Regula, a developer renowned for its identity verification technologies, has unveiled server-side processing of mobile driver's license (mDL) data in its latest version of the Regula Document Reader SDK.
This feature is geared towards enhancing fraud prevention by validating digital IDs within a secure backend environment, rather than depending on user devices alone.
The introduction comes as the adoption of mobile IDs expands across the US and other regions, increasing the necessity for organisations to verify digital credentials under zero-trust security frameworks.
Identity verification
Conducting identity verification on user devices involves inherent risks, as these devices are outside organisational control. Threats such as malware, rooted phones, and modified apps can compromise identity checks before the results are relayed to backend systems.
Moreover, safeguarding sensitive elements like trust lists and cryptographic keys is more challenging under such conditions, raising the chances of data tampering before it reaches backend systems.
Moving mDL verification into a trusted environment
Regula Document Reader SDK utilises advanced document recognition and parsing capabilitiesIn order to reduce these risks, Regula has incorporated server-side verification of mDLs that adhere to ISO/IEC 18013-5 in the updated Regula Document Reader SDK. This feature facilitates secure server-side reprocessing of mDL data, ensuring that essential validation steps occur within a trusted environment. Thus, data gathered on a user’s device is securely transferred and revalidated on the server through a trusted public key infrastructure and signature verification processes, safeguarding the authenticity and integrity of the identity data throughout the verification cycle.
To achieve consistent verification outcomes across various document formats and issuing authorities, the Regula Document Reader SDK utilises advanced document recognition and parsing capabilities. The system is supported by Regula’s extensive identity document template database, the world's largest, encompassing over 16,000 templates from 254 countries and territories. This ensures precise processing of both traditional and digital IDs, including newer formats like mDLs.
Designed for high-risk and regulated environments
This new feature targets sectors where rapid and reliable driver's license verification is crucial for preventing fraud, complying with regulations, or ensuring safety, such as in mobility and ride-sharing, car rental, travel and aviation, and age-restricted commerce.
“Digital identity ecosystems are changing. Physical IDs, mobile credentials, and biometric checks increasingly operate together, which means organisations need to trust every part of the process. Server-side mDL verification helps move critical checks into a controlled environment, strengthening fraud prevention by ensuring identity decisions rely on authentic, untampered data. At the same time, it helps preserve identity signal integrity across the entire verification flow, enabling organisations to make trusted server-side decisions rather than relying solely on client-side inputs,” states Ihar Kliashchou, Chief Technology Officer at Regula.
Regula, a global developer of identity verification solutions, has introduced server-side reprocessing of mobile driver’s license (mDL) data in its updated Regula Document Reader SDK.
This new feature helps organisations strengthen fraud prevention by validating digital IDs in a controlled backend environment rather than relying solely on user devices.
The release comes as mobile IDs gain adoption across the US and other countries, while organisations face growing pressure to verify digital credentials under zero-trust security models.
Identity verification
Identity verification performed on user devices carries inherent risks, as these environments remain outside organisational control. Malware, rooted phones, or tampered apps can interfere with identity checks before results reach backend systems.
In addition, sensitive elements such as trust lists and cryptographic keys are more difficult to safeguard under such conditions. As a result, data collected on the user side may be compromised before reaching backend systems.
Moving mDL verification into a trusted environment
To mitigate these risks, Regula has added server-side verification of mDLs issued in accordance with ISO/IEC 18013-5to the latest version of its Regula Document Reader SDK. This capability enables secure reprocessing of mDL data on the backend, ensuring that critical validation steps take place in a controlled and trusted environment rather than relying solely on device-side checks.
In practice, this means that data captured on a user’s device is securely transmitted and revalidated on the server using trusted public key infrastructure and signature verification mechanisms. This approach helps ensure that identity data remains intact, authentic, and resistant to manipulation throughout the verification process.
To support consistent results across different document formats and issuing authorities, Regula Document Reader SDK also relies on extensive document recognition and parsing capabilities. Regula’s solution is backed by the company’s proprietary, world’s largest identity document template database, covering over 16,000 templates from 254 countries and territories. This enables accurate processing of both physical and digital IDs, including emerging formats such as mDLs.
Designed for high-risk and regulated environments
The new capability is designed for industries where fast, reliable driver’s license verification directly affects fraud prevention, compliance, or safety, including mobility and ride-sharing services, car rentals, travel and aviation, and age-restricted commerce.
“Digital identity ecosystems are changing. Physical IDs, mobile credentials, and biometric checks increasingly operate together, which means organisations need to trust every part of the process. Server-side mDL verification helps move critical checks into a controlled environment, strengthening fraud prevention by ensuring identity decisions rely on authentic, untampered data. At the same time, it helps preserve identity signal integrity across the entire verification flow, enabling organisations to make trusted server-side decisions rather than relying solely on client-side inputs,” says Ihar Kliashchou, Chief Technology Officer at Regula.