Overview
ISO/IEC TR 25219:2025 provides targeted considerations for implementers and developers who are early adopters of ISO/IEC TS 18013-7 (mobile driving licence - mDL add-on functions). The technical report focuses on practical interoperability, maintaining security and privacy properties, and maximizing backward compatibility as protocols evolve. It also highlights related ecosystem initiatives such as the W3C Digital Credentials API and OpenID Foundation (OIDF) work.
Key Topics
-
Wallet and app interoperability: Advice to ensure that issuing authorities can work with mainstream wallets/apps where reasonable, avoiding lock-in to esoteric implementations while recognizing necessary discretion.
-
Binding presentment to request channel: Measures to prevent attackers from forwarding engagement/request information to an mdoc - i.e., binding presentment to the originating request channel as described in ISO/IEC TS 18013-7.
-
Minimizing reader-supplied data: Recommendations to reduce the amount of information an mDL reader must provide to the digital credentials API to retrieve data from the mdoc, protecting user privacy.
-
Verifier identification and attestation: Enabling mdoc readers to convey identifying and attestation information about the verifier to the mdoc, functionally similar to mdoc reader authentication certificates in ISO/IEC 18013-5.
-
Compatibility with existing messages: Delivering messages equivalent in function to DeviceRequest and accepting DeviceResponse as defined in ISO/IEC 18013-5, to allow reuse of existing mechanisms with minimal change.
-
Application-layer encryption: Implementation guidance to use asymmetric key algorithms to derive ephemeral symmetric keys for encrypting mdoc responses, leveraging the session transcript for key derivation as referenced in ISO/IEC TS 18013-7 and ISO/IEC 18013-5.
Applications
This report is practical for:
- Government agencies and issuing authorities planning mDL rollouts.
- Wallet and platform developers implementing W3C Digital Credentials API integrations.
- Security architects ensuring privacy-preserving presentation of driving licence data.
- Organizations participating in OIDF/HAIP or other request–response protocol development.
Benefits include clearer migration paths, reduced integration friction across wallets and readers, and preserved security/privacy guarantees during early deployments.
Related Standards
- ISO/IEC TS 18013-7:2025 - mDL add-on functions (primary protocol referenced).
- ISO/IEC 18013-5 - mDL application and DeviceRequest/DeviceResponse message models.
- W3C Digital Credentials API - browser API for credential requests; TR 25219 discusses integration considerations.
- OpenID Foundation initiatives (OpenID4VP / HAIP) - ongoing protocol work enabling Verifiable Presentations and high-assurance interoperability.
Practical note: TR 25219 is guidance-oriented; it encourages implementers to follow evolving protocol updates while preserving privacy, security and interoperability across wallets, platforms and readers.