Overview
ISO/IEC 25831-2:2026 defines a schema for identity assurance based on the OpenID standard. The standard focuses on describing and verifying claims about a natural person using JSON objects, facilitating robust identity assurance in digital transactions. Central to this schema is the new verified_claims claim, which provides a standardized way to assert verified identity data, registered with the IANA JSON Web Token Claims Registry, as outlined in RFC 7519.
This schema ensures interoperability, privacy, and extensibility in identity assurance by introducing a clear separation between verified and unverified claims. The document also defines a flexible verification element to capture identity verification processes and associated metadata, usable both within and outside standard OpenID Connect flows.
Key Topics
- Verified Claims: Introduction of the
verified_claims JSON object, enabling claim recipients to distinguish between verified and unverified identity attributes.
- Verification Metadata: The
verification element presents details about the verification process, including the trust framework used (such as eIDAS or anti-money laundering regulations), assurance level, process details, and evidence.
- Claims and Evidence Types: The schema supports a wide range of claims (such as name, birthdate, address) and evidence types (documents, electronic records, vouches, electronic signatures) to verify these claims.
- Extensibility and Compliance: The framework is extensible, allowing adaptation to jurisdictional requirements and a variety of trust frameworks, making it suitable for global adoption.
- Data Minimization: Relying parties (RPs) can request only the minimum data necessary, supporting privacy and regulatory compliance.
Applications
The ISO/IEC 25831-2:2026 schema is designed for real-world identity verification scenarios, ensuring a secure and standardized approach to asserting user identity. Key practical applications include:
- Digital Identity Providers: Enhancing OpenID Connect-based platforms to offer interoperable and auditable identity assurance.
- Regulated Industries: Supporting sectors like finance, healthcare, or government where identity proofing is required under specific regulations (e.g., eIDAS, AML laws).
- Cross-Jurisdictional Use: Facilitating trust and compliance in international transactions where verified digital identities must be conveyed securely between systems.
- User Experience: Providing end-users with assurance about how their identity data has been verified and by whom, fostering trust and data minimization.
- Resource Servers: Enabling the delivery of verified claims via OAuth access tokens, benefiting services that rely on robust identity proof.
Related Standards
- ISO/IEC 25831-1:2026: Base specification for OpenID Identity Assurance 1.0, defining assurance requirements for identity claims.
- OpenID Connect Core 1.0: The foundational protocol for user authentication and claims distribution.
- RFC 7519 (JSON Web Token - JWT): Defines a compact, URL-safe means of representing claims to be transferred between parties.
- eIDAS (EU Regulation No 910/2014): Electronic identification and trust services standard in the European Union, referenced as an example trust framework.
- OpenID Connect for Identity Assurance Claims: Specifications for representing additional verified claims relevant to specific compliance requirements.
Keywords: ISO/IEC 25831-2, OpenID identity assurance, verified_claims, digital identity, verification metadata, JSON schema, identity verification, trust framework, identity standards, JWT claims, regulatory compliance, eIDAS, identity assurance schema.