Estonian Electronic Identity Card and Its Security Challenges [pdf]
dspace.ut.ee
dspace.ut.ee
The project was started in 2001 and was to develop ID cards for immigrant workers that regularly crossed the border for work. The purpose was to create an ID card that could not be forged or tampered with.
The cards looked very similar to those in section 3.1 -- identifying information and a picture, with a passport-like encoding. Unlike the picture in section 3.1, all of the information was placed on the front of the card. When a new card was produced, the software created a cryptographic hash of the identifying information and the picture which was stored both on the card's mag-stripe and in a central database.
When users were authenticated at the border, the card was placed face-down on an optical scanner much like you see at airports today. The software then computed a hash of both the personal information and the picture. In offline mode the system would compare the hash only to the hash on the mag-stripe, but in online mode the system would connect to the central database to verify the mag-stripe hash matched and existing entry in the central database.
I think the Estonian government used that system for two or three years.
The best part of this setup was that the system did not in any way create a national registry. Instead, it proved the the ID (token) was not tampered with and that the token had indeed been created by a registered government authority.
Funny story: In early testing, I created an ID using my manager's name and a photo of my co-worker's ass. I still have the card at home somewhere. Who knows... it may still be in the database!
What kind of algorithm is used to ensure different scans of the same picture return the same hash? At first glance it seems like a hard problem.
Card personalization is the bootstrapping problem, and there is another one with potentially hostile readers creating DoS conditions. I've worked on ID cards and digital identity in a few areas in both private and public sectors, and the threat model basically disappears into a cloud of spooky agencies, and it comes out the other end as a vague consensus to just move forward. If you think voting machines are unreliable you haven't seen anything until you've looked into digital identity, as it's a massive host of unresolved political problems tossed over the fence onto technologists, and then laundered back through opaque entities like the ones in this doc, then presented as a good idea.
My impression of identity is it's not a technology problem, but there are lots of people who will take your money to let you say that it is.
I intend to apply at the USDS for the Login.gov team in some capacity to help on the tech side if the necessary legislation can be put in place to support such an initiative. Their system already supports the DOD CAC (common access card), which is a short walk away from a citizen digital ID card (would be a different org and PKI root to administer and govern citizen cards, to grossly simplify).
Login.gov recently expanded to support city and local gov IAM needs (when they have ties to federal programs) [1] [2], so there is roadmap momentum and executive branch will. "Digital identity is a big deal. [3]" They're already serving 30 million users, and 500k DAUs, really just a matter of scaling up.
[1] https://www.gsa.gov/blog/2021/02/18/logingov-to-provide-auth...
[2] https://www.govloop.com/login-gov-expands-use-to-cities-stat...
I think you’re glossing over two major implementation factors that need to be part of the discussion from get-go:
* how much CAC use is dependent on fairly specific govt tech infra to be widely deployed, and how will that work for everyone (ever tried to setup a CAC on a civ computer)
* key control, either extremely decentralized like the iPhone (lock yourself out of your passport?), or extremely centralized and the newest honeypot OPM holds (root cert for all e-citizen PKI). US currently doesn’t have the internal cybersec chops to run that at all (closest equivalent is CISA).
I'm not arguing for such a system without robust support and reasonable downgrades for failure scenarios (identity reproofing if you lose your digital ID, for example). I'm arguing for, admittedly challenging, digital ID modernization without disenfranchisement. I genuinely appreciate you pointing out the challenges, as they must be addressed.
US DHS CISA is absolutely a resource that needs to be leaned on heavily to implement what I describe, and to ensure a strong security posture throughout the federal government's infrastructure.
[1] https://www.google.com/search?q=site%3Aw3.org+%22funded+by+t...
[2] https://www.w3.org/TR/did-core/
[3] https://www.w3.org/TR/vc-data-model/
Additional notes regarding credentials (certificates, badges, degrees, honorarial degrees, then-evaluated competencies) and capabilities models: https://news.ycombinator.com/item?id=19813340
westurner/blockchain-credential-resources.md: https://gist.github.com/westurner/4345987bb29fca700f52163c33...
Value storage and transmission networks have developed standards and implementations for identity, authentication, and authorization. ILP (Interledger Protocol) RFC 15 specifies "ILP addresses" for [crypto] ledger account IDs: https://interledger.org/rfcs/0015-ilp-addresses/
From "Verifiable Credentials Use Cases" https://w3c.github.io/vc-use-cases/ :
> A verifiable claim is a qualification, achievement, quality, or piece of information about an entity's background such as a name, government ID, payment provider, home address, or university degree. Such a claim describes a quality or qualities, property or properties of an entity which establish its existence and uniqueness. The use cases outlined here are provided in order to make progress toward possible future standardization and interoperability of both low- and high-stakes claims with the goals of storing, transmitting, and receiving digitally verifiable proof of attributes such as qualifications and achievements. The use cases in this document focus on concrete scenarios that the technology defined by the group should address.
FWIU, the US Department of Education is studying or already working with https://blockcerts.org/ for educational credentials.
Here are the open sources of blockchain-certificates/cert-issuer and blockchain-certificates/cert-verifier-js: https://github.com/blockchain-certificates
Might a natural-born resident get a government ID card for passing a recycling and environmental sustainability quiz.
So I get the direction you're going, but then this stands out: > if you have mobile apps that can perform the identity proofing
This is assuming folks have a certain tech pattern of: a) smart phones on the right OS version b) smart phones properly patched such that an Android vuln on a cheap phone doesn't lead to your e-SSN getting compromised c) number locks on their phones to prevent SIM swapping, if there's a non-app option d) have a smart phone in the first place!
The risk model there just gets nuts when phones are involved (as a specific counter), at the benefit of including 2FA reqs and somewhat hazy income equality judgements on users (a lot of folks don't have smart phones). If you're really into this, definitely look into mobile security concerns and the ideas around tying identity into it. Cellular network security is... not like internet security assumptions.
That's on top of some really generous trust in US identity security practices... the OPM hack really has to be accounted for in this discussion, if in fact we're unifying IAM.
Also, didn't Estonia's root cert get popped or something to do w/ low entropy keys on their ID cards from the manufacturer, leading to a total reissuance?
Totally on point.
Friends who are actually resident in Estonia tell me it's pretty handy in their actual life.
A strong counterexample is Germany whose ID card also has a similar SIM and robust encryption support. There the legal implementation was seemingly designed in a way to thwart adoption, by privatising the wrong part of the system such that uptake has been nonexistent.
You can still sign something with a government-guaranteed key by plugging your card into your computer, but that will only help you communicate with other nerds. Fun to do once, but other than that useless.
Despite all the trouble to get it (fancy packaging though), transferwise (now WISE) as a real bank account is good enough. Not the p2p foreigner venmo system, the banking system. I have euro bank account through that and business banking too, its good enough. There are a lot of kinds of businesses they dont support so just dont say or advertise your business as one of those. The transaction limit is $1,000,000 per transaction, which you can send in quick succession if over that limit
I will probably post something somewhere when I actually get to availing myself of the Residency status for what it was planned for - the pandemic put the brakes on that a bit ...
So far, I can speak for the ease of the sign up process, quality of the documentation, clarity and community behind the effort. Oh, and, the tech. The tech is very well done. Thoughtful integration -everywere-. Deep buy-in from the state itself (this is a must, and - methinks - what makes it all tick).-
To clarify: the tech is not "ground breaking" (yet?). It is very run-of-the-mill cryptography, certificates, etc ...
It's the -degree- to which it has been implemented in the whole "administrative stack", from government to stakeholders (CPAs, SMBs, the self-employed), and how it has been integrated into a coherent effort, that makes it work.-
Edit: To add to the insightful point below. Yes. A modern, innovative and forward-thinking regulatory framework is a sine qua non, and what has actually made any of this possible. That regulatory overhaul (first) and support is the the most important form "government buy-in" takes ...
I mean, almost. I just need to travel to NY to get my kit. :)
I'm planning on opening a remote SaaS company with Xolo and payments with Paddle.
PS Worth the trip. I had to travel 500 Km. to perform the (brief) in-person part of the process - biometrics. Did it in-and-out, same day. No hassle ...