IDMETRIX
← Secure Identity
IDMS

Digital Identity System Architecture

Components relationship and data flow scheme.

Six stages carry a credential from the counter where an applicant first presents themselves to the border desk where the document is read, and on to the day it is revoked. Scroll down: each stage opens as you reach it, and its components unwrap one after the other along the flow.

Colour code
  • Enrollment & quality
  • Workflow orchestration
  • Data preparation
  • PKI infrastructure
  • Production & encoding
  • Issuance
  • Verification
  • Biometric matching
  • Lifecycle management
  1. 1. Enrollment
  2. 2. Data Preparation
  3. 3. Production
  4. 4. Issuance
  5. 5. Verification
  6. 6. Lifecycle Management
Stage 1

Enrollment

Biometrics and demographics are captured, scored while the applicant is still present, searched against the population, and the application is moved to approved.

Stage 2

Data Preparation

Approved application data becomes data groups, the Security Object Document is signed, and the keys that sign it never leave the hardware security module.

Roots of trust
Stage 3

Production

The signed package reaches the personalization floor: printed, encoded, read back and compared against what was meant to be written.

Stage 4

Issuance

The document reaches the holder — in the hand, on the phone, or both — and the record moves to activated.

Stage 5

Verification

At the border the chip is opened, its signature checked against the country that issued it, the chip itself proven genuine, and only then is biometric data released.

Behind the check
IDMS components at this stage
Stage 6

Lifecycle Management

A credential stays managed after issuance: corrected, replaced, and when it has to be, withdrawn and published as revoked.