On July 10, the Digital Agency announced the DS–500 Identity Verification Guidelines 1’s FY Reiwa 5 Interim Summary on the revision policy. Overall, it is a very well-organized document.

An overview of the interim summary is provided below.

Overview of the Interim Summary

Introduction

  • This document is an interim summary of the policy for revising the guidelines as of FY Reiwa 5, including items still at the draft stage, together with matters for future consideration; it does not constitute a finalized revision policy.
  • The final revision policy is expected to be completed after it is reviewed in light of future expert opinions and coordinated with the relevant parties.

Terminology and Notation

  • The terminology and notation in this document are defined only for this document and do not define the terminology to be used in the revised Identity Verification Guidelines.

Matters for Future Consideration

Definitions of Terms

  1. Reconsideration of the Japanese term corresponding to “Validation”
  2. Reconsideration of the Japanese term corresponding to “Federation”
  3. Reconsideration of the Japanese term corresponding to “Biometric Comparison”
  4. Comprehensive review and updating of the definitions in the current guidelines

Overview of the Draft Policy for Revising the Identity Verification Guidelines

Key Revision Points

  1. Change the scope and title of the guidelines
  2. Explain fundamental principles such as accomplishing the mission
  3. Define and explain the identity verification framework
  4. Partially revise assurance levels and control criteria
  5. Comprehensively revise the risk assessment process

Table of Contents of the Draft Revised Guidelines

  1. Introduction
  2. Identity Verification Framework
  3. How to Evaluate Identity Verification Methods
    • 3.1 Business process reengineering (BPR) of the target procedures with digitalization in mind
    • 3.2 Identification of risks related to identity verification
    • 3.3 Determination of assurance levels
    • 3.4 Selection of identity verification methods
    • 3.5 Documentation of the evaluation results
    • 3.6 Continuous evaluation and improvement
  • Reference Materials for the Identity Verification Guidelines
    • Reference Material 1: Risk Assessment Worksheet for Identity Verification
    • Reference Material 2: Examples of Identity Verification Methods Corresponding to Assurance Levels, etc.

Key Revision Points for the Identity Verification Guidelines

① Change the scope and title of the guidelines

  • Expand “online identity verification” to include face-to-face methods and others
  • Split “individuals, corporations, etc.” into separate versions for individuals and corporations
  • Consider future expansion from “administrative procedures” to internal administrative operations

② Explain fundamental principles such as accomplishing the mission

  • Add a new section, “1.5 Fundamental Principles,” explaining mission accomplishment, fairness, privacy, usability, and other topics

③ Define and explain the identity verification framework

  • Add definitions and explanations of identity proofing, authentication, and federation
  • Add an explanation of the general model used for federation

④ Partially revise assurance levels and control criteria

  • Revise the identity proofing assurance levels and authentication assurance levels with reference to the revisions to xAL in NIST SP 800-63-4

⑤ Comprehensively revise the risk assessment process

  • Revise the entire risk assessment process so that methods are selected with due consideration for fairness, privacy, and other perspectives
  • Expand the reference materials supporting risk assessment

Thoughts and Commentary

As many of you may know, I too have been privileged to serve as a member of the Expert Panel. I am therefore truly grateful to the secretariat staff who prepared this summary. At the same time, many of the points I raised at the panel are included in the “Matters for Future Consideration” presented throughout the document. I hope readers will study those pages carefully.

Take, for example, the “wallet model” on p. 19. It introduces something called a “registry,” with an identity provider shown behind it. But it is not clear what this registry is, is it? In practice, it has an operating entity; in the EU Digital Identity Framework, that entity is referred to as a wallet provider. It is extremely important to recognize that an operator exists here, and it has also been pointed out in Europe that a wallet provider is an identity provider. Viewed in this light, depicting an identity provider as being behind the wallet provider is problematic. In the EU Digital Identity Framework, the “identity provider” referred to here would be an “attribute attestation provider” (or, in OpenID terminology, a claims provider). These points are discussed in “Continued Consideration of the ‘Wallet Model’ (Tentative Name)” on p. 23.

YouTube Live Stream

It has been 1 months since my last YouTube Live stream. I am worried that I may forget how to do it, so I would like to hold a session where we read this document over drinks, starting at around 23 this Friday.

Watch this video on YouTube.
Playing the video connects to YouTube.

Footnotes

  1. Expert Panel on the Revision of the Identity Verification Guidelines