First, please look at the following Cabinet Secretariat diagram concerning My Number. The item labeled “number” is the My Number.

符号変換を利用して、異なる「番号」を必要に応じて紐付けする
(Figure 1) Conceptual image of code-based federation in the Number System

In this diagram, the My Number (“number”) is stored in multiple places, including information-holding institutions A and B.

This inevitably feels wrong to me, because it largely eliminates the point of using an information-federation infrastructure.

Whether an institution stores the My Number or only a “code” makes a major difference both for privacy and for the institution’s risk management.

If the My Number is stored by both institutions A and B, they can collude to match records. If information leaks independently from A and B, a malicious third party can also match the respective datasets and construct a profile of the person that the person does not want, causing enormous privacy harm. Naturally, management costs for security controls rise, and the possibility of penalties under direct-penalty provisions is also a major risk factor for those managing the data.

If only codes are stored, collusion is impossible and leaked records cannot be matched, greatly reducing the damage. Penalties could also be lighter. Information can then be federated only through the information-federation infrastructure, but that is precisely what such an infrastructure is for. Storing My Numbers everywhere is equivalent to creating backdoors everywhere.

The My Number should originally be used to obtain the equivalent of a “code” and then discarded. In a U.S. example, when the Department of Defense links a payroll deposit account to an employee number, it uses the Social Security Number (SSN) only once as linking data and thereafter no longer uses it for that purpose, disposing of it. This can be called the proper way to use it.

Linking with the 4 basic data items?

There is another matter that concerns me. As has repeatedly been pointed out in the Information Federation Infrastructure Technology Working Group, the question is how information-holding institutions link their service numbers (accounts) with My Numbers and codes.

It has been said that each institution will prepare the 4 basic data items in the same format as the Basic Resident Register Network (hereafter, the normalized 4 basic data items) and obtain the code by sending them to the federation infrastructure. Moreover, each institution is apparently expected to store those normalized 4 basic data items and keep them continually up to date.

This is nonsense. My reasons follow.

  1. Although “codes” are being used specifically to ensure privacy, another “identifier”—the “normalized 4 basic data items,” which has a relationship of almost 1 to 1 with the My Number—is attached to the attributes and stored, defeating the purpose.
  2. To begin with, many information-holding institutions do not possess normalized 4 basic data items. Therefore, this does little to reduce costs.

The reason for using “codes” in the first place is that widespread use of the “number” would make record matching easy and increase privacy risks. Yet if every information-holding institution possesses the “identifier” consisting of the “normalized 4 basic data items,” the result is the same as widespread use of the “number.” If this is what we are going to do, neither an information-federation infrastructure nor “codes” are needed. It is like throwing tax money down the drain.

Next, regarding the fact that many information-holding institutions do not have the 4 basic data items: for these institutions to obtain the 4 items, they ultimately have to contact the user and ask for the 4 items. If so, they might just as well ask for the My Number. I do not understand why they deliberately go through the 4 basic data items. It merely increases costs.

Can My Numbers be managed securely?

Under the current proposal, all withholding agents—that is, all companies and some individuals—will ask payees for their My Numbers and store them. Large companies may manage, but can places such as sole proprietorships really manage them securely?

Frankly, I think it is impossible. Yet the My Number is frightening because failure to manage it securely brings direct penalties. This is an extraordinary burden on businesses. They are handed a dangerous object that is useless to them and may explode at any time, and told, “Pay for the system investment yourself and manage it properly.”

What should be done, then?

Thinking it over, the current proposal seems to have been designed with people who can work only on paper in mind. Such companies and individuals certainly exist, but most people can use at least a mobile phone. Rather than lowering the security and privacy level of the whole system to accommodate exceptions, it would be better to treat exceptions as exceptions.

On that premise, the following arrangement would be possible.

  • Distribute a My Number to each individual.
  • Prohibit storing My Numbers. Also prohibit asking for a My Number.
  • Provide 2 methods for replacing a My Number with a “code.”
    • (When the individual can use a mobile phone or similar device) The individual asks for the withholding agent’s company code, accesses a government-provided page, enters the company code and their own My Number, obtains a “code” for that company, and notifies the company. [1]
    • (When the individual cannot use a mobile phone or similar device) The individual notifies the company of the 3 basic data items—name, sex, and date of birth—and the last 4 digits of the My Number. The company sends these to the information-federation infrastructure and obtains a “code.” [2]
  • Information-holding institutions use the “codes” obtained in this way to federate information.

Doing this would mean that:

  • My Numbers would no longer be stored everywhere, reducing privacy risks.
  • Companies would not store My Numbers, lowering their security-management costs.
  • Information federation could proceed without problems.

Thus, I think the objectives would be achieved. What do you think?

(Written in San Francisco)

[1] To generate a company-specific “code,” the infrastructure could either manage and use a cryptographic key for each company or employ a table-based method. One criticism of the cryptographic-key method is that the resulting value would be too long to communicate by handwriting or verbally. For example, even encryption with AES128, an algorithm with a comparatively short key length, after base64 conversion would yield 24 characters. In this respect, and in terms of resilience to My Number changes and to compromised cryptographic algorithms, the table-based method may be preferable.

[2] Addresses change frequently and are therefore poor identifiers. The 3 basic data items change relatively little and are preferable in that respect. It would be even better to use the name at birth rather than the current name. According to a ranking of identical full names, the most common is “Minoru Tanaka,” reportedly shared by 2620 people. With date of birth and the last 4 digits of the My Number, almost completely unique identification should be possible.

Related posts