Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Trusted Palm ID / identity services

Bind the same person,
not just two references.

Control source identity, enrollment session and palm capture together. This is a reference workflow, not an issued backend contract.

Every transition has a gate.

  1. 01Purpose
  2. 02Source identity
  3. 03Session & continuity
  4. 04Capture palm
  5. 05Quality / PAD
  6. 06Protect reference
  7. 07Duplicate review
  8. 08Binding & evidence

State model and evidence.

Proposed model identifiers; reconcile with the deployment contract.

FromToConditionReference
PENDING_PROOFINGPROOFEDSource verification succeeds within the authorized scopeproofingRef
PROOFEDCAPTURE_PENDINGFresh session; same participant; permitted devicesessionRef + operatorRef
CAPTURE_PENDINGQUALITY_ACCEPTEDQuality and PAD meet the configured profilecaptureRef + profileRef
QUALITY_ACCEPTEDBINDING_REVIEWProtected reference; scoped duplicate reviewbiometricRef + reviewRef
BINDING_REVIEWACTIVEBinding requirements, purpose and processing authority remain validbindingRef + evidenceRef
ANY_PENDINGEXPIREDExpired session; do not reuse the old capturereason + sessionRef
ANY_PENDINGREJECTEDParticipant mismatch, refusal or untrusted devicereason + reviewRef
QUALITY_ACCEPTEDDUPLICATE_REVIEWPossible duplicate; do not auto-merge recordsscopedCandidates + reviewer
ACTIVESUSPENDEDSuspend on request or riskreason + authority
SUSPENDEDREENROLL_REQUIREDRe-proofing and fresh capture requirednewSessionRef
ACTIVEREVOKEDRevoke binding; deletion is a separate lifecycle actionrevocationRef

Test exceptions before activation.

A local rule illustration; no biometric input and no RAR/C06 call.

Select illustrative conditions
Simulation resultACTIVE

All illustrative conditions pass.

No real binding is created.

Continuity & recovery controls.

RiskRequired behavior
A verifies, B presents a palmStop binding; re-establish participant identity and record the reason.
Expired session or interrupted networkDo not reuse the old capture. Start a fresh session and re-check conditions.
Possible duplicateRemain within tenant/purpose; send to an authorized reviewer, never auto-merge.
Person declinesStop biometric capture and offer an appropriate alternative.

Start with a controlled PoC.

Define purpose, devices, risks and acceptance criteria before scaling.

Search Trusted Palm ID

Selected interface