Overview
ISO/IEC TS 23220-2:2026 is an international standard that defines data objects and encoding rules for generic electronic identification (eID) systems, focusing on the building blocks necessary for effective identity management via mobile devices. Its primary purpose is to standardize the data models and encoding approaches used in data exchanges between mobile document (mdoc) applications and verification apps in a secure and interoperable manner. The specification helps entities involved in the creation and management of mobile eID systems-including system architects, developers, testers, administrators, and operators-build robust digital identity solutions that facilitate seamless data sharing and uphold high security standards.
By offering a unified approach to data objects and encoding, this standard supports the practical deployment and operation of mobile-based identity verification technologies used worldwide.
Key Topics
- Data Objects for eID Systems: Defines a comprehensive set of personal attributes (e.g., surname, given name, birth date, sex, nationality, address details, biometric templates, professional and organizational information) with clear data element identifiers and encoding formats.
- Encoding Rules: Specifies encoding types such as text string, byte string, unsigned integer, date/time, and boolean values, relying predominantly on CBOR (Concise Binary Object Representation) and JSON formats for data serialization and exchange.
- Namespace Handling: Outlines how namespaces differentiate data elements and support extensibility, ensuring clear identification and context for every data item.
- Meta-attributes: Introduces meta attributes to support interoperability between various eID standards, mapping equivalent attributes (e.g., "birth_date" vs. "birthdate") to facilitate data integration.
- Biometric and Document Data: Details how to structure and encode biometric data (face image, fingerprints) and document-related data to support both visual inspection and automated biometric comparison.
- Deterministic Serialization: Describes best practices for core deterministic encoding, ensuring security and data integrity in mobile document environments.
Applications
Entities that benefit from ISO/IEC TS 23220-2:2026 include:
- National and Local Governments: Implementing mobile eID cards, digital passports, driver’s licenses, and other official identification documents that conform to international interoperability requirements.
- Financial Services: Facilitating secure customer onboarding and authentication through mobile identity solutions that leverage standardized data objects and encoding methods.
- Healthcare Systems: Supporting healthcare professional IDs and patient identity management with compliance to privacy and security best practices.
- Enterprises and Educational Institutions: Issuing employee badges, student IDs, and access credentials using mobile devices for secure, verifiable authentication and access control.
- eCommerce and Private Sectors: Enabling seamless user identity verification for digital services reliant on robust personal identification infrastructure.
- Mobile App Developers and System Integrators: Building mdoc applications and verification tools that rely on clear, unified data models and encoding approaches.
Related Standards
This technical specification interacts and aligns with several important international standards to support interoperability and ensure best practices:
- ISO/IEC 23220 Series: Building blocks for identity management via mobile devices (other parts provide guidance on API serialization, channel establishment, and more).
- ISO/IEC 18013-5: Mobile driving licence (mDL) applications, with guaranteed backward compatibility.
- ISO 3166: Country codes for nationality and residence attributes.
- ISO/IEC 5218: Human sexes code.
- ISO/IEC 7816-11, ISO/IEC 19785-3, ISO/IEC 19794-4/5, ISO/IEC 39794-4/5: Standards for biometric data encoding and exchange.
- RFC 8949: Concise Binary Object Representation (CBOR).
- RFC 7515 & RFC 7165: JSON Web Signature (JWS) and related JSON object security mechanisms.
- ITU-T E.123/E.164: Telephone number formatting and international numbering plans.
Practical Value
ISO/IEC TS 23220-2:2026 ensures that mobile eID systems are interoperable, secure, and extensible. By providing standardized data objects and encoding rules, it greatly reduces integration complexity, enhances cross-border verification processes, and supports the scalability of mobile identity management systems in various sectors. This results in streamlined identity verification workflows, improved security, and a foundation for trusted digital services across industries.