You are here: Resources > FIDIS Deliverables > Forensic Implications > D5.4: Anonymity in electronic government: a case-study analysis of governments? identity knowledge > 
Identification in Belgian federal eGovernment  Identification versus anonymity in e-government
COMMON AUTHENTICATION MEANS: THE BELGIAN ELECTRONIC IDENTITY CARD
 pseudonymous

 

Common authentication means: the Belgian electronic identity card

In this section, we briefly describe some of the technical aspects of the Belgian eID, which can be seen as an example of a so-called PKI infrastructure. An extensive description of this infrastructure can be found in FIDIS deliverable D3.6.

The card looks like a normal smart card (e.g., a bank card) and displays a number of personal and administrative data: 

  1. the identity card holder’s name (family name, up to two given names, and the initial of a third name),  

  2. title,  

  3. nationality,  

  4. place and date of birth,  

  5. gender,  

  6. picture,  

  7. two hand written signatures, i.e., the one of the card holder and the one of the civil servant who issued the card,  

  8. validity period of the card (five years),  

  9. the card number,  

  10. the national Registry Number of the holder,  

  11. the place of delivery of the card, and 

  12. a machine readable ICAO (international civil aviation organization) zone. 

All these visual data are also stored on the chip in a so-called identity file. The residence address of the identity card holder is stored separately, in the address file, to allow easy updating during the validity period of the card. The National Registry digitally signs the address file and the identity file to guarantee the link between both files.

The chip on the card can perform digital signatures and key generation. There are no concrete plans to integrate decryption functionalities in the eID. In total, a Belgian eID holds three different private signing keys: one to authenticate the citizen, one for non-repudiation signatures, and one to identify the card itself towards the Belgian government.

The eID is able to compute digital signatures with all of them. For the citizen’s authentication key and non-repudiation signature key, this is only done after the card holder enters a PIN. It is relevant to note here that both certificates also contain the globally unique identifier of the certificate holder. 

 

Identification in Belgian federal eGovernment  fidis-wp5.del5.4-anonymity-egov_01.sxw  pseudonymous
29 / 45