BS ISO/IEC 18013-5:2021
$215.11
Personal identification. ISO-compliant driving licence – Mobile driving licence (mDL) application
Published By | Publication Date | Number of Pages |
BSI | 2021 | 164 |
This document establishes interface specifications for the implementation of a driving licence in association with a mobile device. This document specifies the interface between the mDL and mDL reader and the interface between the mDL reader and the issuing authority infrastructure. This document also enables parties other than the issuing authority (e.g. other issuing authorities, or mDL verifiers in other countries) to:
-
use a machine to obtain the mDL data;
-
tie the mDL to the mDL holder;
-
authenticate the origin of the mDL data;
-
verify the integrity of the mDL data.
The following items are out of scope for this document:
-
how mDL holder consent to share data is obtained;
-
requirements on storage of mDL data and mDL private keys.
PDF Catalog
PDF Pages | PDF Title |
---|---|
2 | undefined |
7 | Foreword |
8 | Introduction |
9 | 1 Scope 2 Normative references |
11 | 3 Terms and definitions |
13 | 4 Abbreviated terms |
14 | 5 Conformance requirement 6 mDL overview 6.1 Interfaces |
15 | 6.2 Functional requirements |
16 | 6.3 Technical requirements 6.3.1 Data model 6.3.2 Data exchange |
21 | 6.3.3 Security mechanisms |
23 | 7 mDL data model 7.1 mDL document type and namespace |
24 | 7.2 mDL data 7.2.1 Overview |
29 | 7.2.2 Portrait of mDL holder 7.2.3 Issuing authority 7.2.4 Categories of vehicles/restrictions/conditions |
30 | 7.2.5 Age attestation: nearest “true” attestation above request |
31 | 7.2.6 Biometric template 7.2.7 Signature or usual mark 7.2.8 Domestic data elements 7.3 Country codes 8 Transaction 8.1 Encoding of data structures and data elements |
32 | 8.2 Device engagement 8.2.1 Device engagement information |
34 | 8.2.2 Device engagement transmission technology |
36 | 8.2.3 Device engagement time-out |
37 | 8.3 Data retrieval 8.3.1 Data model 8.3.2 Data retrieval methods |
44 | 8.3.3 Data retrieval transmission technologies |
55 | 9 Security mechanisms 9.1 Device retrieval 9.1.1 Session encryption |
57 | 9.1.2 Issuer data authentication |
60 | 9.1.3 mdoc authentication |
63 | 9.1.4 mdoc reader authentication |
64 | 9.1.5 Session transcript and cipher suite |
66 | 9.2 Server retrieval 9.2.1 TLS 9.2.2 JWS |
67 | 9.3 Validation and inspection procedures 9.3.1 Inspection procedure for issuer data authentication 9.3.2 Inspection procedure for JWS |
68 | 9.3.3 Certificate validation procedure |
69 | Annex A (informative) BLE L2CAP transmission profile |
70 | Annex B (normative) Certificate and CRL profiles |
98 | Annex C (informative) Verified issuer certificate authority list (VICAL) provider |
120 | Annex D (informative) Data structure examples |
143 | Annex E (informative) Privacy and security recommendations |
157 | Annex F (informative) IANA Considerations |
161 | Bibliography |