Mykey Platform
It is one of the platforms that enables certification by My Number Card using the Japanese Public Key Infrastructure (JPKI) (JPKI) in public service. We will introduce the supported functions and procedures for introducing the service.
Table of
- What is MyKey Platform?
- What is the MyKey Platform for ①My Number Card utilization plan Realization?
- Query
1. What is the MyKey Platform?
1. 1. Overview
MyKey Platform is a platform for utilizing the functions of Japanese Public Key Infrastructure (JPKI) (JPKI) to utilize My Number Card in public service using an Internet connection system.
Currently, MyKey Platform is used to use My Number Card as a library cards by registering MyKey Platform with a MyKey ID (* 1) and a library user number.
* 1 This is a unique ID issued to MYKEY Platform users. It is issued in response to the issuance number of the My Number Card for user identification of the E-Certificate, and is used as a key to identify users in order to grant various services and Individual Number Card Point of MYKEY Platform.
1.2. Features of the Mykey Platform
The features of MyKey Platform are as follows.
- For local government library services only
- It can be used by introducing "Mykey Platform, etc. Utilization Software" provided by Digital Agency, and modification of the existing system providing public service is not required (WindowsOS only).
- Supports the use of My Number Card's Kazashi
*See the list for a comparison with the MyKey platform for the realization of ①My Number Card utilization plan described below.
1.3. Introduction Procedure
The introduction procedure is as follows.
- Contact Contact: Contact
- Obtain the operation manual from the My Number Card that uses the as a user card for public facilities, etc., and check the necessary procedures and manuals.
- Download "MYKEY Platform Utilization Software"
- Install the "My Key Platform, etc. Use Software" on the local government terminal and make the necessary settings.
*It can be used without modification of the system that provides public service.
2. What is the MyKey Platform for ①My Number Card utilization plan Realization?
2.1. Overview
In order to promote "①My Number Card utilization plan," Digital Agency has renovated the MyKey platform so that it can be used more conveniently in a wide range of local government services, including library services.
The MyKey Platform for ①My Number Card utilization plan Realization provides a function to pay out a unique user ID (PPID (* 2)) for each service, thereby ensuring security in My Number Card use and enabling use of My Number Card for multiple services.
In addition, in order to use Japanese Public Key Infrastructure (JPKI) (JPKI) in various situations in public service, we will provide services by dividing it into two types with different functions and features.
* 2 PPID (Pairwise Pseudonym Identifier) is a unique pseudonym identifier (different from MyKey ID) created by MyKey Platform for each cooperating system and linked to My Number Card.
2. 2. Characteristics of each type
There are two usage patterns for the My Key Platform for Realizing ①My Number Card utilization plan.
- Type 1: The MYKEY platform provides the local government system with a card scanning function and a scanning screen in response to the use of a screen.
- Type 2: Although the card reading function and the reading screen need to be provided by the local government, it is possible to confirm the effectiveness of the E-Certificate for user identification to the Japanese Public Key Infrastructure (JPKI) (JPKI) in a wide range of situations including non-face-to-face environments.
You can choose one or a combination of both, and use it customized to the local government content each public service offers. The characteristics of each type are as follows.
2.2.1. Common to Types 1 and 2
- It is possible to pay out PPID (Pseudonym Identification) that gives an identification for each public service.
- In the local government system that provides public service, by linking PPID (Pseudonym Identifier) with the user number of the local government system in cooperation with MyKey Platform, authentication by My Number Card and integrated operation of public service are possible.
- It is possible to check the revocation status of the E-Certificate for signatures linked to the E-Certificate for user identification and to check whether or not the basic 4 information (name, address, date of birth, sex) has been changed (* 3).
* 3 Please note that it is not a function to read the My Number Card for signature from the E-Certificate and confirm the validity confirmation.
2. 2. 2. Type (1)
- Mainly for face-to-face services such as counters
- CARD READING SCREEN AND CARD READING FUNCTION PROVIDED
- Supports the use of Kazashi
- Basic 4 information (name, address, date of birth, and sex) read from the ticket entry auxiliary AP is provided to the local government system
- WindowsOS is applicable to system terminals.
2.2.3. Type (2)
- Using API, it is possible to confirm the validity of the E-Certificate for user certification to Japanese Public Key Infrastructure (JPKI) (JPKI).
- The OS of the system terminal does not matter.
*Please see Table 1 below for a comparison between MYKEY Platform services. In addition, please contact Contact: Contact for details of each type.
Table 1 Comparison Table for Each Mykey Platform
Item | Mykey Platform | Mykey Platform for the Realization of ①My Number Card utilization plan Type 1 | Types of My Key Platforms for Realization of ①My Number Card utilization plan (2) |
---|---|---|---|
Use scene | Library | Mainly face-to-face services | Services using Japanese Public Key Infrastructure (JPKI) (including non-face-to-face services) |
Accessible to users in an online environment | Not supported | Response | Response |
Issue PPID | Not supported | Response | Response |
The use of a screen | Response | Response | Not supported |
Available without retrofitting existing local government systems | Response | Not supported | Not supported |
Provide scanning screen and scanning function on the platform side | Response | Response | Not supported |
Basic 4: Information provision function | Not supported | Response | Not supported |
Response to E-Certificate for Signature | Not supported | Not supported | Not supported |
Response to E-Certificate for User Identification | Response | Response | Response |
Support for OCSP Responder Method | Response | Response | Response |
Response to CRL Provision Method | Response * Supplement 1 | Not supported * Supplement 2 | Response |
*Supplement 1 Available only if a valid MyKey ID has been issued.
*Supplement 2: When the OCSP responder method is interrupted, it is possible to respond.
2.3. Specifications
The form of use of the MYKEY Platform for realizing ①My Number Card utilization plan and the corresponding functions are as follows.
2.3.1. Expected Forms of Use
- Use in a face-to-face environment using a WindowsPC (Type 1)
- Can be used regardless of the type of OS and the use environment (face-to-face or non-face-to-face) (Type 2)
2. 3.2. Types of E-Certificate for which validation is possible
- E-Certificate for User Identification (Applicable to Types 1 and 2)
It is something that proves the identity of the user online.
*For details, please refer to E-Certificate Types My Key Platform.
2.3. 3. Method of E-Certificate validation
OCSP Responder Method (Applicable to both Types 1 and 2) (* 4)
In online environments, this method inquires about the validity of each E-Certificate and performs authentication. It is possible to check the revocation status in real time.CRL Provision Method (Applicable only to Type 2 (* 5))
It is a method to confirm the validity of a E-Certificate from an expiration list issued periodically (once a day, etc.), and can be processed quickly and collectively.
* 4 If you use private business (JPKI) using the OCSP responder method with Japanese Public Key Infrastructure (JPKI) as the signatory validation holder, in principle, you will be charged a fee for providing E-Certificate Revocation Information (free of charge for the three years from January 1, 2023). On the other hand, if you use MYKEY Platform, public authorities, etc. will be the signatory validation holder, so the fee is free.
* 5 If the OCSP responder method cannot be used due to maintenance or the like, the validity shall be confirmed by the CRL provision method even in Type 1.
*For details, please refer to E-Certificate Validation Method My Key Platform.
2.3.4. Use of My Number Card Displays (Type 1 only)
Through the revision of the Public Personal Authentication Act, regulations have been established for methods that do not require the entry of a personal identification number (PIN) in My Number Card. The amended Act will come into effect on the day specified by Cabinet Order within a period not more than one year and three months from the date of promulgation (June 9, 2023).
Available environments and requirements
- Use for face-to-face, etc. (In addition to face-to-face environments, environments in facilities and areas that are managed and monitored, environments of terminals that are lent to and managed by users. Online and outdoor are not allowed.)
- Situations where the required authentication strength is low
- for the second and subsequent use (For the first registration, it is necessary to affix an electronic signature and an electronic certificate for user identification, etc., and to enter a personal identification number, etc.)
- Confirmation of the genuineness of My Number Card
- Verification of Validity of E-Certificate for User Identification
Type (1) is a implementation of these confirmation functions.
2.4 Implementation Steps
The introduction procedure is as follows.
- Contact: Contact
- When using Type (1), a written pledge of confidentiality shall be submitted between Digital Agency and local government.
- Receive necessary information such as system linkage specifications for the MyKey Platform
- Confirm the content of the information received with the system public service vendor who is responsible for the system providing the development
- Refurbish or public service a system that provides development to work with the system of the MyKey platform
- Implement a collaborative testing
*Currently, we are soliciting local government to be introduced in advance for release and operating it as a model project. For the model project, please see the model project related to the realization of ①My Number Card utilization plan using the My Key Platform.
3. Inquiries
For inquiries related to the MyKey Platform, please contact:
Digital Agency Mykey Platform
E-mail: mykeypf _ atmark _ digital. go. jp
Subject: Write "Inquiries about MYKEY Platform (local government name)"
Main text: Enter the name of the local government, the name of the department, the name of the person in charge, and the contact information.
*To prevent unwanted e-mail, "@" is displayed as " _ atmark _
". When sending e-mail, please change " _ atmark _
" to "@" (one byte).