HOME

TheInfoList



OR:

The Estonian identity card ( et, ID-kaart) is a mandatory
identity document An identity document (also called ID or colloquially as papers) is any documentation, document that may be used to prove a person's identity. If issued in a small, standard credit card size form, it is usually called an identity card (IC, ID c ...
for citizens of
Estonia Estonia, formally the Republic of Estonia, is a country by the Baltic Sea in Northern Europe. It is bordered to the north by the Gulf of Finland across from Finland, to the west by the sea across from Sweden, to the south by Latvia, a ...
. In addition to regular identification of a person, an ID-card can also be used for establishing one's identity in electronic environment and for giving one's
digital signature A digital signature is a mathematical scheme for verifying the authenticity of digital messages or documents. A valid digital signature, where the prerequisites are satisfied, gives a recipient very high confidence that the message was created b ...
. Within Europe (except Belarus, Russia, Ukraine and United Kingdom) as well as French overseas territories and Georgia, the Estonian ID Card can be used by the citizens of Estonia as a
travel document A travel document is an identity document issued by a government or international entity pursuant to international agreements to enable individuals to clear border control measures. Travel documents usually assure other governments that the beare ...
. The mandatory identity document of a citizen of the
European Union The European Union (EU) is a supranational political and economic union of member states that are located primarily in Europe. The union has a total area of and an estimated total population of about 447million. The EU has often been des ...
is also an identity card, also known as an ID card. The Estonian ID Card can be used to cross the Estonian border, however Estonian authorities cannot guarantee that other EU member states will accept the card as a travel document. In addition to regular identification of a person, an ID-card can also be used for establishing one's identity in electronic environment and for giving one's digital signature. With the Estonian ID-card the citizen will receive a personal @eesti.ee e-mail address, which is used by the state to send important information. In order to use the @eesti.ee e-mail address, the citizen has to forward it to his or her personal e-mail address, using the State Portal eesti.ee. The Police and Border Guard Board (PPA) on 25 September 2018 introduced the newest version of Estonia's ID card, featuring additional security elements and a contactless interface, which will begin to be rolled out no later than next year. The new cards also utilize Estonia's own font and elements of its brand. One new detail is the inclusion of a
QR code A QR code (an initialism for quick response code) is a type of matrix barcode (or two-dimensional barcode) invented in 1994 by the Japanese company Denso Wave. A barcode is a machine-readable optical label that can contain information about th ...
, which will make it easier to check the validity of the ID card. The new design also features a color photo of its bearer, which doubles as a security element and is made up of lines; looking at the card at an angle, another photo appears. The new chip has a higher capacity, allowing the addition of new applications to it.


Scope

The Estonian ID cards are used in health care,
electronic banking Online banking, also known as internet banking, web banking or home banking, is an electronic payment system that enables customers of a bank or other financial institution to conduct a range of financial transactions through the financial insti ...
, signing contracts, public transit, encrypting email and voting. Estonia offers over 600 e-services to citizens and 2400 to businesses. The card's chip stores digitized data about the authorized user, most importantly: the user's full name, gender, national identification number, and cryptographic keys and
public key certificate In cryptography, a public key certificate, also known as a digital certificate or identity certificate, is an electronic document used to prove the validity of a public key. The certificate includes information about the key, information about the ...
s.


Types of Estonian ID cards

There are several types of identity documents issued by the Estonian state that are usually referred to as the Estonian ID card. These are the ''identity card'', the ''digital identity card'', the ''residence permit card'', the ''e-resident’s digital identity card'' and the ''diplomatic identity card''. While these identity documents are issued to different categories of persons and have a different appearance, all these documents provide the same electronic functionality via a smart card chip.


Electronic functionality of the ID card

From its introduction in 2002 until now, the core electronic functionality provided by the Estonian ID card has stayed the same. The ID card contains two asymmetric (RSA or ECC) key pairs with the corresponding
X.509 In cryptography, X.509 is an International Telecommunication Union (ITU) standard defining the format of public key certificates. X.509 certificates are used in many Internet protocols, including TLS/SSL, which is the basis for HTTPS, the secure ...
public-key certificates, and symmetric keys to perform card management operations. Authentication key. The authentication key is used to log into e-services by providing a signature in the
TLS TLS may refer to: Computing * Transport Layer Security, a cryptographic protocol for secure computer network communication * Thread level speculation, an optimisation on multiprocessor CPUs * Thread-local storage, a mechanism for allocating vari ...
client certificate authentication process. This key can also be used to decrypt documents encrypted for the cardholder. This is used only infrequently, as such documents would become unreadable if the card were lost or destroyed. Cryptographic signature and decryption operations with this key have to be authorized using the 4-digit PIN1 code. Digital signature key. The digital signature key is used to give legally binding digital signatures that under eIDAS are recognized as qualified electronic signatures. Each signature operation with the key has to be authorized using the 5-digit PIN2 code. Personal data file. The ID card chip contains a publicly readable personal data file, which consists of 16 records containing the same information as is printed on the card. Card management operations. The cards are preloaded with symmetric keys that can be used by the manufacturer to perform various card management operations in the post-issuance phase. This provides a method to reset PIN codes in the event the cardholder forgets them, generate new keys, write new certificates, and even reinstall the whole smart card applet if needed. The Estonian state provides
DigiDoc DigiDoc (''Digital Document'') is a family of digital signature- and cryptographic computing file formats utilizing a public key infrastructure. It currently has three generations of sub formats, ''DDOC''- , a later binary based ''BDOC'' and cur ...
software allowing users to cryptographically sign digital documents. Since 2016 the DigiDoc software can create files that follow the EU-wide
ETSI The European Telecommunications Standards Institute (ETSI) is an independent, not-for-profit, standardization organization in the field of information and communications. ETSI supports the development and testing of global technical standard ...
standard called ASiC-e. By 7 September 2021, 1,391,704,193 electronic signatures were given, thus averaging to 50 signatures per card user per year. Under Estonian law, since 15 December 2000 the cryptographic signature is legally equivalent to a manual
signature A signature (; from la, signare, "to sign") is a handwritten (and often stylized) depiction of someone's name, nickname, or even a simple "X" or other mark that a person writes on documents as a proof of identity and intent. The writer of a ...
. This law has been superseded by the EU-wide eSignature Directive since 2016.


Uses for identification

The card's compatibility with standard
X.509 In cryptography, X.509 is an International Telecommunication Union (ITU) standard defining the format of public key certificates. X.509 certificates are used in many Internet protocols, including TLS/SSL, which is the basis for HTTPS, the secure ...
and
TLS TLS may refer to: Computing * Transport Layer Security, a cryptographic protocol for secure computer network communication * Thread level speculation, an optimisation on multiprocessor CPUs * Thread-local storage, a mechanism for allocating vari ...
infrastructure by providing a client certificate to each person has made it a convenient means of identification for use of web-based government services in Estonia (see
e-Government E-government (short for electronic government) is the use of technological communications devices, such as computers and the Internet, to provide public services to citizens and other persons in a country or region. E-government offers new ...
). All major banks, many financial and other web services support ID-card based authentication. Adding support of Estonian ID-card based identification is very simple nowadays because majority of used browsers, web servers and other software supports TLS (SSL) client-certificate based authentication and Estonian ID-card use exactly that system.


Web discussion forums

Web commentary columns of some Estonian newspapers, most notably '' Eesti Päevaleht'', used to support ID-card based authentication for comments. This approach caused some controversy in the internet community.


Public transport

Larger cities in Estonia, such as
Tallinn Tallinn () is the most populous and capital city of Estonia. Situated on a bay in north Estonia, on the shore of the Gulf of Finland of the Baltic Sea, Tallinn has a population of 437,811 (as of 2022) and administratively lies in the Harju ' ...
and
Tartu Tartu is the second largest city in Estonia after the Northern European country's political and financial capital, Tallinn. Tartu has a population of 91,407 (as of 2021). It is southeast of Tallinn and 245 kilometres (152 miles) northeast of ...
, have arrangements making it possible for residents to purchase "virtual" transportation tickets linked to their ID cards. Period tickets can be bought online via electronic bank transfer, by
SMS Short Message/Messaging Service, commonly abbreviated as SMS, is a text messaging service component of most telephone, Internet and mobile device systems. It uses standardized communication protocols that let mobile devices exchange short text ...
, or at public kiosks. This process usually takes less than a few minutes and the ticket is instantly active from the moment of purchase or since the first use of the ticket. Customers also have the option of requesting e-mail or SMS notification alerting them when the ticket is about to expire, or of setting up automatic renewal through internet banking services. To use the virtual ticket, customers must carry their ID card with them whenever they use public transport. During a routine ticket check, users are asked to present their ID card, which is then inserted into a special device. This device then confirms that the user holds a valid ticket, and also warns if the ticket is about to expire. The ticket check usually takes less than a second. Ticket information is stored in a central database, not on the ID card itself. Thus, to order a ticket, it is not necessary to have an ID-card reader. Ticket controllers have access to a local archive of the master database. If the ticket was purchased after the local archive was updated, the ticket device is able to confirm the ticket from the master database over mobile data link.


Electronic voting

The Estonian ID card is also used for authentication in Estonia's Internet-based voting program called i-Voting. In February 2007, Estonia was the first country in the world to institute electronic voting for parliamentary elections. Over 30,000 voters participated in the country's e-election. In the Parliamentary election of 2011 140,846 votes were cast electronically representing 24% of total votes. The software used in this process is available for
Microsoft Windows Windows is a group of several proprietary graphical operating system families developed and marketed by Microsoft. Each family caters to a certain sector of the computing industry. For example, Windows NT for consumers, Windows Server for serv ...
,
macOS macOS (; previously OS X and originally Mac OS X) is a Unix operating system developed and marketed by Apple Inc. since 2001. It is the primary operating system for Apple's Mac computers. Within the market of desktop and lapt ...
and
Linux Linux ( or ) is a family of open-source Unix-like operating systems based on the Linux kernel, an operating system kernel first released on September 17, 1991, by Linus Torvalds. Linux is typically packaged as a Linux distribution, which ...
.


Use as a travel document

Since Estonia's accession to the
European Union The European Union (EU) is a supranational political and economic union of member states that are located primarily in Europe. The union has a total area of and an estimated total population of about 447million. The EU has often been des ...
(EU) in 2004, Estonian citizens who possess an Estonian identity card have been able to use it as an international travel document, in lieu of a passport, for travel within European Economic Area (except Belarus, Russia, and Ukraine) as well as French overseas departments and territories, Andorra, San Marino, Monaco, Vatican State, Northern Cyprus and Georgia. However, non-Estonian citizens resident in Estonia are unable to use their Estonian identity cards as an international travel document.


Security issues

Over the years the Estonian ID card and its ecosystem has experienced several security incidents and similar issues. Below are listed some of the most significant security incidents that have been encountered.


Infineon's RSA key generation flaw

In August 2017, a security threat was discovered that affected 750,000 ID and e-residency cards issued between 16 October 2014 and 26 October 2017. It was reported that a code library developed by Infineon, which had been in widespread use in security products such as smartcards and TPMs, had a flaw (later dubbed the
ROCA vulnerability The ROCA vulnerability is a cryptographic weakness that allows the private key of a key pair to be recovered from the public key in keys generated by devices with the vulnerability. "ROCA" is an acronym for "Return of Coppersmith's attack". Th ...
) that allowed private keys to be inferred from public keys. As a result, all systems depending upon the privacy of such keys were vulnerable to compromise, such as identity theft or spoofing. Affected systems include 750,000 Estonian national ID cards, and Estonian e-residency cards. On 2 November 2017, the Estonian government decided to suspend the affected certificates on the midnight of November 3. For the next five months until 31 March 2018 (incl.), the holders of the suspended certificates were still able to update their ID cards at PPA customer service points and remotely over the internet. On 1 April 2018, the certificates of the non-renewed ID cards were revoked and the renewal service for the affected ID cards was discontinued. The governments decision to postpone the revocation of the affected certificates and allowing the remote renewal of suspended certificates have been criticized for not being in compliance with
eID Eid as a name may refer to: Islamic holidays An Eid is a Muslim religious festival: * ''Eid Milad un Nabi'', alternate name for Mawlid (, "Birth of the Prophet"), the date of observance of the birthday of the Islamic prophet Muhammad * Eid al ...
legal requirements. The incident resulted in a litigation process as the ID card manufacturer
Gemalto Gemalto was an international digital security company providing software applications, secure personal devices such as smart cards and tokens, and managed services. It was formed in June 2006 by the merger of two companies, Axalto and Gemplus In ...
failed to inform the Estonian state about the vulnerability in a timely manner. In February 2021, it was reported that
Gemalto Gemalto was an international digital security company providing software applications, secure personal devices such as smart cards and tokens, and managed services. It was formed in June 2006 by the merger of two companies, Axalto and Gemplus In ...
and the Estonia state reached a compromise agreement, with
Gemalto Gemalto was an international digital security company providing software applications, secure personal devices such as smart cards and tokens, and managed services. It was formed in June 2006 by the merger of two companies, Axalto and Gemplus In ...
agreeing to pay the state 2.2 million EUR in compensation.


Security flaws in key management

There have been several isolated cases of security flaws being discovered in the ID card key management process. In particular, in some cases, contrary to the security requirements, the ID card manufacturer
Gemalto Gemalto was an international digital security company providing software applications, secure personal devices such as smart cards and tokens, and managed services. It was formed in June 2006 by the merger of two companies, Axalto and Gemplus In ...
had generated private keys outside the chip. In several cases, copies of the same private key have been imported in the ID cards of different cardholders, allowing them to impersonate each other. In addition, as a result of a separate flaw in the manufacturing process, corrupted RSA public key moduli have been included in the certificates, which in one case led to the full recovery of the corresponding private key.


See also

* National identity cards in the European Union * Estonian passport *
Estonian seafarer's discharge book An Estonian seafarer's discharge book (Estonian: Meremehe teenistusraamat) is an identity document issued by Estonian Police and Border Guard Board in which the name, date of birth or personal identification code, and a photograph or facial image ...
* Estonian temporary travel document *
Estonian alien's passport An Estonian Alien's Passport ( et, välismaalase pass) is a travel document that may be issued to a person who is stateless or of undefined citizenship residing in Estonia by the Police and Border Guard Board of the Ministry of Internal Affair ...
* Estonian travel document for refugees *
Estonian nationality law Estonian citizenship law details the conditions by which a person is a citizen of Estonia. The primary law currently governing these requirements is the Citizenship Act, which came into force on 1 April 1995. Estonia is a member state of the ...
*
Visa requirements for Estonian citizens Visa requirements for Estonian citizens are administrative entry restrictions by the authorities of other states placed on citizens of Estonia. As of 11 January 2022, Estonian citizens had visa-free or visa on arrival access to 181 countries a ...
*
Visa requirements for Estonian non-citizens Visa requirements for Estonian non-citizens are administrative entry restrictions by the authorities of other states placed on holders of an Estonian alien's passport. __TOC__ Visa requirements map Visa-free access Non-citizens of Estonia m ...
* e-Residency of Estonia *
e-Estonia e-Estonia refers to the digital society of Estonia, which facilitates its citizens' and residents' interactions with the state through the use of ICT solutions. Estonian e-services created under this initiative include e-Tax Board, e-Business, e ...
*
ROCA vulnerability The ROCA vulnerability is a cryptographic weakness that allows the private key of a key pair to be recovered from the public key in keys generated by devices with the vulnerability. "ROCA" is an acronym for "Return of Coppersmith's attack". Th ...


References


External links


New Estonian ID Card 2019

Information about Estonian ID Card by Estonian Police and Border Guard Board



Sample ID Card of an Estonian citizen, issued by Estonian Police and Border Guard Board starting from 01.01.2011

A map of Estonian representations abroad

Certificate of Return for Estonian citizen

Identity Documents Act

Visa-Free Country List by Estonian Foreign Ministry

Passport Index Visa-Free Score Estonian Passport

Henley & Partners Visa Restrictions Index Map

Issuing authority's official website in English

ID Ticket website

ID card official information page

ID card information on the e-estonia website
{{DEFAULTSORT:Estonian Id Card Government of Estonia National identity cards by country Smart cards