Difference between revisions of "Mobile Driver's License"

From MgmtWiki
Jump to: navigation, search
(Wallet Spread Sheet)
(Wallet Spread Sheet)
 
(4 intermediate revisions by the same user not shown)
Line 253: Line 253:
 
|-
 
|-
 
|Austria|| AT ||Youniqx ID AG || || can download [https://www.oesterreich.gv.at/eausweise.html eAusausweis app] since 2022 and present only within Austria during roadside checks- do not need physical card with you 2024-09 380K activated
 
|Austria|| AT ||Youniqx ID AG || || can download [https://www.oesterreich.gv.at/eausweise.html eAusausweis app] since 2022 and present only within Austria during roadside checks- do not need physical card with you 2024-09 380K activated
 +
|-
 +
|China || || || || 24-11-11 Select cities in mainland China have already implemented the change to digital ID documents.
 
|-
 
|-
 
|Switzerland || || || || [https://github.com/e-id-admin/open-source-community/blob/main/tech-roadmap/tech-roadmap.md published on GitHub] Mid 2024 Decentralized Identifiers (DIDs) v1.0 according to W3C DID Method: did:tdw
 
|Switzerland || || || || [https://github.com/e-id-admin/open-source-community/blob/main/tech-roadmap/tech-roadmap.md published on GitHub] Mid 2024 Decentralized Identifiers (DIDs) v1.0 according to W3C DID Method: did:tdw
 
|-
 
|-
 
|Moldova || || || ||24-06-14 released [https://www.biometricupdate.com/202406/moldovas-first-digital-id-app-sees-24k-downloads-in-five-days EVO ID app]  driver’s licenses and registrations, the app contains the government electronic payment module MPay and a document verification module.
 
|Moldova || || || ||24-06-14 released [https://www.biometricupdate.com/202406/moldovas-first-digital-id-app-sees-24k-downloads-in-five-days EVO ID app]  driver’s licenses and registrations, the app contains the government electronic payment module MPay and a document verification module.
 +
|-
 +
|Honk Kong|| || || || 2024-11-11 [https://www.biometricupdate.com/202411/mobile-drivers-licenses-to-launch-in-hong-kong-in-2025 Mobile driver’s licenses to launch in Hong Kong in 2025]
 
|-
 
|-
 
|Indonesia|| || || || Government Mandated ID with mDL among other licenses
 
|Indonesia|| || || || Government Mandated ID with mDL among other licenses

Latest revision as of 21:09, 11 November 2024

Full Title

User in control of a Mobile Driver's License and other apps that require high assurance control of credentials.

Context

  • There remains continued confusion about whether a Driver's License is a card used for identification that should not be revoked for any reason other than fraud or an Authorization to access some resource (like the public roads) that can be revoked at any time.
  • The ISO standard 18013-5 focuses exclusively on the original purpose of the driver's license, the authorization of a person to operate a motor vehicle on the public roads. Anecdotal evidence (from Queensland) is that only about 1 in 50 (2%) of the request to show a driver's license correspond to this original purpose.
  • iPhone and Android solutions also have NFC, QR Code, Bluetooth, Wifi Aware and Barcode readers technology thoroughly functional
  • The wiki page Smartphone Wireless contains information about the various radio bands used by mDL.

Providers

Much information about the the inter-relationship among the many players on “How the REAL-ID Act is creating a national ID database” is describe by Edward Hasbrouck.[1][2]
Requiring a photo ID to board a flight disproportionately affects certain groups, particularly low-income individuals, elderly travelers, people with disabilities, and those from rural areas, who may face challenges in obtaining or renewing an ID. Just as with voting, these individuals may encounter obstacles such as limited access to transportation, the costs associated with obtaining required documents, and logistical issues due to a lack of nearby government facilities. Moreover, the added financial and time burdens of procuring an ID create unnecessary barriers, effectively restricting their ability to travel and diminishing their personal freedom and mobility. For individuals with urgent travel needs, such as visiting family members in emergencies or pursuing job opportunities, these barriers to flying without an ID could have severe social and economic impacts.

(nb. There is actually no federal requirement for a ID to board a plane, which few people understand. However, that can extend security waits to very long delays. This wait time appears to be the club that the TSA useses to get compliance.)

A real mix of enterprises that might be involved in the process:

  1. Registered application provider = The AID of the mdoc consists of the registered application provider identifier (RID) ('A0 00 00 02 48') followed by the proprietary application identifier extension (PIX) (’04 00’). There is a very short non-normative description of application testing in E.14.2. It is not helpful.
  2. OpenID Provider (OP) 8.3.3.2.2 configuration information comes from the issuing authority OP in a discover process.
  3. Master list Provider. The decentralized PKI trust model adopted by the mDL requires a mechanism to distribute and disseminate the set of certification authorities certificates from issuing authorities.
  4. Technology provider - provide systems and Apps for issuing authorities to issue mDLs. They appear to be entirely controlled by issuing authority, but also work the mDL verifiers to ensure privacy,

Comparison with VC & DID

Problems

State issued driver's licenses in North America have morphed into the default identity credential for residents whether by design or by circumstance. While it might seem to be helpful to try to break the problem down into the original purpose first, that is no longer an option. Even states that seek to create mobile versions of their own driver's licenses need to address the other purposes that existing legislation requires, such as control of alcohol and prescription medicines among many other existing purposes. So this section takes the practical view about what must be supported on day one of the availability of mobile state issued identification documents, aka driver's licenses.

Privacy

  1. States are sovereign, which means that they are not liable for any action where they have not accepted liability. Current practice indicates that mobile driver's licenses will only be available on smart phone apps that are supplied by the state and typically written under contract by in-state vendors. Any impact on these apps can only be enforced if the state's choose to do so. Still the states are wont to accept standards written to address these apps and so it would be good to see such standards approved for use.
  2. Organizations that accept user private information (aka PII) from the apps may be under state or federal regulations which require meaningful user consent for release. Standards should be written to define what "meaningful user consent" really means.
  3. The biometric information and signature of the holder is optionally included in the mDL. This is information that should never be released from the person that holds it as is stated in an non-normative appendix. It is meant to be used for activation (C.1.6.4), but that is not described and E.12 says that "the mDL reader may implement biometric comparison of the person presenting the mDL to the portrait." The exact meaning of that last sentence is unclear.

References:

Authenticity

  1. Apps can be created that mimic Mobile Driver's Licenses that either fool the user, or are intended to allow the user to fool the acceptor of the data. Where legal obligation exist to check the authenticity of user provided data, it is likely that apps will need to prove their authenticity to the reader. Specifications for proving authenticity should be written. Kantara currently has an implementer's draft of such an assurance statement.
  2. States are likely to require that smartphone apps meet certain criteria and a wont to accept existing specifications rather than write their own.
  3. Readers of Mobile Driver's Licenses were imagined in the ISO 18013-5 standard to be certified. Specifications for the certifications of reader that meet privacy and identity requirements are needed.
  4. In an ideal world the Mobile Driver's License would not even respond to requests for data from readers that were not certified.

User Experience

  • All the examples of issued mobile driver's licenses have focuses on issuing the innocence and perhaps using it to shorten the wait times at airports.
  • One exception is a few effort to use the mobile driver's app as a Smartphone Verifier device, in particular the LA app can work both ways.
  • The following is a use case generator which requires an email address to access. Download our mDL Use Case Template Today!

Solutions

Android

Apple iOS

Testing

Connection Protocols

The language for defining the mDL is RFC 8610 CDDL. Occurrence is the one oddity. It is (1) one of the characters "?" (optional), "*" (zero or more), or "+" (one or more) or (2) of the form n*m for min and max. Also "tstr" = text string and "bstr" = byte string, and tdate is something like 1985-04-12T23:20:50.52Z.

Security

North America

US Federal Regulations

State Wallets

This section is focused on implementations in North America at present.

  • Maryland rolled out mDLs to smartphone users in 2022.60 The credentials are created by taking a photo of the front and back of their physical driver’s license and a short video of themselves, which is then sent to issuing authorities for verification. When the information is verified, the[3] individual may add it to their Google or Apple wallets and, where accepted, use it in place of the physical credential
  • Phoenix AZ Sky Harbor Airport is accepting the AZ mDL at TSA gates. 2022-03-23. and Apple's announcement of that.
  • Florida will also use Apple Wallet 2021-10-14 with a current list of all states supporting apple wallet.
  • Utah was feature in an article on the outlooks for mdl that reported "Ryan Williams, with the Utah Driver's License Division, displays his cellphone with the pilot version of the state's mobile ID on Wednesday, May 5, 2021, in West Valley City, Utah. In Utah, over 100 people have a pilot version of the state's mobile ID, and that number is expected to grow to 10,000 by year's end. Widespread production is expected to begin at the start of 2022." Pam Dixon, executive director of the World Privacy Forum was quoted saying “Most people want some kind of a hard token for their identity, but I don’t know how long that will last, I would imagine that at some point, maybe in a generation, maybe less, that people will accept a fully digital system.”
  • Apple announces first states signed up to adopt driver’s licenses and state IDs in Apple Wallet 2021-09-01 Arizona, Connecticut, Georgia, Iowa, Kentucky, Maryland, Oklahoma, and Utah are among the first states to bring state IDs and driver’s licenses in Wallet to their residents
  • A Delaware mobile ID is now a reality 2021-03-10 The app requires users to capture and upload their physical ID as well as a live selfie to compare against the individual’s file with the Delaware DMV. According to state officials, security features, including strong encryption standards, help fight identity theft. "You don't need passwords or usernames because it's based on your biometrics," said DMV spokesperson Marinah Carver. "You cannot use your mobile ID without inputting either your face or your fingerprint. "We're not sharing that data with anyone else, and it can't be accessed through a third party." In addition to safety, Carver said a contactless ID as part of a digital wallet is also a healthier option in a post-COVID world. The program is voluntary and optional and by law. A person is still required to carry their physical credential as applicable for age and identity verification. "You can try it for a bit," said Carver. "If it's not for you, you can opt back out. It's certainly not a replacement at this time to your physical credential." Carver said the mobile ID has not yet been accepted in a law enforcement setting. The DVM offers apps on Apple and Android stores. It allows both a straight scan of the back of the card, or a privacy preserving one of the bar codes only from the physical care or a QR code. At the user's discretion.
  • Iowa Mobile ID mID is reported by IDEMIA to be the first with UL certification 2021-03-11.
  • Award-winning myColorado™ App Offers Residents a Contactless Digital ID Colorado is the first state in the nation to offer residents the option to electronically transmit digital identification, vehicle registration and proof of insurance to law enforcement. They require the state trooper to show you a QR code first. Interestingly the feature has been extended to allow the phone's camera to scan the QR code, which indicates that the URL just sends the data from the DMV to the trooper's computer. After that the user has the option to give the cop what she wants, or dig out the paper version of all 3 documents. The business use of the mDL is a simple display of the back of the physical DL on the screen of the phone so the merchants can scan the 2d barcode in the same way as with the physical DL. It appears that Colorado was involved in app development at some level. Users add their identification in the myColorado app by taking a selfie with the in-app camera as well as a photo of their physical driver’s license or state ID. Several authentication points, including the selfie, the physical card’s bar code and the resident’s phone number are then verified against Division of Motor Vehicles records. The state government is using an identity verification and management platform from Ping Identity Holding Corp., which is based in Denver. The development of Colorado’s digital-ID application started in early 2019 and has cost about $800,000. Much of the effort has involved interacting with state agencies and merchants on features and adoption. Theresa Szczurek has been Colorado’s chief information officer since January 2020. “We discovered that proof of identification without carrying the wallet was really the killer app,” said Ms. Szczurek, who was chief executive of Radish Systems LLC for nine years before becoming state CIO in January. Radish, based in Boulder, Colo., sells software that integrates visuals into phone calls.
  • Identity Services for myColorado™ Mobile App Powered by Ping Identity report from PING dated 2019-11-12.
  • Louisiana adds vaccine status to digital driver’s License App 2021-05-07
  • NBC News reports that Calvin Fabre, president of Envoc, a software firm in Baton Rouge, Louisiana, that helped develop a mobile app to display digital driver's licenses in Louisiana, said most drivers under 40 won't go back home if they forget their plastic license — "but if they forget their phone, they always turn around." It looks like Envoc programs in .NET and Xamarin.
  • [https://www.govtech.com/news/Digital-Drivers-License-Pilot-Comes-to-Wyoming.html Wyoming is piloting a digital driver's license} base on Gemalto technology. (2017-10-05) for only 100 people. The app isn’t connected to the Internet, so there’s virtually no risk of someone tracking a user’s whereabouts or personal information based on when they open the license, said Steve Purdy, Gemalto’s vice president of state government programs. In order to enter the app, people have to enter a five-digit password or use fingerprint identification. “All it does is show your photo and whether or not you’re 21,” Purdy said. Gemalto provides the existing card license to WY.
  • Ontario program with potential to eliminate our need to carry around physical health cards, driver's licenses and other forms of provincially-issued ID. blogTO (2020-11)

Wallet Spread Sheet

State Code Provider ISO Notes
Federal US TSA-yes there is no national ID process but lots of agencies that issue and verifier Identifiers
ALABAMA AL Idemia eID - has been around since 2015 w/o much use
ALASKA AK
AMERICAN SAMOA AS
ARIZONA AZ 2020 Idemia on Apple yes MID 2021-03 - accepted by TSA at Sky Harbor 2022-03-23 mobile ID app
ARKANSAS AR authorized Digital copy for $10
CALIFORNIA CA own app that's dev @ Spruce +apple, Goog yes + VC, TrueAge 2023 California’s Digital ID Project rolled out early 2024 FREE to all that have a state ID record - 3 separate creds MDOC, VC, TrueAGE 2024-08-18 Governor adds Apple & Google apps
COLORADO CO Thales pilot not at first 2021myColorado is a state-sponsored app that offers proof of identification, age, and address within the state. By 2022-10 they included Apple (ISO?)
CONNECTICUT CT Connecticut is working with Apple to develop virtual IDs 2022
DELAWARE DE Idemia yes 2022 MID - holder MUST be able to present physical card on request
DISTRICT OF COLUMBIA DC
FEDERATED STATES OF MICRONESIA FM
FLORIDA FL Thales 2021 - but then suspended Apple Wallet - Ron Hurtibise South Florida Sun Sentinel 2023-04-02 ** 2024-07-10 Cancelled existing vendor - new one next year
GEORGIA GA Apl Goog Sam yes 2023 Apple Wallet and TSA acceptance (2023-05-18) free 2024 Google added
GUAM GU
HAWAII HI Apple yes 2024-08 Your Hawaiʻi driver’s license and state ID. Terminal 1 Makai Checkpoint of the Daniel K. Inouye International Airport, now accepts the mDL
IDAHO ID
ILLINOIS IL 2025 Current Bill 2024-05
INDIANA IN
IOWA IA Iowa Mobile ID app by Idemia 2921 2023-08-29 with TSAPreCheck can present ID on phone when departing from @fly_CID and @dsmairport = Apple later
KANSAS KS
KENTUCKY KY Apple later 2022
LOUISIANA LA home-grown both holder and verifier claims yes 2018 LA Wallet cost user $6 + fee on verification - very high penetration of market- includes VAX status
MAINE ME
MARSHALL ISLANDS MH
MARYLAND MD Thales on Apl Goog Sam AAMVA 2024.04 2022 free - 2022-12-15 testing with Google 2024-06-24 added Samsung only use appears to be in two large airports - 200,000 downloads
MASSACHUSETTS MA
MICHIGAN MI 2023
MINNESOTA MN
MISSISSIPPI MS Idemia Apple Goog https://www.driverservicebureau.dps.ms.gov/mobile-id/ Apple later
MISSOURI MO 2023 released app and then withdrew it status unclear 2024-09
MONTANA MT 2025
NEBRASKA NE
NEVADA NV
NEW HAMPSHIRE NH
NEW JERSEY NJ 2025
NEW MEXICO NM
NEW YORK NY Idemia yes 2024 2024-06-11 digital version of a state-issued driver license, learner permit or ID on a smartphone.” Governor says the optional ID means New Yorkers will be able to quickly display their IDs and enjoy enhanced security
NORTH CAROLINA NC 2025 2024-06-21 Introduces a bill
NORTH DAKOTA ND 2025
NORTHERN MARIANA ISLANDS MP
OHIO OH Apl yes 2024 Legislation introduced 22-09-27 apple available 2024-07-31 accepted by TSA
OKLAHOMA OK Idemia yes 2022 - scans CARD - Apple later
OREGON OR
PALAU PW
PENNSYLVANIA PA
PUERTO RICO PR Apple later
RHODE ISLAND RI
SOUTH CAROLINA SC
SOUTH DAKOTA SD
TENNESSEE TN 2025 HB556 in 2015 - RFP 2020-12
TEXAS TX
UTAH UT GET & Scytales AAMVA 2024.04 2021 Apple later - test mdl in Alcohol purchases You can use it at Salt Lake Airport (SLC) when TSA PreCheck verifies your identity (2023-03-01) FaceTec
VERMONT VT
VIRGIN ISLANDS VI
VIRGINIA VA home grown 2024 avail. early 2024 already works with TSA
WASHINGTON WA bill aims to allow digital driver’s licenses in Washington state 2023-01 = (DOL) is actively assessing technical infrastructure to maximize interoperability, utility, and privacy protection for mDLs
WEST VIRGINIA WV 2025
WISCONSIN WI
WYOMING WY Thales pilot 2025
Province/Territory code
ALBERTA AB
BRITISH COLUMBIA BC Issued VC for personal ID and court records - little impact
MANITOBA MB
NEW BRUNSWICK NB
NOVA SCOTIA NS
NEWFOUNDLAND NF
NORTHWEST TERRITORIES NT
ONTARIO ON Announced future plans
PRINCE EDWARD ISLAND PE
QUEBEC QC
SASKATCHEWAN SK
YUKON YT
Australia AU mDL VICAL available The states have an agreement for mDL 2024-01-25 Uber accepts mDL for proof of age and presence of person ordering the goods. * the have a root VICAL cert that includes other countries already
New South Wales NSW thales 3.9 million opt-in to mDL 2022 But Problems detected early Also lots of blog chatter about apple & google
EU dreaming with EIDAS 2.0 and EUDIW in 2024 sked for 2026
Austria AT Youniqx ID AG can download eAusausweis app since 2022 and present only within Austria during roadside checks- do not need physical card with you 2024-09 380K activated
China 24-11-11 Select cities in mainland China have already implemented the change to digital ID documents.
Switzerland published on GitHub Mid 2024 Decentralized Identifiers (DIDs) v1.0 according to W3C DID Method: did:tdw
Moldova 24-06-14 released EVO ID app driver’s licenses and registrations, the app contains the government electronic payment module MPay and a document verification module.
Honk Kong 2024-11-11 Mobile driver’s licenses to launch in Hong Kong in 2025
Indonesia Government Mandated ID with mDL among other licenses
New Zealand 2024-06 in Beta mode, asking for your help in testing the app and to provide feedback. Information on how to download and take part in testing the app
North Macedonia MK 2024-11-01 North Macedonia launching digital ID wallet, mDL
Singapore ID
Ukraine 22-12-09 First implementation to not require a plastic card as well

User Problems

Q indicates a question from a real user.

  1. Q Why is there no way to validate [scan] the QR code I was given?
  2. Navigating to Apple Store from Google on a PC hangs.
  3. At a minimum your mobile phone number is known to the State DMV/MID.
  4. The Idemia apps scan the physical card and allow the user to display the front or the bar code from the back of the card. (Not part of ISO as of 2022.)
  5. The current process is a long back and forth (user facing / verifier facing) process. (not the tap and go experience expected.)
    1. Open the Mobile ID app.
    2. Go to the "Me"/home screen.
    3. Tap the "Share" icon next to "Generate privacy code."
    4. Present the QR code for scanning to initiate the connection with the verifying device.
    5. Accept (or Decline) the request to share information under "IDs."

References

  1. Edward Hasbrouck, How the REAL-ID Act is creating a national ID database (2016-02-11) https://papersplease.org/wp/2016/02/11/how-the-real-id-act-is-creating-a-national-id-database/
  2. Edward Hasbrouck, Comments on TSA proposal for decentralized nonstandard ID requirements (2024-10-14 https://papersplease.org/wp/2024/10/14/comments-on-tsa-proposal-for-decentralized-nonstandard-id-requirements/
  3. Jordan Pascale,Maryland Launches Digital Version Of Driver’s License On IPhon DCist, (2022-05-26) https://dcist.com/story/22/05/26/maryland-digital-drivers-license/

Other Material