Introduction
As digital identity becomes a cornerstone for secure public service delivery, governments and private sector players are adopting advanced identity solutions that meet the highest standards of security, interoperability, and privacy. This training course by Kincaid Development Center provides in-depth knowledge on the GlobalPlatform Identity Configuration, Mobile ID frameworks, and security protocols essential for the implementation of mobile identity in e-Government services.
Participants will be guided through real-world scenarios and use cases to understand how to build secure, privacy-compliant, mobile-based digital ID services leveraging Secure Elements (SE), Trusted Execution Environments (TEE), Host Card Emulation (HCE), and contactless technologies.
Participants who successfully complete the course will receive Certificate of Participation.
Course Objectives:
By the end of the course, participants will be able to:
- Understand GlobalPlatform’s Identity and Privacy Frameworks
- Analyze advanced security specifications for Government e-ID requirements
- Interpret ID Configuration 2.0 and its changes from 1.0
- Apply the OPACITY protocol and Crypto Agility concepts
- Explore the structure and use of the ISO Framework for digital ID
- Design secure mobile ID solutions using HCE, SE, and TEE
- Practice deploying a mobile identity service in a Mobile Network Operator (MNO) environment
- Build real-world use cases for transit, healthcare, and civil registration systems
Duration
This certificate course involves approximately 10 days.
Who should Attend
This course is ideal for:
- Government digital identity and e-services teams
- System integrators and IT consultants
- Mobile Network Operators (MNOs) and service providers
- Chip and device manufacturers
- Digital security experts and architects
- Project managers and technical leads in identity infrastructure
Note: A background in secure elements or prior participation in Kincaid’s Secure Element (SE) Training is recommended.
Course outline
Module 1: Review of Secure Element (SE) Specifications
- Types of SEs: embedded, UICC, external
- Architecture, access control, and lifecycle
- Trust management and provisioning basics
Module 2: Contactless Services (GlobalPlatform Amendment C)
- Contactless Registry: Definitions, use in NFC and HCE
- Memory and Deletion Enhancements: SE space optimization
- Accessing SE Applications: via mobile OS or middleware
- Device Application Services: Integration of SE with app logic
Module 3: Security Enhancements for Government ID
- Principles of Crypto Agility: Future-proofing cryptography
- GlobalPlatform OPACITY Protocol (Amendment G)
- Strong authentication for offline contactless transactions
- Session encryption and mutual authentication
Module 4: Identity Configuration 2.0
- Transition from ID Configuration 1.0 to 2.0
- Requirements for interoperable, secure identity systems
- Use in e-Passports, e-Health Cards, and National e-ID
Module 5: Privacy Framework and Protocols
- Privacy Master File and OPEN Privacy Extension
- Secure Channel Protocol (SCP21)
- Building privacy-aware mobile ID apps
- Privacy Configuration templates and compliance guidance
Module 6: ISO Framework for Mobile Identity
- ISO/IEC standards in ID architecture
- Integration of ISO layers with GlobalPlatform modules
- Interfacing with national identity registries and databases
Module 7: Use Cases and Deployment Frameworks
- Real-world mobile ID applications:
- National ID systems
- Mobile driver’s licenses
- Digital healthcare ID
- Mobile-based transport ticketing
- End-to-End Simplified Framework for transport services
Module 8: Project: Designing a Mobile ID Service for an MNO Environment
- Group-based workshop
- Use a case brief to develop a service architecture
- Define: authentication flow, security components, user interface
- Presentation and peer feedback
General Notes
- The instructor led trainings are delivered using a blended learning approach and comprises of presentations, guided sessions of practical exercise, web-based tutorials and group work. Our facilitators are seasoned industry experts with years of experience, working as professional and trainers in these fields.
- The participants should be reasonably proficient in English as all facilitation and course materials will be offered in English.
- Upon successful completion of this training, participants will be issued with a certificate.
- The training will be held at Kincaid Training Centre. The course fee covers the course tuition, training materials, two break refreshments and lunch.
- All participants will additionally cater for their, travel expenses, visa application, insurance, and other personal expenses.
- Accommodation and airport pickup are arranged upon request. For reservations contact the Training coordinator at Email: training@kincaiddevelopmentcenter.org or Tel: +254 724592901
- This training can also be customized to suit the needs of your institution upon request. You can have it delivered in our Kincaid Training Centre or at a convenient location.
For further inquiries, please contact us on Tel: +254 724592901 or send mail to training@kincaiddevelopmentcenter.org
Payments are due upon registration. Payment should be sent to our Bank account before commencement of training and proof of payment sent to training@kincaiddevelopmentcenter.org

