Tomorrow's Transactions » id card vision http://tomorrowstransactions.com Thought leadership from Consult Hyperion Wed, 10 Sep 2014 20:33:30 +0000 en-US hourly 1 http://wordpress.org/?v=4.0 RUSI and all that http://tomorrowstransactions.com/2008/07/rusi-and-all-th/ http://tomorrowstransactions.com/2008/07/rusi-and-all-th/#respond Tue, 01 Jul 2008 12:19:08 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/07/rusi-and-all-th/ Summary

The post RUSI and all that appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] One (!) of the conferences I spoke at last week was the Royal United Service’s Institute’s conference on Science and Technology for Homeland Security and Resilience. I decided to put my original presentation about ID card technology to one side and go with my new psychic ID card slides. If you’re at all curious, the slides are here…

There were a couple of tough questions — mostly around “why bother with an ID card at all” — but on the whole the people there were very nice to me, and prepared to listen to what I suppose must seem like a fairly radical idea if you are from a conventional security background.

As the comments on the original blog post seem to indicate, I think I’ve stumbled on a useful way of describing an alternative form of identity card. I’ve been writing it up in more detail for a journal, so hopefully I can address some of those issues as I go along with the “psychic rewrite”, by which I mean that I’d already prepared a paper on how to use smart cards, mobile phones and so on to create new kind of identity card, but I’m currently rewriting it to use the Dr. Who framing as it does seem to speak to people far more effectively than any of my previous attempts.

I’m serious about taking the Dr. Who message out to everyone! It may seem a little odd to base a major piece of national infrastructure on a children’s TV series, but I was at a seminar about the ID scheme today and once again I was made to think about how to present complex ideas about the future of identity and it seems to me that Dr. Who is as good as any framework. Interestingly, it seems as if I may not be the only person to look in this direction. Look at this fan forum suggestion from January 2007…

Dialogue joke about wishfulfillment of Doctor Who’s Psychic I.D. card he flashes in Season 3, and how that’s the future of ID cards…

[From BBC - collective - Torchwood Think Tank]

What is it that makes Dr. Who such a perfect mechanism for explaining technology to the public? I think there are three key factors that U.K. readers will recognise. First of all, we all grew up with Dr. Who, so it engenders warm nostalgia. Now, obviously, there’s an age-related component to this. My favourite monsters were the cybermen and I always wanted to be Brigadier-General Lethbridge-Stewart, so that gives my age away, but my kids look forward to it every week just as I did. Secondly, because the scriptwriters are skilled at engaging a non-technical audience we can piggyback on their imagery to interact with that same audience. And finally, because it’s fun!

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post RUSI and all that appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/07/rusi-and-all-th/feed/ 0
It’s crazy, but it might just work http://tomorrowstransactions.com/2008/06/its-crazy-but-i/ http://tomorrowstransactions.com/2008/06/its-crazy-but-i/#comments Wed, 18 Jun 2008 21:04:24 +0000 http://ec2-54-201-142-57.us-west-2.compute.amazonaws.com/2008/06/its-crazy-but-i/ Summary

The post It’s crazy, but it might just work appeared first on Tomorrow's Transactions.

]]>
[Dave Birch] Let’s create a vision for a 21st-century identity card. Let’s create a vision that we can communicate effectively. Let’s create a vision that is founded on minimising the storage of personal data. Let’s create a vision that the public and the government can understand. Let’s create a vision that contains some genuine innovation, some excitement, some potential. But most of all, let’s create a vision that is founded in mass media, because that’s where the British public get their science and technology education from. I would suggest that, as in so many things, Dr. Who should be our guide.

You’ll be familiar, of course, with Dr. Who’s psychic paper. As any devotee of the BBC’s wonderful series knows, the psychic paper shows the “inspector” whatever it is that they need to see. If the border guard is looking for a British passport, the psychic paper looks like a British passport. If the customs officer on Alpha Centuri wants to see a Betelguesian quarantine certificate, the psychic paper looks like a Betelguesian quarantine certificate.

200806171440.jpg

Now that is what I call a vision for an ID card. And what’s more, it will work.

The variant I propose is to be known as Dr. Brown’s psychic paper, named in honour of the Prime Minister who will scrap the current ID card scheme to universal acclaim and replace it with something fit for the 21st century (namely, this scheme). Unlike Dr. Who’s psychic paper, Dr. Brown’s psychic paper only shows the viewer what he or she wants to see if the holder has the relevant credential. If you are trying to get into a nightclub, you need to prove to the bouncer that you are over 18. The bouncer is looking for a credential that proves you are over 18. You show your psychic paper to the bouncer and all it reveals to the bouncer is whether you are over 18 or not. That is all the bouncer is entitled to see, so that is all they can see: not your name, not your date of birth, not your inside leg measurement, not your address, not your employment status, sexual orientation or credit rating. All the bouncer sees is that you are old enough to drink. Provided you are over 18, of course. If you are not, the psychic paper remains blank, as shown below

nightclub

You cannot forge this credential because it is digitally-signed by the issuer. If a 16-year old copies an 18-year old’s certificate into their psychic paper, it won’t work, because the incoming messages will be encrypted using the 18-year old’s public key, but the 16-year old lacks the corresponding private key (which can’t be copied because it’s never given up by the psychic paper — sorry, ID card). Since transmitting the photograph and appropriate credentials directly into the brain of the nightclub bouncer isn’t possible, we will of course need to use some kind of device instead. Luckily, just such a device already exists: the mobile phone. Now that manufacturers are starting to deliver mobile phones that can read contactless smart cards (such as the Nokia 6131 that we were using at the O2 Wireless Festival and London Fashion Week), we have a straightforward way to implement psychic paper.

psychic_ID_is_6131

This isn’t really magic, or even that complicated. It’s all done using standard contactless communications, standard cryptography, standard protocols, standard chips, cards, phones and photos. In 99 out of 100 cases, displaying your photograph is the only authentication required: There’s no need for the supermarket to check your fingerprints, for the doctor to demand a PIN or for the pub to take a DNA sample.

Why bother doing this? Well, no-one can read your psychic paper — sorry, ID card — unless they are allowed to and when they are allowed to, all they can see is what they are allowed to see. No more showing the guy in the pub your name, date and place of birth and goodness knows what else just to prove you are 18. Under the hood, it’s all done using keys and certificates, credentials and local authentication: The nightclub bouncer has had to obtain a digital certificate that allows him to interrogate your ID card. His phone sends the certificate to your ID card. The ID card checks it, sees that it is asking for a proof of age. It sends back your photograph, digitally-signed (that’s how his phone knows it’s a real ID card, because it can check this signature). If you’re not old enough to drink, it sends back a digitally-signed red cross (or whatever). Yesterday, the Prime Minister said that the ID card will help people

if they want to prove their age, or open a bank account, or apply for a job, or register with a GP – it will provide a better, more convenient and more secure way of doing it

[From Speech on Security and Liberty - 17 June 2008]

So will the psychic paper, but with an important difference: It will show the GP only your health service number (if you have the right to NHS healthcare, otherwise it will be blank), it will show the employer only your national insurance number (if you have the right to work in the U.K.), it will show the bank only your financial services number and it will show the pub absolutely nothing except your photograph (if you are old enough to drink). So this is a user-friendly way to implement all of the privacy-enhancing technologies that we would like to see incorporated in a modern national identity card scheme: sector-specific identifiers, pseudonyms, mutual authentication. It’s a way of tapping into the identity utility (as ably described by Neil McEvoy) without needing to understand how it all works (and, as I presented at EEMA, the combination of mobile phones and identity utility looks promising).

This is a way to deliver an identity card scheme that provides both more security and more privacy. It does not need a big database with everyone’s details and it does not need expensive, custom-built, specialist equipment. We (by which I mean people who post on Digital Identity blogs) know perfectly well how to implement such a system with mathematical rigour. And now that Microsoft have purchased Credentica, I look forward to seeing it deployed on a large scale. It’s about time. I argued in favour of this approach during the government’s first consultation on what was then known as the Entitlement Card, to no avail. Back in 2005, I wrote a piece for Prospect magazine arguing that the government’s vision for the proposed ID card scheme was tragically out of date and backward-looking. Even No2ID were nice about it…

At last someone in favour of an ID card who knows what he’s talking about and cares about privacy and security. Unfortunately his preferred scheme is incompatible with the Government’s plans.

[From ID in the News» Blog Archive » A Better Class of ID Card]

As I said at the time “The glory of using computers, biometrics and digital signatures is that they can work together to disclose facts about someone without disclosing their full identity”: I can now see that trying to explain asymmetric cryptography, blinded digital signatures and pseudonymous certificates was a waste of time. I should have had more faith in The Doctor!

I shall be unveiling my new scheme — well, actually the same old scheme, but without mention of anything frightening such as daleks or public key infrastructure — at the Royal United Service’s Institute’s conference on Science and Technology for Homeland Security and Resilience conference in London next week. See you there.

P.S. I wonder if other large scale government IT flagship projects — such as the Ministry of Defence and the Child Support Agency — might have got off on a better foot if they’d watched more of The Doctor?

These opinions are my own (I think) and are presented solely in my capacity as an interested member of the general public [posted with ecto]

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post It’s crazy, but it might just work appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2008/06/its-crazy-but-i/feed/ 7