Analyzed architecture for bank-driven authorization of narrow actions on verified mDL holders, indicating usability impacts.
This paper analyses a reference architecture in which a relying party (bank) initiates intent, drives attribute and policy requirements, and obtains a cryptographically bound authorization that a specific agent instance may execute a narrowly scoped action on behalf of a holder of a verified ISO/IEC 18013-5 / 18013-7 mobile driver’s license (mDL). The architecture works with or without an IAM platform as intermediary. Version 1.4 incorporates a clearer separation between the baseline demonstration flow and the recommended hardened target, a formal definition of the holder co-signature claim set, refined language on legal non-repudiation and liability, added caution regarding PSD2 SCA and scheme liability-shift applicability to post-authentication agent actions, and clarification of the relationship between classic OAuth and the emerging AAuth protocol draft. The paper examines residual gaps, recommended flow changes, the direct agent-to-resource path, and the impacts of hardening on credential-holder usability, latency, and exceptions management.
No takes yet. Share an insight, caveat, or question.
Juliana Cafik (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: