Comments on: An open source national ID scheme http://tomorrowstransactions.com/2007/07/an-open-source/ Thought leadership from Consult Hyperion Tue, 09 Sep 2014 00:19:19 +0000 hourly 1 http://wordpress.org/?v=4.0 By: Salvatore D'Agostino http://tomorrowstransactions.com/2007/07/an-open-source/#comment-2056 Sat, 28 Jul 2007 12:19:30 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2007/07/an-open-source/#comment-2056 Open source has a role but it is unlikely to meet all the requirements particularly on the enabling infrastructure and applications.
What is important is that the scheme absolutely establish standards for the identity components and leverage standards for as many of the components as possible.
As you know FIPS 201 in the United States is an approach along these lines that has taken this approach and has met with some success.
As far as a contactless travel ID, I would look at a contactless certificate and match of additional factors on the system.
This is much along the same lines as the card authentication certificate in FIPS 201.
Clearly the cryptography in any approach needs to be open. Its the only way you can hope of having a secure solution. Proprietary, “just trust me its really secure” will never fly or work.

]]>