Study Meeting on smartphone Installation of My Number Card Functions (2nd)
Overview
Date and time: Wednesday, October 26, 2022 from 1:30 pm to 3:00 pm
Location: Online
Agenda:
Opening
Proceedings
(1) Status of efforts to install smartphones
(2) Information security measure
(3) Proposed checklist items for whitelist registration
(4) Terminal requirements for the use of electronic certification for smartphones
(5) Exchange of opinionsAdjournment
Materials
Exhibit 1: Status of efforts to install smartphones (PDF / 1,021 kb)
Material 2 Information security measure * Limited to members, etc.
Data 3: Proposed checklist items for whitelist registration * Limited to members, etc.
Data 4: Terminal requirements for the use of electronic certification for smartphones and validation methods * Limited to members, etc.
Summary of proceedings
Date
Wednesday, October 26, 2022, from 1:30 p.m. to 3:00 p.m.
Location
Held online
Attendees
Experts
Chairman Tezuka, Acting Chairman Ota, Member Obi, Member Taki, Member Nomura, Member Miyauchi, Member Moriyama
Local government and industry associations
Mr. Okada, Director of the Information Policy Division, Policy Department (Maebashi City), Mr. Nishimori, Director in charge of My Number Promotion (Kobe), Mr. Shimonaka, General Manager of the Individual Number Center, Mr. Hashimoto, Deputy General Manager of the Individual Number Center, Mr. Hayashi, Public Personal Authentication New System development Department, Senior Councilor (local governments Information Systems Institute), Mr. Sasaki, Chief of the Steering Subcommittee of the MVNO Committee (Telecom Service Association), Mr. Maruyama, Mr. Saito, Mr. Baba, Mr. Shizuka, Mr. Okada, Mr. Fukushima, Mr. Yamada, Mr. Ueno (Telecommunications Carriers Association)
Observer
FeliCa Network Co., Ltd., Graduate University of Information security, xID Co., Ltd., NEC Corporation, NTT Communications Corporation, Hitachi, Ltd., Reuse Mobile Japan, Japan Information Economy and Society Promotion Association, National Association of Mobile Phone Sales Agents, TRUSTDOCK CO., LTD., Ministry of Internal Affairs and Communications
Secretariat, etc.
(Digital Agency)
- Mizushima Chief Product Officer
- Fujimoto Chief Technology Officer
- Saka Chief Information Security Officer
- Director-General of For the public Group
- Deputy Director for Yumoto Strategy & Organization Group Special Mission
- Director General of Digital social common function Group Kusunoki
- Hayashi, Identity Architect, Shimoe Trust Service Manager, Ariyama Android Engineer, Digital social common function Group
- Counselor Kamikariya, Assistant Counselor Futakaya, Product Manager Tsubonochi, Project Manager Tsuburaya (For the public Group)
Main opinions from Members, etc. (Summary)
Exhibit 1: Status of efforts to install smartphones
Speaker: . Please explain whether the service will always start even if there are concerns about security, and whether it is a target schedule and can be revised.
- Secretariat: Regarding the first point in On October 13, 2023, the Minister Kono announced that the service will start on May 11, 2022. Since the schedule has been announced externally, we would like to keep this schedule and work on it.
Speaker: service. In addition to the security criteria, isn't it necessary to have criteria that are sufficient for starting the service based on the results of the user testing?
- Secretariat: Regarding the first point in user testing are necessary. At present, we are incorporating the results of the first user testing conducted from July to August 2022. A user testing is also scheduled for February to March 2023. We would like to continue to make improvements from an objective perspective.
Speaker: Terms of Use, systems, technical standards, etc., if there is any progress. Unless the development of the Terms of Use, systems, technical standards, etc., is determined, it is impossible to clarify the responsibility decomposition point between Digital Agency, Ministry of Internal Affairs and Communications, J-LIS, and users.
- Secretariat: Regarding the first point in Slide 9, based on the terms and conditions of use at JPKI in My Number Card, Digital Agency, J-LIS, and Ministry of Internal Affairs and Communications are cooperating in considering the terms and conditions of use at Smartphone JPKI. J-LIS is leading the examination of certification operations, and Ministry of Internal Affairs and Communications is leading the examination of government ordinances, ministerial ordinances, technical standards, and public notices based on the Public Personal Authentication Act.
Speaker: service is important. Please explain if there are any decisions made at this point, such as whether to issue a message saying, "It is not necessary to carry a card. I would like you to use the service more and more from today" immediately after the start of the service, or whether to reduce the risk in the event of a problem without conducting a large-scale public relations.
- Secretariat: Regarding the first point in Slide 9, only the part related to security is extracted from the materials of the Review Meeting, but there is also a part related to public relations. Since the service start is after the Golden Week and outside the busy period of municipalities, we would like to make public relations in an easy-to-understand manner so that the people can firmly recognize the start of the service.
Speaker: There are three comments. First, I would like to hear an explanation of the impact on this initiative of the integration of My Number Card with health insurance card and driver's license card. Second, it would be better to specifically publicize safety in the form of the security Concept in order to dispel public concerns about safety. Third, I would like to hear a specific explanation of the load design and availability design. As a result of the high penetration rate of My Number Card, is it a load design that is assumed to be used by many people at the same time?
- Secretariat: Regarding the first point in , the use of the smartphone JPKI as a health insurance card is under consideration in Ministry of Health, Labor and Welfare, but the specific implementation method and implementation date have not been determined. The integration with driver's license card is under consideration in the form of a card application. Therefore, even if a E-Certificate is installed in a smartphone, it cannot be used as a driver's license card. Regarding the second point, as you pointed out, we would like to publicize to the people in an easy-to-understand manner how the security of the terminal and the security of the application are secured. Regarding the third point, we would like to explain after preparing materials separately in Digital Agency.
Appendix 2 Information security measure
Members, etc. only
Appendix 3: Proposed checklist items for whitelist registration
Members, etc. only
Data 4: Terminal requirements and validation methods for the use of electronic certification for smartphones
Members, etc. only
End