Overview
ISO/IEC TS 23220-6:2025 is an international technical specification within the ISO/IEC 23220 series, focusing on cards and security devices for personal identification. Specifically, Part 6 defines the mechanism for using certification to attest to the trustworthiness of a secure area in mobile devices. This standard provides a structured approach for secure area providers to describe the capabilities and confidence level of their secure environments. This enables verification by eID issuers and mobile eID attestation service providers, supporting trusted identity management in the growing ecosystem of electronic identification through mobile devices.
The standard fills a critical need for interoperability and trust across different implementations of secure areas, referencing existing approaches from widely recognized industry specifications and standards such as GlobalPlatform DLOA, FIDO Alliance MDS, and prior parts of ISO/IEC 23220.
Key Topics
-
Certification on Trustworthiness
The specification outlines a mechanism to leverage a certificate-possibly affixed to a secure area-detailing key trustworthiness attributes. The goal is to support eID systems and mobile ID (mID) solutions in verifying that a secure area meets expected assurance levels.
-
Describing Secure Area Capabilities
Provides a comprehensive list of elements that describe the capacity, integrity, authenticity, and confidence level of secure areas. These elements include information such as vendor identity, certification references, supported security functions, cryptographic features, and access control mechanisms.
-
Certificate Structure and Management
Defines how to structure trustworthiness certificates and how their management supports attestation of secure area properties. These certificates help ensure that each secure area’s attributes can be independently validated.
-
Interoperability and Alignment
Aligns with other industry certifications and standards (e.g., DLOA, MDS, SAAO) to reduce gaps and differences, promoting consistency and harmonized trust models across technologies and use cases.
-
Trust Anchors in Mobile Identity
Recognizes and defines roles for trustworthiness certificate authorities (TCA) as well as evaluation entities and registration authorities-increasing assurance for all participants in the ecosystem.
-
Relevant Security Criteria
Maps capability and confidence level elements to functional security components found in established standards like ISO/IEC 15408-2, enabling integration with security certification practices.
Applications
- Mobile eID and mDL
Critical for secure issuance, storage, and verification of mobile electronic identification credentials and mobile driving licences, particularly as mobile devices become primary vectors for digital ID.
- Banking & Financial Services
Ensures trust in secure areas used within mobile payment apps and financial services, supporting strong authentication and privacy requirements.
- Government and Legal Identity
Facilitates trusted deployment of national eID programs, electronic passports, and digital licenses by enabling issuers to verify the trustworthiness of device-based secure areas before credential issuance.
- Enterprise Access & Membership Cards
Supports secure mobile-based access control, employee identification, and privilege management by assuring that only certified secure areas store and manage identity credentials.
- Interoperable Identity Management
Provides a foundation for worldwide interoperability and interchangeability of secure area attestation information, which is essential in global digital identity networks.
Related Standards
- ISO/IEC 23220-1
Defines the secure area concept and overall framework for identity management via mobile devices.
- ISO/IEC TS 23220-3
Specifies Secure Area Attestation Objects (SAAO) for capability information exchange.
- GlobalPlatform GPC_SPE_095 (DLOA)
Describes the Digital Letter of Approval model for secure element certification.
- FIDO Alliance Metadata Service (MDS)
Provides metadata about the trustworthiness and security attributes of authenticators.
- ISO/IEC 15408-2
Covers evaluation criteria for IT security, offering security functional components relevant to secure areas.
By leveraging ISO/IEC TS 23220-6:2025, organizations and solution providers can implement standardized, validated, and interoperable mechanisms for certifying the trustworthiness of secure areas in mobile identity environments, improving trust, security, and user confidence in digital identity services.