Overview
ISO/IEC TS 23220-2:2024 defines data objects and encoding rules for generic electronic ID (eID) systems used on mobile devices. As Part 2 of the ISO/IEC 23220 series, it standardizes building blocks for mobile document (mdoc) infrastructures and generic data models for exchanges between mdoc apps and verification applications. The Technical Specification targets interoperable identity management, secure data formats and conversion mechanisms to support a wide range of mobile eID use cases.
Key topics and technical requirements
- Data model and encoding rules
- Standard meta-attributes for person, issuer and document entities.
- Field formats, identifier conventions and namespace rules.
- Data elements for document authenticity and level-of-confidence metadata.
- Serialization and payload formats
- CBOR (Concise Binary Object Representation) as a primary binary format (RFC 8949).
- JSON conversion and mappings for human- or web-oriented workflows.
- Base encodings referenced (RFC 4648) for transport or display.
- Cryptographic and transport primitives
- Defined cipher-suite guidance including elliptic curves, TLS configurations, digest, signature and HMAC algorithms (document lists supported families rather than vendor specifics).
- Support for issuer-signed and holder-signed payload structures (aligned with JOSE concepts, RFC 7165 / RFC 7515).
- Interoperability building blocks
- Generic mdoc data model to enable consistent data exchange between mdoc apps and verification apps across different mobile security elements (TEE, secure element, eUICC, server-backed).
- Support for multiple communication channels (NFC, BLE, Wi‑Fi, mobile networks) and Trust on First Use (TOFU) mechanisms.
- Applicability
- Intended for architects, designers, implementers, testers, operators and administrators of mobile eID systems.
Practical applications
- Mobile national ID and driver’s license implementations (including backward compatibility considerations with mDL / ISO/IEC 18013-5).
- Governmental, healthcare and financial mobile identity apps that need standardized data exchange and verification.
- Mobile access control, employee credentials and federated identity use-cases where secure, interoperable mobile credentials are required.
- Developers and integrators implementing mdoc apps, verification SDKs, backend issuers and verifier services.
Who should use this standard
- System architects and security engineers designing mobile eID systems.
- Software developers and testing teams implementing mdoc serialization, CBOR/JSON conversion and signature handling.
- Standards compliance officers and product managers coordinating interoperability across devices and verification ecosystems.
Related standards
Keywords: ISO/IEC TS 23220-2, mobile eID, mdoc, CBOR, JSON, encoding rules, data objects, identity management, verification applications, eID systems.