On April 1, the Digital Agency published the summary of the Expert Meeting on Revising the Digital Identity Verification Guidelines (FY6). “DS-500 Guidelines for Online Identity Verification Methods in Administrative Procedures” (commonly known as the “Digital Identity Verification Guidelines”) sets out rules and methods for securely verifying identity when digitizing administrative procedures. You might think of it as a “textbook for online identity verification.” The guidelines draw on documents developed by the U.S. National Institute of Standards and Technology (NIST), among others, while also incorporating approaches specific to Japan, such as identity verification using the My Number Card.
The environment surrounding identity verification has changed significantly in recent years, with more administrative procedures moving online, wider use of the My Number Card, and an increase in online fraud.
In the United States, a draft revision of the NIST guidelines has been released, while Europe is moving to introduce the “Digital Identity Wallet,” a digital ID system that can be used on smartphones.
Against this backdrop, the Digital Agency convened experts for the “Expert Meeting on Revising the Digital Identity Verification Guidelines” and spent 2 year discussing how the guidelines should be changed in light of current issues and developments overseas. The final session was the FY6, Meeting 5.
The documents published were the “Policy for Revising the Digital Identity Verification Guidelines: FY6 Summary (Draft),” the Draft Revised Digital Identity Verification Guidelines (Draft as of the FY6 Summary), and the minutes compiling expert comments on them (these comments will presumably be reflected as well).
I have also included a YouTube video explanation at the end, so please take a look at that as well.
Document 1: Policy for Revising the Digital Identity Verification Guidelines: FY6 Summary (Draft)
First,
summarizes the results of this expert meeting in FY6 and presents ideas for how the guidelines should be revised. It includes the following.
Background to the Revision
- The shift of administrative procedures online and the spread of the My Number Card
- Increasingly sophisticated phishing attacks and more cases of forged identity documents
- Moves to revise the U.S. NIST guidelines and introduce digital ID wallets in Europe
Main Points of the Revision
- Review of the guidelines’ scope and title: Expand the scope to include in-person identity verification and government services other than administrative procedures.
- Definition of the “basic principles” for considering identity verification methods: Emphasize 5 perspectives: fulfilling the business purpose, fairness, privacy, usability and accessibility, and security.
- Definition of a basic framework for identity verification: Clarify the concepts of identity proofing, authentication, and federation; define federated and non-federated system implementation models; and make the federated model the default.
- Updating threats and countermeasures and reviewing assurance levels: In light of the latest threat and technology trends, review threats and countermeasures for identity proofing and authentication, as well as the role of assurance levels and the corresponding countermeasure criteria.
- Comprehensive review of the risk assessment process: Evaluate identity verification methods from 5 perspectives and simplify the risk assessment process.
Other
- In addition to the main guidelines, create a new “Digital Identity Verification Guidelines Handbook” covering specific technologies, methods, and examples.
Document 2: Draft Revised Digital Identity Verification Guidelines (Draft as of the FY6 Summary)
Meanwhile,
shows the actual draft revision of the guidelines.
The main points include the following.
- Selecting an “appropriate assurance level” according to risk:
- Traditionally, a uniformly high assurance level has often been required, sometimes at the expense of convenience.
- The revision makes it a basic principle to select an appropriate assurance level based on the risk of the procedure (a degree of confidence in identity verification) .
- It seeks to avoid excessive rigor and provide secure, safe, and convenient government services.
- The 5 perspectives for consideration:
- When selecting an assurance level and identity verification method, consider the following 5 perspectives.
- Fulfilling the business purpose (whether identity verification creates a barrier to the procedure)
- Fairness (whether there is unfairness, such as making the service unavailable to certain people)
- Privacy (whether personal information is handled appropriately)
- Usability and accessibility (whether it is easy for users to use)
- Security (whether its strength is appropriate for the risk)
- When selecting an assurance level and identity verification method, consider the following 5 perspectives.
- Components of identity verification:
- Define and organize identity verification into the following 3 components.
- Identity Proofing: Verify that the applicant is a real, living person (including attribute collection, document validation, and applicant verification).
- Authentication: Verify that the person attempting to use the procedure is the same person who was registered during identity proofing (authentication based on knowledge, possessions, or biometrics).
- Federation: Rely on identity proofing or authentication results provided by another trusted identity provider.
- Define and organize identity verification into the following 3 components.
- Implementation models:
- Federated Model: A model that uses a common identity provider (the preferred option for efficiency).
- Non-Federated Model: A model in which each system builds its own identity verification functionality.
- The two can also be combined.
- Threats and countermeasures:
- The draft specifies threats to identity proofing, authentication, and federation (such as impersonation, forged documents, phishing, and duplicate enrollment), and defines countermeasure processes, example methods, and countermeasure criteria for each assurance level.
- For identity proofing in particular, it organizes methods for validating authenticity (such as digital signature validation, checks against authoritative sources, and physical inspection) and methods for verifying applicants (such as facial comparison, PINs, and sending verification codes).
- For authentication, it mentions the importance of multi-factor authentication and phishing-resistant authentication methods (such as public-key authentication).
- Process for Considering Identity Verification Methods:
- The process presented is: ① identify risks → ② assess risk impact (high, medium, or low) → ③ determine the assurance level (Level 1–3) → ④ evaluate methods (from 5 perspectives) → ⑤ consider compensating controls and exceptions → ⑥ conduct ongoing evaluation and improvement.
- Identity Proofing for Corporations and Other Entities (Appendix 2):
- This requires an approach different from that used for individuals.
- It is organized into 3 steps: ① verifying the existence of the corporation or other entity (corporate number, name, address, etc.); ② verifying the existence of the individual applicant; and ③ verifying the relationship between the corporation or other entity and the individual applicant (representative seal, letter of authorization, etc.).
Next Steps
The revised guidelines will presumably be issued after the draft is published, public comments are invited, and consultations are held with the relevant ministries. I think it is shaping up to be a fairly good document, so I am already looking forward to it. I very much hope that an English version will also be produced.
Details
The following provides a little more detail for reference.
Key Themes
Expansion and Renaming of the Guidelines’ Scope:
- Expand the current scope of “online identity verification” to include in-person procedures and government services other than administrative procedures.
- Rename the guidelines “DS-511 Guidelines for Handling Digital Identities in Identity Verification for Administrative Procedures and Other Services.”
- The document number will also change from DS-500 to DS-511.
- (From Document 1) “In light of the expansion of opportunities to use digital technology for identity verification, including in-person settings and contexts other than administrative procedures, the policy is to expand the scope of these guidelines.”
- (From Document 2 P.2) “These guidelines apply to identity verification when individuals, corporations, and other entities submit applications or notifications, register accounts, log in, or perform similar actions in administrative procedures or government services provided by national government agencies (hereinafter, ‘covered procedures’).”
Definition of the “Basic Principles” for Consideration:
- Define 5 perspectives—“fulfilling the business purpose,” “fairness,” “privacy,” “usability and accessibility,” and “security”—to support the selection of methods appropriate to the characteristics of each procedure or service.
- (From Document 2 P.i) “This revision is intended to make it possible to select an ‘appropriate assurance level’ according to the risk of the covered procedure. As the basic principles for doing so, it defines 5 perspectives: ‘fulfilling the business purpose,’ ‘fairness,’ ‘privacy,’ ‘usability and accessibility,’ and ‘security.’”
- (From Document 1) “It is not sufficient simply to select a method with a high security level. An identity verification method at a level appropriate to the risk must be selected while also considering the impact on fulfilling the business purpose, fairness, privacy, and usability and accessibility.”
Definition of the Basic Framework for Identity Verification:
- Define identity verification as consisting of 3 components: “Identity Proofing,” “Authentication,” and “Federation.”
- Define the “Federated Model” and “Non-Federated Model” as implementation models.
- (From Document 2 P.9) “These guidelines define ‘identity proofing’ and ‘authentication’ as components of identity verification. They further define ‘federation’ as a component through which identity proofing or authentication is achieved by relying on another party (a trusted identity provider).”
Updating Threats and Countermeasures and Reviewing Assurance Levels:
- Update the assumed threats and example methods for each component in light of domestic and international threat trends, the latest technology trends, and revisions to NIST SP 800-63-4.
- Review the role of identity proofing assurance levels and authentication assurance levels, and the corresponding countermeasure criteria, from the perspective of resistance to threats.
- Define the identity proofing process as “collecting attribute information,” “validating identity evidence,” “verifying the applicant,” and “enrollment,” and clarify the threats in each process.
- For identity proofing assurance levels, treat the use or non-use of digital validation through an IC chip or similar means as an important distinction, and redefine “Level 1” for low-risk procedures (simplified identity proofing).
- Define the authentication process as “authenticator enrollment,” “performing authentication,” “response to theft or loss,” and “account recovery,” and consider countermeasures throughout the lifecycle.
- Review the countermeasure criteria for authentication assurance levels to strengthen responses to current threats such as phishing. At Level 3, phishing-resistant authentication methods will be mandatory for all users.
- For federation, do not establish assurance levels; instead, define uniform countermeasure criteria. With reference to the requirements of NIST SP 800-63-4 FAL2, establish criteria for trust establishment; configuration, enrollment, and key management; assertion-related countermeasures; and periodic confirmation and review.
- (From Document 2 P.3) “3 Threats and Countermeasures in Identity Verification”
- (From the minutes) “Regardless of developments concerning NIST SP800-63-4, Japan has developed an environment in which rigorous identity proofing using IC chips is relatively easy to use. However, because warnings alone cannot prevent phishing scams, I believe that Identity Proofing Assurance Level 3 is becoming increasingly important.”
- (From the minutes) “The authentication assurance level table includes wording such as ‘phishing resistance (recommended).’ Would it be appropriate to add similar wording recommending facial comparison in identity proofing? This might help dispel the misconception that PIN-based validation without facial comparison in an in-person setting constitutes robust validation.”
Comprehensive Review of the Risk Assessment Process:
- Introduce an assessment process that considers the impact on business purposes, fairness, privacy, and other factors while simplifying the process up to the determination of assurance levels.
- Add a new “risk identification” process as the initial stage of risk assessment.
- Base the impact assessment criteria on infringements of users’ rights and interests, while classifying cases involving potentially severe privacy impacts or exploitation for crime or attacks as “high.”
- Establish a new process for evaluating identity verification methods and evaluate them from the 5 perspectives defined in the “basic principles.”
- Introduce a process for considering compensating controls based on the evaluation results, such as combining multiple methods, adding countermeasures, or adopting methods with a higher or lower assurance level.
- Define a specific process for ongoing evaluation and improvement that collects and analyzes user inquiries, security events, threat trends, and other information and implements improvements as needed.
- (From Document 1) “The risk assessment process in Chapter 4 has been comprehensively reviewed to simplify the process up to the determination of assurance levels while incorporating tailoring that considers the impact on fulfilling the business purpose, fairness, privacy, and other factors.”
- (From Document 2 P.40) “4 Method for Considering Identity Verification Methods”
Creation of a New Guidelines Handbook:
- In addition to the normative main text, create a new, informative “Digital Identity Verification Guidelines Handbook.”
- The handbook will consolidate rapidly changing information, including specific technologies, methods, examples, and worksheets for consideration, allowing the main text to remain concise and the material to be revised flexibly.
- (From Document 1) “In conjunction with this revision, the policy is to prepare a ‘Digital Identity Verification Guidelines Handbook’ separate from the main text.”
- (From Document 1) “While the main text is normative, the ‘Handbook’ will be informative. By compiling information with a rapid cycle of change (specific technologies, methods, examples, etc.) in the ‘Handbook,’ the structure will be able to respond flexibly to future developments.”
- Approach to Identity Proofing in Procedures for Corporations and Other Entities:
- Because this requires approaches and methods different from identity proofing for individuals, an appendix presents the identity proofing process and example methods for procedures involving corporations and other entities.
- It consists of 3 stages: verifying the existence of the corporation or other entity, verifying the existence of the individual applicant, and verifying the relationship between the corporation or other entity and the individual applicant.
- (From Document 2 P.48) “Appendix 2: Approach to Identity Proofing in Procedures for Corporations and Other Entities”
Issues Raised in the Minutes
- The guidelines should reflect technological advances, such as adding the My Number Card to smartphones. (From the minutes)
- Because the guidelines and laws and enforcement regulations affect one another, their relationship needs to be clarified through FAQs and similar means. (From the minutes)
- More rigorous identity proofing procedures, such as facial comparison, are becoming increasingly important as a countermeasure against phishing scams. (From the minutes)
- It would be desirable for the summary document also to reflect the mapping between identity proofing assurance levels and threat resistance. (From the minutes)
- As with the recommendation of phishing resistance in authentication, stating that facial comparison is also recommended for identity proofing could be effective in dispelling misconceptions. (From the minutes)
- Charts and tables need to be revised so as not to mislead users, such as by displaying the number of digits in a PIN and stating its validity period. (From the minutes)
- A clearer description is needed of obtaining information from an identity provider in federation. (From the minutes)
- Clear wording that also takes private-sector use of the Digital Authentication App into account would be desirable. (From the minutes)
- The need to document the process and conduct audits when identity proofing is performed by the identity provider has been noted. (From the minutes)
- The wording on tamper resistance needs to be revised to make clear that it concerns keys, not electronic signatures as a whole. (From the minutes)
- It has been proposed that definitions of terms such as identity verification and assurance level be revised to make them more accurate and easier to understand. (From the minutes)
- The descriptions of the components of “identity verification” need to be consistent. (From the minutes)
- Terminology in charts and tables needs to be standardized (e.g., passcode vs. PIN). (From the minutes)
Related posts

The “DS-511 Guidelines for Handling Digital Identity in Identity Verification for Administrative Procedures, etc.” Have Been Published
After 3 years of development, the Digital Identity Guidelines, to which I had the privilege of contributing as an expert (Expert Meeting on the Revision of…

Digital Agency Releases FY Reiwa 5 Interim Summary on the Policy for Revising the Identity Verification Guidelines (YouTube Stream Friday Night)
On July 10, the Digital Agency announced the DS--500 Identity Verification Guidelines ’s FY Reiwa 5 Interim Summary on the revision policy. Overall, it is a…

NIST SP 800-63-4 Digital Identity Guidelines Update: Aiming to Balance Security and Usability
Overview In recent years, the rapid development of the digital society has made online identity proofing and authentication increasingly important. The U.S. National Institute of Standards…
