Thank you so much for coming to my presentation session. So, we're now leaving the European Union, or the Europe, and I would like to take you all to the Far East, Japan.
So, the mobile digital identity is not something that's only happening in Europe, but also in Japan too, and I'm going to talk about it today. But before the mobile, we have physical one.
So, I actually brought mine from Japan today. It's called, in Japanese, it's called as my number kado, or my number card. But officially in English, it's called as the individual number card.
So, sometimes it's called as my number card, sometimes it's called the individual number card. And here, during my presentation, I'll call this as either the card or the individual number card.
So, almost over 70% of the Japanese citizens, residents, have this card. And with this, there are several things that, not only the face-to-face identity verification, but digitally, there are several things that this card can help you to do.
So, the first one is, there's the IC card app for displaying confirmation of the card surface. I know it's long, but it's basically the image data of what's on the surface of the card. Why do you need it? It's because there could be bad actors who counterfeit the card.
And then, right, so for example, replace the facial portrait on the card. But if you scan the IC chip, and then you can confirm, oh, the face is different in the data. And it's almost impossible to change the data.
And so, that's what this is for. And the second one is the IC card app for the individual information. And I know it's long again, but it's, so the first one was the data in image. And the second one is data in the plain text.
So, you can use this for entering your, let's say, your name, your resident address, your birth date, your gender. And so, you don't have to type in by using a keyboard, but just scan this, and it automatically fills in everything. And the third one, I'll talk in detail about it a bit later, but this is called JPKI. It stands for Japan Public Key Infrastructure.
So, it's basically for e-signature and identification, and you can do it on this card. And last but not least is the basic resident registration app, and this contains the resident record code. And the card, the IC card, has extra spaces, which means that more apps or more functions can be added on it.
So, it's a pretty nice card. And now, what's going to happen on the mobile?
So, I personally call this as the smartphone, in Japanese, I'm saying as smartphone, tousai mandan bakado. In English, I would say the individual number card on a smartphone.
So, how it's going to go? Basically, the individual number card, which is based on the MDoc format, is going to be on the wallet of the smartphone in this spring, 2025.
So, I was hoping it would come by here today, but unfortunately, it didn't make it. So, but I'm expecting it to come by this month or next month. And the data here, and it's long again, but I have named it as the digital identity based on the stored information in the card chip, and I'll call this as the digital identity.
And now, the slide's getting busy. So, this is how a user is expected to get the digital identity to be issued on your smartphone.
So, initially, user use this physical individual number card, and I'll take my smartphone out, and then you type in your PIN for the card, and you scan it, and this will automatically sign an application. So, applying for the issuance of the MDoc data, and then the phone generates the key pair, so public key and the private key. And the public key and the application data get sent to the MDoc ICA, and they check whether the data is valid or not, and once they confirm the data, they'll issue the MDoc.
So, in the MDoc, there is the name, resident address, birth date, gender, and the individual number, and I forgot to explain what the individual number or the my number is. So, it's a number that's used mainly for social security in Japan, and also the face of portrait.
So, what's on here will be also on the front, too. And these are the attributes for the digital identity. And the public key that was generated in the smartphone is to be also signed by the MDoc ICA, and they're, again, aligned with the ISO IC 18013-5 2021 specification, so it's international standard compliant, and gets downloaded to the user's device. And once the card and the data has been downloaded, the user sets up either biometric authentication or PIN for the usage.
It's pretty simple, but we had a session about the e-signature right before, so I'm also going to talk about what about the e-signature in Japan, and also with how it's going to go, or what's actually happening. Well, as I mentioned a little bit, this individual number card has a function called JPKI, Japan Public Key Infrastructure. And inside the card is the private key and digital certificate, which includes the user's identities and the public key, which is paired for the private key. So the user's identity is the name, resident address, birth date, and gender.
These four attributes are in it. And so, as I've shown, when you're going to apply for issuance of the digital identity, the user enters the password of the card on the smartphone, and then the user scans the card, and then the document to be e-signed gets signed. And the device will send out the digital certificate and the e-signed document to the verifier, and then the verifier validates the digital certificate, and they often retrieve the attribute from the digital certificate.
Which means that, unlike how Europeans are doing in Japan, this digital certificate is commonly used for identity verification. So, when you're going to open a bank account, you can use this method.
So, scan the individual number card and e-sign, and you can open, because this, again, this certificate has the attributes, and the government of Japan says this is one of the ways to comply with the regulation, and you can open a bank account with it. But what about for the smartphone?
So, we already have one since 2023. So, the phone I brought here today is my Pixel 5 from Google, and I already have my digital certificate on it.
So, many, or almost all the Android devices in Japan, sold in Japan, can e-sign with using the device, individual, on-device individual number card digital certificate since 2023, spring. And this depicts how a user gets the on-device certificate.
So, just like how you get the MDoc, it's similar. So, user firstly gets their physical individual number card, user types in their password, or the PIN for the card, scans it, and submits application. But there is a new actor called Trusted Service Manager.
So, they are the ones who handle the communication between the global platform security element on user's device. And the reason that this is not yet covered for iPhone is because currently only the Android devices in Japan have this global platform security element. It's kind of a historical reason.
So, the government of Japan has decided to use this for issuing the on-device digital certificate. And they request the key pair generation, and the key pair gets generated, and the public key gets sent to the national agency side, and then the on-device digital certificate gets issued. It's pretty simple too, I guess. And this global platform security element securely stores the key and the on-device certificate, and once a user wants to electronically sign, user doesn't need this physical card anymore.
So, I'll swipe in my pocket. So, the verifier, or the RP, requests for a signature, and users just have their phone, and type in the password, and the document gets signed. Pretty simple, again.
So, this is how it looks like. Unfortunately, I couldn't bring the actual screenshot, but this I've depicted from one of the major Japanese telecom carriers.
So, they allow the identity verification online with the individual number cards. And so, if you open their app for identity verification, one of the choices is to use your individual number card. And you click that button, and the second one you get is whether you use your phone, so on-device certificate, or, I'm taking it out, use your physical card.
So, let's say that because I already have one on my phone, I would choose the top button, so using my phone. And then the app called Minor Portal App gets opened, and they ask for your password for the digital certificate. And I type in, and then it shows what attributes are to be sent to the relying party. Simple again. And this system is pretty common in Japan, and there are many KYC vendors that support this.
So, if you have an Android device, if you're living in Japan, and having the Android device sold in Japan, you can use this very commonly. So, the last part of my presentation, my session is, can the individual number card on a smartphone be able to use here in Berlin, Germany, and Europe, outside of Japan? My personal answer is probably not.
Firstly, there needs to be a legal basis established, but also the identity, what's on the data. So, what is expected to be on my MDoc is my data in Japanese.
So, Japanese attendees, please don't raise your hand, but how many of you non-Japanese attendees here can pronounce this, or understand what's on it? Yeah. It says Furukawa Hideaki, because in Japan, the last name comes first, and then first name comes after.
So, the name is in Japanese, and then the birth date. Luckily, it's understandable. And please, for my privacy, I'm selectively closing some of my personal data. Not selective disclosure, but selectively closure.
So, thank you for my joke. Yes.
So, I was born in 1996, and then the address here is also in Japanese, too. And it says Tokyo-to, the Tokyo prefecture, and the rest part is also in Japanese. And then the gender. The detail hasn't come yet, but it's expected to be written in Japanese, too.
So, it's saying male in Japanese, too. And, well, one of the problems is overcoming the legal basis between Europe, Germany, and Japan.
Now, we have to handle how to transfer this data to alphabets. And one interesting trivia about the Japanese residential record system is that there is no phonetic data of the name yet.
Well, right now, they're starting to establish the data set for it. But until that, even what's written as in the kanji, Chinese character, well, technically or legally speaking, I could say my name as, well, let's say, Furukawa Naohiro, because I saw Fujii-san right there.
And, well, because only, again, the kanjis could be pronounced in various ways, and they're now starting to register how you pronounce it, but at this moment, again, there's no phonetic data of the name. Well, once they get the phonetic data, then they may be able to start issuing the MDoc for digital identity in alphabets, but we have to do that for the birth date and address and also for gender.
So many people here may often talk about the interoperability in the standards, but my personal view is we also have to consider the human readability interoperability, because I'm curious how many of the German names or German addresses can Japanese people be able to read. And this is my last slide.
So, in Europe, I know that there is a trusted list for the EIDES RFPs, but in Japan, I'm not sure about what's going to happen, so I'm kind of transferring my topic a bit. So, in the world of money, there's many fraud cases where a user gets tricked, and the user sends out their money to a scammer, and because the money gets transferred so fast, then the money is taken out rapidly, and the user cannot take their money back. Maybe the same thing could happen for digital identity. That's what I'm really fearing about.
I'm saying this as in cross-border, but this could be in Japan too, not cross-border. So, a user can get tricked by a scammer, and the scammer could be confiscating their money. They're maybe impersonating other legal entities, or in some way they get sneaked into the trusted ecosystem, and then get the identity out. But there could be more information, or more personal data could be transferred besides the digital identity.
I'm curious how many of you are concerned about this kind of stuff, because I'm not sure how the trusted list can really limit, because when you're registering on the trusted list for the first time, the verifier or the RFPs could be really legit, but they could turn to a bad verifier afterwards. I'm not sure how we have to handle with that. I have two minutes and 13 seconds left, and I may be able to take some questions. Are there any questions?
Yeah, so your hand raised first. You've been talking about the wallet and the identity. Is there any other sort of credentials that you might want to put on there, like driver's license or other things like that?
Yes, so the question was besides the identity for identification, like the mobile driver's license on the phone. So my personal answer is not the official answer of the government of Japan. So I guess they're planning to have the mobile driver's license too, and there may be more credentials that can be loaded. But the one thing I've missed out is Japan is not building wallets. The government of Japan is firstly building what's to be put on the wallet. So the wallet for this, the individual number card, is going to be Apple Wallet, so they're using Apple Wallet as the wallet.
And so the user can basically take in whatever the Apple Wallet can accept. So I hope this answers. And the second question was, oh yeah, Daniel. You mentioned that 70% of the Japanese have the individual number card. What about the other 30%? And what does it mean, 70%? Does it mean they use it on a regular basis? Because there are use cases that they can use it often.
Yes, so for the rest, 30%, well, they literally don't have one. And well, there could be various reasons. They may not trust, they're doubting about the government or not trusting the government. And the daily use case is the health care. So with this, this is linked to the health insurance data. And when you go to a hospital or clinic, you put in a machine and it checks what kind of health care you're in. And you get the, yeah, so it's pretty used commonly in Japan. And the time is up. Thank you very much. Thank you so much.