Proofing methods
Choosing a route
When Alex opens the clinic portal's sign-up page, there is more than one way through. Alex could scan a driver's license and record a short video at home, wait for a code in the mail, or bring identification to the front desk at the next appointment. All three aim at the same result, a portal account linked to the right patient record, but they gather different evidence and fail in different ways.
In What proofing establishes, the work split into validation, which asks whether evidence is genuine, and verification, which asks whether it belongs to the applicant. Most methods are much better at one of those questions than the other. A complete process combines methods until both are answered well enough for what the service protects.
Inspecting documents
Identity documents are designed to be hard to forge. Printed patterns, holograms, special inks, and a machine-readable zone of encoded text give an inspector several things to check. In person, a trained receptionist can tilt the card, feel the surface, and compare it with known examples.
A photo of a document is weaker evidence. Holograms and texture barely survive a phone camera, and an edited image can look convincing on a screen. Remote document checks look for signs of editing and for a real card held in front of a real camera, but they are working with far less than a person holding the card.
Many passports and some identity cards also contain a chip. The data on it, including the holder's details and photo, is digitally signed by the issuing authority. A phone can read the chip and check that signature. Unlike a printed card, the data cannot be altered without the check failing. Digital identity credentials held in a phone wallet work on a similar principle: the issuer signs the data, and the service checks the signature. Some can also share only the attributes a service asks for, such as confirming that someone is over 18 without revealing a birth date.
A valid issuer signature settles validation, not verification. It shows that the data came from the issuer and was not changed. It does not show who is holding the phone or the passport. Digital signatures explains how such a check works and what it can and cannot conclude.
Checking records
Instead of examining a document, a service can compare the applicant's details with records held elsewhere. An issuing authority can confirm that a license number exists and matches the name and birth date presented. An insurer can confirm an active policy. The clinic's own history, such as a recent visit, is a record too.
These checks are strong validation of the details and weak verification of the person. Anyone who has Alex's details can submit them. That is the problem with knowledge-based verification, where the applicant answers questions generated from records, such as which of four streets they once lived on. Years of data breaches have made many of those answers available to attackers, while real applicants often forget them. Many services now treat this method as too weak to rely on.
Comparing a face
Remote verification commonly compares a live image of the applicant with the photo on a document or chip. This is a one-to-one comparison: is the person in front of the camera the person in this photo? Searching a whole database of faces for a match is a different and far more intrusive activity, and proofing does not need it.
The comparison produces a similarity score rather than a certain answer. A threshold decides what counts as a match, and any threshold allows some false matches and rejects some real people. Accuracy also varies with lighting, cameras, age, and appearance, and can vary across groups of people. A service using face comparison needs a fallback for people the system does not handle well, not a permanent rejection.
Attackers target the camera itself. A presentation attack holds up something that is not a live face: a printed photo, a screen playing a video, or a mask. Liveness checks look for signs of a real, present person. An injection attack skips the camera entirely and feeds prepared or generated video straight into the app. Defending against it depends on checking the integrity of the capture device and software, not only the image.
Face images are biometric data. The clinic should explain how they are used, keep them only as long as the decision requires, and avoid reusing them for anything else.
Confirming an address
The clinic can mail a one-time code to Alex's address and ask Alex to enter it in the portal. Receiving the code shows that the applicant can collect mail at that address. It is cheap and does not require any document or camera.
Where the code goes decides what it proves. If the portal sends it to an address the applicant just typed, it only shows that the applicant can receive mail somewhere. If it sends it to the address already held in the validated patient record, receiving it connects the applicant to that patient. The same principle applies to a code sent by text message: it needs to go to a number from a trusted record, and even then phone numbers can be reassigned or moved to another SIM.
Postal confirmation is slow, and anyone who shares Alex's mailbox could intercept the letter. It is a reasonable piece of evidence alongside others, rather than a complete answer on its own.
People who vouch
Some people cannot use document or camera-based methods. They may not have current photo identification, may not have a suitable phone, or may have details that do not match any record after a life change. A trusted referee gives them another route: someone accountable, such as a clinician who knows the patient or a trained staff member, confirms the applicant's identity and records how they did it.
Supervised remote proofing works similarly. A trained agent joins a video session, watches the applicant handle the document, and asks them to perform actions that are hard to fake in real time. People can notice things automated checks miss, and they can also be persuaded, rushed, or impersonated. Clear procedures, training, and a record of each decision matter as much as the method.
Comparing the methods
Looking at the clinic's options side by side shows why they are usually combined. Each one is strong at a different question.
| Method | Mainly supports | Common weakness |
|---|---|---|
| Document inspected in person | Validation and verification | Staff must be trained, and it requires a visit. |
| Document photographed remotely | Validation | Edited or replayed images, and security features that do not survive a camera. |
| Signed chip or digital credential | Validation | Shows the data is genuine, not who is holding it. |
| Record and issuer checks | Validation of details | Anyone who knows the details can submit them. |
| Knowledge-based questions | Weak verification | Answers are often available from breached data. |
| Face comparison with liveness | Verification | Presentation and injection attacks, and uneven accuracy. |
| Code sent to an address on record | Verification against a record | Slow, and shared or intercepted mail. |
| Trusted referee or supervised session | Verification | People can be deceived and need clear procedures. |
For lab results, the clinic might accept a chip read with a face comparison, or a record check with a mailed code, or an in-person visit. Offering more than one path at the same level of confidence keeps the portal usable for patients whom one method does not suit.
Once Alex's account is linked, the question changes from who Alex is to how the portal will recognize Alex next time. That depends on credentials, the subject of Secrets and key pairs.