This page has been translated using TexTra by NICT. Please note that the translation may not be completely accurate.If you find any mistranslations, we appreciate your feedback on the "Request form for improving the automatic translation ".

The second meeting of the Advisory Council on Identifying Issues in Attribute Certification in FY 2025

Outline

For the overview of this conference, please see the Advisory Council on Organizing Issues for Attribution Certification .

Event Information

Date:
Thursday, February 26, 2026 from 10:00 a.m. to 12:00 p.m.
Location:
Online (Microsoft Teams) * Live distribution has ended.

Proceedings

  • 1. Opening
  • 2. Agenda: "Discussion on measures to realize the use of VC and DIW"
  • 3. Closing and Communications

Data

Minute

Digital Agency (Kita Inoue): Now that we are on time, we would like to start the "Expert Panel on Summarizing Attribution Verification Issues (Second Meeting)". Everyone, thank you very much for taking time out of your busy schedule today. Thank you very much. Since time is limited, I would like to move straight to the proceedings. Prior to the discussion, the secretariat will explain the materials. After the explanation of the materials, I will ask the Chairman of the Council to proceed with the discussion. Now, the secretariat will explain based on Document 1.

Digital Agency (Sawada): Since much time has passed since the first meeting in November, I would like to begin by looking back on that period. Once again, the purpose of this conference is to explore further computerization and advancement of paper and simple PDF certificates that remain in administrative procedures, etc., by using VC and DIW to share information through users. In order to realize the utilization of VC and DIW in public administration, it is necessary to first sort out the technical issues, feasibility, and restrictions, then sort out the usage environments and infrastructure such as signature keys and wallets, and then develop laws and regulations institutional arrangements to allow public certificates to be used as VCs. It is necessary to solve these issues with stakeholders, not only in Digital Agency. That is the reason why we started this meeting. In this context, at the first meeting of the Main Body, I proposed to create guidelines, etc., that show risk measures, etc., for the realization of public use cases, in order to start discussions on how to utilize the new technologies, VC and DIW, with peace of mind in the administration. I received general support for this proposal, and the technical working group was scheduled to discuss the content and standards of these technical measures. Let me briefly update you on the status of the technical working group. Technical working groups were held in December and January, and when the secretariat suggested that guidelines and other issues should be studied, we received opinions on the premise and direction of the discussions, such as that it would be better to look at a wider range of items, such as the lifecycle of protocol layers and keys, and the lifecycle of the entire digital identity, and that the presented use cases are highly abstract and it may be difficult to have in-depth technical discussions. Therefore, we have determined that it is too early to create an outline of the guidelines for risk measures this fiscal year, and we will continue to consider this point in the next fiscal year and beyond after organizing the preconditions and details. In addition, in the discussion of the technical working group, it was suggested that it is necessary to continue discussions on a wide range of issues, especially the issuance method and the ideal wallet, at the main body meeting and in the next fiscal year and beyond. In particular, regarding the VC issuance system, we received opinions that under the hypotheses presented by the secretariat, there is doubt about the need to use VCs, and that as a result, we will continue to review the issue of issuing VCs, and there were also opinions on the issues of trust chains for signature keys in the case of issuing function agent. It was also suggested that a variety of entities should be able to provide wallets, that it is necessary to consider use cases that present multiple different credentials simultaneously, and that it is important to assume how many people cannot use smartphones. Although it is simple, we would like to ask Committee Member Nakamura, Chair of the Technical Working Group, to make a brief retrospective comment in response to such an opinion in the Technical Working Group. Committee Member Nakamura, thank you.

Dr. Nakamura: This is Dr. Technology Working Group. I have briefly explained, but more detailed records are summarized in the summary of Material 2. I would like you to take a look at it when you have time. Given the limited time of two meetings, I would like to hear as many opinions as possible from the members of the committee. I think there were many cases where it was not a good way to proceed, but since many issues have been pointed out, I hope we can continue discussions while looking at those issues. That is all, although it is brief.

Digital Agency (Sawada): Thank you very much. As shown on the right side of the diagram in the material, we will discuss the provision of a usage environment necessary for each of the Issuer, Holder, and Verifier to utilize VCs, and what the government should work on at an early stage for the formation of an ecosystem. Specifically, as shown in the figure below, we will discuss the scope of requirements for various standards of measures, including risks, when individuals receive certificates issued by the government and submit them to the private sector, and when certificates issued by the private sector are submitted to the government. In today's discussion, we will present two use cases as points of discussion that need to be discussed early, including the use environments and the way the ecosystem should be to maintain them. As described on the right side of the diagram in the material, next, we will talk about the scope of the discussion in today's meeting. This is a hypothetical use case in which the working person obtains it online and submits it online or at the window in order to prove household information, etc., and in this discussion, selective disclosure, etc., can be used. As described on the right side of the diagram in the material, next, we will talk about the scope of the discussion in today's meeting. This is a hypothetical use case in which the working person's company issues a work certificate as an example of a certificate issued by the private sector and presented to the government. This is used, for example, in the first meeting of the main meeting, it is submitted at the counter). The second, the certificate issued by the government, the copy of the certificate issued by the government, and the copy of the certificate issued by the government. As an example of the certificate issued by the government. This is assumed as a use case. The second, the scope of the scope of the scope of the copy of the certificate issued by the government, and the scope of the certificate issued by the private sector, and Verifier, and the private sector. We will discuss the use case. Next year. The next year. The scope. The scope of the certificate issued by the private sector and issued by the private sector.

Digital Agency: First, I would like to explain the "Action Items for Realization of Utilization from Public to Private Sector." A public-to-private use case is an IHV model use case in which an administrative organization issues a VC, individual users hold the VC in their wallets, and present it to a private company. Specifically, we envision a case in which public certificates issued by administrative organizations, such as copies of residence certificates, are converted into VCs. In the past, public certificates were issued in writing at local government counters, but now they are electronically issued as VCs, stored in the wallet of smartphones, and can be immediately presented to private companies. It is expected that the convenience of citizens in various private procedures will be greatly enhanced. On the other hand, public certificates are required to have high reliability based on existing laws and regulations and systems, and the ecosystem for this purpose has not yet been established. In addition, there are only a limited number of precedent initiatives in Japan. Therefore, there are likely to be concerns about the costs of consideration and development resulting from these issues, making it difficult to make a decision to introduce them. In order to solve these problems, each box in this slide defines the ideal image of each entity in a few years. In addition, in order to realize it, the Secretariat's draft of the short-term action items to be prioritized in the next fiscal year and after and the medium - and long-term action items to be addressed in the future for social implementation and dissemination is given. The details of each action item are summarized in the following pages, so I will explain them. First of all, we will explain the "action items concerning the issuance of VCs." The "ideal form" mentioned here refers to a state in which each issuing government agency issues VCs based on a common, compatible specification rather than fragmented, proprietary specifications, and increases the efficiency of certificate issuance operations. To achieve this, we have listed two "short-term initiatives." The first is the arrangement of VC issuance requirements in (1) -1. Specifically, we need to create a document that summarizes the requirements for how government agencies should issue VCs, including what should be used for the VC signature key, how that signature key should be managed, and how the public key should be made public. We also need to present the document to the ministries and agencies in charge of the system so that it can be referred to by local governments and others. The second one is verification test of ① -2. Since it is difficult for the ministries, agencies, and local governments that issue the certificates to consider the implementation of a VC on their own, we believe that it is necessary to make a verification test of whether it can be technically realized in cooperation with Digital Agency and what value it has in order to create examples. In addition, as one of the "Medium - to Long-term Initiatives," for example in (1) -5, we believe that it is necessary to prepare assets and tools, including reference implementations, so that government agencies, which will be issuers, can efficiently prepare a VC issuance environment. Next, I will explain the "Wallet Initiatives." The "ideal form" here means a state in which a highly reliable and compatible wallet can be used by users to securely hold and manage their own public certificate VCs on their smartphones and other devices. As a "short-term initiative" to achieve this, we have listed the clarification of wallet requirements in (ii) -1. Although many wallet providers provide wallets, the guidelines and criteria for selecting a wallet to store the public certificate VC are unclear. Therefore, we believe that it is necessary to organize the requirements for wallets that handle public certificate VCs, specifically, VC issuance and presentation protocols, security measures, key management methods, interoperability, and other requirements. In addition, as one of the "Medium - to Long-Term Initiatives," (2) -3, for example, we believe that it is necessary to consider to what extent the suitability of the wallet requirements summarized in (2) -1 should be required, to what extent such suitability should be ensured, and if it is ensured, how its suitability should be evaluated, or whether it should be provided by the government itself. This is followed by an explanation of "VC Verification Efforts." The "ideal form" mentioned here refers to a state in which a person in charge visually checks the authenticity of the contents of the entry and receives a public certificate in VC format, which had been manually transferred to the system, thereby automatically automating or improving the efficiency of a series of operations. (iii) -1. verification test is listed as a "short-term initiative" to achieve that goal. I also mentioned verification test in the initiatives regarding the issuance of VCs. However, even if VCs can be issued, the ecosystem will not be established unless they can be presented. Therefore, I believe we need a verification test that involves private companies as verifiers and goes into the incentives of the verifiers, such as whether they can actually make work more efficient and whether the reliability of certificates increases. In addition, as one of the "Mid - and Long-term Issues to Be Considered," for example, in ③ -4, we believe that it is also necessary to provide a simple VC viewer from the government agency as an allowance for private companies acting as verifiers to efficiently develop a VC verification environment. Finally, I will explain the points I would like to discuss. We have compiled a list of the Secretariat's proposals for the "matters to be addressed in the short term" and the "matters to be considered in the medium to long term." Please provide your opinions on the appropriateness of the direction of the "matters to be addressed in the short term" highlighted in blue. We also ask for your opinions on what is necessary to enhance its effectiveness, as well as on other matters that should be prioritized. This is the end of the explanation from the secretariat, but I would like to first introduce the comments of Committee Member Taki, who is absent today. "I believe that the Secretariat's proposal for short-term measures is appropriate. I understand that the use case of My Number Card itself is that the ability to issue certificates of residence at convenience stores ultimately helped improve public awareness. Convenience store certificate of residence may not be the original government DX, but it is a keyword with very high recognition. In the past, there were many cases where resident cards were used in identity verification, but since society is shifting to authentication using the card itself, I agree that we should focus on use cases other than resident cards, which can be implemented quickly. That's all from Commissioner Taki. Further proceedings will be handed over to the Chairman of the National Land Council. Thanks in advance.

Chairman: Good morning, ladies and gentlemen. Thank you very much for taking time out of your busy schedule. First of all, as Chairman, I would like to express my gratitude and some apologies to the members of the Technical Working Group. I also listened to some of the discussions, but not all of them. The main body meeting did not provide a clear definition of what is important for collaboration through users, or what exactly we want to do. As a result, various points of discussion erupted. However, among them, there were many discussions on very important individual themes. However, I think what we learned this time is that if we rush too much, this will happen. So, I think our mission for today's final landing is to clearly define why we want to do it and what we want to do, and quickly organize them so that we can accelerate them in the future. I hope we can proceed with the discussions in this way. As for the short-term, I think we should clearly define the direction and bring it to a point where the necessary work can be properly carried out as early as next fiscal year. Thank you for the introduction, but is page 22 easier to understand than the page you are showing now?

Digital Agency (Sawada): Page 22 is the next discussion. Page 15 is a summary of the issue of issuing by the government, followed by three pages of Issuer, Wallet, and Verifier. This time is for discussing use-cases issued by the government. In particular, there is no fixed time for discussing Issuer, Wallet, and Verifier.

Chairman: I see. Then, using this page as a base, as a short-term initiative, I would like to hear your opinions on these matters. Thank you very much.

Dr. Sakimura: Mr. . Thank you very much for putting this together in such a short period of time. I would like to express my gratitude to the members of the secretariat. Then, when we think about this kind of thing, I think it is important to firmly recognize the significance of promoting VC issuance to society. Based on this, I think we will think about the public and private sectors or the private sector. We recognize that promoting VC issuance aims to improve economic efficiency and productivity, in other words, to achieve economic growth by distributing structured data in accordance with the data minimization principle, and by automatically processing the validity of the issuer of the data and the verifiability of the data, including its falsifiability and the validity of the presenter. Back-end collaboration within the government is difficult, so front-end is chosen. Of course, there is such an aspect, but it is a by-product, or rather, it is only one use case. It may be a mistake to discuss it in a reduced way and then expand it to the whole, so I think it is important to have a proper sense of the whole. In order to do so, it must be issued and used widely by both the public and private sectors. However, in order to do so, we must start with ourselves. One of the conclusions of last year's DIW Advisory Board was that the public sector should first issue certificates and disposition notices as verifiable digital credentials. I think this approach is still right. And I think he is saying that the first use case is from the public sector to the private sector. At that time, regarding the use of VC, it is important to thoroughly enforce the verification rules. Just because received data is VC-like, it will be accepted without signature verification. Such cases are quite common, I think. It is very important to prevent misuse. For example, in other countries, personal identification numbers used for various procedures are used as if they were credentials, and we have experienced many accidents. This is an example of treating something that is unverifiable as verifiable. In the same way, even when a signature is attached, some people don't verify the signature, or they don't confirm that the key used for the signature is provided by the correct party. These kinds of things are quite common. So, not only is it important that the data you receive has not been tampered with and is in the correct format, but of course checking that is an important first step. Issuing keys according to the correct process = It is important to create a trust chain leading to a trustworthy issuer and verify that the key is trustworthy. Here, "the issuer is reliable" means that it is possible to verify that the issuance process also meets the relevant assurance level in the form of a third party evaluation. This will be in the latter half. It will be issued by the private sector, and this alone should eliminate most of the risk of accepting VCs issued by unauthorized issuers. Therefore, I think it would be better to discuss individual issues based on a holistic view. It is almost a will from the "DIW Advisory Board", but I told you at the beginning.

Chairman: . Mr. Kasai, please.

Committee Member Kasai: . I believe that the current discussion and points of contention are matters to be addressed in the short-term. Copy of certificate of residence given in the example of public sector to private sector I agree with Mr. Taki that VC should be seriously considered. On the other hand, what is lacking is a demonstration from the beginning. Copiers, which you are talking about as analog products, have a long history and are used frequently. Stakeholders in this area, such as local governments, our convenience store machines, and the user's perspective, should be thoroughly examined to clarify the current situation and issues. Then, it would be better to compare how it would be if it were used as a VC. In addition to that, on page 12, there is a section on stores, which is probably based on this assumption, as well as convenience stores and other places. For example, I think it will be at financial institutions when you apply for a housing loan somewhere. What is extremely important when considering the introduction of a VC is the reading device. Mr. Digital Agency is saying that he will provide an SDK. However, those tablets and other devices combined with other machines are quite costly, and business operators are often stopped by them. Therefore, in order to use various VCs in the future, what kind of function should be required for the reader, and what kind of function, such as QR, NFC, or Bluetooth, should be used to standardize most VCs, should be firmly identified. Although the issue of VCs tends to be discussed, it will not be used unless it is verified. Therefore, I think that this point also needs to be discussed in parallel. Also, for the sake of the future, I think it would be good to discuss whether or not dual operation should be allowed when the issuance of certificates at convenience stores is changed to a copy of the VC's certificate of residence, and whether or not a legal system is necessary for that. That's it.

Chairman: Thank you very much. Mr. Sakae Fuji, please.

FUJI Sakae: . Thank you so much for putting this together. Page 15 is currently being displayed, and I will speak based on this. The first question that comes to mind is, what is behind the promotion of VC utilization in the public and private sectors? Is it based on the premise that government-issued VCs will be stored in private sector wallets? I would like to confirm this part as the first point. Let's assume that the answer is yes. In No. 2 in the middle, it is written that requirements for a highly reliable and compatible wallet will be organized. Considering that My Number Card has already issued an Apple Wallet, can we conclude that the Japanese government has already approved the Apple Wallet as meeting the requirements for a highly reliable and compatible wallet? If you are judging that it is accepted, I think that the inference that the requirements have already been issued may be valid. In other words, if there is a private wallet on the same level as the Apple Wallet, it would automatically fulfill the requirements. In other words, clarifying the requirements here is described as a short-term measure, but I think it can be said that the requirements have already been issued, and if not, My Number Card may not be listed on Apple Wallet. I would like to ask about this point. I have two more questions. One of them is about verification test. This is because we are in the era of the Trusted Web. If we include verification test, which the People's Service Group for My Number Card Utilization is working on, I believe that a considerable amount of verification test has already been affected. On top of that, there is talk that verification test will be done further. I wonder how this is different from verification test in the past. Thinking in this way, as Mr. Sakimura mentioned earlier, we should start with ourselves. Although there is an assumption that technology will change in administrative agencies, I feel that starting to use it in actual business operations is actually a short-term effort. As for the issue of certificates of residence issued at convenience stores, I can only say that it is extremely convenient now that copies of certificates of residence can be issued at convenience stores. However, regarding the question of whether this was the final goal, I personally have considerable doubts. If the original idea was to include the topic of eliminating paper, even if it is said that it is a successful example because it is currently available and convenient, and there are many users, my personal impression is that it is very unconvincing. The last one was a comment. I have just talked about four points, and I would like to receive your comments.

Chairman: Is there anything from the secretariat on this?

Digital Agency (Sawada): Wallet a little bit. First of all, with regard to the question of whether certificates issued by the administration will be inserted into the private sector's Wallet, although it is not the case that all certificates will be inserted or that all certificates will be inserted, we would like to have discussions on the possibility of including the possibility of including all certificates, including this time. Furthermore, with regard to the point that My Number Card smartphones have begun to be installed in the operating system's Wallet, and this requirement already exists, this point is as you have mentioned. After various requirements have been determined, we are proceeding with the installation of certificates on smartphones as indicated. However, I believe that this point requires discussion on whether these requirements and the requirements for certificates handled by various other administrations should be equal. As you have mentioned, when advancing various discussions, including on copies of residence certificates, we will consider whether additional requirements are necessary, for example, or conversely, whether the requirements for My Number Card are too severe, taking into account the specifications of My Number Card.

FUJI Sakae: .

Chairman: I think the confirmation you just gave is quite important, so can I understand that your answer is that although the storage of My Number Card in the Apple Wallet is organized to a certain extent, it is OK to have some that are not so strict? I think it would be better to clarify what the requirements are once again.

FUJI Sakae: That's how I took it.

Digital Agency (Sawada): My Number Card, or whether it is acceptable to require the same requirements for other wallets.

Chairman: However, they are almost the same in the sense that a copy of a certificate of residence is posted.

Digital Agency (kusunoki): should be called an "identity document" or an "attributes document." Depending on how you look at it, in the age of personal computers, it is possible to download and upload a copy of a certificate of residence alone, for example, in a bank account, so there is no photograph attached. It is probably similar to a certificate of tax payment in terms of its nature as a residence certificate, and on the other hand, it has been historically used as a identity verification document by the Ministry of Internal Affairs and Communications Study Group, so there is a major problem with its ability to be duplicated. There are two sides. In the age of personal computers, it is possible to download and upload a copy of a certificate of residence alone, for example, in a bank account, and there is no particular restriction. In that sense, in a world where agents handle documents, it is probably because users want to put My Number Card on their smartphones, and Japanese smartphones are generally iPhone or Android, and it is sufficient if it can be operated by both. In this sense, we have not made any such judgment. In the future, various procedures will be automated while AI agents handle various Attributes Documents. In that sense, in a world where agents handle documents, it is probably because users want to put on their smartphones, and Japanese smartphones are generally iPhone or, and it is sufficient if it can be operated by both. identity verification Android

Chairman: Then, we have to consider a little whether a copy of a residence certificate is enough as a use case.

Digital Agency (kusunoki): Of course, I think that various documents should be examined. In particular, it was a copy of the certificate of residence that the System Division happened to request that these requirements be met. Therefore, there is a background that it is necessary to examine these in a proper manner, and it is under consideration.

FUJI Sakae: Mr. Kusunoki's explanation is very easy to understand. As for identification, compatibility, security, and security may be of course, but rather than that, the most important thing is that it is available to everyone. Therefore, the top priority was to include it in what everyone had. I think this is very easy to understand as logic. Therefore, I also understood that on the other hand, how to make other things widely available while maintaining convenience is a different argument. So, from among them, I chose one that is likely to be widely used as much as possible, and that also has good technical requirements. This is also related to what Mr. Sakimura mentioned earlier, but I thought it would be good if you could somehow take it to the point where we should try it first, not from the demonstration.

Dr. Sakimura: Mr. . The reason why it is easy to say, "Why don't you try a little bit?" is that, in fact, selective disclosures can be made. Even if it is presented quickly, it can be presented after being cut down. Therefore, it is not necessary to present it by narrowing it down to this much from the beginning. I believe that new technology will make it possible to expand the range of considerations in that regard.

Chairman: Selective disclosure is a strong argument for why wallets are better. Committee Member Itakura, please.

Committee Member Itakura: . Thank you very much. I would like to say that it is extremely important to issue copies of residence certificates or part of their information, and that there may be another way out, which verification test is trying to do. One is that in this Diet session, the Act on the Protection of Personal Information will probably be amended, and for children under 16 years of age, when obtaining consent related to personal information or under the Act on the Protection of Personal Information, the consent of a legal representative must also be obtained, and if notification is to be made, the legal representative must also be notified. These are the rules that will be included. At the same time, although it hasn't reached that level in Japan, in other countries, rules such as prohibiting people under 16 from using SNS in the first place are becoming quite popular. Australia has already succeeded. This matter has an extremely large impact. Even now, when money is involved, the rule of minors under the Civil Code of course applies. Each service provider does this as it sees fit, but being legally required for personal information protection means that some form of consent of the legal representative or notice to the legal representative must be guaranteed. If you do not think about it and leave it alone, what will happen is that everyone will take a copy of the family register, which is hell. The minimum necessary information is whether the person is a legal representative or not. Although a legal representative does not necessarily mean that the person is a parent and child, this is sufficient for about 99.9% of the cases. Therefore, if only part of the information on the copy of the certificate of residence, that is, the information that this person and this person are a parent and child, can be disclosed, this can be covered to a considerable extent. This is an urgent matter until the Act on the Protection of Personal Information is enforced. Therefore, when I first started talking about this issue, I thought that the issue of copies of certificates of residence was so important. However, although the age of 16 is the age of majority for personal information according to the Act on the Protection of Personal Information, all businesses that provide services used by children must confirm whether or not they are this legal representative. I don't think it is necessary to emphasize it too much, and I am saying that it is not good to check the box of "My child says it is good." However, Japanese business operators respond very excessively when it is legally stipulated, and there is a very high possibility that they will send a copy of the family register. This is the worst thing that can happen, so the time line to prepare a situation where there are two terminals that can at least prove the parent-child relationship by the time the Act on the Protection of Personal Information is enforced is almost cut off. This is based on the premise that the revised law will be passed by the Diet. This is not the time to talk about verification test. By the time the minors section of the Act on the Protection of Personal Information comes into effect, there is a problem that it must be fairly easy to introduce. On this occasion, the exit has actually been prepared through the amendment of the law, and since it is next to Mr. Digital Agency, I believe you are probably aware of how it is being done. With regard to the amendment prepared for the digital banks, it is assumed that part of the Digital Administration Promotion Act will be amended to approve a type of sandbox-like system. One of these examples was about a scheme in which information on businesses held by the government is provided through an API. He said he would accept the scheme and provide information without revising the law. In the same way, a scheme in which part of the information on resident records is released and used by everyone who meets certain requirements may not necessarily require revision of the Residential Basic Book Act, but it may be better to use that scheme as an exit and eventually revise it. However, if everyone meets those requirements, it may be allowed to do it, and the exit may be to do it for a while. Whether it should be called verification test or not, there was some discussion about Professor Fujisakae and others, but I think that as a temporary goal, it would be good to proceed with the assumption that the scheme certification under the Digital Administration Promotion Act will be made. That's it.

Chairman: : Thank you very much. Is Mr. Wakae listening? If you don't mind, I would like to ask all the members. After the discussion between the public and private sectors, I would like to ask the public and private sectors to give their comments. How about this timing?

Dr. Wakae: Thank you, . Actually, like Professor Itakura, I was thinking that the need for selective disclosure of age is increasing in the context of amendments to the Personal Information Protection Act and restrictions on children's use of social media, so I was thinking that using DIW in that situation might be a good idea, and I agree with Professor Itakura's first half. However, I am a little concerned that if we do it now, not in verification test, if we move forward in the form of wanting to enter the current Apple Wallet and Google Wallet, there will be no room for new independent wallets to enter. Considering this, I was thinking that if we do verification test, even if it is just for a short period of time, it would be good to examine how there is room for an independent wallet to enter and what kind of business model would be needed to make it possible. That's all.

Chairman: .

YOKOTA: I'm Yokota. In the short term, what we should do is to come up with a vision that we are thinking in this direction, although it is difficult to determine whether it is a short-term or a long-term plan, and to consider whether we can use what we have now in that case, including local governments as well as consumers and users. As for the next big issue, I think we can recognize that it will be the next challenge to draw out what kind of usage there is, which is not limited to this, or to consider how to implement it in society in response to it. It is probably very important as a short-term mission to avoid the reaction that we don't want to use it because we don't understand it. As one breakthrough, as Committee Member Itakura said, drawing a picture that it is just around the corner, and drawing a picture that everyone will be happy if selective disclosure is possible, will be the biggest challenge. This is all. How much we can avoid the reaction that we don't want to use it because we don't understand it is very important as a short-term mission. As one breakthrough, as Committee Member Itakura said, we can draw a picture that it is just around the corner, and that everyone will be happy if selective disclosure is possible. If we do not encourage it in this way, the administration will not start to work hard. If we can make one successful example from the public sector to the private sector will make it. This is the end.

Chairman: Actually, it is a reflection that we should have done it in this half year or so.

YOKOTA: In a sense, there are areas that have been caught up by the revision of the Act on the Protection of Personal Information and its implementation in society, so I think we can go so far as to say that these areas are already urgent.

Chairman: Dr. Nakamura, please.

Dr. Nakamura: This is Dr. This is Mr. Nakamura. From the viewpoint of technical review, item (I) -1 among today's short-term tasks is to present the concept of the VC issuance method to each ministry and agency. As Mr. Sakimura mentioned earlier, if it is necessary to clarify the overall design, I think the expression "concept of the issuance method" is a little vague. Including the verifier, what kind of use cases? It is a technical reliability mechanism. First of all, have them understand it. Then, we will need materials that will allow us to properly examine how it can be applied to your procedures. As for the verification test, I think that such an assumption is necessary for the experiment to be conducted. Therefore, we need to clearly clarify the initial design, as well as the next technical review. Then, next year, although we have an idea of what we want to do, no one has decided what will happen when we implement it in technology. If this is not decided, we may not be able to discuss it. So, I would like you to make preparations for that. That's all.

Chairman: Thank you very much. Now, I would like to conclude with general discussion. I would like to end the discussion from the public sector to the private sector and move on to the discussion from the public sector to the private sector. I understand that the secretariat will explain this matter again.

Digital Agency: Let me explain. Next, I would like to explain the "Action Items for Realization of Utilization from Private to Public". In public-private use cases, we envision an IHV model use case where a private company issues a VC, and individual users hold the VC in their wallets and present it to government agencies. For example, we envision a case where a document issued by a private company, such as a Certificate of Employment, is converted into a VC. In the past, applications were submitted to private companies and documents were issued in paper or PDF format. However, documents are now issued electronically as VCs, stored in the wallet of smartphones, and can be immediately presented to local governments and other administrative agencies. It is expected that this will greatly improve the convenience of citizens in various administrative procedures. On the other hand, the requirements for the VC that administrative agencies, including local governments, can receive are not defined, and the environment for administrative agencies to receive the VC is not yet in place. Therefore, due to these issues, concerns such as consideration and development costs are likely to arise, making it difficult to make a decision to introduce. In order to resolve these issues, similar to the use cases from the public sector to the private sector, this slide shows the Secretariat's proposed vision for each entity in a few years, as well as short-term and medium - to long-term initiatives to achieve the vision. We will explain the details of each initiative on the following pages. First of all, I will explain the "VC Issuance Initiative". The "ideal form" mentioned here refers to a situation where there are a certain number of private companies that can issue VCs in a format that complies with the technical requirements and trust standards stipulated by government agencies, and where private documents that were previously issued in paper or PDF are issued as VCs. As a "short-term initiative" to realize this, we listed the organization of VC issuance requirements in (1) -1. When an administrative agency accepts an application by a VC, we believe it is necessary to set certain requirements so that the VC issued by private sector can be appropriately accepted and verified by the administrative agency. Specifically, we need to clarify how to define requirements for data formats, schemas, and the signature method discussed in the technical working group, taking into account the development and operating costs of private companies. In addition, as one of the "Medium - to Long-term Considerations," for example, in (I) -2, we appeal to the merits of verifiability and machine-readability in administrative procedures. In addition, we believe that it is possible to encourage private sector to issue VCs by considering the current administrative issues, such as whether or not the contents of submitted private documents are checked one by one in current paper-based administrative affairs, and whether or not it takes time to investigate the existence of issuing companies, as well as the possibility of using VCs, which is one of the solutions. Next, we explain the "Wallet Initiatives." Here, the "ideal form" refers to a state in which a wallet can be used to store VCs such as credentials and property certificates issued by private sector and to present the VC to government agencies in various administrative procedures. As a "short-term initiative" to achieve this, we have listed the clarification of wallet requirements in (ii) -1. I presented the secretariat's proposal that the requirements for the wallet to store the public certificate VC should be clarified for both public-private use cases. Similarly, even when an administrative agency is the verifier, in order for the administrative agency to accept a VC that can be trusted with confidence, it may be necessary for the wallet to store that VC to satisfy certain requirements. Therefore, we believe that these requirements should be established first. In addition, as one of the "Mid - to Long-term Considerations," as in the case of public sector to private sector use cases, we believe that we need to consider (2) -3, such as to what extent we should seek conformance to the wallet requirements identified in (2) -1, to what extent we should ensure conformance, and how we should evaluate conformance. Next, I will explain the "VC Verification Initiative." The "ideal model" mentioned here refers to a state in which, in administrative procedures, the authenticity of the content is visually confirmed and attached documents, etc., for which a large amount of time is spent on manual transcription, are received as VCs, thereby realizing mechanical authenticity verification and automatic input. In this way, the government officials serving as the point of contact can streamline their work. As "short-term measures" to achieve this goal, verification test in ③ -1 is listed. Depending on the administrative procedure, there are systemic issues such as three tier separation and operational issues of the government officials, which is the contact point. It may be difficult for the ministries and local governments with jurisdiction over the system to develop the verification environment for VCs on their own. Therefore, I think it is necessary for verification test to go into incentives such as "To what extent can the work of administrative agencies be made more efficient?" and "Will the reliability of private certificates be increased?" while cooperating with Digital Agency. In addition, as "mid - and long-term considerations," we believe that it is necessary to "provide reference implementation and testing tools" and "provide a simple VC viewer" for the verification environment described above. Finally, I will explain the points I would like to discuss. On this page, as in the case of the public-private Use Cases mentioned earlier, we have summarized the Secretariat's proposals for the "Short-Term Initiatives" and "Medium - to Long-Term Considerations" that I have just explained as a list. Therefore, we ask for your opinions on the appropriateness of the direction of the "Short-Term Initiatives" highlighted in blue. We would also like to hear your opinions on what is necessary to enhance the effectiveness, other priority initiatives, and different points of view between public-private use cases and public-private use cases. This is the end of the explanation from the secretariat, but I would like to first introduce the comments of Committee Member Taki, who is absent today. "I believe that the Secretariat's proposal for short-term measures is appropriate. The certificate of employment is the number one topic that resonates with users due to the severe time and movement constraints of users, and I think it is a use case that can be used as a reference for implementation without being fictional. The regulatory reform Promotion Council has already reduced the local rules and issued a standard format. The groundwork has been laid for information sharing. Data such as working hours can be somewhat complex, so if we can achieve results in reliably passing on these data, I think it will be easier to connect to the next time. As a company that provides payroll and time and attendance management services, we believe that this is a function where it will be easy to provide information to customers and gain recognition when the system is actually put into operation. As already mentioned, such private-sector partnerships are important. That's all from Commissioner Taki. Once again, I will hand over the proceedings to the Chairman of the National Land Council. Thanks in advance.

Chairman: Thank you very much. Now, with regard to the issue of transferring responsibilities from the private sector to the public sector, in particular short-term efforts, focusing on what we would like to work on most, a hand has already been raised. Mr. Kasai, please go ahead.

Committee Member Kasai: Although it is related to the previous discussion, as I listened to the discussions of the VCs, what I thought was difficult was that until now it was only two characters, for example, if you look only at the part where it is used, if it is issued by the government it is handed over to the individual, it does not matter in the previous case, but in this case, as the characters are in three places and three people in the final receipt, I think it is necessary to thoroughly investigate the missing parts and areas where there has been no contact until now. So, although the case of receiving is relatively easy to investigate in this case, I think it is necessary to thoroughly investigate how it is issued, that is, whether the private sector is doing it, probably from the initial stage, so that it is difficult to understand who the stakeholders are, and I don't think it is even necessary to discuss how to switch from volume to switching. As for the previous case, as for how it is used, after it is issued by copy machines, convenience store delivery, etc., whether it is probably possible to understand how it is used, that is, whether the private sector is doing it, probably from the initial stage, so that in either case, I think it is necessary to investigate the insufficient parts when it is issued from two to three.

Chairman: , that's why you are talking about a trust chain or a network rather than just a chain.

Committee Member Kasai: On the other hand, the burden on the equipment for the verification, and the difference between the previous case and this case is whether the user pays or not. There are considerable differences in these areas, so I thought it would be necessary to consider how to handle the cost burden, putting the actual specific case aside.

Chairman: Thank you very much. That's a big point when we actually try to spread it. Is there anything else?

YOKOTA: On a somewhat meta note, there are probably various types of privately issued certificates. One of them is a work certificate as a use case. Since there are various types of certificates, it is likely that the receiving side will not know how to interpret them. I think this is the case on our side. I was wondering where it is written about, in other words, the way of issuing is completely different between Company A, Company B, and Company C, and on the receiving side, the way of receiving is different between City A, City B, and City C. I think that wanting to do something about such things is probably within the scope of the VC this time, but I didn't really know where the part of adjusting it was included. Is this something that can be done with a standard form of issuing method?

Chairman: I'm trying to say that this is what you see on the screen right now under the section on how to issue VC.

YOKOTA: I am not sure if I can do something about it. In other words, as Committee Member Kasai just mentioned, in the case of this pattern, the number of actors will increase dramatically. For example, if I could not receive it, or if I could not apply for a nursery school as a result of that, it could be an issue of who should take responsibility. Therefore, I think it is necessary to strongly state the standardization of the issuance method and the presentation method, which is to make sure that everything that needs to be completed is in place. I think it is necessary to strongly state the standardization of the issuance method and the presentation method, which is to make sure that everything that needs to be completed is in place. As long as it is done for the same purpose and with the same system, it can be used by any municipality and any company. I think it is difficult to say that VC is better than paper, so I would like to say this point strongly. I think it would be good to incorporate such an ideal at the stage of system design.

Chairman: Is this something that someone, somewhere, is thinking about? For example, with regard to a certificate of employment, it is written that what kind of items must be stated in order to complete the procedure, and that this should be standardized by the country. Is this something that someone is thinking about?

Digital Agency (Sawada): : Children and Families Agency has been making various efforts to standardize the format of the employment certificate, and I am not fully aware of the details. While a standard format or something has been created and issued, I have heard that the actual sites have not yet been unified.

YOKOTA: : From an administrative or legal point of view, it is probably the work of some ministry or agency taking the lead in unifying what are the standard lines in the confirmation work that is done in the administrative affairs of local governments. On the other hand, creating a system that can provide technical requirements that match it will be our discussion. I think we should write down what we think is necessary in order to serve as a guideline for designing the system.

Dr. Nakamura: This is Dr. From the current point of view, for example, I think that ① -1 on page 22 mentioned earlier corresponds to the clarification of the requirements for a VC that is acceptable by the government. For a moment, I thought that the keyword in it was expressed in "how to define requirements such as trust standards." However, since the phrase "in the case where there is a consignment relationship" is added, I understand that the issue is that we must first clarify what technical requirements must be satisfied by a certificate issued by a company in order for it to be accepted even if there is no consignment relationship. What do you think?

Dr. Sakimura: Mr. Is it okay to supplement that? As I mentioned in the technical working group, the issue of legitimate issuers comes up, but this is about how to create a trust chain to reach that point, and not just in this case of delegation. It is necessary for all cases. Therefore, I wonder if it is a problem that the trust chain is crammed into this delegation.

Chairman: Not bad. That's a story about building a big infrastructure.

Dr. Sakimura: Mr. I don't think the infrastructure is necessarily that expensive. But when presentation, publication, and metadata discovery are all not on a standard protocol, the costs explode.

Digital Agency (kusunoki): There are various levels to be considered, and the requirements required by the Code of Civil Procedure are quite simple. It can be confirmed whether the document has been officially issued, and if asked whether it has been issued, it can be answered. In terms of how far the security control measures are actually taken technically, I think individual judgment may be made based on the nature of the affairs and the threat model. In any case, taking the employment certificate as an example, it has two layers, respectively. How to align the items of the content, and how to confirm the contents of the undercarriage, the technical method, and the technical interoperability. Unless these items are aligned and can be received, there will be no function. This is what was pointed out by Mr. Maruyama.

Dr. Sakimura: Mr. Trust chains are particularly important for private issuers.

Digital Agency (kusunoki): That's a big difference. It won't be an official document.

Chairman: , Committee Member: Is your statement relevant to the point being discussed? If not, I would like to ask the relevant questions first. What do you think?

Committee Member Itakura: , if it is related, it is related. Here again, you just talked about the cost. As you can see in the section on "Distribution of publishing tools and applications," I don't think each company will develop something. Instead, it will be SaaS, or a company will register and publish a set of SaaS that they have been using. Although this has been discussed, I don't think it will be that expensive. One difference from the public one I mentioned earlier is that, of course, it is necessary to prove whether the contents are correct or not, but VC does not do it. However, I think there is a risk that people think that the receiver is right because it is done at VC. I say this because I am a sole proprietor. I submit a certificate of employment to my blue full-time employee and send him / her to a nursery school or an after-school club, and I can easily write it. It is important for everyone to use it while understanding that doing it this way does not mean that the content is correct. If I don't say that, I might think that the contents are correct as soon as it comes to this. This is probably due to the digital nature, which tends to be the case. However, the Code of Criminal Procedure professor recently told me that there is an overseas paper that says warrants are issued in about three seconds when requested electronically, which is an urban legend that warrants are still reviewed relatively easily. I have not read the original text, but only heard it. In other words, if you put too much trust in the fact that it comes in electronic form, and you keep doing it even with a sloppy Certificate of Employment, Nursery schools increased a lot for a while, and so far, it has not become such a social problem that it is very difficult to be on standby. However, as it affects people's lives, if the number of lies increases easily, it could destroy the trust infrastructure. So, of course, I think it is better to do it. As I just mentioned, SaaS will come out, so I don't think it will cost that much, but it is about the content. I thought that if I do not know the contents, I can not leave it alone.

Chairman: This is an old but new problem. Thank you.

Committee member Matsumoto: It was around 2000 when the Electronic Signatures in Global and National Commerce Act was established, but I was naive at the time, as I am now, and I couldn't understand the gap between existing business models that are based on paper documents and others. I thought a lot of things could be done if electronic signatures were possible, but I don't think they fit in with existing business models at all, or I think there is a gap. Off the topic of corporate trust chains, there is another Digital Identity Wallet in the EU, the Business Wallet. Just as individuals want to prove their attributes, companies also want to prove their attributes. Business identity wallets do this with Verifiable Credentials, and I think if you include that much, you can see the relationship between the two sides. However, although it is outside the scope here, it is quite close in terms of specifications. We are aiming for the same system. Another point I would like to make is that, of course, I am well aware of the considerable differences that exist between the public and private sectors, and between the private sector and the public sector. However, in the case of eIDAS within the EU, the situation is relatively the same, with both the public and private sectors being the same. It is the same as the GDPR, and the basic idea is that the government does not believe unconditionally. In this case, the Electronic Signatures in Global and National Commerce Act itself is a law for the people and does not apply to the public sector. This is also a system that is not the same in a sense, but there is a problem from the beginning whether it is really good. I think we need to take that into account as well. In other words, it is possible that both the public and private sectors must be the same in terms of how we view reliability and trustworthiness. I repeat, but the Electronic Signatures in Global and National Commerce Act is the people. Therefore, we need to consider a framework of trust that would essentially utilize the Electronic Signatures in Global and National Commerce Act. I believe that the EU's position is that a similar framework should essentially be applied to the public sector. Within the EU, the idea of a shift from the private sector to the public sector, and from the public sector to the private sector, is not very strong. Recently, a public EAA has been introduced in the EAA, and I think the authority has been clarified because it is the public sector. However, another point is that what should be done between the public sector in Japan and the public sector overseas should be discussed at a higher layer, so I feel that a mechanism such as third party certification will be necessary even for the public sector.

Dr. Sakimura: Mr. What Professor Matsumoto just said is exactly the same as what I said at the beginning. It is extremely important to ensure trust that third parties can check the legitimacy of issuance and show it. In the case of the EU, PID, QEAA, and PubEAA, and what must be done for each has been decided, so I thought that such things could be used as reference. In addition, in Europe, even those operated by administrative agencies are kicked out (from the trust framework) without hesitation when certification lapses.

Chairman: I think what you have just said belongs to the category of discussion that unless international interoperability is ensured in the end, the world will end up being like the Galapagos Islands. So, in other words, in Japan, trust in the public sector is very strong, and the private sector is required to conduct verification properly. However, looking beyond that, interoperability will not be achieved unless verification is conducted in a world where people will not believe it just because it is issued by the Japanese government. That is their concern.

YOKOTA: From another perspective, I would like to ask you to consider the protection of Japanese nationals residing abroad, which is the usual point.

Chairman: . So it's like believing or not believing a passport.

YOKOTA: We are currently discussing the issue of issuance by the private sector. However, this issue is probably the same for both the public and private sectors. We need to take a long-term view to the future in which the establishment of such a system is mutually approved. At the very least, there should have been discussions at the DIW Advisory Board on issues such as whether it is easy for foreigners to use, or what happens when Japanese living abroad use what they have obtained. Since this is a short-term issue, I thought it would be no use saying too much, but I think we should be aware of that kind of discussion again. However, since it is said that it is not necessary to discuss to such an extent in the short term, I think it is probably out of the question with this report, but as a general rule, the Japanese government offices are too indifferent to making other countries trust Japan, and they had a hard time with the Act on the Protection of Personal Information. I think we need to be aware of that.

Chairman: I think it is possible to write that we should be aware of the medium - and long-term perspective in this report as well.

YOKOTA: Yes. I think it is a good idea to include it there.

Digital Agency (kusunoki): I would like to have frank discussions on this matter, and I think that we are doing what we need to do. It is not necessarily the case that the Government of Japan is indifferent to interoperability with other countries. For example, the Government Certification Authority of the GPKI has obtained certification for WebTrust. We are making thorough efforts including external audits, and will do so if necessary. On the other hand, the European framework that you pointed out is based on the fact that Europe is originally a region, and there are very unique European circumstances, such as how to create a digital single market where there are multiple countries within the region. Whether that is truly a global rule or an initiative based on the regional situation of Europe was discussed in detail. Japan is not only associated with Europe, but also has contact with many countries including the United States and Asia. Under the current situation where interoperability of digital identity wallets has not been realized even in Europe, we would like to have down-to-earth discussions.

Chairman: This is not a question of whether or not the European way of thinking should be included, but rather that we must aim for interoperability in the international environment.

Digital Agency (kusunoki): What we can see now is that the international framework for border control and driver's licenses is already in place in the U.N. and the ICAO, and Japan is of course a member of this framework. As for other cross-border use cases, the Japan-EU Digital Partnership is working on the issue of academic background, but it is difficult to see specific use cases. I believe that how to secure it internationally is a theme that needs to be thoroughly discussed in detail.

Chairman: We will put it on the agenda. . Now, I believe most of you have spoken on Issue No. 2. Is it all right from private to public? I understand. To give an intermediate summary of the discussions so far, for the public sector to the private sector, when assuming something like an independent wallet, what should be the requirements? The reason for wanting to do so is to consider realizing something like selective disclosure from an independent wallet. That is why we would like to consider it with a bit of a sense of speed. From the private sector to the public sector, an extremely diverse range of players, including individual business operators, are coming up with various types of products. In this situation, standardization at the protocol level as well as semantic standardization will have to be considered. In addition, when many players are involved, how will a trust-chain-like system be established? Unless Japan is able to deal with these issues, which I believe is a matter that concerns both the public and private sectors, the cost will explode and the system will end up in a situation where it is no longer useful. I would like to prevent this from happening, and I think we need to create a model of who will actually bear the burden and how. The other point is the one raised at the end. In the end, this will become a cross-border issue, so we must work on something that properly takes these issues into account. In any case, issues such as the right of representation have already emerged as a fairly urgent issue, so we cannot take this issue too leisurely. This time, we were too hasty and on the contrary, we were late in some areas. I am not saying that we should hurry up, but if we do not do it with a sense of speed, there will be issues that do not work in reality. This sense of crisis is shared by the main body meeting, and I would like to share it with you. Including whether this kind of summary is good or not, I would like everyone to freely discuss how we should think about the agenda for next year and beyond. Can I go on to the next one now? It's good to go.

Digital Agency (Sawada): Finally, the secretariat will briefly introduce some of the other opinions that have been expressed so far, as well as initiatives for the next fiscal year and beyond. First of all, although I mentioned short-term measures earlier, it is of course necessary to consider medium - to long-term measures. The table on the left of page 27 is a reprint of the proposals raised in the previous pages. In addition to the issues raised at each meeting this year, various issues were presented by the committee members, and the main issues are listed on the right. For example, in the next fiscal year and beyond, we plan to continue discussions on matters such as how to ensure international interoperability, which was already discussed earlier, sorting out the relationship between card-substituting electromagnetic records and My Number Card's use of smartphones, and issues related to derivative venture capital. Among them, we are currently considering three matters that Digital Agency will work on in the next fiscal year and beyond. The first is, continuing from this fiscal year's discussion, risk countermeasures, requirements for VC and Wallet in administrative use cases, and specifying and documenting them. At the same time, how will you encourage the relevant parties to demonstrate this? This is my first point. The second is to involve actual players in individual use cases to specify business and function requirements and consider specifications. Of course, interoperability is also taken into consideration, but we will try to actually build it. This is my second point. Third, as I mentioned earlier, we will advance discussions on topics that could not be taken up or discussed in this fiscal year. This is the way we are currently thinking. That is all for the introduction by the secretariat. However, as this meeting is held at the end of the fiscal year, we would like each of you to speak for about two minutes, passing around a microphone, about the progress of our initiatives and our expectations for the roles of the administration in this regard, based on our medium - to long-term initiatives and Digital Agency's plans for initiatives in the next fiscal year and beyond. First of all, I would like to read on behalf of Committee Member Taki who is absent. "We believe that the Secretariat's proposal for" "medium - and long-term considerations" "is appropriate." Regarding our expectations of the administration for our efforts in the next fiscal year and beyond, as a whole, I believe it is very important to be aware of the Early Wynn, including today's two efforts. In addition, in order not to generate technical debts by being too conscious of Early Wynn, we understand that you are making as much effort as possible at this point by being comprehensive with the list of matters to be considered that has been developed in advance. The completeness of the list is not limited to this study. I think it will be a document that will be used as a reference in the future. That is all. Then, I would like to turn the microphone in turn. I think the seating order will be fine, so I would like Committee Member Kasai to speak in about 2 minutes. Thank you very much.

Committee Member Kasai: : This is the opinion of the users, or rather the Verifier side. Consumers and consumers will resist any change, even if there is such a way. As for the legal system and how it should be, not only in Digital Agency but also under a slightly larger umbrella, while properly including the competent ministries and agencies, the competent ministries and agencies may present issues. For example, the copy of the certificate of residence mentioned earlier. With VCs, as I mentioned earlier, we don't know how they are being used, so on the other hand, it will be necessary to conduct surveys on financial institutions and others. This cannot be done by individual optimization at all, and unless we consider the government as a whole, I think there is a risk of a considerable failure. As mentioned by Professor Yokota, the grand design should be established first, and then, in order to obtain the understanding of the public and business operators, it will be necessary to create successful examples or gain understanding through frequent use. To be honest, I wonder how often work certificates are issued, and where we should really start. I think the subsequent fate of this project will largely depend on these points. I think VCs are good, and they can be used for such purposes, including the My Number Card of the operating system, which will be accepted by the people, and be included in the wallet, and I expect discussions on the entire use to continue.

Dr. Sakimura: Mr. , Committee Member: All of the points listed here are extremely important, but if we were to take up any of them, we would have to consider which ones include delegation and delegation. I think this is extremely important. This is true for the age-verification issue mentioned earlier, as well as for corporations and AI agents. Currently, most of the hot spots are involved in delegation, so I would like to see them included. In addition, there are points to keep in mind regarding derivative VCs. I think this will probably involve format conversion, or issuing a paper version instead of the original issuer because they do not support it. In that case, I think it is possible to issue such a notary type. Taking these things into consideration, derivative VCs will probably become essential. Therefore, it is important to sort out the ideal form at that time in terms of diffusion. If possible, since everyone is running, I would like it to be in a form that does not shrink the private sector. These are the three points.

Dr. Nakamura: This is Dr. . The technical working group has studied various issues, and the topic of the VC issuance platform has come up. At the bottom of page 27, there is an article titled "Differentiation from signed PDFs." What are the problems with such a thing? These should be sorted out from a more technical point of view. Then, we should study VCs now and theoretically explain that we need to make VCs usable in the future. I thought it would be good if we could share this at the beginning and proceed with the study. Also, from an academic standpoint, universities are also starting to have to seriously consider the use of VCs. There are ID cards and micro-credentials. Micro-credentials have been discussed for a long time. However, just like the discussion here, from the standpoint of issuing certificates, I think it would be good if we could discuss how to make use of them to make everyone happy. I think this is a very close topic for discussion, and in that sense, I think it would be good if we could discuss how to make use of them, taking into account the advantages for the issuer, such as being able to exempt them from testing. That's it.

FUJI Sakae: The issues and opinions written on page 27 are all important efforts. What I think is that in addition to the issue of how consumers can use the system without confusion, when we consider the entry of the private sector, it is probably necessary to create a system that does not cause confusion in the private sector. In order to do so, I believe it will probably be necessary to convey the correct message of what Digital Agency is thinking and what the administration is thinking. For example, I referred to My Number Card's smartphone installation earlier. On the other hand, Digital Agency has released a digital Authentication App, which is connected via OpenID Connect. And now we start talking about the wallets of other VCs. From the point of view of users and the private sector, it seems that there are multiple trains running similar services under different names. I think this makes it difficult to understand what needs to be done. We have been talking about derivative wallets and derivative VCs since last year. The emergence of derivative minors is a problem, which was discussed a lot last year as well. I think it is true that this is leading to the possibility that, because it is difficult to understand, such things will be created, and through abstraction, services will be established. I don't think this is such a happy thing for everyone, so from the perspective of consumer protection, I think it would be good for you to focus on giving the right message in the right way. Similarly, I think interoperability is also important. When we think about international interoperability, it is assumed that credentials used internationally and credentials used locally will be separated. It is assumed that they will be separated for each use. This is also discussed below, but it is necessary to simultaneously consider presenting multiple credentials. Given that credentials for international presentation and credentials for local use will be issued from the same wallet at the same time, it would be unfortunate if the people creating the wallet had to support two standards. So international is quite difficult, including the question of who the international is. I think it is a difficult issue because we are talking about something like the least common multiple. However, I think we need to create a system that does not diverge from things that are too local. Although this has been mentioned a lot in the discussion points this time, I expect very much that you will lead to the organization of requirements, technology surveys, and the formulation of policies on how to implement them. That's it.

Committee member Matsumoto: It was around 2000 when the Electronic Signatures in Global and National Commerce Act was established, but I was naive at the time, as I am now, and I couldn't understand the gap between existing business models that are based on paper documents and others. I thought a lot of things could be done if electronic signatures were possible, but I don't think they fit in with existing business models at all, or I think there is a gap. : In particular, what I felt after that was that even though signatures became possible, standardization of the subject of signatures did not progress at all. This is also the case from the beginning, but since society has become based on human visual observation, we have not been able to break through it. I think this DIW / VC is likely to be one of the triggers to break through it. Even so, from my point of view, DIW and VC are only one means. Including that, as has been the case since then, we have to automate things that do not require visual observation, and there are many things that we do not understand unless we do it. I think it is highly likely that Digital Agency will be one of the triggers to break through it. Even so, from my point of view, both DIW and VC are only one means. Including that, I think it is good to try it first. It is a complex system, and there are many things that we don't understand unless we try it. I think that it is better to share such a sense of To-I have been able to do so. I was able to do. I. I. I. I think that it is not. I have been able to do it. I. I have been able to do such things. I. I think. I. I. I. I think. I think. I think. I think. I. I was able to sign. I. I thought. I. I. I. I. I think that I. I. I. I. I can do. I. I. I. I. I. I. I. I. I. I think that I think. I. I think that it is good. I think I. I think it is possible. I can be done. I. I. I. I. I. I think that it is good. I. I. I. I. I think. I thought. I. I think I. I. I think. I think. I think. I think I. I can. I. I can be done. I. I. I. I can. I. I. I think that I can. I have to do. I think it is good. I have to expect. I expect. I. I think. I think I. I think I believe I. I think I. I think I. I can expect. I think it first. I can think it. I don't understand it. I have to. I think of I think. I. I think that. I think. I believe. I. I thought. I. I thought. I. I. I can. I thought. I don't understand. I think. I thought. I can. I can. I. I think. I. I think it. I. I. I. I. I think it I think it. I thought. I. I thought I thought that I thought I believe I think. I think it is. I think it is. I think it. I think. I. I think it. I think it is. I. I think. I

YOKOTA: Basically, I agree with what you just said. In particular, what the breakthrough this time is is important in the mid - to long-term. Although the technology may change, what we want to change is probably to accumulate technical knowledge in order to review the current way of doing administrative work. I think this is probably the very big point of this project. I think the basic policy is to clearly state what we want to change, such as visual observation and the current situation where analog and digital are disconnected. However, in order to change that, it is also necessary to accumulate use cases from the bottom up. One thing to keep in mind when doing Agile is not to let people off the ladder. What I have in mind is, for example, when an advanced local government worked on a policy, the central government intervened later and ruined the approach. In that sense, I would like the Government to ensure the trust of the entire policy at the same time. In other words, starting small and growing big sounds good, but when branches and leaves are cut, if the system is such that those who bet on the cut branches and leaves lose money, then no one will come. This is the same for private sector in all sectors, as well as for local governments and actors within the country, and it is difficult if the number of people who think that what they did did not lead to results increases. So, where is the sandbox and where is the implementation? Each actor has a different profit structure, so I hope you will pay attention to these as you proceed. In addition, the perspective of how to get the government to get on board is also very important. It is probably the same as the people in the government that they don't know which one to do when similar systems are running. It is very important to think about a system that allows people who are not familiar with digital to take advantage of the fact that it is to make everyone's life easier. In fact, in the past five years, I have strongly felt that the local government level has been able to communicate fairly well about this, but the national level has not been able to do so. I hope we can do a good job on this. That's it.

Committee Member Itakura: : I would like to repeat what I stated at the beginning. Some parts of the certificate of residence, especially the issue of legal representation, are likely to be confirmed more seriously by the business operator. However, in terms of parent-child relations, or in other words, when it becomes necessary to provide legal representation, if copies of paper copies of the certificate of residence or the family register begin to circulate, I would like you to proceed with the idea that you have lost. Of course, my opinion is that there is no need to go that far. Most of the services can be provided by checking the box that says to the child that the parents say it is good. However, when I was asked to explain the revision of the Act on the Protection of Personal Information, I found that many business operators seem to be concerned about such a thing. Therefore, proving only the parent-child relationship with an extremely simple system is a very urgent task. In any case, we should proceed with the idea that we lose if copies of the family register begin to circulate. That is the worst case. As I mentioned earlier that the Australian government has introduced age restrictions. In this case, only the age should be checked, and in the first place, they are doing their basic policy of not even using the Public Personal Authentication. In any case, it is obvious that we should proceed with the idea that we lose if copies of the family register begin to circulate. That is the end. However, I would like to repeat what I have stated at the beginning. Of the Personal Information. Of personal information. It is not necessary. Of the work. However, most of the services, I think that it is good. However, I think it is good. Of the Personal Information I was asked. Of the Of course, I was asked to proceed with it. Itakura. Of course, I do not to that. Of the beginning. I was asked. Of personal information. Of personal information. I. I. Of the business I am asked to do so. Of personal information Of personal information, I, I was asked to provide such services, I was asked to provide I. Of personal information. I. I am concerned. Of the Of personal information Of personal information. Of course, Of the personal information. Of the personal information. Of personal information Of personal Of the personal information. Of the Of the Of the personal information. Of the I was asked to explain the revision of the Personal Information Personal information, I was concerned I. I. I. I. I. I. Of the parentI. I. I. I. I. I. Of the personal information. It is a. It. It. I. I. It. It is a It is the worst I. It is the worst case It It is a. It be done, I. I. I. I. I. It I. I was asked to explain that I. I believe that it is better. I. I. It I am concerned. It is concerned. I said I. I. That. I have been done. Of the letter of separation I. I. I. I. I. I. I. I. Of the. I. I. I think that, I. I believe. I believe, I think that I. I believe. I

Dr. Wakae: Thank you, . I think consumers have high expectations for this system. I think it is undesirable to require complete authentication and require the provision of unnecessary information when obtaining the consent of a legal representative for children's use of SNS. In that sense, if selective disclosure of age becomes possible on SNS, it will provide what users really want, which will boost the system and spread widely. As a consumer, you want to see the distributed, disintermediated nature of DIW. I don't think there will be discussions like the platform issued by the previous Technical Working Group, but I would like to see you keep in mind the importance of decentralized, non-mediated solutions. Also, as a consumer, it is very important to be able to make choices. In that sense, I think the perspective of how to make the ecosystem a business in the future is quite important. I think Apple and Google will do well in attracting their own services even if they do it for free. However, in order for independents to survive, we must consider what kind of business model there is. Actually, I think that there are things that are being done at high cost in identity verification even now. Like checking the money laundering bank. Of course, this is an international issue and we may not be able to change the rules of the law on our own. However, I think it would be a good idea to look for a long-term business model, taking into consideration the fact that it would be great if we could introduce this system in areas where identity verification costs are high. We support the independents. When we think about making it possible to make that choice properly, I think that certain legal rules for wallet providers and OS providers will become important, so I would like to see such things considered in the mid - to long-term. That's it.

Chairman: As such, unless this issue is properly discussed with a sense of urgency to a certain extent, digitalization will not make progress. We need to consider the world of procedures through users. Relatedly, as Mr. YOKOTA mentioned earlier, there are business operators who are likely to support this issue. As you mentioned earlier, there are various business operators who are likely to give consideration to this issue. Uncertainties should be eliminated. This is the direction in which we should proceed with this issue. We need to come up with clear policies at an early stage. There is an opinion that there is no time for verification test to take action. I understand this opinion, but I don't think that will be the case with the administration. I don't think so, but I think it is important to follow the procedures properly to a certain extent and to consolidate opinions properly, but at the same time to move swiftly. Under these circumstances, as you can see on page 27, the Technical Study Group has really raised various points of issue. Each of them is very important, but at the moment, it is still a laundry list, but I don't know what kind of system you will use next fiscal year to work on properly positioning it in the overall list. Although I don't know what system you will use next fiscal year, I think it would be good if you could work on properly organizing and advancing it with a sense of urgency. I think you will compile the draft of the report with such a tone, so I will be able to present that. This will be the last meeting in real life, but I would like to ask the committee members to massage it again, and although it may be a bit rough, I would like you to trust it and leave it with us. Up to now, we have carried out various kinds of chair-taking, and this one is close to the highest level of chair-taking. However, I think it is important to produce an output in this fiscal year in order to lead it to the next fiscal year to a certain extent. Of course, we will show the original plan and have various discussions. Depending on the situation, I may ask you to give me your opinion on this part in particular. I would like to make a landing within this fiscal year with your support. Is that OK? <No objection> Thank you. Now, I would like to end with a speech from the secretariat, followed by a speech from Mr. Director-General Kusunoki. First, the secretariat, please. Here's your change.

Digital Agency (Kita Inoue): . Regarding the report you have just pointed out, we intend to draft the report after fully reflecting the results of today's discussions. At the moment, the secretariat is still working on a proposal. For the time being, the table of contents is being prepared in this manner. Broadly speaking, I would like to create a table of contents that includes the background and objectives of the meeting, the results of specific discussions, and a summary at the end. My understanding is that the opinions we received today will basically center on the second point. In any case, the secretariat has prepared a solid report, which will be sent to the committee members around the second week of March. We will work on it, and at that time, we would like you to confirm and point out in writing. We will take the points raised there seriously and reflect them. I have heard that the final decision will be left to the chair, as decided by the members of the committee. I hope that this decision will be accepted. Thank you very much. That is all about the report. In addition, not only the report but also administrative communications from the Secretariat will be issued before the closing of the meeting. Today is the final day of this year's meeting of the Advisory Panel. As for the next fiscal year, I would like to inform you as soon as it is decided. Thank you in advance. In addition, today's meeting minutes will be published on the Digital Agency website after being confirmed by the committee members later. Of course, when the report is finally set, we would like to publish it on the Digital Agency website. In that case, you will have to confirm various matters after the meeting. I would like to ask for your cooperation. Finally, on behalf of the secretariat, I would like to say a few words from Mr. Kusunoki, Mayor of Digital Agency Group of Common Functions for Digital Society.

Digital Agency (kusunoki): Thank you very much for discussing freely and actively. This fiscal year, we had a very quick start, but initially, we received many suggestions for actually promoting the use of VC, DIW, etc., including methods for risk countermeasures and matters to be addressed for their realization. Digital Agency has entered the latter half of its 5th year, and we have been studying Wallet in a different form for nearly 4 years. I think the first VC issued by the Japanese government was for a vaccination certificate in 2021, but I had not taken it seriously at that time, and it took less than a year for the certificate to be issued, and by now, wallets are being used in various parts of the world, and they have been standardized and have international interoperability. It was 2026, so there were expectations that this level of interoperability could have been achieved in just five years. On the other hand, we are not the only ones in trouble. Since Digital Agency was established, we have had to go to experts, ISO committees, and various other experts, not only to hear their opinions, but also to get live information much more often than in the past. I think we are in trouble all over the world. Probably, compared to the European large-scale pilot, the one equipped with a smartphone in My Number Card is actually operating in a much more large scale manner. In the U.S., various efforts for driver's licenses have been made at the state level, but when it comes to whether or not these efforts are being made at the national level, I think the entire world is suffering in the same way. In a similar vein, something that's been hard to come by in the last few years, This year or last year, thanks to you, we also released the "Guidelines for the Treatment of Digital Identities in identity verification in Administrative Procedures, etc." Immediately before that, NIST SP 800-63, which had been a public draft for a long time, became an official version. In the first place, we are aware that we are doing something difficult, and I am very sorry that it was held with a very small number of meetings. From the next fiscal year onward, we would like to start from what we should work on in the short term as a Digital Agency, including the concretization of requirements required for administrative use cases and the promotion toward the realization of individual use cases. Some people have said that now is not the time to hold a verification test, but even so, I think that because it is a government office, it will hold a verification test. However, the Civil Procedure Code is a relatively well-established law, and since it is surprisingly simple for the government to issue a VC, I think it can be done even under the current rules. I think we have to think seriously about starting with things that can be done properly and making it into the real thing, rather than calling it a verification test and running away. Now, Vice-Minister for Digital Transformation, Chief Officer of Digital Agency has become a triangular figure, and people are very interested in security and trust. In this situation, it is important to move your hands and try them out. We are being pushed to move our hands properly instead of just discussing. Therefore, I think it would be ideal if we could do the right things quickly and think while running. By the way, regarding these contents, I would like to fully reflect today's opinions in the compiled materials scheduled to be released later. Therefore, I hope that the members of the committee will continue to support us until the end. Thank you so much.

Digital Agency (Kita Inoue): This concludes the meeting of the Advisory Council on Attribution Verification Issues. Thank you very much.

Greater Than