Company history

A decade of building trust
in internet identity

From its initial concept in 2013 through formal incorporation in 2014, Https Card — Internet Identity Card Ltd has evolved from an early-stage initiative into a structured Internet identity framework, with ongoing engagement in institutional and technical ecosystems. This trajectory spans interactions and references across national and international bodies, including the INPI, the UK Intellectual Property Office, the Library of Congress, the United Nations, and the OECD, culminating in five open defensive publications and the release of version 9.0 in July 2026 — the first Internet Identity Card with hybrid post-quantum signing.

2013

Concept inception

Https Card — Internet Identity Card Ltd was founded in France and the United Kingdom with a clear objective: to provide individuals with a robust solution to prove and protect their online identity. The first public work on the Internet Identity Card was conducted under the domain httpscard.com; the domain internetidentitycard.com was registered on 5 January 2014 as a continuation.

CNIL France
1726245
UK Companies House
09168431
ICO UK Data Controller
ZA457585
D&B D-U-N-S
220301971
2014

INPI France — Trademark

The French National Industrial Property Institute (INPI).

Official registration number
INPI — FR 4071419
2014

US Library of Congress

In 2014, Https Card registered original work of authorship with the United States Copyright Office at the Library of Congress. This registration may enable statutory damages and attorney fees in eligible litigation.

Official registration number
USCO — USA TX0008508373
2015

Borderpol

Https Card — Internet Identity Card presented the Internet Identity Card at the 7th BORDERPOL Forum, attended by heads of border forces, police, customs, and airport security, co-hosted by the Ministry of Interior in Spain.

2016

IPO United Kingdom — Trademark

The UK Intellectual Property Office registered the trademark "INTERNET IDENTITY CARD" (filed 25 May 2016).

Official registration number
IPO UK — UK00003166480
2018

Paris Call for Trust and Security in Cyberspace

Https Card — Internet Identity Card ™ is an official supporter and signatory of the Paris Call for Trust and Security in Cyberspace, launched on 12 November 2018 during the Internet Governance Forum (IGF).

2019

First decentralised Internet Identity Card ™

This Internet Identity Card was embedded in IPFS and timestamped via a Bitcoin transaction on 13 May 2019 (block 575,758), providing verifiable proof of existence at that time. Seven years later, both proofs remain live: the transaction is permanently recorded on the Bitcoin blockchain, and the card itself is still retrievable from the IPFS network.

IPFS CID
QmXXvokcgvtjqCsyWynRkuhco6YWhPqdDfRevee2zbLBsC
View the 2019 card (live)
Card hash (SHA-256)
ED70CEF5A086E264386AB026EDAAABB8F25C378F1E3A699A2C0A72A20D53C7FB
Bitcoin transaction
929bb2d8…fc754540 ↗ · 13 May 2019, 00:13:27 UTC
2019

Accredited participation at the United Nations OEWG — New York

Through resolution 73/27, the United Nations General Assembly established an Open-Ended Working Group (OEWG). On 2–4 December, Https Card — Internet Identity Card participated as an accredited non-state actor in the intersessional meeting of the United Nations Open-Ended Working Group (OEWG) in New York, on developments in the field of ICTs in the context of international security. These discussions on international peace and security in cyberspace were open to non-state actors for the first time in the United Nations' history.

2020

Decentralized Identity Foundation (DIF)

Https Card — Internet Identity Card joined the Decentralized Identity Foundation to contribute to the development of an open, standards-based decentralized identity ecosystem.

2020

World Bank Group — Annual Meetings

Https Card — Internet Identity Card was listed among the participants of the World Bank Group / IMF Annual Meetings 2020.

2021

Statement delivered at the United Nations OEWG

“73 years ago, the United Nations General Assembly adopted the Universal Declaration of Human Rights and today digital technology has created new threats to Human Rights such as data privacy and identity fraud. Fortunately, digital technology has the power to transform the world and to protect the privacy of all of us.”

Read the declaration
2022

Statement — OEWG, United Nations Headquarters, New York

Statement by Https Card — Internet Identity Card Ltd (IIC) to the UN Open-Ended Working Group on Security of and in the use of Information and Communications Technologies (ICTs) in the context of international security — Third substantive session, 25–29 July 2022 at UNHQ, New York.

Read the declaration
2023

BORDERPOL Journal — Podcast Interview

Michael Benaudis, founder & CEO of the Internet Identity Card and long-time colleague of BORDERPOL, was interviewed on the BORDERPOL Journal podcast (Bob and Tom interview, 27 April 2023).

2023

OECD — Digital Identity Governance

Https Card, represented by its founder Michael Benaudis, contributed comments to the OECD (Organisation for Economic Co-operation and Development) public consultation on the draft Recommendation for Digital Identity Governance.

12 May 2026

Defensive publication — TDCommons #10079

Https Card published an open defensive disclosure on Technical Disclosure Commons (operated by Elsevier): "Cryptographic Identity Document System Using TOTP-Derived Symmetric Keys for Offline Issuer-Mediated Access Control". Released under the Creative Commons Attribution 4.0 license as defensive prior art.

19 May 2026

Defensive publication — TDCommons #10167

A second open defensive disclosure on Technical Disclosure Commons: "Self-Verifying Single-File Cryptographic Documents with Dual-Passphrase Architecture for Offline Recipient-Mediated Access Control". It discloses the SHA-256 page integrity scheme (with fail-closed lockdown) and the dual-passphrase architecture using Argon2id. Released under CC BY 4.0.

7 June 2026

Defensive publication — TDCommons #10394

A third open defensive disclosure on Technical Disclosure Commons: "Composite Defense-in-Depth Architecture for Self-Contained Offline Cryptographic Identity Documents". It discloses the layered combination of memory-hard Argon2id key derivation, AES-256-GCM authenticated encryption, SHA-256 self-verification with fail-closed lockdown, and ECDSA P-256 signing within a single zero-dependency file. Released under CC BY 4.0.

June 2026

Internet Identity Card ™ v8.4.1

A new generation of the Internet Identity Card is released. The single-file generator (~336 KB) introduces a memory-hard Argon2id key derivation function (RFC 9106, 96 MiB, t=4, p=4), a dual-passphrase architecture separating the issuer's long-term secret from per-export recipient passphrases, and SHA-256 page integrity (self-verifying documents with fail-closed lockdown). Both cards and backups use the same memory-hard Argon2id key derivation, and exported cards self-verify fully offline. The card maintains full offline recipient decryption with no server-mediated key exchange. The complete v8.4.1 package is available for download with ECDSA P-256 signature verification and blockchain timestamping (Bitcoin + Ethereum).

Single-file generator
~336 KB
Key derivation
Argon2id (RFC 9106, 96 MiB, t=4, p=4)
Encryption
AES-256-GCM
Integrity
SHA-256 self-verification
Signatures
ECDSA P-256, NIST FIPS 186-4
Download
3 July 2026

Two further defensive publications — anchored on Bitcoin & Ethereum

Two new open defensive disclosures extend the prior-art record to five. “Canonical Multi-Zone Neutralization for Self-Serialized Documents” (v2) discloses the deterministic ordering by which one file simultaneously carries hybrid classical + post-quantum signatures, a self-referential integrity digest, and a post-signing blockchain anchor. “In-File Stapled Freshness” discloses Zone F: hash-chain validity tokens stapled by the holder into a frozen self-verifying document, giving offline verifiers a fail-stale FRESH / STALE / INVALID ruling with no re-signing, no server, and no PKI. Both were SHA-256 fingerprinted and anchored on the Bitcoin and Ethereum blockchains on 3 July 2026; Technical Disclosure Commons publication is in progress.

Multi-Zone Canonical Neutralization v2
In-File Stapled Freshness (Zone F)
Blockchain anchors
July 2026

Internet Identity Card ™ v9.0 — Post-Quantum Ready

The first Internet Identity Card with hybrid post-quantum signing. Where authorship must be provable, cards and signed documents now carry two signatures verified together: the classical ECDSA P-256 and the post-quantum ML-DSA-65 (FIPS 204), following ANSSI transition guidance for hybrid constructions. A future quantum computer able to break ECDSA does not break authorship: the ML-DSA-65 component remains secure, and the blockchain anchor proves signing predated any deprecation. v9.0 also introduces an embedded offline verification engine in every exported card, crypto-agile suite registry, hybrid receipts v3.0 (backward-compatible with v2.0), and a deterministic modular build — identical sources always produce an identical SHA-256, the prerequisite for meaningful blockchain anchoring. The release was anchored in two steps: the documentation set, both new defensive publications and the initial package build on 3 July (one Bitcoin and one Ethereum transaction covering seven fingerprints, plus per-file OpenTimestamps proofs), and the final package build on 4–5 July. “PQC-ready” denotes FIPS 204 algorithmic conformance in code; it is not a FIPS 140 CMVP validation or an ANSSI qualification.

Signatures
Hybrid: ECDSA P-256 + ML-DSA-65 (FIPS 204)
Key derivation
Argon2id (RFC 9106, 96 MiB, t=4, p=4)
Encryption
AES-256-GCM
Integrity
SHA-256 self-verification, fail-closed, fully offline
Single-file generator
~493 KB, zero dependencies
Package anchor
Download