International Journal of Networking and Computing
Online ISSN : 2185-2847
Print ISSN : 2185-2839
ISSN-L : 2185-2839
Special issue on the Thirteenth International Symposium on Networking and Computing
Proposal of an Identity Verification System Using Trusted Execution Environment in the Japan's Digital Authentication App
Tomoki YasuiHidenobu Watanabe
著者情報
ジャーナル オープンアクセス

2026 年 16 巻 2 号 p. 118-146

詳細
抄録
As digital identity systems continue to evolve, ensuring the secure handling of personal data and authentication tokens on the service provider side has become increasingly critical. Japan's My Number Card is a national identification card that contains an IC chip storing personal information such as name, address, and date of birth, and is increasingly used for digital services. The Digital Authentication App provided by Japan's Digital Agency enables online identity verification using the My Number Card and provides APIs that allow service providers to access user information with the user’s consent. Although the Digital Agency mandates the secure management of such data, its guidelines do not specify concrete technical countermeasures for server-side environments that process and store tokens and personal data. To address this issue, we propose a practical server-side architecture that integrates AWS Nitro Enclaves, a Trusted Execution Environment (TEE), with Japan's Digital Authentication App APIs. Our system confines OpenID Connect (OIDC) token validation and user information access entirely within a TEE, thereby resisting insider threats and compromised operating systems. Furthermore, audit logs are protected with digital signatures and hash chaining, enabling verifiable integrity and non-repudiation. To validate the feasibility and performance of the proposed architecture, we implemented a prototype demo system and conducted measurement experiments. Preliminary measurement results indicate that the integration of TEE introduces limited performance overhead while enhancing security guarantees. This architecture demonstrates a practical and scalable approach to strengthening trust in digital authentication services from the service provider's perspective.
著者関連情報
© 2026 International Journal of Networking and Computing
前の記事 次の記事
feedback
Top