Overview
ISO/IEC TS 23220-3:2026 is an international standard developed by ISO and IEC focused on cards and security devices for personal identification. Specifically, it provides standardized building blocks for identity management through mobile devices during the installation and issuing phases. This technical specification defines essential protocols, interfaces, and services for mobile document (mdoc) applications-including installation, attribute and credential issuing, security and privacy mechanisms, and discoverability processes for mobile electronic identification (eID) systems.
The document targets organizations and professionals involved in specifying, architecting, designing, testing, maintaining, and operating mobile eID systems, with an emphasis on robust security and privacy protocols.
Key Topics
1. Protocols and Interface Normalization
- Specifies standardized interfaces for data interchange during:
- Installation phase: mdoc app deployment and setup
- Issuing phase: allocation and derivation of user attributes and credentials
- Ensures efficient, interoperable communication between mobile devices, mdoc apps, secure areas, and issuing authorities
2. Security and Data Protection Mechanisms
- Details mechanisms for the secure storage and transmission of personal data
- Introduces privacy-enhancing technologies to minimize data leakage and support user consent
- Utilizes mdoc app capability descriptors and Secure Area Attestation Objects to establish trust models
3. Discoverability and Attestation
- Defines discoverability protocols that allow issuing authorities to validate mdoc app capabilities and secure area features during installation
- Mdoc app capability descriptors (MCD) and attestation objects facilitate assessment of compliance with issuer policies
4. Privacy and User Control
- Empowers holders to initiate installation and issuing processes securely (e.g., via QR code, push notification, or app interface)
- Enables secure communication and flexible workflows, supporting multi-device and companion device scenarios
- Applies privacy-focused workflows, ensuring minimal data exposure and user control over their digital identities
Applications
Mobile eID Issuance:
Entities such as government agencies, banks, or trusted third parties can use these protocols to securely issue digital credentials, such as identity cards, driver’s licenses, or access badges onto mobile devices.
Mobile App and Secure Area Validation:
Issuing authorities can validate that installed mdoc apps and secure hardware modules meet security, privacy, and feature requirements before issuing any credentials or attributes.
Interoperable Ecosystem Development:
Developers and solution architects can design mobile eID systems that are interoperable across various devices and platforms, thanks to standardized data objects, attestation formats, and communication protocols.
End-User Experience Enhancement:
Holders benefit from a more streamlined and secure installation and issuance process, often with choices in authentication methods and device usage, including restoration and migration of credentials.
Companion Device Support:
The standard supports workflows involving limited-input devices (such as smartwatches) paired with smartphones, increasing flexibility and user adoption.
Related Standards
- ISO/IEC TS 23220-1: Generic system architectures for mobile eID systems
- ISO/IEC TS 23220-2: Data objects and encoding rules for generic eID systems
- ISO/IEC TS 23220-4: Protocols and services for the operational phase
- ISO/IEC 7816-15: Cryptographic information application for integrated circuit cards
- RFC 9360: COSE header parameters for X.509 certificates
- IETF RFC Draft 06 (2025): OAuth 2.0 attestation-based client authentication
These related standards provide foundational concepts, data models, cryptographic techniques, and operational protocols, forming a comprehensive framework for secure, privacy-focused mobile identity management and issuance.
By following ISO/IEC TS 23220-3:2026, organizations enable secure, standardized deployment and issuing of digital credentials, strengthening trust and interoperability across the mobile identity ecosystem. This enhances security, fosters privacy, and supports evolving digital identification requirements.