MyKey platform (authentication platform for local governments, etc.)
- Last Updated:
It is one of the platforms that enable certification by by utilizing the My Number Card Japanese Public Key Infrastructure (JPKI) in administrative services. It introduces the supported function and procedures for introducing the service.
Table of Contents
- What is My Key Platform (PPID method)?
- What is My Key Platform (My Key ID method)?
- Terms of use and privacy policy
- Inquiry
1. What is My Key Platform (PPID method)?
1. 1. Overview
The MyKey platform (PPID method) ensures the security of function usage by providing a My Number Card that pays out a unique user identification (PPID (*)) for each service and enables the use of My Number Card for multiple services.
In order for Japanese Public Key Infrastructure (JPKI) to be used in various situations for administrative services, we provide services in two categories with different function and features.
- *PPID (Pairwise Pseudonymous Identifier) is a unique pseudo nymous identifier (different from MyKeyID) generated by the MyKey platform for each linked system and linked to a My Number Card.
1.2. Characteristics of each type
The MyKey platform (PPID method) has the following two usage patterns.
- Type (1) APIs: In response to the use of a smartphone by scanning over the Internet without the need to enter a My Number Card security code, the MyKey platform provides local governments with a card scanning function and a scanning screen that support face-to-face use. The validity of the electronic certificate for user certification to Japanese Public Key Infrastructure (JPKI) can be confirmed.
- Type 2 (APIs): Instead of municipalities having to prepare a card reading function and a reading screen, it is possible to confirm the validity of the electronic certificate for the user identification to Japanese Public Key Infrastructure (JPKI) in a wide range of scenes including non-face-to-face environments.
By selecting either or a combination of both, it is possible to customize the service to match the content of the administrative services provided by each local government. The characteristics of each type are as follows.
1. 2.1. Type (1) API, Type (2) Common API
- It is possible to issue PPID (pseudonym identifier) which is given identifier for each administrative service
- For municipal systems that provide administrative services, by linking PPIDs (pseudonymous identifiers) to the user number of the municipal system in cooperation with the My Key platform, it is possible to operate authentication by My Number Card and administrative services in an integrated manner
- It is possible to confirm the revocation status of the signature electronic certificate associated with the user identification electronic certificate and to confirm whether or not there has been a change in basic four information (name, address, date of birth, gender) (*)
- * Keep in mind that it is not a electronic certificate that reads the signature function from the My Number Card to confirm its validity.
1.2. 2. Type ①
- Mainly face-to-face services such as over-the-counter services
- CARD-READING SCREEN AND CARD-READING function
- Support for "Hold"
- Provision of basic four information (name, address, date of birth, gender) scanned from a app for assisting input of card information to a local public system
- System terminals are WindowsOS.
- Verification by smartphone is available (Type 1 in cooperation with Digital Verification Service (when using APIs ))
1.2.3. Type ② API
- Validity of electronic certificate to Japanese Public Key Infrastructure (JPKI) for user identification can be confirmed using APIs
- The OS of the system terminal does not matter.
Please see Table 1 below for a comparison of MyKey platform services. For details on each type of service, please contact Inquiry Form (Digital Agency MyKey Platform) .
Table 1 Comparison of Mikey Platforms
| Item | My Key Platform (PPID method) Type 1 API | My Key Platform (PPID method) Type (ii) API | Digital certificate service | Digital Verification Service (when using APIs |
|---|---|---|---|---|
| Usage Scenarios | Enable Public Personal Authentication by embedding in counter terminals for face-to-face services | Certified function only (PPID issuance and Public Personal Authentication are possible) | By installing the app on users' smartphones, Public Personal Authentication can be performed on the smartphone. | Public Personal Authentication is possible by embedding it in the counter terminals of face-to-face services. In addition, by installing an application on the user's smartphone, Public Personal Authentication can be performed on the smartphone. |
| Available Organizations | Executive branch | Executive branch | Government / private sector | Executive branch |
| Reader terminal | PC terminal (Windows) | - (Developed by service provider) * 1 | Smartphone (iOS/Android) | PCs (windows), Smartphones (iOS/Android) |
| Scanning screen and scanning function provided by Digital Agency | Windows Apps | - (Developed by service provider) * 1 | iOS app / Android app, computer browser * 2 | Windows app, iOS app / Android app, personal computer browser * 2 |
| PPID Disbursement | Correspondence | Correspondence | Correspondence | Correspondence |
| Use of Kazashi | Correspondence | Not Supported | Not Supported | Correspondence |
| Function provided by basic four information | Correspondence | - (Developed by service provider) * 1 | Correspondence | Correspondence |
| Response to the Signing electronic certificate | Not Supported | Not Supported | Correspondence | Not Supported |
| Response to electronic certificate for Identification | Correspondence | Correspondence | Correspondence | Correspondence |
- * 1 We can also develop by incorporating the "Kazashi scanning client software" (DLL file for Windows, iOS / Android library) provided by Digital Agency into the service.
- * 2 For authentication on a computer browser, by displaying a QR Code on the browser and having the smartphone read it, the My Number Card can be read via the smartphone.
1.3. Specifications
My Key Platform (PPID method) usage patterns and supported regions / function are as follows.
1. 3.1. Assumed Usage Patterns
- Use in face-to-face environments using Windows PCs (Type 1)
- Can be used regardless of the type of OS and usage environment (face-to-face or non-face-to-face) (Type II)
1.3.2. Types of electronic certificate that can be validated
- Electronic certificate for Identification (Compatible with both Types 1 and 2)
- It is something that proves the identity of the user online.
- *For details, please refer to the electronic certificate Class electronic certificate.
1.3. 3. Methods of electronic certificate validation
- OCSP Responder Method (Both Types 1 and 2 Supported) (* 1)
In an online environment, the validity of each electronic certificate is inquired and authenticated. This system makes it possible to check the revocation status in real time. - CRL Provision Method (Only Type ② is supported (* 2))
This method confirms the validity of a electronic certificate from a revocation list that is issued periodically (once a day, etc.), making it possible to process requests quickly and in batches.
- * 1 When using private sector (JPKI), which uses OCSP responder method with Japanese Public Key Infrastructure as the signature verifier, in principle, a fee will be charged for providing electronic certificate revocation information (however, it will be free of charge for the next three years from January 1, 2023). On the other hand, when using the MyKey platform, no fee is charged because the administrative agency becomes the signature verifier.
- * 2 If the OCSP responder method cannot be used due to maintenance, etc., validity confirmation is also performed in the CRL provision method even in Type (1).
For details, please refer to the validity confirmation method for the electronic certificate.
1.3.4. Using My Number Card's Kazashi application (Type 1: APIs only)
With the amendment to the Public Personal Authentication Act, a provision has been established regarding a method that does not require the entry of a personal identification number (PIN) for identity verification by the City of My Number Card. For details, please visit , Client Software for in-person use of My Number Card without PIN, .
1.3.5 Types of collaboration with digital authentication services (1) APIs
Type (1) In the linkage of digital authentication services of API, the same PPID is issued for Type (1) API and digital authentication services of My Key Platform, so authentication using smartphones is possible.
- *For more information on digital certification services, see "Digital Certification Services Digital Agency Web Service Application."
1.4 Implementation Steps
The installation procedure is as follows.
- 1. Inquiry Form (Digital Agency MyKey Platform)
- 2. Receive application forms, etc. from Digital Agency
- 3. Submit the application form, etc. * After submitting the application form, etc., approximately three weeks are required until the specifications are provided, due to the procedures required for the disclosure of technical information, etc.
- 4. Mykey Receive information necessary for development, such as platform specifications
- 5. Renovate or develop the system of providing administrative services to link with the system of the My Key platform
- 6. Perform an integration test
- *Type ② If you use API, you can skip steps 1 to 3. Start checking from step 4.
- *When using Type (1) API, which is linked to digital authentication services, you need to apply for digital authentication services, in addition to the Type (1) API introduction procedure. You will be informed after applying from the inquiry form.
2. What is My Key Platform (My Key ID method)?
2.1. Overview
The MyKey Platform (MyKey IDmethod) is a platform that utilizes the function of Japanese Public Key Infrastructure (JPKI) to utilize My Number Card in administrative services using Internet connection systems.
Currently, the My Key platform is used to register My Key IDs (* 1) linked to library user numbers on the My Key platform, allowing My Number Card to be used as a library card.
- * 1 Unique IDs issued to users of the MyKey platform. Issued in response to the issuance number of the My Number Card for electronic certificate user certification, it is used as a key to identify users in order to provide various services and Individual Number Card Point on the MyKey platform.
2. 2. Features of the MyKey platform (MyKey ID method)
The Mikey platform (Mikey ID method) has the following characteristics.
- For municipal library services only
- Can be used by introducing the "My Key Platform Utilization Software" provided by Digital Agency, and no need to renovate systems providing existing administrative services (WindowsOS only)
- Response to Use of Kazashi on the My Number Card
2.3. Implementation Steps
The installation procedure is as follows.
- 1. In order to obtain the information necessary for the introduction procedure (IDs, passwords, etc.), please contact via the inquiry form (Digital Agency My Key Platform).
- 2. Please refer to the pages in the "Getting Started" guide we will send you from Digital Agency to obtain the operation manual and to confirm the necessary procedures and manuals.
- 3. Download the "software for use with MyKey Platform, etc."
- 4. Install the "MyKey Platform Utilization Software" on the local government's terminal and perform the necessary settings.
- *It is possible to use without modifying the system that provides administrative services.
3. Terms of Use and Privacy Policy
4. Inquiry
For inquiries related to the MyKey platform, please contact the Inquiry Form (Digital Agency MyKey Platform) .