SardineCon SF/2026

Learn More
Identity verification4 分で読めます

Document authenticationとは?

SUBSCRIBE

Document authentication decides whether an ID is genuine and unaltered by inspecting security features, fonts, microprint, the machine-readable strip, and signs of tampering or full fakery. A forged or edited document is the foundation many other frauds are built on, so this check is often the first line of defense at onboarding.

What is document authentication, in plain English?

Document authentication answers one question: is this ID a real, unaltered document? It inspects the things a genuine passport or driver's license should have and a fake usually gets wrong: security features like holograms and optically variable ink, the correct fonts and layout, microprint that stays crisp under magnification, and the machine-readable strip with its check digits. It also hunts for signs of tampering, like edited fields or mismatched fonts.

The recurring attacks fall into three buckets: template counterfeits that copy a real design, digitally edited fields where a name, date, or photo has been swapped in an editor, and recaptures, which are photos of a screen or a printout rather than a real document. Each leaves different traces, so good authentication looks at pixels, layout, and physical cues together.

In fraud and AML, this check sits right at the front of onboarding. Because so many downstream frauds start with a fake or altered ID, catching a bad document early stops synthetic identities, impostors, and mule accounts before they ever get a foothold.

Authentication versus verification

What changes

Document authentication

Document verification

Core question

Is the document genuine and unaltered?

Does this genuine document belong to the person here?

Main method

Inspect security features and detect tampering.

Add a face match and data cross-checks to the document.

What it misses

A real ID that was stolen from its owner.

Little on its own if the document was never authenticated first.

Best use

Filter out forgeries and edits.

Tie a real document to a real, present human.

Who is involved?

Who

Their role

The applicant

Submits the ID image, genuinely in most cases, fraudulently in the ones you care about.

The IDV vendor

Runs the automated authentication model and returns a genuine, altered, or fake verdict.

The fraud analyst

Reviews edge cases, tunes thresholds, and confirms whether a flagged document is truly fake.

The fraudster

Supplies template counterfeits, edited fields, or screen recaptures to slip a bad ID through.

What it looks like in practice

In practice

An application arrives with a driver's license that looks clean at a glance. The authentication model flags that the date-of-birth font is slightly heavier than the rest of the card and that the microprint along one edge is blurred, both consistent with a digitally edited field.

An analyst pulls the image and sees a faint rectangle around the birth date where a layer was pasted in. The same base template turns up on three other applications with different names. What looked like one edited license is really a batch of counterfeits from one source, caught because the document check looked past the surface.

Why it matters to operators

Document authentication is cheap leverage. A bad ID caught at onboarding stops a chain of downstream harm: the synthetic account never funds, the mule never receives, the impostor never takes over. Miss it, and you spend far more later chasing the fraud it enabled.

The trap is treating authentication as the whole answer. A genuine, authentic ID can still be stolen, so this check tells you the document is real but not that it belongs to the person holding it. That is why strong flows pair authentication with face match, liveness, and a chip or strip cross-check rather than trusting the document alone.

What to watch in the data

  • Font and spacing drift. A single field in a different weight or alignment is a classic sign of a digitally edited document.
  • Screen glare and moire. Reflections or a fine grid pattern suggest a photo of a screen, not a real document.
  • Reused template. The same base design across many applications with different names points to counterfeits from one source.
  • Strip mismatch. When the machine-readable strip disagrees with the printed page, tampering is likely.
  • Blurred microprint. Genuine microprint stays sharp; smearing where fine text should be crisp is a red flag.

Quick questions

Is document authentication the same as verification?

No. Authentication asks whether the document is genuine and unaltered. Verification adds whether it belongs to the person presenting it, usually with a face match. You generally want both.

Can it catch a photo of a screen?

Often, yes. Recaptures leave traces like glare, moire patterns, and pixel artifacts that models are trained to spot. Pairing it with liveness and requiring a live capture makes recaptures much harder.

What is a template counterfeit?

It is a fake built from a copy of a real document design, then filled with the fraudster's chosen details. Because the layout looks right, detection often relies on subtle print quality and security feature flaws.

Does a passing document mean the person is legitimate?

No. It only means the document appears genuine. A real ID can be stolen, so you still need a face match and liveness to tie the authentic document to the actual person.

Why cross-check the machine-readable strip?

The strip carries a second copy of the holder's details with check digits. If it disagrees with the printed page or the chip, that mismatch is a strong tampering signal that a visual glance would miss.

Go deeper

  • NIST Digital Identity Guidelines (SP 800-63) ↗ — The US standard for identity proofing and authentication assurance levels.
  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.

Document authenticationと併せて知っておきたい用語