...
B_BIND I would move F_SELECTION DEFINED and F_AUTHENTICATION earlier
---
new Structure based on yesterdays discussion:
I Initiation/Initiate → what is needed here?
- Request
- Factorselection???
- Appointment
- Code???
A Authentication/Authenticate
- Factor1
- Factor2
- FactorN
- Code (e.g. QR-Code)
V Vetting/Vet
- Eligiblity
- Proof
- Liveness
- Source
- Record
B Binding/Bind
- DigitalID
- Activation
- Confirmation
*F Factor Initiation?/(pre-)registration?
...
In order to request an additional factor the user applicant provides user information.
...
Input:
Output:
REFERENCED FROM: B
I V Identity Vetting
Capture and verify information about a user for identification.
(Optional) I V_SCHEDULING SCHEDULE Identification session arrangement and scheduling
...
Effect on LoA: not applicable
IV_CHECK_ELIBILITY CHECK Check Eligibility of User
...
Effect on LoA: not applicable
I_VET Vet Identity of User
Vet the real-world identity of the user.
This action consists of multiple sub actions.
...
V_PROOF???
Compare the claimed identity (information) which is transmitted by the user or system with user's identity proof (e.g. ID doc, activation code).
Input:
Output:
Effect on LoA: I_VET
V_LIVENESS Perform Liveness Check
In case online identity vetting mechanisms are used (such as video identification, online document upload) a liveness check may be performed to prevent fraud.
Example1: Show ID document besides the head to prove ID document and holder match.
Example2: Upload ID document and real-time recorded selfie.
Input: any mean to show liveness
Output:
Effect on LoA: ???
(Optional)
...
V_SOURCE
Check user's identity proof (e.g. national ID document, employee ID card) against its original source for validity.
Make sure the identity proof is not expired/revooked/invalid/...
Input: user's identity proof
Output: verified identity proof
Effect on LoA: typically higher LoA require this action
I_VET
V_RECORD Record Identity Proof
For accountability purposes (parts of) the identity proof (e.g. last 6 digits of national ID document) is recorded.
Input: identity proof
Output: record
Effect on LoA: not applicable
B Binding
Establishment of a binding between the digital identity of the user and factor
...