DEMONSTRATION LEGAL DATA · Licence XXX-YYY is demonstration data and must be replaced with official evidence before production publication.
Mobile-ID · Digital Trust Platform
ISO/IEC 27001:2022Security policyService policyService status
MOBILE-ID TRUST SERVICES

Trust Infrastructure

Cryptographic, identity, time, certificate-status, evidence and preservation components supporting Trusted Delivery.

REFERENCE ARCHITECTURE

Layered architecture with separation of duties

The design separates identity, delivery, evidence generation, cryptographic keys, trusted time and audit preservation.

Access channels
PortalWeb / Mobile
REST APIOAuth 2.1 / mTLS
AS4eDelivery
ConnectorsERP / DMS / BPM
WebhookSigned events
Identity layer
Sender IDVNeID / eID / OIDC
Recipient IDPerson / Legal entity
AuthorityRepresentation
PolicyIAL / AAL
ConsentPurpose binding
Delivery core
S-ERDSSubmission
RoutingPolicy engine
R-ERDSConsignment
HandoverPush / Pull
StatusLifecycle events
Evidence layer
Event modelETSI-aligned
Evidence EngineHash / metadata
eSealService signature
TSATrusted time
VaultLong-term archive
Trust infrastructure
HSMKey protection
PKICertificates
OCSP / CRLStatus
AuditTamper-evident logs
BCP / DRContinuity
TRUST COMPONENTS

Trust infrastructure components

Production endpoints and certificates are published only after security review and approval.

HSM

Hardware Security Module

Protects eSeal/TSA keys with multi-person control and operation logs.

TSA

Time-Stamping Authority

Attaches trusted time to events and evidence packages.

PKI

eSeal & Certificates

Signs evidence and manages certificate chains and key rollover.

OCSP

OCSP / CRL

Checks certificate status at verification time.

OID

OID Registry

Identifies policies, profiles and evidence types.

WORM

Evidence Vault

Immutable storage, retention, legal hold and integrity checks.

PUBLIC TRUST DATA

Production registry and endpoints

Version 3 provides the structure without inventing endpoints, certificates or OIDs.

Published endpoints

OCSPPENDING PRODUCTION
CRLPENDING PRODUCTION
TSA PolicyPENDING PRODUCTION
eSeal CertificatePENDING PRODUCTION

Publication controls

  • Do not expose keys, secrets or internal endpoints
  • Fingerprints require trusted-source reconciliation
  • Announce key rollover before transition
  • Retain expired certificate history for old evidence verification