OID4VCI Standard.”

DIA believes there is a “possibility of one or two issuers on or near day one” of the portal’s launch, and while it notes that the number of agencies that will eventually issue credentials through the platform is unknown, there will be time to scale ahead of time as each agency is onboarded.

The successful bidder will be expected to work with the project team to complete security accreditation for the platform under the country’s new Digital Identity Trust Framework.

DIA also addresses how issuers will know if a user deletes a credential from their digital wallet and how public keys will be verified through a VICAL in the responses.

The question and answer portal closes August 21 at 5pm New Zealand time, and the RFP closes August 27.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

MOSIP delves into biometric data quality considerations

Biometric data quality was in focus at MOSIP Connect 2026 in Rabat, Morocco, from policies for ensuring good enrollment practices…

 

NIST nominee pressed on AI standards, facial recognition oversight

The Senate Committee on Commerce, Science and Transportation on Thursday considered the nomination of Arvind Raman to serve as Under…

 

Trulioo’s Hal Lonas on how he applies aeronautics principles to fighting fraud

Rocket science is routinely held up as the ultimate example of a highly complex discipline. But Trulioo’s Hal Lonas found…

 

Vouched donates MCP-I framework to Decentralized Identity Foundation

An announcement from Seattle-based Vouched says it has formally donated its Model Context Protocol – Identity (MCP-I) framework to the…

 

California’s OS-based age verification law challenges open-source community

California’s new online safety bill, AB 1043 (the Digital Age Assurance Act), adopts a declared age model for operating systems….

 

87% of failed biometric verifications in Southern Africa due to AI spoofing: Smile ID

A new report spotlights deepfake fraud posing an acute problem for Africa. Digital identity, banking and e-government are being used…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events