Mobile-ID / Certificates & scope
RAR/C06 · eID / SSO / ShareInfoISO/IEC 24745:2022
Trust service catalogue

Authenticate

Use a biometric result within an authentication flow, adding factors according to risk.

May an authenticated session be established?

Establish a kiosk session after verification and policy checks.

Purpose & scope

Use a biometric result within an authentication flow, adding factors according to risk.

Identity is bound to an authoritative source within an organization. Search population and access rights must be configured in advance.

Identity source
HIS / SIS / HRM / VNeID / CCCD
Data exchanged
Scoped references; no returned biometric template
Evidence
Service, purpose, session, device, policy, result

From request to decision

Checks are bound to the same session.

  1. 01Authenticate the relying system
  2. 02Check scope & purpose
  3. 03Capture & assurance
  4. 04Authenticate
  5. 05Evaluate policy
  6. 06Create evidence

Deployment-specific assurance

Do not use one threshold indiscriminately across devices and contexts.

ComponentEvaluation requirementEvidence
PADAttack scope and evaluated configurationDevice / algorithm evaluation report
PerformanceThreshold, test population, gallery, environmentVersioned evaluation profile
DeviceFresh session, certificate and revocation stateDevice and configuration records
Authority & purposeProcessing basis and resource authorizationPolicy version

Workflows using this service

When palm verification cannot continue

Review the draft API contract →

Search Trusted Palm ID

Selected interface