Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Trusted Palm ID / identity services

Protect references.
Secure bindings.
Separate purposes.

Mobile-ID confirms that the Trusted Palm ID data-organization model follows ISO/IEC 24745:2022. Deployment versions, testing and exceptions require separate supporting records.

Separate stores. Govern the binding.

Within the customer environment

Biometric vault

biometricRef

Reference protected under the profile.

bindingRefControlled binding

Business identity store

subjectRef

HIS / SIS / HRM / eGov

Tenant + purpose scoped. No cross-customer sharing by default.
Capture image
No default retention; exceptions need approval
Evidence
Minimal references, no image or palm payload
Lifecycle
Retain, revoke, re-enroll, delete
Explore the data model →

Six stages. A clear boundary at each one.

Choose a stage for inputs, processing, exceptions and evidence.

PROCESSING MODEL · 01/06

RGB / IR images

Capture within an authorized session.

Input
Person, purpose and fresh capture session.
Processing location
Device sensor by model; the profile determines edge or server processing.
Controls
Device identity, participant continuity, session expiry and approved transport.
Output
Capture data and session reference, not an identity decision.
Lifecycle
No default image retention; exceptions need an approved purpose and time limit.
Exceptions and evidence
Failed capture: retry or assistance. Record outcome/configuration without putting images in logs.
Explore the workflow and records →Subject to the approved deployment profile

Source identity, biometric references, business records and evidence have separate boundaries. Revocation and deletion remain controlled after each decision.

Explore data lifecycle →

Data classes & responsibilities.

Actual retention periods need organizational approval. Do not use a single period for every data class.

DataPurposeLocationAccessRetentionLifecycle
Palm capture imagesQuality, PAD, extractionProcessing memory; retention exceptions require approvalSession-scoped processing engineNo default retention; explicitly time-bound exceptionsClear buffers; inspect logs, dumps and backups
Biometric referenceScoped matchingSeparated biometric vaultAuthorized matching servicePurpose and approved retention scheduleRevoke/renew under the scheme; delete replicas
Identity referenceResolve the subjectDomain identity storeBinding service / source systemOnly permitted minimum attributesUnlink and process data-rights requests
Binding recordBind biometric and identity referencesVersioned binding storeAuthorized API; reviewerLifecycle and change reasonsRevocation differs from deletion; minimal evidence retained
Notice & processing basisDocument purpose and authorityOrganization governance storePrivacy functionNotice version and applicable basisHandle withdrawal; record lawful exceptions
Device recordCapture contextDevice management storeAuthorized operations teamModel, firmware and state; no palm payloadDocument revocation, replacement and retirement
Evidence / auditTrace decisionsAccess-controlled evidence storePurpose-bound audit accessMinimized; no raw image, template or source tokenDeletion / legal hold under approved schedule

Describe biometric protection precisely.

Do not equateCorrect interpretation
Template = anonymous dataA reference may still identify a person and needs protection and processing authority.
Encryption = impossible reversalDo not infer non-invertibility/unlinkability. The mechanism and evaluation must support the claim.
Revocation = changing the palmRevoking a binding/credential does not alter biology. Renewability depends on the protection scheme.
Encrypted storage = encrypted-domain matchingDescribe decryption and engine-processing boundaries according to the real deployment.

Map controls without inventing clause numbers.

ObjectiveReference controlEvidence to review
Confidentiality / integrityVault, access permissions, protected channelConfiguration and test report
Secure BR / identity bindingSession, participant continuity, binding versionState matrix, review and audit event
Lifecycle / revocationRe-enrollment, revocation, replica deletionTest results and retention practice

Start with a controlled PoC.

Define purpose, devices, risks and acceptance criteria before scaling.

Search Trusted Palm ID

Selected interface