The Humble QR Code: A Technical Deep-Dive and Its Multispectral Industrial Applications |
Chapter 36 | Industry 23 - Government - Digital IDs |
Brief Summary: This chapter explores how QR codes have become a foundational technology for modern government-issued digital identity documents, enabling secure, privacy-preserving verification without requiring a central database lookup. It provides a technical yet accessible overview of how national and state ID cards incorporate QR codes containing signed public keys and cryptographically protected data, allowing verification apps to read and validate credentials entirely offline. The narrative explains the cryptographic principles that make this possible and highlights how this approach enhances privacy through selective disclosure. Through detailed examples from U.S. state mobile driver's license programs, federal initiatives like the U.S. passport digital ID pilot, and the work of standards bodies like NIST, the chapter demonstrates how QR codes are transforming identity verification across America. |

|
Introduction: The Paper Wallet in the Digital Age |
For generations, proving one's identity has meant reaching for a physical wallet and pulling out a plastic card: a driver's license, a passport, a national ID. This simple act, repeated millions of times daily, is the foundation of countless transactions---from buying alcohol and boarding a flight to opening a bank account and picking up a package. But these physical cards have profound limitations. They are easily lost, stolen, or forged. They force the holder to reveal far more personal information than is necessary for a given transaction. And they rely on a visual inspection by a human verifier, a process that is slow, subjective, and increasingly insufficient in a world of sophisticated counterfeiting. |
The digital identity revolution promises to solve these problems. A digital ID, stored securely on a smartphone, offers the potential for enhanced security, unparalleled convenience, and robust privacy protection. But a critical question arises: how can a verifier---a bouncer at a bar, a TSA agent at an airport, a bank teller---trust a digital ID displayed on a screenHow can they know it is authentic and has not been tampered with, especially without a direct connection to a government database |
The answer, elegantly, is the QR code. In the world of government digital IDs, the QR code is not just a convenient way to share data; it is a cornerstone of a sophisticated cryptographic architecture. When you see a QR code on a digital ID card---whether on a smartphone screen or printed on a physical card---it is not simply a representation of the data printed on the front. It is a container for a digitally signed payload that includes a public key and verified identity attributes. This QR code can be scanned by a verification app, which uses the embedded public key to cryptographically validate the signature, confirming that the data is authentic and has not been altered. Crucially, this entire process can happen entirely offline, device-to-device, without the need for a central database lookup. This ensures privacy, speed, and availability even in areas with poor internet connectivity. |
This chapter provides a technical deep-dive into this application. We will explore the cryptographic principles---public-key infrastructure, digital signatures, and hashing---that make offline QR code verification possible. We will explain the international standards, particularly ISO 18013, that govern how these digital credentials are structured and presented. And, most importantly, we will journey across the American identity landscape, looking at real-world examples from state mobile driver's license (mDL) programs, federal pilots for digital passports, and the standards development work of the National Institute of Standards and Technology (NIST). We will see how the QR code is evolving from a simple barcode into a secure, privacy-enhancing tool that is reshaping how Americans prove who they are. |

|
Part I: The Cryptographic Foundation of Trust |
To understand how a QR code on a digital ID can be trusted without a central database, one must understand the basic principles of public-key cryptography. |
1.1. Public and Private Keys: A Digital Signature |
Imagine two keys: a public key and a private key. These are mathematically linked but unique. The private key is kept secret by the owner---in this case, the government agency that issues the ID. The public key can be shared freely with anyone. |
When a government issues a digital ID, it creates a digital signature. This is done by taking the identity data (name, date of birth, license number, etc.) and creating a mathematical summary, called a hash, of that data. This hash is then encrypted using the government's private key. The result is the digital signature. This signature is then embedded in the QR code along with the data itself and the government's public key. |
When a verification app scans the QR code, it performs a simple but powerful verification process: |
1. It decrypts the signature using the public key that was embedded in the QR code. |
2. It independently computes a hash of the identity data in the QR code. |
3. It compares the decrypted signature (which contains the original hash) with the newly computed hash. |
If the two hashes match, the verification app knows two things with mathematical certainty: first, the data has not been tampered with (because any change would result in a different hash), and second, the data was signed by the holder of the private key (the government), confirming its authenticity. This is the essence of a 'signed public key' on a QR code. |

|
1.2. Offline Verification: The Power of Self-Contained Trust |
This cryptographic approach is what enables offline verification. Because the QR code contains all the necessary components---the data, the signature, and the public key---the verifier's device does not need to connect to a central database to validate the ID. The trust is 'self-contained' within the QR code itself. |
This is a profound advantage. It ensures that verification can happen anywhere, instantly, without relying on an internet connection or a centralized system that could be a point of failure or a privacy risk. A bouncer at a club, a TSA agent at an airport, or a merchant at a pop-up market can all verify an ID without needing to call back to a government server. This speed and reliability are critical for real-world adoption. |

|
Part II: The Standards: ISO 18013 and the mDL Framework |
The cryptographic principles described above are implemented in a specific international standard: ISO/IEC 18013. This standard defines the technical specifications for mobile driver's licenses (mDLs) and other digital identity documents. It provides the blueprint for how a digital ID is structured, how it is presented, and how it is verified. |
2.1. ISO 18013-5: In-Person Verification |
The most widely used part of the standard is ISO 18013-5, which focuses on in-person presentation scenarios. This is where a holder and a verifier are physically present with each other. The standard outlines two primary ways the digital ID can be presented: |
QR Code Engagement: The holder opens their digital wallet app and taps a 'Share ID' button. The app generates a QR code on the phone's screen. This QR code does not contain the user's personal data. Instead, it contains an 'engagement payload'---a set of information that tells the verifier's device how to establish a secure, encrypted connection. This can include a random identifier, a list of supported communication methods (like Bluetooth Low Energy, or BLE), and ephemeral cryptographic material that is only valid for that single session. |
NFC (Tap-to-Share): Alternatively, the holder can tap their phone against a near-field communication (NFC) reader, similar to how mobile payments work. This also establishes a secure connection. |
Once the connection is established via the QR code (or NFC), the verifier's device and the holder's device perform a secure handshake. They exchange cryptographic keys to create an encrypted channel. Then, the verifier can request specific pieces of information from the holder's wallet. The holder is prompted to consent to sharing each piece of information. This is the 'selective disclosure' feature, where a user can share only their age (e.g., 'Over 21') without revealing their full name, address, or license number. |
After the holder consents, the requested data is transmitted over the encrypted channel to the verifier's device. The verifier's app then validates the data using the cryptographic signatures embedded in the credential, confirming its authenticity. This entire process, from scanning the QR code to receiving a verified result, takes only a few seconds. |

|
2.2. ISO 18013-7: Remote (Online) Verification |
A newer part of the standard, ISO 18013-7, extends the framework to remote or online scenarios. This is where the holder and verifier are not physically co-located, such as when a user is verifying their identity to access a government service website or complete an age-restricted online purchase. |
In this model, the QR code takes on a different role. It is often used to initiate the process by linking the user's phone to the verifier's online portal. The user scans a QR code displayed on the website, which opens a secure session between the mobile wallet and the online service. The same principles of encrypted communication and selective disclosure apply, but the data is exchanged over the internet rather than a local device-to-device connection. This is a critical capability for enabling the full potential of digital IDs in the online world. |

|
Part III: The American Application Landscape |
The United States does not have a single national digital ID. Instead, it has a patchwork system driven by federal pilots and state-level mobile driver's license (mDL) programs. The QR code is the common thread tying these diverse initiatives together. |
3.1. Federal Initiatives: The U.S. Passport Digital ID Pilot |
The federal government is entering the digital identity space through a significant pilot program. The U.S. Department of State, in coordination with the Transportation Security Administration (TSA) and Google, has launched a pilot allowing U.S. citizens to create a digital version of their passport, known as an 'ID Pass,' which can be stored in Google Wallet. |
This digital ID is derived from a physical U.S. passport or passport card. Users scan their physical passport using their phone's camera, and a signed digital credential is securely stored in their Google Wallet. Currently, this digital passport ID is accepted by the TSA at select airport security checkpoints for domestic travel. At the checkpoint, the traveler taps their phone on a TSA reader or scans a QR code, and the encrypted identity data is securely transmitted and verified. This digital ID serves as a substitute for a physical ID in this specific context. |
This pilot is a crucial test case for the broader adoption of digital identity at the federal level. It demonstrates the technical feasibility of using a smartphone as a secure identity document and leverages the same QR code and NFC technologies defined in the ISO 18013 standard. The program is expected to expand alongside the growing acceptance of mobile driver's licenses under TSA's digital ID rules. |

|
3.2. State Mobile Driver's Licenses (mDLs): The Primary U.S. Implementation |
The most visible and widespread application of government digital IDs in the U.S. is the mobile driver's license, or mDL. As of 2025, 19 states and Puerto Rico have fully active mDL programs, with several more in the process of launching. Each state takes a slightly different approach, but they all share a common foundation in the ISO 18013 standard and the use of QR codes for secure, offline verification. |
New York: A Model of Privacy-First Design |
New York launched its Mobile ID in June 2024, and within months, over 170,000 New Yorkers had enrolled. The New York DMV has been particularly vocal about the privacy advantages of its mDL design. |
The New York Mobile ID generates a QR code when the user taps 'Share ID.' The QR code contains no personal data; it simply establishes a secure, encrypted connection between the user's phone and the verifier's device. This connection can happen without any internet or Wi-Fi signal, ensuring the process is fast and private. The user is then prompted to consent to sharing only the specific information the verifier requests. For example, if the user is buying alcohol, they can consent to share only their age, not their full name or address. The verifier's device receives only the data the user agreed to share and a confirmation that the mobile ID has been verified. Critically, the New York DMV emphasizes that it cannot track where or when a user presents their Mobile ID---this information is stored only on the user's phone. |

|
Delaware: Contactless and Cryptographically Secure |
Delaware's mDL program, developed with IDEMIA, is another example of the technology's real-world application. Delawareans can download the Mobile ID app and, after verifying their identity, add their digital ID. The app is secured by a PIN or biometrics (FaceID or TouchID). When needed, the user can display a QR code or barcode for scanning. The verification app reads the cryptographically protected data and confirms its authenticity. This allows for contactless transactions where the user never has to hand over their phone to the verifier. |
Maryland: A Full-Service Verification Ecosystem |
Maryland offers a comprehensive mDL ecosystem. The state's Motor Vehicle Administration (MVA) provides both the digital ID for residents and a dedicated verification app called 'Mobile ID Check by MD' for businesses and other relying parties. |
This app allows a merchant or a bouncer to verify an mDL by scanning a QR code or using an NFC tap. It supports verification of mDLs from Maryland and many other states, including Arizona, California, Colorado, Georgia, Louisiana, and New York. The app is designed with a 'privacy-first' architecture, storing no personally identifiable information (PII) on the verifier's device. It also restricts screenshots and screen recordings for added security. This shows a mature ecosystem where both the issuer and the verifier have the tools to make the system work. |
The Verification Apps: IDEMIA's Mobile ID Verify |
The private sector has stepped up to provide verification solutions for these state programs. IDEMIA, the global leader in Augmented Identity and the 1 issuer of physical driver's licenses in the U.S., has developed the 'Mobile ID Verify' app. This free app allows any business or individual to scan and verify digital IDs from various states. |
The app operates entirely offline, using device-to-device communication over Bluetooth Low Energy (BLE) and data encryption. It adheres to the ISO 18013 standard, ensuring that verification is secure and trusted. It can be customized to meet regulatory needs, such as verifying a customer is over 18 for tobacco or 21 for alcohol. This app is a key piece of infrastructure, making mDL verification accessible to businesses of all sizes, from large retail chains to a small corner store. |

|
3.3. The Role of NIST and Federal Cybersecurity Guidance |
The National Institute of Standards and Technology (NIST) is playing a crucial role in guiding the development and implementation of digital identity in the U.S. NIST is not an enforcement agency, but its standards are widely adopted as best practices across the federal government and the private sector. |
NIST has been actively involved in the development of mDL standards and guidance. Its National Cybersecurity Center of Excellence (NCCoE) has a dedicated mDL project, and NIST authors have contributed to explaining the technical nuances of mDL presentation, such as the differences between the in-person (ISO 18013-5) and online (ISO 18013-7) standards. |
Furthermore, NIST's 'Cybersecurity Insights' blog has published detailed articles on verifiable digital credential presentation, breaking down how the cryptographic technologies work and the challenges implementers face. This federal guidance provides the technical framework and assurance that state programs and private sector implementers can rely on, fostering interoperability and trust across the fragmented U.S. identity landscape. |

|
3.4. Innovative Extensions: Offline Biometric QR Codes |
A fascinating extension of the QR code concept for identity verification is being pioneered by companies like FaceTec. They have developed a technology called the 'UR Code,' which is an offline, privacy-preserving biometric QR code. |
This technology embeds a 3D face map into a QR code. The user's phone captures a live 3D face scan, which is then cryptographically signed and encoded as a QR code. A verifier can scan this QR code and, using the public key embedded within it, confirm that the face map matches the person standing in front of them. This allows for a form of offline biometric verification without transmitting any biometric data over a network or storing it in a central database. |
Former federal agents have spoken about the potential of this technology for use cases like interim licenses, law enforcement IDs, and ID bracelets for vulnerable individuals. It represents a significant step toward highly secure, privacy-preserving identity verification that leverages the QR code's offline capabilities. |

|
Part IV: The Workflow in Action: A Secure, Private Interaction |
Let's bring this technology to life with a detailed scenario of a real-world interaction. |
The Scenario: A young professional named Sarah is at a concert venue in New York City. She wants to buy a beer. She has a New York Mobile ID on her phone. She approaches the bar, which uses a verification app (like IDEMIA's Mobile ID Verify) on a tablet. |
Step 1: Initiation: |
Sarah unlocks her phone and opens her Mobile ID app. She taps the 'Share ID' button. The app generates a dynamic QR code on her screen. This QR code does not display her name, date of birth, or any personal information. It is simply an invitation to establish a secure connection. |
Step 2: Scan and Connect: |
The bartender opens the verification app on the tablet and selects 'Scan QR Code.' They point the tablet's camera at the QR code on Sarah's phone. The app reads the code. Using the information in the code, the two devices (Sarah's phone and the tablet) negotiate a secure, encrypted Bluetooth connection. This connection is created using ephemeral keys that are only valid for this single transaction. |
Step 3: Request and Consent: |
The verification app sends a request to Sarah's phone: 'Requesting: Age Verification (Over 21).' Sarah's phone displays a pop-up: 'This transaction is requesting to verify your age. Do you consent to share your age' Sarah taps 'Yes.' The phone sends a cryptographically signed attestation that Sarah is over 21 over the encrypted Bluetooth connection. It does not send her name, address, or license number. |
Step 4: Verification: |
The verification app receives the attestation. The app validates the cryptographic signature using the public key that was embedded in the original QR code (or that it obtains during the secure session). The app confirms the data is authentic and has not been tampered with. The tablet displays a green checkmark: 'Age Verified.' The bartender sees this and serves Sarah her beer. |
Step 5: Completion: |
The transaction is complete. The secure connection between the two devices is closed. The verification app deletes all data from the transaction. No personal information about Sarah has been stored on the tablet. The DMV does not know she was at the concert or that she bought a beer. The entire process took less than 30 seconds, was completely secure, and preserved Sarah's privacy. |

|
Part V: The Benefits and the Road Ahead |
The adoption of QR code-based digital IDs in the United States is bringing significant benefits to individuals, businesses, and governments alike. |
Enhanced Security: Digital IDs are significantly more secure than physical cards. They are protected by the phone's security features (PIN, fingerprint, FaceID) and use strong cryptography to prevent forgery and tampering. If a phone is lost or stolen, the digital ID can be remotely deactivated or is protected by the phone's lock screen. |
Unparalleled Privacy: The selective disclosure feature is a game-changer. It allows individuals to prove specific attributes (like age or citizenship) without revealing their full identity. This minimizes the amount of personal information that is shared and reduces the risk of identity theft. |
Convenience and Speed: A digital ID is always with you, assuming you have your phone. It enables contactless, frictionless transactions that are faster than pulling out a physical ID and waiting for it to be inspected. |
Interoperability: The adoption of the ISO 18013 standard means that, in theory, an mDL from one state should be verifiable in another state or even internationally. The TSA's acceptance of mDLs from multiple states is a key step towards this vision. |
The road ahead is one of expansion and standardization. While state mDL programs are proliferating, full interoperability and nationwide acceptance are still a work in progress. The federal government, through NIST and the TSA, is playing a key role in encouraging this. The U.S. Cyber Trust Mark program for IoT devices is an interesting parallel that could pave the way for more government use of QR codes for consumer information and security validation. As more Americans adopt digital IDs and more businesses and government agencies accept them, the QR code's role as the foundational technology for this trust will only become more entrenched. |

|
Part VI: Conclusion |
The QR code, a technology that began as a simple tool for tracking automotive parts, has evolved into a cornerstone of modern identity verification. In the context of government digital IDs, it is far more than a convenient way to share a number. It is a secure container for cryptographic keys and signed data that enables trust without a central authority, privacy without revealing more than necessary, and offline verification without the need for an internet connection. |
Detailed Summary |
This chapter has explored the foundational role of QR codes in enabling secure, privacy-preserving digital identities for U.S. government applications. We began by examining the limitations of physical identity documents and the need for a more secure, convenient, and private alternative. |
We then delved into the cryptographic principles that make the QR code solution so powerful. Public-key cryptography, digital signatures, and hashing create a system where a QR code can contain a self-verifying payload. The data, signed with a government's private key, can be validated by anyone with the public key, which is also embedded in the QR code. This enables offline verification without a central database lookup, a critical feature for speed, reliability, and privacy. |
The chapter then explored the international standards framework, particularly ISO 18013-5 and ISO 18013-7, which govern the presentation and verification of mobile driver's licenses and other digital credentials. We explained how a QR code initiates a secure 'device engagement' that leads to an encrypted channel for selective data sharing, where a user can consent to sharing only the specific information a verifier needs. |

|
The core of the chapter focused on real-world American applications: |
Federal Initiatives: The U.S. Passport Digital ID pilot, which allows citizens to add a digital version of their passport to Google Wallet for use at select TSA checkpoints, represents a significant federal step forward. |
State mDL Programs: The detailed examples from New York, Delaware, and Maryland showcased the practical implementation of mDLs. New York's privacy-first design, where a QR code establishes an encrypted connection with zero personal data and mandatory user consent for every share, was highlighted. The availability of verification apps, such as IDEMIA's Mobile ID Verify and Maryland's Mobile ID Check, demonstrates the maturation of the ecosystem. |
NIST Guidance: The work of the National Institute of Standards and Technology in developing standards and providing cybersecurity guidance was identified as a crucial element that underpins trust and interoperability. |

|
We also looked at innovative extensions like FaceTec's biometric UR Code, which pushes the QR code into the realm of offline biometric verification. |
Through a detailed workflow scenario, we saw how a QR code enables a secure, private, and frictionless transaction where a user proves their age without revealing their identity, all while the government issuer remains unaware of the transaction. |
In conclusion, the QR code has evolved into a powerful tool for digital identity in America. It is the key that unlocks a future where individuals have greater control over their personal information, businesses can verify identity with confidence, and governments can issue credentials that are more secure, convenient, and privacy-enhancing than anything that can be printed on a piece of plastic. The humble square has become a powerful symbol of trusted, decentralized identity. |