Documentation

Official guides & specifications

The complete, public documentation of the Internet Identity Card — current release v10.0, with the superseded v9.0 and v8.4.1 editions preserved below. Every file is SHA-256 fingerprinted and timestamped on the Bitcoin and Ethereum blockchains.

Documentation is public — the generator and the Wallet are access-controlled

The official documents below — User Guide, Technical Specification, Engineering Specification, and Threat Model — are freely available for review, audit, and reference. Their integrity is anchored on the Bitcoin and Ethereum blockchains and on OpenTimestamps. The underlying architecture is disclosed in six open defensive publications on Technical Disclosure Commons (CC BY 4.0).

The generator application and the IIC Wallet (both distributed inside the Complete Package), however, are not publicly downloadable. Due to the critical and sensitive nature of identity infrastructure, access to the generator and the Wallet is granted through a controlled onboarding process intended to support security, compliance, and operational alignment.

For demo requests or partnership inquiries, please contact us at demo@internetidentitycard.com.

Current release — v10.0 · Vault key protection

v10.0 focuses on the protection of the issuer’s local vault. The vault encryption key is never written to storage: it is wrapped in two independent Argon2id envelopes — one derived from the memorable word, one from a recovery phrase issued once at setup — and exists in memory only for the duration of a session.
The hybrid signature suite and the exported card format are carried forward from v9.0; cards exported by v9.0 are unaffected. The Technical Specification and the Engineering Specification set out the complete change record for this release.

USER
GUIDE
For everyone

User Guide

Creating, opening, sharing and signing. Rewritten for v10.0: the vault now asks for your memorable word each time it opens, and a recovery phrase is issued once at setup. Both follow from the vault key protection introduced in this release.

PDF · v10.0 · 10 KB
Blockchain timestamp proofs
SHA-2564186ef719db7c6eb8017a660e592e0e012641ac2904c8bc194aaa94763ece7d8
TECH
SPEC
For integrators & auditors

Technical Specification

Architecture, cryptography and verification flows. New in v10.0: dual-envelope vault key protection with per-envelope KDF labelling, the corrected signature chain with a persistent counter and truncation anchor, and the receipt status field that distinguishes a classical receipt from a hybrid one. The hybrid ECDSA P-256 + ML-DSA-65 suite and the exported card format are unchanged from v9.0.

PDF · v10.0 · 17 KB
Blockchain timestamp proofs
SHA-256b9dfb25c633d61b35b02aba9bd9b2d5d9c21d4f8c00b98d87a8c2488b56196e8
ENG
SPEC
For engineers

Engineering Specification

Provenance, implementation and standards. Includes a section on the verification method used for this release: why a correction is treated as complete only once its journey has been executed end to end from a file:// URL with the network disabled.

PDF · v10.0 · 13 KB
Blockchain timestamp proofs
SHA-2569e0c825f66b5416f1fe375146b8a2c3c4a2263c84dfaa61d08e129d88d64dd80
THREAT
MODEL
For security reviewers

Threat Model

Assets, adversaries, STRIDE analysis and residual risks. This edition adds an asset the v9.0 model did not name — the issuer’s local vault at rest — and the adversary that reaches it. Two STRIDE dispositions are marked as corrected: they were stated more favourably than the implementation supported.

PDF · v10.0 · 16 KB
Blockchain timestamp proofs
SHA-256c0ca8014e9cd671188a805380abf394f44d920139f819c18e69e0b4a561c4d98
WALLET
GUIDE
For Wallet users

Wallet User Guide

Installing, using and managing the IIC Wallet. The Wallet software is unchanged at v1.0 and is unaffected by the v10.0 corrections. Revision 5 corrects three cross-references: the companion guide version, the list of defensive publications, and the description of where the Wallet is distributed.

PDF · v10.0 · 18 KB
Blockchain timestamp proofs
SHA-2569320ac7e5b481f5ab7b8798b4d2f3bb37918cf6dbe6bf7ae9b0ace0af6daaafe
Access-controlled

Release package v10.0 — generator + documentation PQ-Hybrid

A single archive containing the IIC generator v10.0 (~537 KB), the four official v10.0 documents, the Wallet User Guide v1.0 r5, the change specification, the pre-release audit, the manifest tool, and a SHA256SUMS checksum file. This package does not contain the Wallet application itself, which ships in the access-controlled Complete Package. Because it includes the generator, it is provided through the controlled onboarding process described above.

🔒 Request access — demo@internetidentitycard.com
Package integrity
SHA-256 · generatordcfc708d70059fdfc1fe22ba11c2f3407a996095ffd24228fe914fbeb1e9bc36
SHA-256 · SHA256SUMS (anchored)2980397441afd0fe9c6fb3746b4197ceb074318d5381129a7803a004f95086b5
The anchored digest is that of SHA256SUMS, which lists every file in the package. It is not the digest of any archive: a ZIP embeds timestamps and compression choices that differ between runs, so its digest cannot be reproduced and proves nothing about the contents. Verify with shasum -c SHA256SUMS, then compare the result with the digest above. Anchored on Bitcoin at block 961351 and on Ethereum at block 25701188 on 7 August 2026. The value written in the Bitcoin OP_RETURN is the OriginStamp Merkle root of that batch; the package digest is a leaf beneath it, and the certificate supplies the path.
Previous release — v9.0 · Superseded

Released 3 July 2026, superseded by v10.0. v9.0 introduced hybrid post-quantum signing — ECDSA P-256 combined with ML-DSA-65 (FIPS 204) — an embedded offline verification engine in every exported card, and a deterministic modular build. Those mechanisms are carried forward unchanged into v10.0, which refines the implementation rather than replacing the architecture. These editions remain published and fully verifiable: their blockchain timestamp proofs are permanent.
“PQC-ready” denotes FIPS 204 algorithmic conformance in code; it is not a FIPS 140 CMVP validation or an ANSSI qualification.

USER
GUIDE
For end users

IIC User Guide

Step-by-step instructions to create your first card, choose between Quick and Secure modes, share your identity safely, understand SHA-256 page integrity, and answer common questions about Memorable Words, Card Passphrases, and recovery. Updated for v9.0.

PDF · v9.0 · 9 KB
Blockchain timestamp proofs
SHA-2567b8655adad980da539e59227d3d82bf250eba69b1c33994f1e02bd406f1aa382
Also independently anchored on Bitcoin via OpenTimestamps (.ots proof available on request).
TECH
SPEC
For integrators & auditors

Technical Specification

Architecture, cryptography and verification flows — including the hybrid post-quantum signature suite introduced in v9.0: ECDSA P-256 combined with ML-DSA-65 (FIPS 204), crypto-agile suite registry, hybrid receipts v3.0, deterministic modular build, and the embedded offline verification engine.

PDF · v9.0 · 10 KB
Blockchain timestamp proofs
SHA-2561095a671bb2bf7eba4fd16167d91e445d268d3e6f51c52255b206b50d4edc7cf
Also independently anchored on Bitcoin via OpenTimestamps (.ots proof available on request).
ENG
SPEC
For evaluators

Engineering Specification

Provenance, engineering innovations and standards compliance: single-file zero-dependency architecture, offline self-verification, hybrid post-quantum signing, multi-zone canonical neutralization, and the complete prior-art and registration record since 2013.

PDF · v9.0 · 9 KB
Blockchain timestamp proofs
SHA-256f7435515d8ec7429d1ff2d268da60cfa7276bd883ef2c5cb2fdccbd47731b9e7
Also independently anchored on Bitcoin via OpenTimestamps (.ots proof available on request).
THREAT
MODEL
For security teams

Threat Model

Security analysis, trust assumptions and residual risks — with the quantum adversary now explicitly addressed: harvest-now/decrypt-later and harvest-now/forge-later scenarios, STRIDE analysis of the hybrid posture, and a candid statement of what remains out of scope.

PDF · v9.0 · 12 KB
Blockchain timestamp proofs
SHA-256f692768adc79c9d25ab903b5b042efa29b7434802d42114d772ef757284a819a
Also independently anchored on Bitcoin via OpenTimestamps (.ots proof available on request).
WALLET
GUIDE
For end users

IIC Wallet User Guide

How to install and use the IIC Wallet — the optional offline PWA that collects and organizes your cards. Unchanged since v8.4.1: the v1.0 edition and its blockchain anchor of 7 June 2026 remain current.

PDF · v1.0 · 28 KB
Blockchain timestamp proofs
SHA-25634002ce3a519286212cf4d9967414bdb6defbd993671ccde13313bd64cc57697
Access-controlled

Complete Package v9.0 — generator + Wallet + documentation PQ-Hybrid

The Complete Package is a single archive (14 files) containing the four official v9.0 documents (User Guide, Technical Specification, Engineering Specification, Threat Model), the Wallet User Guide v1.0, the IIC generator application v9.0 (~493 KB, hybrid post-quantum signing), the IIC Wallet PWA (offline card viewer, with manifest, service worker and Apache config), the README, and a SHA256SUMS checksum file. Because it includes the generator and the Wallet, this download is provided through the controlled onboarding process described above.

🔒 Request access — demo@internetidentitycard.com

Once granted, you can verify the authenticity of the archive against the published SHA-256 hash.

Blockchain timestamp proofs
SHA-2567b2dcffde07a29975097cff3d0246ea460762630dd8037798f7644e063818afd
The initial v9.0 package build (SHA-256 dc081d5ef881bf15dce069f85a519b39d52118e8d439586a2bf453505395b710) was anchored on Bitcoin and Ethereum on 3 July 2026 and remains permanent historical evidence; it was superseded the following day by the corrected 4 July build, which corrects a timing-dependent behaviour in the exported cards’ offline integrity check. Only the generator file differs between the two builds.
Previous release — v8.4.1 · Superseded

Superseded by v9.0 on 3 July 2026. These editions remain published and fully verifiable: their blockchain timestamp proofs are permanent.

USER
GUIDE
For end users

IIC User Guide

Step-by-step instructions to create your first card, choose between Quick and Secure modes, share your identity safely, understand SHA-256 page integrity, and answer common questions about Memorable Words, Card Passphrases, and recovery.

PDF · v8.4.1 · 20 KB · 7 pages
Blockchain timestamp proofs
SHA-256c151638e93fdf7c89298ec4ff98371f33511decbc52ff6e667be77497cada2e5
TECH
SPEC
For developers & auditors

Technical Specification

Full cryptographic architecture and API reference. Covers AES-256-GCM, Argon2id RFC 9106 (96 MiB, t=4, p=4) for both cards and backups, ECDSA P-256, the dual-passphrase architecture, SHA-256 page integrity (Mode A), IIFE module isolation, threat model, and storage format.

PDF · v8.4.1 · 23 KB · 8 pages
Blockchain timestamp proofs
SHA-256d61908e6f7fec563d5351faeec3a1d9c557f677c3d6c9ef993fbf6bb7642d41e
ENG
SPEC
For integrators & reviewers

Engineering Specification

System architecture, provenance timeline (2013–2026), defensive publications (TDCommons #10079, #10167 and #10394), standards compliance, and version history. Documents NIST, RFC, GDPR alignment and the registration timeline of Https Card — Internet Identity Card Ltd. Reference document for procurement, due diligence, and compliance reviews.

PDF · v8.4.1 · 20 KB · 7 pages
Blockchain timestamp proofs
SHA-256760129676c9852902c4e086c5a27ae1023df5d25162a8be5ad98425e29051975
THREAT
MODEL
For security auditors

Threat Model

Realistic security analysis: trust assumptions, assets, adversary model (A1–A4), STRIDE analysis, ten concrete attack scenarios, and an honest account of residual risks and out-of-scope threats (compromised devices, generator authenticity, coercion, quantum). Companion to the Technical & Engineering Specifications.

PDF · v8.4.1 · 17 KB · 6 pages
Blockchain timestamp proofs
SHA-2564394a8f69b5d78af68ebfcbef7b73927d460c4932e84aa6577a975b0156606c1
WALLET
GUIDE
For Wallet users

IIC Wallet User Guide

Complete step-by-step guide to the IIC Wallet: installation (desktop and mobile, local use or PWA), first-launch consent dialog, three methods to add cards (drag-drop, file picker, auto-open .iic), opening cards, removing cards, the six-layer security model, troubleshooting common dialogs, and a full FAQ.

PDF · v1.0 · 28 KB · 12 pages
Blockchain timestamp proofs
SHA-25634002ce3a519286212cf4d9967414bdb6defbd993671ccde13313bd64cc57697
Access-controlled

Complete Package v8.4.1 — generator + Wallet + documentation

The Complete Package is a single archive containing the five official documents (User Guide, Wallet User Guide, Technical Specification, Engineering Specification, Threat Model), the IIC generator application (~338 KB), the IIC Wallet PWA (offline card viewer, ~31 KB, with manifest, service worker and Apache config), the README, and a SHA256SUMS checksum file. Because it includes the generator and the Wallet, this download is provided through the controlled onboarding process described above.

🔒 Request access — demo@internetidentitycard.com

Once granted, you can verify the authenticity of the archive against the published SHA-256 hash and ECDSA P-256 signature.

Blockchain timestamp proofs
SHA-256a26ccb19f13301bfb04cffbce9dfbd5b73534181867c736b3d8d1f40e1a9289f

IIC Wallet — open your cards offline

The IIC Wallet is an optional offline application that lets you collect and organize all your IIC cards in one place. It runs entirely in your browser, stores nothing on any server, and works without an internet connection. The Wallet never sees the unencrypted content of secured cards — each card retains its own cryptographic protections (Argon2id key derivation, AES-256-GCM encryption, SHA-256 page integrity, ECDSA P-256 signatures).

Distribution model: the Wallet is included in the IIC Complete Package — the same controlled-access archive that contains the generator. It is never hosted publicly. After receiving the package, you choose how to use it: locally on your desktop, or by hosting it on your own private server for mobile use.

Wallet security model — six layers of defence
  1. Multi-marker validation at ingestion — the Wallet refuses any file that doesn't contain all four IIC structural markers (integrity meta tag, hash comment, flip-card DOM structure, and CID declaration). Spoofed or look-alike files are rejected.
  2. CID/filename match check at ingestion — if a card has been renamed with someone else's identity number, it is rejected immediately with a clear dialog.
  3. Re-verification before opening — defence in depth: even after a card is in the Wallet, every open re-checks the embedded CID against the stored CID and filename, blocking any post-ingestion tampering.
  4. Per-card SHA-256 integrity — each card carries its own page-integrity hash and verifies itself when opened. Any byte modification triggers a fail-closed lockdown overlay.
  5. Anti-rename verification at open time — the card itself also checks that its filename CID matches its embedded CID, preventing identity swap attacks.
  6. Cryptographic encryption — for Secured cards, contents are encrypted with AES-256-GCM using a key derived from the passphrase via Argon2id (RFC 9106, 96 MiB, t=4, p=4). The Wallet never sees this content; only the recipient with the passphrase can unlock it.
🔒
Zero server
Cards are stored in your browser's local database. Nothing leaves your device.
Works offline
No network connection required. The Wallet works fully air-gapped.
📱
Cross-platform
Same experience on iPhone, Android, Mac, Windows and Linux.
Auto-open .iic files
On supported browsers, double-clicking an .iic card opens it directly in the Wallet.

How to use the Wallet

Once you have received the IIC Complete Package, the Wallet is in the wallet/ folder. You can use it two ways:

💻 Desktop (local use)

  1. Extract the Complete Package on your computer.
  2. Open wallet/iic-viewer.html in Chrome, Edge, Brave, Safari or Firefox.
  3. Drag-drop your .iic or .html cards into the Wallet, or use the file picker.
  4. Cards stay in your browser's local database; nothing leaves your machine.
No installation needed. This is the simplest path and works immediately without any setup.

💻 Desktop (install as app)

  1. Host the wallet/ folder on any HTTPS server you control (local Apache, nginx, or a private cloud).
  2. Open your private URL in Chrome, Edge, or Brave.
  3. Click the Install icon in the address bar or in the Wallet header.
  4. The Wallet appears in your Applications / Start menu like a native app, with .iic auto-open support.
Why self-host? Browser PWA installation requires HTTPS. The Wallet is never published publicly — you host your own private copy.

📱 Mobile (iPhone & Android)

  1. Host the wallet/ folder on an HTTPS server you control.
  2. On the phone, open your private URL in Safari (iPhone) or Chrome (Android).
  3. iPhone: tap ShareAdd to Home Screen.
    Android: tap menu → Install app.
  4. The Wallet icon appears on your home screen and behaves like a native app.
iOS restriction: Apple does not allow installing apps from local files — HTTPS hosting is the only path on iPhone.
About iOS auto-open: on iPhone and iPad, no application (including this one) can register itself as the default handler for .html or .iic files — this is an Apple OS-level restriction that applies to every web-based app. On iOS, the Wallet still works fully, but each card must be added manually via the file picker or drag-and-drop inside the Wallet. The other platforms (Android, macOS, Windows, Linux with Chromium browsers) support full auto-open.

Defensive publications

The cryptographic constructions underlying the Internet Identity Card are disclosed as open prior art on Technical Disclosure Commons (operated by Elsevier), released under the Creative Commons Attribution 4.0 license with explicit patent waivers from the inventor. They are indexed by Google Scholar, Semantic Scholar, and the bepress Digital Commons Network. The v9.0 multi-zone canonical neutralization and in-file stapled freshness constructions were blockchain-anchored on 3 July 2026 and published on 5 July 2026. The sixth and most recent disclosure — the post-quantum ready, offline-verifiable credential construction — was published on 23 July 2026 and anchored on Ethereum and Bitcoin on 23–24 July 2026.

Because disclosures are filed continuously, each specification edition cites the publications that existed on its own date of issue: the v9.0 editions of 3 July 2026 therefore predate the sixth disclosure and do not reference it. This page is the authoritative index of the complete corpus.

TD
NEW
TDCommons #11121 · Published 23 July 2026 · Anchored BTC + ETH

Post-Quantum Ready, Offline-Verifiable Digital Identity Credential: Hybrid ECDSA P-256 and ML-DSA-65 Signing with Embedded Offline Verification Engine, Crypto-Agile Suite Registry, and Deterministic Build in a Self-Contained Single-File Document

Discloses the complete v9.0 credential construction: hybrid classical + post-quantum signing (ECDSA P-256 and ML-DSA-65, FIPS 204) verified together, an embedded verification engine enabling full verification inside the document itself with no network, a crypto-agile suite registry allowing future algorithm migration, and a deterministic build producing a reproducible self-contained single-file credential.

SHA-256 966b24d856e478dc378a6a0bbe58246d0d693c447bdfda9fd8e96ffb91ba22db · BTC · ETH · CC BY 4.0
TD
#10795
TDCommons #10795 · Anchored 3 July 2026 · BTC + ETH

Canonical Multi-Zone Neutralization for Self-Serialized Documents Carrying Heterogeneous Hybrid Signatures, a Self-Referential Integrity Digest, and a Post-Signing Timestamp Anchor

Discloses the canonical neutralization ordering (v2) by which one self-serialized document simultaneously embeds hybrid classical + post-quantum signatures, a self-referential SHA-256 integrity digest, and a blockchain anchor written after signing — collapsing the triple circular dependency to a single deterministic fixed point verifiable fully offline.

SHA-256 1bd43a9ae765eba9e36ca39ed890e2946931ac1a61b9ae351b983595b02ba103 · BTC · ETH · CC BY 4.0
TD
#10796
TDCommons #10796 · Anchored 3 July 2026 · BTC + ETH

In-File Stapled Freshness: Hash-Chain Validity Tokens Written into a Frozen Self-Serialized Document via a Length-Preserving Neutralized Zone, with Fail-Stale Offline Verification

Discloses Zone F: successive Micali-style hash-chain freshness tokens stapled by the holder into a dedicated length-preserving zone of an immutable self-verifying document — excluded from both signature and integrity coverage — giving an offline verifier a FRESH / STALE / INVALID ruling with no re-signing, no server, and no PKI.

SHA-256 ac311f338e89adb1061b44e6bd65cf03952123b1aeaa07164ea1c6ae4d3ff902 · BTC · ETH · CC BY 4.0
TD
#10079
12 May 2026

Cryptographic Identity Document System Using TOTP-Derived Symmetric Keys

Discloses the TOTP-derived symmetric key system, dual-domain PBKDF2 architecture, AES-256-GCM encryption, IIFE module isolation, ECDSA P-256 signatures, and single-file HTML distribution model for offline issuer-mediated access control.

Defensive Publications Series · CC BY 4.0
TD
#10167
19 May 2026

Self-Verifying Single-File Cryptographic Documents with Dual-Passphrase Architecture

Discloses two new constructions: (i) the SHA-256 page integrity scheme (Mode A) with fail-closed lockdown, and (ii) the dual-passphrase key architecture using Argon2id RFC 9106 (96 MiB, t=4, p=4) for per-export recipient passphrases.

Defensive Publications Series · CC BY 4.0
TD
#10394
7 June 2026

Composite Defense-in-Depth Architecture for Self-Verifying Cryptographic Documents and Their Optional Offline Launchers

Discloses the ecosystem-wide defense-in-depth architecture: multi-marker structural validation, bidirectional filename-identifier verification with triple checkpoint, the non-degrading optional offline launcher pattern (PWA), and bundled access-controlled distribution with universal blockchain verifiability — combined with the prior two publications into six independent fail-closed verification layers.

Defensive Publications Series · CC BY 4.0

Which document should I read?

Pick the one that matches your role and what you want to do.

I want to use IIC
→ User Guide
I want to integrate IIC
→ Technical Specification
I am evaluating IIC
→ Engineering Specification
I am assessing security risk
→ Threat Model
I am auditing the cryptography
→ Technical Specification + Threat Model
I need standards compliance
→ Engineering Specification

Page integrity

In addition to file verification, you can verify the SHA-256 integrity of every HTML page on this site in real time — directly in your browser, using the W3C Web Crypto API. Nothing is uploaded.

View page integrity →

Important notice

The documents and records on this page are provided for informational purposes only. They do not constitute legal recognition, certification, accreditation, or endorsement by any authority, and no warranty of any kind is given in relation to them. Internet Identity Card ™ is a private software-based identity and verification platform developed by Https Card — Internet Identity Card Ltd. References to standards, electronic signatures, eIDAS, or regulatory frameworks are informational only; conformance to a cryptographic standard in code is distinct from formal evaluation and does not constitute a FIPS 140 CMVP validation or an ANSSI qualification. Use of this website and of the software is governed by the Terms & Conditions.