Prior art record

Dated public disclosures

Every disclosure below is held by an independent registrar or a public blockchain. Each entry states how to confirm its date without contacting this company.

What this record is, and what it is not

What it establishes. That the described techniques were publicly available from the dates shown. From those dates the material is in the public domain and cannot be validly claimed as novel by anyone.

What it does not establish. Any exclusive right. A defensive publication is the opposite of a patent: it places the work beyond exclusive appropriation, including by its own author. Under the absolute novelty rule of the European Patent Convention these disclosures are prior art against this company as much as against anyone else, with no grace period. They are published deliberately, to keep the field open.

Timeline

Dates read from the issuing source, not from internal records.

13 May 2019
Decentralised deployment
First decentralised Internet Identity Card ™
Three checks ran offline from the start, in any browser, with no server, no account and no connection: the CID itself, derived from the card's own bytes, so that any alteration yields a different address; an embedded TOTP token check (SHA-1, six digits, thirty-second period) for issuer-mediated access control, the same principle later formalised in TDCommons #10079; and an embedded SHA-256 calculator to recompute and compare the card's own fingerprint. The same TOTP design has run in every release since. Seven years on, both external proofs remain live: the transaction is permanent on Bitcoin, and the card is still retrievable by its CID.
View the 2019 card via IPFS ↗
IPFS CID (v0)QmXXvokcgvtjqCsyWynRkuhco6YWhPqdDfRevee2zbLBsC
Anchored SHA-256ed70cef5a086e264386ab026edaaabb8f25c378f1e3a699a2c0a72a20d53c7fb
Merkle root5bced000f3226ddb6460dc9e85a1f1198604d4f74c12abf6b35361678919a593
Verify it yourselfTwo independent proofs, neither of which needs this site. Content: resolve the CID with a local IPFS node, then run ipfs add -r --only-hash --cid-version=0 on what you retrieved — it must reproduce the same CID, since a CID is computed from the bytes. Compare across independent gateways if you use HTTP instead: a public gateway can inject or rewrite content in transit with no indication to the visitor. Timestamp: the anchored SHA-256 is a leaf of the Merkle tree in the OriginStamp certificate; hashing each level upward yields the Merkle root. This predates OP_RETURN, so OriginStamp used the root as a secp256k1 private key and anchored its address: derive the uncompressed address from the root and it is the recipient of the transaction above, in block 575,758. Nobody could have produced that address without already holding the root.
12 May 2026
Defensive publication
TOTP-derived symmetric keys
TDCommons #10079 · CC BY 4.0
TDCommons #10079 ↗
Verify it yourselfOpen the record page and read the recommended citation, which carries the publication date. Technical Disclosure Commons is operated independently and the date cannot be altered by the author after publication.
19 May 2026
Defensive publication
Dual-passphrase self-verifying documents
TDCommons #10167 · CC BY 4.0
TDCommons #10167 ↗
Verify it yourselfOpen the record page and read the recommended citation, which carries the publication date. Technical Disclosure Commons is operated independently and the date cannot be altered by the author after publication.
8 June 2026
Defensive publication
Composite defense-in-depth
TDCommons #10394 · CC BY 4.0
TDCommons #10394 ↗
Verify it yourselfOpen the record page and read the recommended citation, which carries the publication date. Technical Disclosure Commons is operated independently and the date cannot be altered by the author after publication.
5 July 2026
Defensive publication
Multi-zone neutralization v2
TDCommons #10795 · CC BY 4.0
TDCommons #10795 ↗
Verify it yourselfOpen the record page and read the recommended citation, which carries the publication date. Technical Disclosure Commons is operated independently and the date cannot be altered by the author after publication.
5 July 2026
Defensive publication
In-file stapled freshness
TDCommons #10796 · CC BY 4.0
TDCommons #10796 ↗
Verify it yourselfOpen the record page and read the recommended citation, which carries the publication date. Technical Disclosure Commons is operated independently and the date cannot be altered by the author after publication.
23 July 2026
Defensive publication
Post-quantum ready credential — hybrid ECDSA P-256 and ML-DSA-65
TDCommons #11121 · CC BY 4.0
TDCommons #11121 ↗
Verify it yourselfOpen the record page and read the recommended citation, which carries the publication date. Technical Disclosure Commons is operated independently and the date cannot be altered by the author after publication.
1 August 2026
Research deposit
IIC v9.0 specification corpus
DOI 10.5281/zenodo.21738537. Deposit recorded 2026-08-01 11:49:03 UTC. The record also carries a declared publication date of 2026-07-22, which is metadata set by the depositor; the deposit timestamp is the one a third party can rely on.
Zenodo record ↗
Verify it yourselfQuery the Zenodo API at zenodo.org/api/records/21738537 and read the created field. It is set by Zenodo, not by the depositor.
1 August 2026
Standards record
The IIC Credential Format — IETF Internet-Draft
draft-benaudis-iic-credential-00, submitted 2026-08-01 12:21:39 UTC, expires 2027-02-02. An expired draft remains permanently in the archive.
IETF Datatracker ↗
Verify it yourselfQuery datatracker.ietf.org/api/v1/doc/document/draft-benaudis-iic-credential/?format=json and read the time field, set by the IETF on submission.
7–8 Aug 2026
Release anchor
Release manifests, v10.0 and v10.0.1
The digest of each release SHA256SUMS anchored on both chains. v10.0 at Bitcoin block 961,351 and Ethereum block 25,701,188; v10.0.1 at Bitcoin block 961,512 and Ethereum block 25,704,773.
Bitcoin, v10.0.1 ↗ · Ethereum, v10.0.1 ↗
Verify it yourselfRead the block time on any explorer. It is set by the network, not by the party submitting the transaction. Block times are stated here in UTC; timestamping certificates commonly render local time and will read two hours later in summer.
24 Aug 2026
Package and site anchor
Complete Package v10.0.1 manifest, and the sealed state of this website
Two digests anchored as leaves of one Merkle tree, so a single transaction per chain covers both: the seventeen-file SHA256SUMS at 265e7eaf… and SITE-SHA256SUMS at 818ceb7f…. Bitcoin block 963,856 at 12:22:05 UTC; Ethereum block 25,826,727 at 18:06:47 UTC.
Bitcoin ↗ · Ethereum ↗
Verify it yourselfThe Bitcoin transaction carries the batch Merkle root in its OP_RETURN output; the Ethereum transaction carries it as call data. Take either digest above as a leaf, hash upward along the path in the proof file, and the result is that root. The current digests are on the verification page.

Independent timestamping

Each published release and each sealed state of this website is anchored on Bitcoin and Ethereum. The anchor proves that a given set of bytes existed before a given block, and the block time is set by the network, not by this company.

Verify an anchor yourself Download the manifest, compute its SHA-256, follow the Merkle path in the OriginStamp proof file up to the root, then read that root in the transaction on any block explorer. The block time of that transaction is the timestamp. Every step runs on your machine with standard tools.

The current sealed state of this site, its manifest and the anchoring records are listed on the verification page, and every page can be checked against its fingerprint on the integrity monitor — including with no network connection.

Registered rights — related, but not prior art

The company holds registered rights that are sometimes listed alongside records of this kind. They are set out separately because they establish something different, and a reader assessing prior art should not have to disentangle them.

A copyright protects the expression of a work, never the idea, procedure, process, system or method it describes — 17 U.S.C. §102(b) is explicit on the point. The deposit itself is not published. A registration therefore discloses no technique and cannot be prior art against a technical claim.

A trademark establishes a right in a sign used in trade. It says nothing about what a product does and discloses nothing technical.
US Copyright
TX 8-508-373, registered 9 November 2017. Type of work: text; authorship claimed: text and photograph(s), covering material published at internetidentitycard.com. It does not cover the generator source code. Claimant: Michael Benaudis.
US Copyright Office record ↗
UK trademark
UK00003166480, INTERNET IDENTITY CARD, filed 25 May 2016, class 45. Renewed May 2026, in force to May 2036.
UK IPO case page ↗
French trademark
FR 4071419, filed February 2014, registered 20 June 2014, transferred to the company in August 2019. Lapsed: the ten-year term expired in 2024 and the mark was not renewed within the grace period. Recorded for completeness; it is not a subsisting right.

Scope

The documentation, the specifications and the disclosures listed here are public. The generator application and the IIC Wallet are not published and are not downloadable from this site; access is granted through a controlled onboarding process. Nothing on this page should be read as a claim of certification, accreditation or endorsement by any authority.