The MOSIP “Standard”

I’ve previously discussed the false impression that standards achieve recognition via a free, fair, universal consensus. In truth, standards are bullied through the process by one or more interested parties, who then shut out competitors that don’t comply with their…I mean, the industry’s standard.

Meanwhile, companies that don’t comply with the standard ridicule it and say how the standard stifles innovation and brings the whole industry down.

For example, in a few years smartphone manufacturers will complain that the EU’s adoption of USB-C as a universal common charger standard will cause the EU to lag behind when new charging technologies emerge.

Which brings us to MOSIP.

What is MOSIP?

So what does this acronym stand for, and what does it mean?

“The Modular Open Source Identity Platform was established in 2018 to support governments in providing its residents with an official form of the most important human asset – identity.

“As nations around the world proceed on their digital transformation journeys towards true digital economies, a robust and secure national ID system is the crucial first step. With a foundational national ID system in place, a government can build effective civil registries, and service delivery systems, serving the population in a myriad of ways. Among other benefits, robust systems like these enable faster disaster relief, climate resilience, ease of starting new businesses, and better access to financial inclusion, healthcare, and education.”

Established and incubated in Bangalore, India, MOSIP is aligned with the United Nations Sustainable Development Goals and supported by the Gates Foundation and others.

In case you didn’t get the drift, the MOSIP people aren’t regular visitors to Mar-a-Lago.

But their principles align with the goals of many biometric companies that have chosen to list their MOSIP-compliant products on the MOSIP Marketplace.

The marketplace categorizes MOSIP-compliant solutions into six categories:

  • Registration devices.
  • Authentication devices.
  • ABIS (Automated Biometric Identification Systems).
  • SDKs (Software Development Kits).
  • Print devices.
  • Labs.

I won’t list all the MOSIP-compliant solution providers, but there are many of them, including two of the “big three” biometric firms, NEC and Thales.

Any questions?

MOSIP but not MOSIP

I hear a question from the back row from a guy wearing a multicolored wig.

Falco in “Rock Me Amadeus.” From https://youtu.be/cVikZ8Oe_XA.

After all, the third of the “big three,” IDEMIA, has advertised that it provides MOSIP solutions.

“The Togolese Agency for Identification, ANID-TOGO, has partnered with IDEMIA and Atos to build a national biometric eID system based on the Modular Open Source Identity Platform (MOSIP). IDEMIA and Atos will design, build, test, and run a biometric national eID solution for Togo based on iris, face, and fingerprint recognition technology.”

Sounds impressive…until you scan the MOSIP Marketplace and find no listed solutions from IDEMIA or ATOS.

Because “based on” does not equal “compliant with.”

I can say that Bredemarket’s seven-question process is based upon some marketing standard or another, but that doesn’t mean that an independent third party has certified my compliance, or even stated its conformance.

So why doesn’t IDEMIA offer MOSIP-compliant solutions?

Honestly, I don’t know. I haven’t had regular official contact with IDEMIA in years, and the person that I know who just rejoined IDEMIA probably doesn’t know either.

So I have no authoritative answer, but Google Gemini provides this very unauthoritative answer as to IDEMIA’s MOSIP non-compliance:

“IDEMIA’s core business model historically relies on end-to-end, proprietary solutions. MOSIP, by contrast, is an open-source framework designed specifically to prevent vendor lock-in by letting governments mix-and-match components from different tech providers.”

Let’s assume for the moment that Gemini is right in this case. So while IDEMIA may be willing to speak about a solution in Togo “based on” MOSIP, when IDEMIA goes after a critically important opportunity in the FBI or the CIA or the BBC (you know the rest), it’s going to provide a solution based upon IDEMIA-authored components such as its own MorphoKit software development kit.

Knowing full well that the U.S. Federal Bureau of Investigation doesn’t give a hoot about MOSIP compliance.

Because it’s not critically important in that market.

Know Your Market

Some biometric vendors focus on the developing world, some adopt the developing world as a secondary opportunity, and others just don’t care because their real revenue comes from elsewhere.

Where should your company focus its attention?

Bredemarket can help your company with analysis, and provide focused content as the analysis progresses. (Analysis is never complete. Things change.)

If Bredemarket can help you decide if MOSIP compliance is worthwhile or worthless, schedule a free meeting.