We began a relaxed read-through last week of the US NIST SP 800-63-4 Initial Public Draft, published last year on December and open for public comment through 3/24. Its session number 3 will be held on February 2 from 10 p.m. This time, we will begin with Section 2.2 of Part A, the identity-proofing criteria. I expect this to include discussion of whether asking for a person’s name is reasonable. What, you think asking someone to enter their “name” is obviously normal? It is not. Asking for a family name and given name is itself an extremely Western cultural convention. Some cultures do not have family names, yet systems may refuse to process an application without one. Conversely, a name may exceed a character limit, or contain characters the system cannot accept.
These are actually issues of cultural equity. This equity issue is also one of the highlights of the current revision of SP 800-63.
In Japan, this issue is comparatively hard to see because names were standardized into family and given names during the Meiji era. It nevertheless still exists. For example, a foreign tenant to whom I rent a house has no family name, so they repeat their given name in the family-name field.
International airline tickets may accept only 8 characters, so my ticket says SAKIMURA NATSUHIK. A certain bank’s system had the same problem and asked me to shorten the romanized name on my cash and credit card because the full name could not be entered. I took the opportunity to make it NAT SAKIMURA1.
Many systems cannot even accept the kanji in my family name: “﨑.” I do not mind using “崎,” but my family register uses “﨑,” so entries using anything else are sometimes rejected. Yet some systems cannot accept the character, while others produce garbled output.
Katakana names are also a problem. “Nat Consulting” cannot be entered in eLTAX because the small “ッ” and “ィ” are not accepted. Yet the system may automatically pull the name from the kanji field, making it impossible to tell what caused the error. I was practically crying, “Please, just let me pay my taxes!” Finding the cause was difficult. Incidentally, my tax accountant advised me to pay at the service counter.
Such input restrictions should be reconsidered by returning to the reason for requiring a name in the first place. In eLTAX, for example, a corporate number already exists and should be sufficient. Corporate names are not unique anyway, so they cannot serve as identifiers.
Returning to individuals, eliminating the process of requiring a “name” could actually reduce various disadvantages caused by changing one’s surname. From an equity perspective, it is important to assess whether requiring people to enter names creates barriers that make applications harder for certain groups or functions discriminatorily. I therefore invite supporters of optional separate surnames for married couples to consider this issue with us.
Of course, the central issue in SP 800-63-4 is not names, but requirements such as presenting photo identification.
Version 4 has a considerably broader scope than Version 3, “SP 800-63-3.” It is still somewhat lacking from this perspective. When I asked one of the authors, “Hasn’t ○○ been completely omitted?”, I was told they recognized the issue and planned to write it. “All comments are welcome,” they said.
SP 800-63 is a standard for the US federal government, but it substantially influences related standards in other countries. Japanese government standards are among them. The Japanese government also appears to be considering revisions in this area, making it worthwhile to study SP 800-63 properly.
I therefore intend, over about 8 sessions, to read SP 800-63-4. I am dividing it into 8 sessions because the related documents include:
- SP 800-63-4 https://nvlpubs.nist.gov/nistpubs/Spe…
- SP 800-63A-4 https://doi.org/10.6028/NIST.SP.800-6…
- SP 800-63B-4 https://doi.org/10.6028/NIST.SP.800-6…
- SP 800-63C-4 https://doi.org/10.6028/NIST.SP.800-6…
There are 4 documents, so there is no conceivable way to finish in 1 sessions.
OpenID Foundation Japan also appears to be working diligently on Japanese translations, so some portions may be available in Japanese by the stream. If they are usable, I intend to use them as supplementary reading.
You may participate by chat or video2. We use mmhmm for video participation. Contact me if you wish to join with mmhmm, and I will send you a link. You should be able to join the chat after subscribing to this YouTube channel and waiting at least 1 minutes. However, someone who subscribed immediately before the previous session could not send chat messages, so I recommend subscribing in advance.
- with the added consequence that transfers cannot be made to my actual name
- video participation is limited to people I know personally
Related posts

On January 26 (Thursday) from 22 o’clock: Casual Read-Through Livestream of “Draft NIST SP 800-63-4”
After a publication delay of nearly 1 years, the pre-draft of the US NIST SP 800-63-4 was released on December, and public comments are being accepted…

CODE BLUE and Cosplay Companions
There is a conference called CODE BLUE. According to the organizer, it is “an international information-security conference originating in Japan, featuring world-class security experts”, and I…

Getting a SIM in the Schengen Area at Helsinki Airport
So, in a week when the words “information bank” are splashed across the front page of the Nikkei, it seems that a large contingent from Japan…
