PARAMETA

[Special Contribution] From the 'Resident Registration Card' to the 'Digital ID'

2021.03.15News
Blog — ArticleScroll

What should an ideal digital ID actually look like?

As the shift to a contactless era accelerates and the shape of digital ID services starts to emerge around the world, we came across a contributed piece that sets out a concrete vision for the ideal digital ID, and we wanted to share it. You can read the full article at the link at the bottom of this post.

[Special Contribution] From the "Resident Registration Card" to the "Digital ID"

As of March 2021, countries around the world — the UK, the EU and others — have settled on the concept of a digital, integrated identity credential functioning as a "smart key," and are announcing the "digital ID" (Digital ID, eID) of the Fourth Industrial Revolution.

The biggest difference between Korea and the EU is this: is the credential an "integrated ID," or is it merely "a way to confirm who you are"? In Korea, using a digital ID to buy a home or take out a bank loan still differs from a process in which you print out dozens of documents, have them certified by the issuing bodies, and submit them.

By contrast, the "digital ID" that some 40 countries worldwide have spent the past several years bringing to completion is designed to fuse smartphone biometrics with government services such as finance, pensions and real estate, so that you can get a bank loan approved or buy property in one go simply by presenting the digital ID — no identity card and no dozens of accompanying documents required.

In terms of convenience, credit information for a bank or a property purchase only has to be checked once, and when you travel abroad you can put proof that you were vaccinated against a particular disease into a digital wallet and present it, with no separate supporting document. That is more convenient, and it saves time, money and effort.

We have to move beyond what Korean telecom operators and others are pursuing — "connecting a simple plastic ID card to a digital (mobile) ID credential in an inadequate state of security" — and evolve toward the concept of granting every citizen a digital identity. That means it is designed so that citizens can use it regardless of status (with no restrictions based on race, age, income and so on), and it is built with multi-factor security so that confidentiality (unrelated parties cannot read the data), integrity (information cannot be altered at will) and availability (recovery is possible even in the event of a disaster) are properly maintained.

Consider, for example, the "integrated digital ID" as an analogy to the makeup of a KTX train.

It is being built with multi-layered, converged security — "biometrics + private certificate + certificate from institution X (PKI)" — so that carriages can be added or removed depending on the purpose or the need. In other words, in the extended area of the private key linked to the certificate stored in the secure element of the smartphone — the locomotive, the carriage with the engine — services can be added in sequence like carriages: "Car 1 (fingerprint), Car 2 (voice), Car 3 (electronic resident registration card), Car 4 (driver's license), Car 5 (national pension), Car 6 (health insurance), Car 7 (primary bank), Car 8 (electronic money / cryptocurrency), Car 9 (QR codes, barcodes), and Car 10 (Internet of Things: robots, drones, shared cars, TVs, refrigerators and so on)," and finally special carriages (car keys, apartment keys, hotel keys, company access passes, Zoom meeting IDs, virtual meeting IDs and the like) can be added and used according to that particular user's circumstances.

On top of that, this structure adds an audit function — complying with government-designated periodic monitoring and the latest version of the standards — to protect users from potential threats and rule out forgery, avoids collecting unnecessary data, and is designed to implement self-sovereign control over one's own information.

This approach to digital identity, prepared by the EU with the UK leading the way, is also being pursued by Canada, Australia, Sweden and New Zealand, and it is being driven by non-profit organizations and national governments in step with the African Union, the UN's global ID project and others.

Each country calls this a Digital Identity Framework, and once the DIF is in place, individuals will no longer need to obtain dozens of accompanying documents; fraudulent behavior such as illegitimate authentication against institutions and users will be prevented; and people will be authenticated by a set of government-approved rules that make it easier to prove who they are through government online services.

From the user's side too: if the resident registration abstracts, loan certificates, property documents and credit information that you currently obtain separately from different institutions can all be shared from a digital ID on your smartphone, then the starting point of the Fourth Industrial Revolution is the digital ID used as a smart key — and that is what the government should build first.

Across a far wider and more varied range of converged industries, the digital ID (Digital ID, eID) is indispensable, and it is self-evident that it will be used far more. For the future digital society, Korea should introduce a "digital ID framework" that oversees these services as a core pillar of intelligent e-government and the Fourth Industrial Revolution, in order to build and spread a "K-digital ID" — and use it as a bridgehead for going global.

  • Source: Daily Secu
  • Original: https://www.dailysecu.com/news/articleView.html?idxno=121935
Back to list