Recipients are first made aware of the agreement via an email notification which contains a Review and sign button to access the agreement contents:
Enable a method of recipient authentication using government issued documents.
Overview
Powered by advanced machine learning algorithms, Adobe Acrobat Sign's Government ID process empowers companies across the globe with the ability to secure a high-quality authentication of their recipient's identity.
Government ID is a premium identity authentication method that instructs the recipient to upload the image of a government-issued identity document (driver's license, national ID, passport) and then evaluates that document for authenticity.
Supported documents include:
- Global Passport
- All ICAO-compliant passport books
- Driver license / National ID / Residence Permits
Country | Driver's License | Identification Card | Residence Permit |
---|---|---|---|
Australia | Supported | ||
Austria | Supported | Supported | |
Belgium | Supported | Supported | Supported |
Bulgaria | Supported | ||
Canada | Supported | Supported | |
Croatia | Supported | ||
Czech Republic | Supported | ||
France | Supported | Supported | Supported |
Germany | Supported | Supported | Supported |
Hungary | Supported | ||
Ireland | Supported | ||
Italy | Supported | Supported | |
Latvia | Supported | ||
Lithuania | Supported | ||
Malta | Supported | ||
Mexico | Supported | ||
Netherlands | Supported | Supported | Supported |
New Zealand | Supported | ||
Poland | Supported | Supported | |
Portugal | Supported | Supported | |
Romania | Supported | Supported | |
Slovakia | Supported | ||
Spain | Supported | Supported | Supported |
Sweden | Supported | ||
Switzerland | Supported | Supported | |
United Kingdom | Supported | Supported | |
United States of America | Supported | Supported |
The service evaluates the document image for authenticity by validating dozens of elements within the document, including:
- Document structure
- Biographical data
- PDF417 barcode (if applicable)
- Machine-readable zone (if applicable)
- Security features
- Photo zone
- Signature
Availability:
Government ID authentication is available for enterprise ETLA license plans only. VIP license plans don't have access.
Government ID is a premium authentication method that has a per-use charge:
- Transactions must be purchased through your Adobe sales representative.
- Transactions are an account-level resource. All groups consume from the same global pool.
Configuration scope:
The feature can be enabled at the account and group levels.
Biometric comparison: In addition to the document verification, an optional biometric comparison can be enabled upon request. The biometric comparison guides the recipient to take a real-time image (a "selfie") and then evaluates that image relative to the image on the uploaded document. The biometric comparison requires the recipient to respond to on-screen prompts to display "liveness," ensuring previously taken static images are not used.
How it's used
-
The authentication challenge is triggered when the Review and sign button is selected.
-
The recipient is prompted to provide a phone for a smartphone that can accept text messages.
This is required for the image-capturing application that compares the ID document to the government database.
- A 15-minute time limit to complete the verification process starts once the email link is selected.
- Once the text message is sent, a blue message appears indicating the message is sent, and the link in that message has a five-minute expiration.
Megjegyzés:This phone number step is skipped if the signature process is started on a smartphone.
-
A text message is delivered to the provided phone number with a link to the ID service.
Once the link is selected, the recipient can authenticate with either a Driver's License / ID card or a Passport.
Megjegyzés:During the process of gathering and verifying the document content, the original notification page displays a status message that the details are being verified:
-
When using a driver's license or ID card, the app prompts the recipient to take an image of:
- The front of the card
- The back of the card
- Themselves (Optional based on account configurations)
If using a Passport, only one image of the passport is required.
-
Optional real-time self-image for biometric comparison to the document image.
If the real-time "selfie" option is enabled for the account, the recipient is instructed to perform some live action to demonstrate that the recipient is real and reacting to the prompts of the image capture application.
When the "liveness" test is passed, the app captures the image and performs the biometric comparison to the identity document's image.
-
Once the identity is verified, the recipient can interact with the agreement on the original device where the email was opened.
- The recipient's name, as presented on the ID, is imported to the signature field and can not be edited.
The recipient has five attempts to verify their ID successfully. If they all fail five attempts, the agreement is canceled, and the sender is notified.
Layer 1 - Document validation:
The first layer of technology provides a seamless and secure method to validate an identity document presented in a digital transaction, ensuring that the document is genuine and unaltered.
Combining a best-in-class capture experience with a proven ID document verification engine ensures trusted digital identity proofing with a seamless user experience.
Government ID verification is available for all Latin-based languages and supports thousands of international and domestic identity documents, including:
- Passports
- ID Cards
- Driver's Licenses
To achieve reliable results, the service delivers each of the following:
- Guided document capture - Users are instructed on how to take a quality photo for optimal processing.
- Document classification – "Computer vision" algorithms recognize and classify thousands of government-issued documents, allowing for reliable data extraction and document validation.
- Data extraction - Going beyond simple optical character recognition, this service deconstructs the document and analyzes the content of each field.
- Evaluation of authenticity elements - A combination of artificial intelligence techniques validates dozens of elements within the identity document, including:
- Document structure - Physical attributes of the ID document are evaluated for the correct size, material, shape, color, layout, etc.
- Biographical data - Printed data that identifies the individual is evaluated for font usage, color, acceptable values, etc.
- PDF417 barcode (if applicable) - OCR results of the biodata from the front are compared with the data extracted from the PDF417 barcode at the back.
- Machine-readable zone (if applicable) - The Machine Readable Zone (MRZ) printed area is checked for font usage, presence, check digits, etc.
- Security features - Both visual and invisible security features of the ID are checked for presence, position, content, etc.
- Photo zone - Portrait, or main picture, is evaluated for having a human face, orientation, color, etc.
- Signature - The signature section is checked for presence, font type, matching with known samples, etc.
Layer 2 - Biometric comparison:
The second layer of authentication matches the portrait extracted from the ID document with a "selfie" from the user through a biometric facial comparison, affirming that the user submitting the ID document is its rightful owner.
Anti-spoofing techniques
- Video frame analysis ensures the user can take a quality selfie in optimal capture conditions.
- While capturing the selfie, the recipient is instructed to perform an action (e.g., Smile!) to demonstrate "liveness."
- Lighting, focus, and alignment are some of the conditions evaluated.
Configuring the Government ID authentication method when composing a new agreement
When Government ID is enabled, the sender can select it from the Authentication drop-down to the right of the recipient's email address.
If Government ID isn't on the list, then Government ID isn't enabled for the group from which the user is sending the agreement, and an admin will have to enable it.
Consumption of premium authentication transactions
Government ID authentication is a premium authentication method that has a per-recipient charge.
- Government ID transactions must be purchased and installed before the option can be used.
- Government ID transactions are consumed per recipient configured with the Government ID authentication method.
- One agreement configured with three recipients, two of which authenticate with Government ID, consumes two authentication transactions.
- Authentication transactions are deducted from the account total when the agreement is sent to authoring (as a draft agreement) or sent to the first recipient (as an in-progress agreement).
- Canceling a draft agreement refunds the authentication transactions to the account's total.
- Canceling an in-progress agreement does not refund any authentication transactions.
- Changing an existing authentication method to Government ID consumes one license.
- Changing the authentication method from Government ID does not refund the authentication transaction.
- Changing the authentication back and forth with Government ID only ever consumes one transaction (for any given recipient).
Signer Identity Report (SIR)
Acrobat Sign does not retain the identity information gathered during a Government ID authentication by default. However, account-level admins can request to store the identity information in the Acrobat Sign system via the Signer Identity Report (SIR).
The SIR contains data collected during Government ID verification (e.g., signers’ Government ID image, face image, phone number, data extracted from Government ID, etc.).
The SIR:
- persists alongside the audit report
- can be accessed by the Sender using the Manage page interface or a v6 REST API call
- can be destroyed through the same data governance or GDPR delete actions that delete the audit report
Audit Report
The audit report clearly indicates that the recipient's identity was verified with a Government ID authentication:
The reason is explicitly stated if the agreement is canceled due to the recipient's inability to authenticate.
Best Practices and Considerations
- If second-factor signature authentication isn't required for your internal signatures, consider using the Acrobat Sign Authentication method instead of Government ID to reduce the friction of signing and save on the consumption of the premium authentication transactions.
- Government ID:
- Isn't intended for regulated or high-value electronic signature workflows and use cases.
- Cannot identify all fraudulent or "fake" identification documents.
- May not replace the need for human review.
Configuration Options
Enable the authentication method under Send Settings
Access to Government ID authentication requires that a contract is in place for an annual volume of recipients. The option isn't visible in the administrator's interface until this is configured on the back end.
Once the purchase of the identity transactions has been entered into the system, admins will find the controls for exposing Government ID authentication on the Send Settings page with the other identity authentication methods.
Enable the method by checking the Government ID authentication box.
- Once the method is enabled, the admin can set Government ID authentication as the default value for new agreements. The option is not visible until the method is explicitly enabled:
Optional "Selfie" biometric comparison
Customers who would like to include the biometric comparison between the identity document and a real-time selfie of the recipient can contact the support team to have the feature enabled.
Automatic agreement cancellation when a recipient fails to authenticate
The Government ID service is configured to allow up to four consecutive failed attempts to authenticate the recipient's identity. After the fifth failure, the agreement is automatically canceled in the system, and the agreement owner is notified of the agreement being canceled due to an authentication failure.
The option to configure this threshold is not in the customer-facing interface. Account admins can request that the cancellation threshold be adjusted to another value through the support team.