1. Verification Scenario
Target context2. Wallet Platform & Protocol
Cryptographically hide unrequested fields via signed attribute digests
Enforce reader certificate trust chain & rotating MAC addresses
Audit Diagnostic Engine
Optimal privacy preservation active. Using ISO/IEC 18013-5 signed attribute tokens, the verifier only receives a cryptographic boolean confirmation that you are 21 or older. Your legal name, physical address, and exact date of birth remain sealed in hardware storage.
Data Payload Transmitted Over Proximity Channel
Payload encoding: CBOR / mdocWhy Digital License Privacy Matters
As reported by technology analysts and security researchers, digital IDs in Apple Wallet and Google Wallet leverage standard ISO/IEC 18013-5 mdoc profiles. Unlike handing an officer or a bouncer a physical plastic card—revealing your home address, exact birthdate, organ donor status, and driver license number at once—the digital mdoc architecture allows selective disclosure.
However, privacy risks remain if untrusted reader hardware queries unauthorized namespaces, or if users present credentials without biometric consent. Furthermore, unauthenticated BLE broadcast channels can theoretically allow commercial foot-traffic tracking unless ephemeral MAC rotation and strict mutual reader authentication are enforced.