Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

Proofing methods

Choosing a route

When Alex opens the clinic portal's sign-up page, there is more than one way through. Alex could scan a driver's license and record a short video at home, wait for a code in the mail, or bring identification to the front desk at the next appointment. All three aim at the same result, a portal account linked to the right patient record, but they gather different evidence and fail in different ways.

In What proofing establishes, the work split into validation, which asks whether evidence is genuine, and verification, which asks whether it belongs to the applicant. Most methods are much better at one of those questions than the other. A complete process combines methods until both are answered well enough for what the service protects.

Inspecting documents

Identity documents are designed to be hard to forge. Printed patterns, holograms, special inks, and a machine-readable zone of encoded text give an inspector several things to check. In person, a trained receptionist can tilt the card, feel the surface, and compare it with known examples.

A photo of a document is weaker evidence. Holograms and texture barely survive a phone camera, and an edited image can look convincing on a screen. Remote document checks look for signs of editing and for a real card held in front of a real camera, but they are working with far less than a person holding the card.

Many passports and some identity cards also contain a chip. The data on it, including the holder's details and photo, is digitally signed by the issuing authority. A phone can read the chip and check that signature. Unlike a printed card, the data cannot be altered without the check failing. Digital identity credentials held in a phone wallet work on a similar principle: the issuer signs the data, and the service checks the signature. Some can also share only the attributes a service asks for, such as confirming that someone is over 18 without revealing a birth date.

A valid issuer signature settles validation, not verification. It shows that the data came from the issuer and was not changed. It does not show who is holding the phone or the passport. Digital signatures explains how such a check works and what it can and cannot conclude.

Checking records

Instead of examining a document, a service can compare the applicant's details with records held elsewhere. An issuing authority can confirm that a license number exists and matches the name and birth date presented. An insurer can confirm an active policy. The clinic's own history, such as a recent visit, is a record too.

These checks are strong validation of the details and weak verification of the person. Anyone who has Alex's details can submit them. That is the problem with knowledge-based verification, where the applicant answers questions generated from records, such as which of four streets they once lived on. Years of data breaches have made many of those answers available to attackers, while real applicants often forget them. Many services now treat this method as too weak to rely on.

Comparing a face

Remote verification commonly compares a live image of the applicant with the photo on a document or chip. This is a one-to-one comparison: is the person in front of the camera the person in this photo? Searching a whole database of faces for a match is a different and far more intrusive activity, and proofing does not need it.

The comparison produces a similarity score rather than a certain answer. A threshold decides what counts as a match, and any threshold allows some false matches and rejects some real people. Accuracy also varies with lighting, cameras, age, and appearance, and can vary across groups of people. A service using face comparison needs a fallback for people the system does not handle well, not a permanent rejection.

Attackers target the camera itself. A presentation attack holds up something that is not a live face: a printed photo, a screen playing a video, or a mask. Liveness checks look for signs of a real, present person. An injection attack skips the camera entirely and feeds prepared or generated video straight into the app. Defending against it depends on checking the integrity of the capture device and software, not only the image.

Face images are biometric data. The clinic should explain how they are used, keep them only as long as the decision requires, and avoid reusing them for anything else.

Confirming an address

The clinic can mail a one-time code to Alex's address and ask Alex to enter it in the portal. Receiving the code shows that the applicant can collect mail at that address. It is cheap and does not require any document or camera.

Where the code goes decides what it proves. If the portal sends it to an address the applicant just typed, it only shows that the applicant can receive mail somewhere. If it sends it to the address already held in the validated patient record, receiving it connects the applicant to that patient. The same principle applies to a code sent by text message: it needs to go to a number from a trusted record, and even then phone numbers can be reassigned or moved to another SIM.

Postal confirmation is slow, and anyone who shares Alex's mailbox could intercept the letter. It is a reasonable piece of evidence alongside others, rather than a complete answer on its own.

People who vouch

Some people cannot use document or camera-based methods. They may not have current photo identification, may not have a suitable phone, or may have details that do not match any record after a life change. A trusted referee gives them another route: someone accountable, such as a clinician who knows the patient or a trained staff member, confirms the applicant's identity and records how they did it.

Supervised remote proofing works similarly. A trained agent joins a video session, watches the applicant handle the document, and asks them to perform actions that are hard to fake in real time. People can notice things automated checks miss, and they can also be persuaded, rushed, or impersonated. Clear procedures, training, and a record of each decision matter as much as the method.

Comparing the methods

Looking at the clinic's options side by side shows why they are usually combined. Each one is strong at a different question.

Proofing methods at the clinic
MethodMainly supportsCommon weakness
Document inspected in personValidation and verificationStaff must be trained, and it requires a visit.
Document photographed remotelyValidationEdited or replayed images, and security features that do not survive a camera.
Signed chip or digital credentialValidationShows the data is genuine, not who is holding it.
Record and issuer checksValidation of detailsAnyone who knows the details can submit them.
Knowledge-based questionsWeak verificationAnswers are often available from breached data.
Face comparison with livenessVerificationPresentation and injection attacks, and uneven accuracy.
Code sent to an address on recordVerification against a recordSlow, and shared or intercepted mail.
Trusted referee or supervised sessionVerificationPeople can be deceived and need clear procedures.

For lab results, the clinic might accept a chip read with a face comparison, or a record check with a mailed code, or an in-person visit. Offering more than one path at the same level of confidence keeps the portal usable for patients whom one method does not suit.

Once Alex's account is linked, the question changes from who Alex is to how the portal will recognize Alex next time. That depends on credentials, the subject of Secrets and key pairs.

Try it in the Lab

PUT IT INTO PRACTICE

Check your understanding

Try these questions before moving on. If an answer isn't right, use the feedback and try again.

0 of 2 answered correctly

Enable JavaScript to answer these questions and save progress in this browser.

QUESTION 1 OF 2The portal confirms an applicant by mailing a code. Which address should it use?

QUESTION 2 OF 2A phone reads a passport chip and confirms that the data is signed by the issuing authority. What is still needed?

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

Learn identity