{"title":"数码“黄卡”,使用社区PKI证书安全地记录疫苗接种","authors":"Stephen Wilson","doi":"10.1109/ISTAS50296.2020.9462214","DOIUrl":null,"url":null,"abstract":"The Yellow Card or carte jaune is a paper booklet in a standard format set by the World Health Organisation in which a person’s vaccinations are recorded by healthcare officials. Numerous initiatives are striving to create both digital vaccination records and new digital identities for people with little or no official documentation; i.e. “low doc” persons. Yet there is no globally agreed model for identity, nor any standardized way to establish identity. Nevertheless, field workers today are able by and large to establish the bona fides of Yellow Card holders with adequate certainty for the paper-based system to function most of the time. This paper contends that vaccinations should be digitized without introducing new identity systems, since a lack of formal identification is obviously not preventing Yellow Cards today. This paper describes a new digital Yellow Card, deployable on most regular mobile phones, in which public key certificates represent vaccinations and other credentials, vouched for by officials or field workers. The design has practical benefits for the digital engagement and privacy of low doc persons. It also shows how traditionally hierarchical public key infrastructure can be deployed without dictating identification protocols to communities, thus avoiding some of the controversies that plague this technology. The PKI security function can remain centralized while certificate issuance is decentralized, which leaves community organizations free to carry on their business as usual.","PeriodicalId":196560,"journal":{"name":"2020 IEEE International Symposium on Technology and Society (ISTAS)","volume":"44 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-12","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"1","resultStr":"{\"title\":\"A digital “Yellow Card” for securely recording vaccinations using Community PKI certificates\",\"authors\":\"Stephen Wilson\",\"doi\":\"10.1109/ISTAS50296.2020.9462214\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The Yellow Card or carte jaune is a paper booklet in a standard format set by the World Health Organisation in which a person’s vaccinations are recorded by healthcare officials. Numerous initiatives are striving to create both digital vaccination records and new digital identities for people with little or no official documentation; i.e. “low doc” persons. Yet there is no globally agreed model for identity, nor any standardized way to establish identity. Nevertheless, field workers today are able by and large to establish the bona fides of Yellow Card holders with adequate certainty for the paper-based system to function most of the time. This paper contends that vaccinations should be digitized without introducing new identity systems, since a lack of formal identification is obviously not preventing Yellow Cards today. This paper describes a new digital Yellow Card, deployable on most regular mobile phones, in which public key certificates represent vaccinations and other credentials, vouched for by officials or field workers. The design has practical benefits for the digital engagement and privacy of low doc persons. It also shows how traditionally hierarchical public key infrastructure can be deployed without dictating identification protocols to communities, thus avoiding some of the controversies that plague this technology. The PKI security function can remain centralized while certificate issuance is decentralized, which leaves community organizations free to carry on their business as usual.\",\"PeriodicalId\":196560,\"journal\":{\"name\":\"2020 IEEE International Symposium on Technology and Society (ISTAS)\",\"volume\":\"44 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2020-11-12\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"1\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2020 IEEE International Symposium on Technology and Society (ISTAS)\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/ISTAS50296.2020.9462214\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 IEEE International Symposium on Technology and Society (ISTAS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ISTAS50296.2020.9462214","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 1
摘要
黄卡(carte jaune)是世界卫生组织(World Health organization)制定的标准格式的纸质小册子,由卫生官员记录个人接种疫苗的情况。许多举措正在努力为很少或没有官方文件的人创建数字疫苗接种记录和新的数字身份;即“低doc”人。然而,目前还没有全球公认的身份模式,也没有建立身份的标准化方法。尽管如此,今天的现场工作人员基本上能够确定黄卡持有人的真实身份,并有足够的确定性,使以纸张为基础的系统在大多数情况下发挥作用。这篇论文认为,疫苗接种应该数字化,而不引入新的身份系统,因为缺乏正式的身份证明显然不能防止今天的黄牌。本文描述了一种新的数字黄卡,可在大多数普通移动电话上部署,其中公钥证书代表疫苗接种和其他凭证,由官员或现场工作人员担保。该设计对于低文档人员的数字参与和隐私具有实际的好处。它还展示了如何在不向社区规定识别协议的情况下部署传统的分层公钥基础设施,从而避免了困扰该技术的一些争议。PKI安全功能可以保持集中,而证书颁发是分散的,这使得社区组织可以像往常一样自由地开展业务。
A digital “Yellow Card” for securely recording vaccinations using Community PKI certificates
The Yellow Card or carte jaune is a paper booklet in a standard format set by the World Health Organisation in which a person’s vaccinations are recorded by healthcare officials. Numerous initiatives are striving to create both digital vaccination records and new digital identities for people with little or no official documentation; i.e. “low doc” persons. Yet there is no globally agreed model for identity, nor any standardized way to establish identity. Nevertheless, field workers today are able by and large to establish the bona fides of Yellow Card holders with adequate certainty for the paper-based system to function most of the time. This paper contends that vaccinations should be digitized without introducing new identity systems, since a lack of formal identification is obviously not preventing Yellow Cards today. This paper describes a new digital Yellow Card, deployable on most regular mobile phones, in which public key certificates represent vaccinations and other credentials, vouched for by officials or field workers. The design has practical benefits for the digital engagement and privacy of low doc persons. It also shows how traditionally hierarchical public key infrastructure can be deployed without dictating identification protocols to communities, thus avoiding some of the controversies that plague this technology. The PKI security function can remain centralized while certificate issuance is decentralized, which leaves community organizations free to carry on their business as usual.