Understanding Digital Identity Credentials
What Is a Digital Identity Credential?: A digital identity credential is a cryptographically verifiable government or institutional credential that lives on a device instead of in a physical wallet. Mobile Driver's Licenses, the EUDI Wallet, national digital IDs, and ePassports are all part of this category. Each one is digitally signed by its issuing authority, so a verifier can confirm the credential is genuine and untampered using cryptography alone, typically without any live connection to the issuer at the moment of verification.
These credential types share the same core principles: cryptographic signatures instead of visual inspection, selective disclosure of only the data a transaction requires, and device-local verification that works even without an internet connection. The sections below walk through each major credential type, followed by a look at how verification actually works underneath all of them.
Mobile Driver's Licenses (mDL)
mDL Overview: Your Mobile Driving License (mDL) is an ISO compliant driving license application that resides on your mobile device. Standardized by ISO/IEC 18013-5, it provides the same core function as your physical driving license but with enhanced capabilities for digital interactions and a strong focus on protecting your personal information.
What is a Mobile Driving License (mDL)?
Your Mobile Driving License (mDL) is a digital version of your physical driver's license that lives on your smartphone. Built to international standards, it is designed to be recognized and verified across countries and systems while giving you control over your personal information.
Unlike traditional digital copies or photos of licenses, an mDL uses advanced cryptographic technology to prevent forgery, protect your data, and ensure that only you can authorize the sharing of your information.
Key Benefits of mDL
Key benefits of the mDL:
Convenience: Carry your driving license securely on your mobile device, making it readily accessible whenever you need it
Complete Data Control: You have the power to decide precisely what information to release to a verifier during any transaction
Cryptographic Security: Advanced cryptographic mechanisms protect against forgery, cloning, and eavesdropping, ensuring the integrity and authenticity of your data
Privacy by Design: Built with privacy principles like data minimization and unlinkability to safeguard your personally identifiable information and usage patterns
Global Interoperability: International standards enable use and mutual recognition across different countries and verification systems
The mDL Ecosystem: Key Players
Several essential entities work together to ensure your mDL operates securely and effectively:
mDL Holder (You)
You retain complete control over your data and provide consent for all information sharing
You receive clear notifications about data requests and can actively confirm or deny sharing
Issuing Authority (IA)
Official organizations like Department of Motor Vehicles that issue your driving license
Responsible for digitally signing your mDL data and ensuring secure provisioning
Maintains the infrastructure for the most current version of your credentials
mDL Verifiers and Readers
Law enforcement officers, retail clerks, airline agents, and other authorized personnel
Use specialized devices or services to retrieve and verify your mDL data
Encouraged to request only the minimum necessary data for their specific use case
VICAL Providers
Organizations that compile and distribute lists of trusted Issuing Authority certificates
Serve as trust anchors for mDL readers to authenticate data origin and integrity
Your mDL Data Elements
Your mDL contains carefully organized information designed for flexible, privacy-respecting sharing:
Mandatory Information
Core identification details: name, birth date, photo
License information: issue/expiry dates, document number, issuing authority
Driving privileges: vehicle categories, restrictions, conditions
Optional Information
Physical characteristics: height, weight, eye/hair color
Location data: place of birth, resident address
Biometric templates for enhanced security
Privacy-Enhanced Features
Age Attestations: Verify "age over 21" without revealing exact birth date
Selective Disclosure: Choose exactly what information to share
Domestic Customization: Country-specific data elements when needed
Enhanced Capabilities: Online Interactions (ISO/IEC TS 18013-7)
Building on the ISO/IEC 18013-5 foundation, this companion standard introduces expanded functionality:
Online Presentation: Present your mDL to verifiers over the internet
OpenID Integration: Direct presentation to online verifiers using standardized protocols
API Integration: Integrates into broader digital credential ecosystems
Real-World Applications
Your mDL serves you in numerous scenarios:
Traffic Stops: Secure, contactless presentation to law enforcement
Age Verification: Privacy-preserving age confirmation for purchases
Airport Security: Faster identity verification for travel
Online Services: Remote identity verification for digital services
Vehicle Rentals: Quick, secure credential verification
EUDI: the European Digital Identity Wallet
The European Digital Identity (EUDI) Wallet is the credential framework created under the EU's eIDAS 2.0 regulation. It gives every EU member state a standardized way to issue digital identity and attribute credentials, such as national ID, driving credentials, and other attestations, into a wallet that citizens control on their own device.
Like an mDL, an EUDI Wallet credential is digitally signed by its issuing member state and presented to relying parties using standards-based protocols, so verification does not depend on any single central system. A verifier requesting a credential only receives the specific attributes a transaction requires, following the same data minimization principle used across digital identity standards.
What verifiers need to accept EUDI Wallet credentials:
Support for the presentation protocols used by EUDI Wallets, so credentials can be requested and received in a standardized format
The ability to validate the issuing member state's cryptographic signature and trust chain
A device-local verification path that does not require routing citizen data through a third party
National Digital IDs
Beyond driver's licenses, many countries are issuing national digital identity credentials directly, independent of any single regional framework. MIDNI, Spain's national digital identity, is a production example: it is accepted today at 300+ locations across Spain, verified the same way as other digital identity credentials, cryptographically and on-device.
National digital ID programs like MIDNI typically follow the same architecture as mDL and EUDI Wallet credentials: an issuing government authority digitally signs the credential, the holder keeps it in a wallet app on their device, and a verifier checks the signature and requested attributes locally, without a live connection back to the issuer being required to complete a check.
ePassports
An ePassport is a physical passport with an embedded chip, standardized under ICAO 9303. The chip stores the holder's identity data along with a digital signature from the issuing government, which allows the passport's authenticity to be verified cryptographically rather than relying on visual inspection of the physical document alone.
Because the signature and data live on the chip itself, ePassports can be verified fully offline. ONEPROOF verifies ICAO 9303 ePassports offline on ONEPROOF EDGE hardware (Patent Pending), reading the chip and validating its cryptographic signature without requiring a network connection to complete the check.
How Verification Works
Across mDL, EUDI Wallet, national digital IDs, and ePassports, verification follows the same underlying model: cryptographic checking performed locally on the verifying device, not a lookup against a remote database.
1. Device Engagement
Proximity Methods: Tap a device to an NFC reader, scan a QR code, or read an ePassport chip directly
Device Retrieval: Direct exchange using Bluetooth Low Energy, NFC, or Wi-Fi Aware - no internet connection required
Secure Communication: An encrypted channel is established between the holder's device or document and the verifier's reader
2. Cryptographic Signature Verification
The verifier checks the credential's digital signature against the issuing authority's public key or trust list
Any tampering with the underlying data invalidates the signature, so forged or altered credentials are rejected
This check happens on the verifying device itself and can complete without an active internet connection
3. Selective Disclosure
The holder is shown exactly what data has been requested and must consent before anything is shared
Only the specific attributes requested, such as an age threshold rather than a full birth date, are disclosed
Ephemeral session keys prevent linking one verification to another
Advanced Security Features
Digital identity credentials incorporate multiple layers of security protection:
Cryptographic Protection
Session Encryption: All communications encrypted using ephemeral keys
Digital Signatures: Data digitally signed by the issuing authority for authenticity
Anti-Cloning Technology: Private keys stored only within the credential holder's device prevent unauthorized duplication
Privacy Protection
Informed Consent: Clear, just-in-time notifications about data requests
Data Minimization: Share only essential information for each transaction
Unlinkability: Ephemeral session keys prevent tracking across transactions
No Usage Tracking: Issuing Authorities cannot monitor credential usage patterns
Getting Started with Digital Identity Credentials
Here's what you need to know to get started:
Check Availability: Verify if your state or country offers mDL, EUDI Wallet, or national digital ID services
Download the App: Install your jurisdiction's official wallet application
Secure Setup: Follow the secure enrollment process with identity verification
Learn the Features: Familiarize yourself with privacy controls and sharing options
Frequently Asked Questions
What is a digital identity credential?
A digital identity credential is a cryptographically verifiable government or institutional credential held on a device, such as a phone or wallet app. Mobile Driver's Licenses, EUDI Wallet attestations, national digital IDs, and ePassports are all examples. Each is digitally signed by its issuing authority and can be verified offline using cryptography, without contacting the issuer at the moment of verification.
What is the EUDI Wallet?
The European Digital Identity (EUDI) Wallet is a credential framework defined under the EU's eIDAS 2.0 regulation. It lets EU member states issue digital identity and attribute credentials that can be verified cryptographically across borders and industries, using standards-based presentation protocols.
Is an ePassport the same as a physical passport?
An ePassport is a physical passport with an embedded chip, standardized under ICAO 9303. The chip stores your identity data and a digital signature from the issuing government, which lets a verifier check the passport's authenticity cryptographically, offline, without needing a live connection to the issuing country.
Is mDL accepted everywhere?
mDL acceptance is growing rapidly. While not yet universal, many states, law enforcement agencies, and businesses are implementing mDL verification capabilities. Always carry your physical license as backup until full adoption is achieved.
What if my phone battery dies?
Your mDL is designed with power-efficient protocols. Many implementations allow basic functionality even with very low battery. However, carrying your physical license as backup is recommended.
Can my digital identity data be tracked?
Digital identity standards, including mDL and the EUDI Wallet, specifically prohibit tracking. Using ephemeral keys and unlinkability features, your usage patterns cannot be monitored by issuing authorities or verifiers.
Contact Information
Questions about digital identity credentials, implementation, or privacy? Contact us:
General Inquiries: info@oneproof.com
Technical Support: support@oneproof.com
Privacy Questions: privacy@oneproof.com
Partnership Opportunities: partnerships@oneproof.com
Stay Updated
The digital identity landscape continues to evolve with new credential types, expanded acceptance, and enhanced security measures. Visit our Understanding Digital Identity Credentials page regularly for the latest information about mDL, EUDI, national digital IDs, ePassports, and how they are verified.
Digital identity credentials replace physical documents with cryptographically verifiable, privacy-preserving equivalents.
