VDSIC of France strengthens email OTP login with Passwordless X1280

VDSIC (Visible Digital Seal International Council) is a French non-profit association founded in Paris in 2016. It governs the Visible Digital Seal (VDS) — a 2D barcode printed on documents and products that allows tampering to be detected without an online connection. VDSIC defines the VDS technical specifications and security policies (aligned with ISO 22385 and ISO 22376), operates the Root LoTL as the ultimate trust anchor, and accredits and oversees Scheme Operators. Its members include government agencies, certification authorities (CAs) and trust service providers (TSPs).
The material exchanged through the member portal — the root trust list, Scheme Operator accreditation reviews, draft specifications — is therefore pre-publication and sensitive. The strength of the portal’s authentication becomes a question for the trust framework as a whole.

The limits of email OTP

Under the previous scheme, entering an ID triggered an OTP code sent to the registered email address, which the user then typed in manually. Three issues followed: the inconvenience of opening the mailbox at every login; the possibility of code interception through a real-time relay attack via a phishing site; and the absence of biometric verification, which meant only “someone with access to the mailbox” was verified, not the registered member.

ITU-T Recommendation X.1283 (09/2024) likewise notes that some passwordless implementations inherit the weaknesses of the methods they replace.

X.1280 deployed by id3 Technologies

id3 Technologies, a French technology member of VDSIC, integrated Passwordless X.1280 into the member portal. ITU-T Recommendation X.1280 (03/2024) defines a framework for out-of-band server authentication using mobile devices. Its central idea is a reversal of the verification order: instead of the user proving their identity first, the service is verified as genuine before any user authentication information is provided — which addresses verifier impersonation.
An authentication code is displayed automatically on the login screen, and the same code is generated on the user’s smartphone. The user compares the two and, if they match, approves the login with biometric verification. Because no code is typed in, interception during entry does not arise.
CategoryPrevious (email OTP)X.1280
Code deliverySent by emailDisplayed on screen
User actionManual entryCompare, then approve
VerificationOne-wayMutual
Identity checkNoneBiometric

“We were able to replace a weaker OTP method with the more secure X.1280 framework, improving security and convenience at the same time. We plan to extend this to other online services.”

X.1280 is not a vendor-specific specification but a published ITU-T international standard. That an organisation which underwrites document authenticity at national scale was itself relying on email OTP for its own portal shows how easily authentication upgrades are deferred. This transition reduced the number of user actions while raising the level of verification.

Christophe Candela — Technical Representative, Passwordless Alliance France

An engineer with over 25 years of experience in biometrics, cryptography and embedded identity software, Christophe currently serves as VP Innovation at id3 Technologies, a French technology company specialising in biometric recognition, secure documents and trust services, where he heads the Biometric Research Lab and leads the company’s authentication and digital trust portfolio. He combines expertise in PKI and certificate lifecycle management with hands-on work on biometric algorithms and embedded software for constrained platforms, including Match-on-Card recognition and standards-based trust infrastructure such as Visible Digital Seal technology aligned with ISO 22376 and ISO 22385. He contributes to international standardisation and interoperability work in digital identity and document authentication, and is active in the VDS International Council (VDSIC) and the Passwordless Alliance.
Facebook
Twitter
LinkedIn