Comparative analysis of mDL to current CIP techologies New

Note

The considerations below have been replicated from NIST Special Publication (SP) 1800-42A Initial Public Draft, Digital Identities - Mobile Driver’s License (mDL): Accelerating Development and Adoption of Digital Identity for Financial Institutions.

This page summarizes security, privacy, and usability implementation considerations when compared to the following CIP documentation models as defined below:

Non-Documentary - Self-asserted data (e.g. name, address, tax identifier) checked against third party data sources, SMS verification, and email verification.

Government Identification Check - Self-asserted data coupled with software-driven document authentication against an uploaded image of a physical identification card, SMS verification, email verification.

Government Identification Check (Biometric Match) - Self-asserted data coupled with document authentication and a biometric comparison of the user to their presented evidence, SMS verification, email verification.

Government Identification Check (mDL) - Presentation of signed mDL data and local holder authentication, SMS verification, email verification, party validation of an SSN.

Comparative Analysis of CIP Techniques: Security

CIP Model

Non-Documentary

Gov ID Check

Gov ID Check (Biometric)

Gov ID Check (mDL)

Security Considerations

Accuracy & Authenticity

Low – manual data entry provides no confidence that attributes are associated with the individual presenting them. There is no ability to confirm the authenticity of any evidence.

Moderate – Document analysis provides some confidence in authenticity of a DL.

Moderate – Live document capture and liveness biometric comparison provide increased assurance Gov ID is legitimate.

High – mDL verification provides means to mitigate risk associated with identity theft or fraudulent account opening by leveraging cryptographic security features embedded within the digital credential that can attest to the authenticity and integrity of the information presented.

User Verification & Binding

Low – SMS verification provides minimal binding to the legitimate users and are subject to sim swap, phishing, and account compromise.

Low – SMS/Email verification provides minimal binding to the legitimate users. Government ID image can be easily generated using artificial intelligence.

Moderate – User verification and binding confidence increases with sufficient presentation attack detection (PAD) controls.

High – Authentication to the mobile device through biometrics and other local authentication factors, this an increased degree of confidence that 1) the evidence is real and not forged, and 2) in the possession of the individual who is represented by the credential.

Common Attack Types

  • Phishing

  • Reuse of compromised PII

  • SIM Swapping

  • Guessing attacks

  • Automated & scripted data entry

  • Phishing

  • Reuse of compromised PII

  • SIM Swapping

  • Deepfakes

  • Deepfakes

  • Image/Video Injection

Refer to Threats to mDL Verification Environments section.

Threat Scale

High – Attacks have been and will continue to be highly scalable in nature due to automation and minimal ability to verify the end user’s identity.

High – The quality of generative image AI continues to improve. Scaling attacks become more feasible as the AI compute price decreases.

Moderate – An attacker would have to defeat PAD mechanisms, requiring sophistication and/or higher level of resources.

Low – Attacks would require a high degree of sophistication in one or more mDL ecosystem pillars – issuance, presentation, and verification.

Comparative Analysis of CIP Techniques: Privacy

CIP Model

Non-Documentary

Gov ID Check

Gov ID Check (Biometric)

Gov ID Check (mDL)

Privacy Considerations

Notice & transparency

Low – Customers may not know which third party sources are verifying their data; additionally, risk scoring and fraud management based on user submitted data and transaction data may not be clear to the user and may not have appropriate mechanisms for redress.

Low – The customer may consent to the use of their ID in onboarding processes but rarely knows what happens to the data captured of the ID, which parties are processing it, and what happens to unnecessary data captured during the process.

Moderate – A customer may not predict how much information is exposed when they share a government ID, vs. how much data is required.

Also, a customer may not have visibility into what happens to their biometric data after verification.

High – Customers see which specific attributes are requested from their mDL before sharing with the FI, and they maintain a record in their mobile wallet of their transactions for easy review.

Biometrics are performed locally on the device and not provided to the FI.

User control & selective disclosure

Low – While customers execute data entry, the accuracy and validation processes are outside of their control. Inaccurate or incomplete data at third party services are not easily corrected and the processes for doing so are outside of user control.

Low – Customers have no control over which attributes are shared when images are captured of identity evidence (e.g., driver’s license or passport). Even when paired with limited retention and privacy policies, more user attributes are exposed than required for the transaction.

Low – Customers lack choice in what data they provide; government ID and selfie are required. They can’t control which specific attributes are shared, as they provide entire documents with more information than is required. Their biometric template is typically shared with a 3rd party vendor for review, reducing user control over their own biometric data.

High – Individuals only share the specific attributes that are required for identity verification.

Biometric verification can be performed locally on the device and not provided to the FI.

User verification

Low – There is minimal ability to confirm the participating individual is the one represented by the data. Even with SMS verification, which is highly phishable, these approaches leave past victims of PII theft and privacy breaches highly vulnerable.

Low – There is minimal ability to confirm the participating individual is the one represented by the data.

Moderate – Customers provide biometric data before they’re otherwise verified; selfie does add a layer of protection, but there’s some risk that the individual in the ID is not the same individual applying for the account.

High – Authentication occurs before attributes are sent; local biometric authentication provides user verification.

Data retention/exposure

Low – Since there is no cryptographic signing to support authenticity and accuracy, all data goes to third party data sources for validation. This increases the exposure of customers’ personal data.

Third parties may have long retention periods for customers’ personal data.

Low – Since there is no cryptographic signing to support authenticity and accuracy, all data goes to third party data sources for validation. This increases the exposure of customers’ personal data.

Overcollection of data on the government ID exposes the user to increased risks if images of IDs are compromised or the proofing services are compromised.

Low – Biometric authentication is done server-side (rather than locally)—and typically is done by a third-party vendor, not the financial institution. This biometric matching in a centralized location by a third-party vendor is greater exposure for the customer. It may be unclear what happens to the biometric data after verification.

High – Provides the option for local biometric authentication, reducing the amount of data the user sends server-side. Integrity and authenticity of the mDL attributes come from being cryptographic signed, alleviating the need for third party data validation. Only those attributes needed for identity verification are collected.

Comparative Analysis of CIP Techniques: Usability

CIP Model

Non-Documentary

Gov ID Check

Gov ID Check (Biometric)

Gov ID Check (mDL)

Usability Considerations

Effectiveness

High – this method is effective if the third-party data sources are accurate and up-to-date, and customers provide reliable information.

High – this method effectively confirms a customer’s identity by verifying a physical document.

Very High – by combining document verification with biometric liveness checks, this process is a robust and effective.

Very High – this method effectively verifies a customer’s identity using a secure and standardized digital identity credential.

Efficiency

High – the process is typically fast and efficient, requiring only the customer’s input to verify their identity via SMS and email.

Moderate - customers must upload a form of Gov ID, which may involve scanning or taking a photo, potentially adding time to the verification process.

Low to Moderate – this process requires customers to upload a Gov ID and perform a biometric liveness check, which can complicate and prolong the verification process.

High – this process is relatively fast and seamless, as customers can present their mDL digitally.

Satisfaction

Moderate - while the process is convenient, some customers may be skeptical about the security and safety of this method.

Moderate - while the process is generally straightforward, some users may struggle with issues related to document quality or formatting.

Low to Moderate - while this process is secure, some users may face difficulties with document quality or formatting. Additionally, some may find the biometric liveness check intrusive or encounter technical issues.

High - customers with compatible mobile devices and mDLs may find the process both convenient and secure.

User Experience

The process is familiar to most users and consists of only a few steps. The user experience is usually straightforward. However, some users might be concerned about the lack of tangible verification, which can impact their trust in the method.

The user experience is generally acceptable, but document quality or formatting issues could impact it. Some customers might also be concerned about the security and privacy of uploading sensitive documents.

Issues related to document quality, formatting, and technical challenges during the biometric liveness check could impact the user experience. However, if executed correctly, the process can be both seamless and secure.

The user experience is generally positive, as the process is streamlined and secure. However, users without compatible devices or mDLs, or those not familiar with mDLs, may face difficulties or distrust the process.

Summary

Ensuring third-party data sources are accurate and up-to-date is crucial to reduce false negatives or false positives. Clear explanations of the verification process and data protection measures can help alleviate user concerns. Implementing additional verification steps can further enhance security and build user trust.

It’s important to make the document upload process user-friendly, wit clear guidance on acceptable document types and formats. Ensuring secure transmission and storage of sensitive documents is essential. Feedback mechanisms can help customers resolve upload issues, reducing frustration and potential drop-off.

To ensure a positive user experience, the document upload process and biometric liveness check should be user-friendly with clear instructions. Reducing technical challenges and providing feedback mechanisms can help customers troubleshoot problems, decreasing frustration. Clearly explaining the purpose and benefits of the biometric liveness check can help alleviate user concerns and increase acceptance.

Ensuring compatibility with a range of devices and platforms is crucial. Clear explanations of the benefits and requirements of using mDL verification can also help educate customers and encourage adoption. Providing alternatives for those without compatible devices or mDLs is essential for a positive onboarding experience.