Overview
ISO/IEC TS 18013-7:2024 specifies add-on functions for an ISO-compliant mobile driving licence (mDL) by extending ISO/IEC 18013-5 to support presentation of an mDL to a reader over the internet. It defines data structures, exchange flows, and security mechanisms that enable a verifier (mDL reader) to request and retrieve an mDL (an mdoc) remotely while preserving integrity, authenticity and selective data release.
Key topics and technical requirements
- Scope and conformance
- Augments ISO/IEC 18013-5; an mDL or mDL reader conforms if it meets requirements in this TS.
- Data model and formats
- Uses CBOR and CDDL conventions consistent with ISO/IEC 18013-5; Clause 7 details the mDL data model.
- Data exchange flows
- Supports at least one retrieval method: device retrieval (with ReaderEngagement and DeviceEngagement structures) and OID4VP (OpenID for Verifiable Presentations) as alternative channel (Annex B).
- Enables setup via remote engagement or out-of-band channels; device retrieval uses mdoc request/response structures defined in ISO/IEC 18013-5.
- Engagement and discovery
- Defines engagement phase where a reader transmits a ReaderEngagement and the mDL responds with DeviceEngagement to establish a secure transmission channel.
- Security mechanisms
- Security architecture is designed for confidentiality, integrity, and authenticity by default.
- Protection against forgery and cloning: IA-signed data elements and session authentication keys stored in the mDL.
- Supports selective release of mDL data elements; portrait image may be used to link holder to mDL but verification methods vary by context.
- Normative references
- Builds on ISO/IEC 18013-5 and references standards like RFC 5280, RFC 9112, OID4VP drafts and relevant encoding RFCs.
Practical applications and who uses it
- Issuing authorities (IAs) - to define mDL issuance and signing practices that enable internet-based presentation.
- mDL app developers - to implement the device retrieval and engagement flows, CBOR/CDDL data structures, and security controls.
- Verifier and reader vendors - to support remote retrieval, OID4VP integration, and conformance testing.
- Government agencies, law enforcement, and service providers - to accept mDLs remotely for licensing checks, age verification, or access control while minimizing data exposure.
- Identity solution integrators and security architects - to design secure, privacy-preserving deployments.
Related standards
- ISO/IEC 18013-5 (mDL application interface and mdoc structures)
- OID4VP (OpenID for Verifiable Presentations)
- Relevant IETF standards: RFC 5280 (X.509), RFC 4648 (base encodings), RFC 9112 (HTTP/1.1), RFC 9101 (JAR)
Keywords: ISO/IEC TS 18013-7:2024, mobile driving licence, mDL, device retrieval, OID4VP, mdoc, remote engagement, CBOR, CDDL, mDL security.