From its initial concept in 2013 through formal incorporation in 2014, Https Card — Internet Identity Card Ltd has evolved from an early-stage initiative into a structured Internet identity framework, with ongoing engagement in institutional and technical ecosystems. This trajectory spans interactions and references across national and international bodies, including the INPI, the UK Intellectual Property Office, the Library of Congress, the United Nations, and the OECD, culminating in six open defensive publications and the releases of version 9.0 in July 2026 and version 10.0 in August 2026 — the first Internet Identity Card with hybrid post-quantum signing.
Work on the Internet Identity Card began in France in 2013, with a clear objective: to provide individuals with a robust solution to prove and protect their online identity. The first public work was conducted under the domain httpscard.com, registered on 1 December 2013; internetidentitycard.com followed on 5 January 2014.
Both domains were registered before the company existed — the initiative ran under the founder’s own name until incorporation in August 2014, recorded below.
None of these sources is held by this company, and none of them can be back-dated. The registry records and archive captures can be queried directly today; the CNIL entry cannot, for the reason given against it.
httpscard.com · 2013-12-01T10:26:31Zrdap.verisign.com/com/v1/domain/httpscard.cominternetidentitycard.com · 2014-01-05T22:15:50ZRegistry timestamps and archive captures verified 25 August 2026. The archive is operated by the Internet Archive and the registry record by Verisign; neither is under the control of this company.
Https Card — Internet Identity Card Ltd was incorporated on 8 August 2014, eight months after the first domain registration. From that date the initiative, until then run under the founder’s own name, was carried by the company. The French trademark filed in February 2014 followed the same path: it was transferred to the company by a recorded entry in the national register in August 2019, not held by it from filing.
The incorporation date, the registered office and the company status below are held by Companies House and can be read there directly. They are not restated from company files.
The mark was filed in February 2014 with the French National Industrial Property Institute, published in BOPI 2014-12 of 21 March 2014, and registered without modification in BOPI 2014-25 of 20 June 2014. Ownership was transferred to Https Card — Internet Identity Card Limited by entry no. 766592 of 13 August 2019, published in BOPI 2019-37 of 13 September 2019.
This registration has lapsed. A French trademark runs for ten years from filing; the renewal window, including the six-month grace period, closed in 2024 and the mark was not renewed. It is recorded here as a dated element of the history, not as a subsisting right. The company’s subsisting trademark registration is UK00003166480.
Https Card — Internet Identity Card presented the Internet Identity Card at the 7th BORDERPOL Forum, attended by heads of border forces, police, customs, and airport security, co-hosted by the Ministry of Interior in Spain.
The UK Intellectual Property Office registered the trademark "INTERNET IDENTITY CARD" (filed 25 May 2016).
A claim to copyright in the text and photographs published at
internetidentitycard.com was registered with the United States Copyright Office on
9 November 2017. The work is recorded as created in 2014 and first published on
1 January 2014; the registration followed nearly four years later.
Two points that the record states and that bear on what this registration covers. The type of work is text, and the authorship claimed is text and photographs: it does not cover the generator source code, for which no United States registration exists. The claimant is Michael Benaudis in his own name, not the company — the same sequence as the domains and the French trademark.
Registration made more than three months after first publication limits the remedies available: under 17 U.S.C. §412, statutory damages and attorney’s fees may be sought only for infringements commencing on or after the effective date of registration — here 9 November 2017. Actual damages and profits remain available for earlier infringement. This is a statement of the record, not legal advice.
Https Card — Internet Identity Card ™ is recorded as a supporter of the Paris Call for Trust and Security in Cyberspace, launched on 12 November 2018 during the Internet Governance Forum.
The source is no longer reachable. As of
25 August 2026, pariscall.international returns HTTP 503 on every page, including its
root. This entry rests on an archived capture of the supporters list and cannot currently be
confirmed at source. It is stated here with that limitation rather than omitted or presented as
verifiable.
Three checks ran offline from the start, in any browser, with no server, no account and no connection: the CID itself, derived from the card's own bytes, so that any alteration yields a different address; an embedded TOTP token check (SHA-1, six digits, thirty-second period) for issuer-mediated access control, the same principle later formalised in TDCommons #10079; and an embedded SHA-256 calculator to recompute and compare the card's own fingerprint. The same TOTP design has run in every release since. Seven years on, both external proofs remain live: the transaction is permanent on Bitcoin, and the card is still retrievable by its CID.
ipfs add -r --only-hash --cid-version=0 on what you retrieved — it must reproduce the same CID, since a CID is computed from the bytes. Compare across independent gateways if you use HTTP instead: a public gateway can inject or rewrite content in transit with no indication to the visitor. Timestamp: the anchored SHA-256 is a leaf of the Merkle tree in the OriginStamp certificate; hashing each level upward yields the Merkle root. This predates OP_RETURN, so OriginStamp used the root as a secp256k1 private key and anchored its address: derive the uncompressed address from the root and it is the recipient of the transaction above, in block 575,758. Nobody could have produced that address without already holding the root.Through resolution 73/27, the United Nations General Assembly established an Open-Ended Working Group (OEWG). On 2–4 December, Https Card — Internet Identity Card participated as an accredited non-state actor in the intersessional meeting of the United Nations Open-Ended Working Group (OEWG) in New York, on developments in the field of ICTs in the context of international security. These discussions on international peace and security in cyberspace were open to non-state actors for the first time in the United Nations' history.
Https Card — Internet Identity Card joined the Decentralized Identity Foundation to contribute to the development of an open, standards-based decentralized identity ecosystem.
Https Card — Internet Identity Card was listed among the participants of the World Bank Group / IMF Annual Meetings 2020.
“73 years ago, the United Nations General Assembly adopted the Universal Declaration of Human Rights and today digital technology has created new threats to Human Rights such as data privacy and identity fraud. Fortunately, digital technology has the power to transform the world and to protect the privacy of all of us.”
Statement by Https Card — Internet Identity Card Ltd (IIC) to the UN Open-Ended Working Group on Security of and in the use of Information and Communications Technologies (ICTs) in the context of international security — Third substantive session, 25–29 July 2022 at UNHQ, New York.
Internet Identity Card is listed as a non-governmental entity for the sixth substantive session of the Open-ended Working Group on security of and in the use of information and communications technologies, held at United Nations Headquarters in New York from 11 to 15 December 2023. The list is General Assembly document A/AC.292/2023/INF/6, issued 20 November 2023, where the entry appears at number 47 of 86.
Stakeholder participation in the OEWG proceeds by circulation of applicants to Member States under a non-objection procedure. Being listed reflects admission to a process; it carries no assessment of the listed entity or of its products, and no organisation named here has reviewed, tested or approved the Internet Identity Card.
Michael Benaudis, founder & CEO of the Internet Identity Card and long-time colleague of BORDERPOL, was interviewed on the BORDERPOL Journal podcast (Bob and Tom interview, 27 April 2023).
Https Card, represented by its founder Michael Benaudis, contributed comments to the OECD (Organisation for Economic Co-operation and Development) public consultation on the draft Recommendation for Digital Identity Governance.
An OECD Recommendation is a legal instrument adopted by the OECD Council: not legally binding, but a political commitment by Adherents to the principles it contains. The consultation was open to governments, civil society, international organisations and interested stakeholders. A contribution to it is neither a review nor an endorsement of the contributor.
Https Card published an open defensive disclosure on Technical Disclosure Commons (operated by Elsevier): "Cryptographic Identity Document System Using TOTP-Derived Symmetric Keys for Offline Issuer-Mediated Access Control". Released under the Creative Commons Attribution 4.0 license as defensive prior art.
A second open defensive disclosure on Technical Disclosure Commons: "Self-Verifying Single-File Cryptographic Documents with Dual-Passphrase Architecture for Offline Recipient-Mediated Access Control". It discloses the SHA-256 page integrity scheme (with fail-closed lockdown) and the dual-passphrase architecture using Argon2id. Released under CC BY 4.0.
A third open defensive disclosure on Technical Disclosure Commons: "Composite Defense-in-Depth Architecture for Self-Verifying Cryptographic Documents and Their Optional Offline Launchers". It discloses the layered combination of memory-hard Argon2id key derivation, AES-256-GCM authenticated encryption, SHA-256 self-verification with fail-closed lockdown, and ECDSA P-256 signing within a single zero-dependency file. Released under CC BY 4.0.
A new generation of the Internet Identity Card is released. The single-file generator (~336 KB) introduces a memory-hard Argon2id key derivation function (RFC 9106, 96 MiB, t=4, p=4), a dual-passphrase architecture separating the issuer's long-term secret from per-export recipient passphrases, and SHA-256 page integrity (self-verifying documents with fail-closed lockdown). Both cards and backups use the same memory-hard Argon2id key derivation, and exported cards self-verify fully offline. The card maintains full offline recipient decryption with no server-mediated key exchange. The complete v8.4.1 package is available for download with ECDSA P-256 signature verification and blockchain timestamping (Bitcoin + Ethereum).
Two new open defensive disclosures extend the prior-art record to five. “Canonical Multi-Zone Neutralization for Self-Serialized Documents” (v2) discloses the deterministic ordering by which one file simultaneously carries hybrid classical + post-quantum signatures, a self-referential integrity digest, and a post-signing blockchain anchor. “In-File Stapled Freshness” discloses Zone F: hash-chain validity tokens stapled by the holder into a frozen self-verifying document, giving offline verifiers a fail-stale FRESH / STALE / INVALID ruling with no re-signing, no server, and no PKI. Both were SHA-256 fingerprinted and anchored on the Bitcoin and Ethereum blockchains on 3 July 2026, and published on Technical Disclosure Commons on 5 July 2026.
The sixth open defensive disclosure completes the prior-art record of the v9.0 architecture: “Post-Quantum Ready, Offline-Verifiable Digital Identity Credential: Hybrid ECDSA P-256 and ML-DSA-65 Signing with Embedded Offline Verification Engine, Crypto-Agile Suite Registry, and Deterministic Build in a Self-Contained Single-File Document”. It discloses the hybrid classical + post-quantum signing construction (ECDSA P-256 and ML-DSA-65, FIPS 204), the embedded offline verification engine, the crypto-agile suite registry, and the deterministic build of the self-contained single-file credential. Published under CC BY 4.0, SHA-256 fingerprinted, and anchored on the Ethereum and Bitcoin blockchains on 23–24 July 2026.
The first Internet Identity Card with hybrid post-quantum signing. Where authorship must be provable, cards and signed documents now carry two signatures verified together: the classical ECDSA P-256 and the post-quantum ML-DSA-65 (FIPS 204), following ANSSI transition guidance for hybrid constructions. A future quantum computer able to break ECDSA does not break authorship: the ML-DSA-65 component remains secure, and the blockchain anchor proves signing predated any deprecation. v9.0 also introduces an embedded offline verification engine in every exported card, crypto-agile suite registry, hybrid receipts v3.0 (backward-compatible with v2.0), and a deterministic modular build — identical sources always produce an identical SHA-256, the prerequisite for meaningful blockchain anchoring. The release was anchored in two steps: the documentation set, both new defensive publications and the initial package build on 3 July (one Bitcoin and one Ethereum transaction covering seven fingerprints, plus per-file OpenTimestamps proofs), and the final package build on 4–5 July. “PQC-ready” denotes FIPS 204 algorithmic conformance in code; it is not a FIPS 140 CMVP validation or an ANSSI qualification.
This release concentrates on the protection of the issuer’s local vault. The vault encryption key is never written to storage: it is wrapped in two independent Argon2id envelopes, one derived from the memorable word and one from a recovery phrase issued once at setup, and exists in memory only for the duration of a session. Forgetting the memorable word is therefore recoverable, provided the phrase has been kept. The release also brings a persistent counter and a truncation anchor to the local signature chain, so a retained chain verifies to a known point, and a receipt status field that states plainly whether a signature is classical or hybrid. The hybrid ECDSA P-256 + ML-DSA-65 suite and the exported card format are carried forward from v9.0; cards exported by v9.0 are unaffected. The Technical Specification and the Engineering Specification set out the complete change record.
v10.0.1, released the following day, refines the vault backup and restore path: a backup now restores on any browser rather than only the one that produced it, and a password digest is no longer written into the backup file. No capability is added, and the exported card format is untouched. Both corrections were found by executing the restore journey across browser profiles. The four v10.0 documents remain applicable in full and keep their original digests; the v10.0.1 change specification records the delta.
This page is a historical record provided for informational purposes only. It does not constitute legal recognition, certification, accreditation, or endorsement by any authority, and no warranty of any kind is given in relation to it. Blockchain anchors referenced on this page establish that specific bytes existed at a given time; they do not establish that a document is correct, complete, or reviewed. Use of this website and of the software is governed by the Terms & Conditions.