Overview
ISO/IEC TR 25219:2024 provides practical considerations for early adopters of ISO/IEC TS 18013-7 when implementing ISO-compliant driving licence (mDL) functionality. The Technical Report targets implementers and developers who participate in updates to TS 18013-7 and focuses on preserving the security, privacy and backward compatibility properties already established by the mDL family of standards.
This guidance explicitly supports convergence with emerging web-based digital credentials initiatives such as the W3C Web Platform Incubator Community Group (WIGC) digital credentials API while advising on interoperability with existing mDL mechanisms.
Key Topics
-
Wallet and app interoperability
- Ensure the issuing authority can work with the wallet/app of choice where reasonable (for example, mainstream implementations such as those from the OpenWallet Foundation). Discretion is advised to avoid forcing support for niche wallets.
-
Presentation binding and replay protection
- Protect against attackers forwarding engagement or request information by binding presentment to the originating request channel (see Clause 6.5 of ISO/IEC TS 18013-7).
-
Minimized reader requirements
- Reduce the amount of information an mDL reader must provide to the digital credentials API to retrieve mdoc data, minimizing exposure of verifier-side data and lowering privacy risk.
-
Independent functional building blocks
- Allow the mdoc reader to convey verifier identity and attestation information to the mdoc in a way functionally similar to the mdoc reader authentication certificate in ISO/IEC 18013-5.
- For the digital credentials API, enable wallet selection and deliver payloads that allow continued use of existing ISO/IEC TS 18013-7 and ISO/IEC 18013-5 mechanisms with minimal changes.
- Deliver and accept messages equivalent in function to the DeviceRequest and DeviceResponse constructs from ISO/IEC 18013-5, preserving doctype, namespace and field identifier concepts.
- Implement application-layer encryption for mdoc responses using an asymmetric key algorithm to derive an ephemeral symmetric key; include the session transcript (per ISO/IEC TS 18013-7 and ISO/IEC 18013-5) in key derivation.
Applications
- Governments and issuing authorities planning early mDL deployments
- Wallet and operating system developers integrating digital credentials APIs
- Verifier implementers seeking to maintain privacy certifications and authorization assertions
Practical value: TR 25219:2024 helps ensure that early deployments remain compatible with future updates, preserve existing trust and privacy guarantees, and interoperate with mainstream wallet ecosystems.
Related Standards
- ISO/IEC TS 18013-7 - Mobile driving licence (mDL) add-on functions
- ISO/IEC 18013-5 - mDL application and mdoc reader authentication concepts
Implementers should consult the referenced documents and the ISO/IEC Directives for normative guidance and updates. For terminology and definitions, refer to the ISO Online Browsing Platform and the IEC Electropedia.