In an initiative led by the Finnish Population Register (VRK), a department of the Finnish Ministry of the Interior, mobile specialist SmartTrust is helping mobile users in Finland to securely identify themselves and sign for goods and services across a range of public and private sector providers using just their mobile phone.
Since 1999, VRK has been responsible for issuing State Citizen Certificates to Finns, a national ID card driven by the Finnish Government and seen as an important means of identification within an electronic information society. Now, in the advanced mobile market of Finland, the security functionality contained within these cards (based on the EU Directive for electronic signatures) has been incorporated into the SIM card by SmartTrust, turning the mobile phone into a personal trusted device able to remotely authenticate an individual, protect identities and create a legally binding digital ‘signature’. SmartTrust has signed agreements with three Finnish operators, including Elisa, who will issue new SIM cards – containing the State Certificate – to subscribers.
Using the new SIMs in the handset will enable users to access a range of public and private sector services, including electronic banking and government web and mobile services. With their mobile phones, Finns will be able to authenticate themselves when electronically filing tax returns, registering for social security and paying for goods online. Creating a digital signature from the handset may even be used as proof of identity at a physical point of sale.
“The mobile phone and SIM card have, by default, become the world’s most pervasive smart card / card reader combination,” explains Paul Cuss, CEO of SmartTrust. “Unlike the existing credit-card sized ID cards that Finns carry around in their wallets, the SIM-based certificates do not require the user to be present when authenticating himself via an independent card reader. In this instance, the handset acts as the card reader, requesting the user to authenticate himself through a PIN code request, and sends an electronic digital signature to the service provider.”
“Following the example of Finnish banks, commercial service providers and public institutions are moving their services into electronic channels. The mobile citizen certificate will become a secure, user friendly and cost effective tool for consumers when authenticating themselves for electronic services. The mobile citizen certificate will replace service specific user ID´s and passwords and the one time passwords that are used today. Service providers will now benefit from a government guaranteed identity for the person accessing a service.” states Mikko Saarela, Enterprise Director of Elisa.
“Working within EU guidelines, and the Finnish Parliamentary Act on electronic signatures, the SmartTrust solution is built around Public key Infrastructure [an industry standard security protocol]. This means that when a Finn uses his mobile phone to make a payment, place an order or simply register an application with a public service it is legal and binding,” adds Cuss.
With mobile penetration in Finland currently at 90%, the move to embed the state identification onto the phone is a logical step and one that will help to grow the network of available services for consumers. Each of the Finnish mobile operators working within the scheme will coordinate with VRK and the police to manage the authentication of citizens and the issuance of cards.