Overview
ISO/IEC TS 23220-4:2026 - Protocols and Services for Operational Phase is part of a key international standard series for personal identification via mobile devices. Developed by ISO and IEC, this specification defines vital building blocks for the operational phase of mobile electronic identification (mobile eID) systems and other mobile documents (mdoc). It details critical interfaces, protocols, and security mechanisms for communication between mdoc applications, readers, and issuing authority infrastructures, enabling national bodies or document-specific standards to implement customized identity management profiles.
The focus of this part is to ensure secure, interoperable, and efficient operational procedures for mobile ID and credential verification, supporting both proximity and remote (internet) communications.
Key Topics
- Operational Phase Building Blocks
- Defines the structures, functions, and flows needed for mobile eID operation after initial set-up (provisioning is covered elsewhere).
- Interfaces and Protocols
- Specifies the interface between mdoc apps and mdoc readers, as well as between readers and issuing authorities.
- Details engagement and communication sub-phases, supporting both proximity (RF) and internet-based channels.
- Transport Protocols
- Supports various radio-frequency (RF) solutions, including NFC and BLE, for proximity exchanges.
- Specifies secure internet-based transport using established protocols.
- Request-Response Protocols
- Details application layer protocols for secure messaging and data exchange, ensuring reliable interactions between apps, readers, and authorities.
- Security Mechanisms
- Covers issuer authentication, mdoc authentication, and credential holder verification.
- Utilizes digital signatures and public key infrastructure (PKI) to confirm authenticity, integrity, and binding of credentials.
- Data Retrieval and Verification
- Enables authorized parties (beyond the issuer) to retrieve mdoc data, bind documents to holders, verify data origin, and check data integrity.
- Conformance and Profile Creation
- Provides guidance for creating standardized, conforming operational-phase profiles to ensure national and sectoral requirements are addressed.
Applications
ISO/IEC TS 23220-4:2026 supports a broad range of practical applications for mobile identity management, including:
- National eID Programs: Offers a framework for government-issued mobile IDs, driver's licenses, or residence permits that can be securely verified at borders, banks, or public services.
- Digital Credentials in Private Sector: Enables banks, healthcare providers, and other organizations to validate identity and access rights via secure mobile documents.
- Contactless Identity Validation: Supports proximity-based interactions, such as NFC or QR code scans for entry control, service access, or transactions.
- Remote Verification: Ensures safe online verification of identity through robust protocols and end-to-end encryption, suitable for remote onboarding or e-Government services.
- Custom Identity Profiles: Facilitates the definition of tailored identity solutions to meet sector-specific or document-specific legal, security, and functional requirements.
- Interoperability: Promotes cross-border, multi-platform compatibility for mobile device-based identification efforts.
Related Standards
To ensure broad compatibility and robust security, ISO/IEC TS 23220-4:2026 references and complements numerous related standards, including:
- ISO/IEC 23220-1: Foundations and architectures for mobile eID systems.
- ISO/IEC TS 23220-2: Data objects and encoding rules.
- ISO/IEC TS 23220-3: Processes for provisioning mdoc data (out of scope for Part 4).
- ISO/IEC 18013-5: Specifications for mdoc operations, including engagement and server retrieval.
- ISO/IEC 7816-4: Organization, security, and commands for identification cards.
- Security and Transport Protocols: References to CBOR, JSON, TLS, COSE, JWT, OID4VP, Elliptic Curve Cryptography, and others to guarantee secure data exchange and robust cryptographic verification.
Practical Value
Adopting ISO/IEC TS 23220-4:2026 enhances operational efficiency, security, and compliance for mobile identity solutions. By following these standardized protocols and services, organizations and national bodies can deliver mobile eID systems that are secure, interoperable, and user-friendly, reducing fraud while enabling seamless interactions across digital and physical environments. These standards also prepare identity management ecosystems for future technological advancements and regulatory requirements.