👨💼Partners
Overview
The MOSIP platform requires integration with several other systems. Typically, a System Integrator (SI) would assemble all the pieces together to build a complete national ID solution. All entities that participate in providing the external components are called MOSIP Partners.
Partner types
Partner type | Description | Label* |
---|---|---|
Authentication Partner/Relying Party | Entities that use MOSIP for authentication like banks, telecom, Govt. institutes etc. |
|
Online Verification Partner | Authorised and entrusted partners who host IDA module to provide authentication service to various partners. Even MOSIPs IDA module an is an Online Verification Partner. |
|
Credential Partner | Provider of credentials like printed ID card, QR code etc. to residents |
|
Device Provider | Provider of biometric devices that connect to registration client and authentication apps |
|
FTM Provider |
| |
Manual Adjudication | Providers of Manual Adjudication Systems(MAS); enrollment data is shared with MAS |
|
ABIS Partner | Provider of ABIS |
|
MISP Partner | MOSIP Infra Service Provider (MISP) provide network infrastructure/channel/pipe to various Authentication Partners to connect to the MOSIP system. Example, broadband service providers. |
|
* Label: Reference in partner_type
table of mosip_pms
database.
Partner policies
Partner policies control the data that needs to be shared with a partner. Learn more about partner policies.
Partner onboarding
Onboarding of a partner refers to registering a partner in a particular deployment of MOSIP. Partners need to be onboarded to establish trust. The onboarding process consists of loading partner details in the database, exchanging certificates etc, detailed in the later sections. Such onboarding is required to be done on any fresh MOSIP installation. For instance, if you install a sandbox, you would need to follow the onboarding process for each partner.
The sections below describe the onboarding process for each type of partner.
MISP
MISP should have a trusted X.509 certificate with a chain of CA certificates.
MISP self-registers on the PMS portal providing partner id, name, organisation name (same as in certificate), partner type (
MISP_type
) (This functionality will be available on the portal in the 1.2.x version of MOSIP)MISP uploads all certificates.
MOSIP Admin generates the MISP license key and provides it to MISP.
Authentication Partner (AP)
Policy for the AP must be pre-defined (see Partner policies).
AP should have a trusted X.509 certificate with a chain of CA certificates.
AP registers with MISP and obtains the MISP license key (this setup is outside of the MOSIP system).
The MISP used by AP should have been already onboarded onto MOSIP.
AP self-registers on the PMS portal providing partner id, name, organisation name (same as in certificate), partner type (
Auth_Partner
) etc.AP uploaded all certificates.
AP selects the policy group and policy. This request is sent to MOSIP Admin for approval.
On approval, AP generates an API key that can be used along with the MISP license key to interact with the IDA system.
Device Provider (DP)
DP should have a trusted X.509 certificate with a chain of CA certificates.
DP self-registers on the PMS portal providing partner id, name, organisation name (same as in certificate), partner type (
Device_Provider
) etc.DP uploads all certificates.
Any approval from MOSIP? (TODO)
FTM Provider (FTMP)
FTMP should have a trusted X.509 certificate with a chain of CA certificates.
FTMP self-registers on the PMS portal providing partner id, name, organisation name (same as in certificate), partner type (
FTM_Provider
) etc.FTMP uploads all certificates.
TODO
Credential Partner (CP)
Datashare policy must be pre-defined (see Partner policies).
CP should have a trusted X.509 certificate with chain of CA certificates.
CP self-registers on PMS portal providing partner id, name, organisation name (same as in certificate), partner type (
Credential_Partner
) etc.CP uploades all certificates.
CP selects the policy group and policy.
CP maps policy to one of the supported credential types.
CP adds biometric extractors for the policy.
Online Verification Partner (OVP)
Datashare policy must be pre-defined (see Partner policies).
OVP should have a trusted X.509 certificate with a chain of CA certificates.
OVP self-registers on the PMS portal providing partner id, name, organisation name (same as in certificate), partner type (
Credential_Partner
) etc. (Using APIs, as OVP support on PMS Portal is available in the later version of MOSIP.)OVP uploads all certificates.
OVP selects the policy group and policy.
OVP maps policy to
auth
credential type.OVP adds biometric extractors for the policy.
MOSIP Partner Program
The MOSIP Partner Programme (MPP) was initiated to help stakeholders connect with MOSIP, and become part of an ecosystem invested in building foundational digital ID systems that are trustworthy, secure, efficient, and interoperable while being customised to specific needs.
Refer MPP document for further details.
PMS module
Refer to Partner Management Services.
Last updated