The complete, public documentation of the Internet Identity Card — current release v9.0 (hybrid post-quantum), with the superseded v8.4.1 editions preserved below. Every file is SHA-256 fingerprinted and timestamped on the Bitcoin and Ethereum blockchains.
The five official documents below — User Guide, Technical Specification, Engineering Specification, and Threat Model — are freely available for review, audit, and reference. Their integrity is anchored on the Bitcoin and Ethereum blockchains and on OpenTimestamps. The underlying architecture is disclosed in two open defensive publications on Technical Disclosure Commons (CC BY 4.0).
The generator application and the IIC Wallet (both distributed inside the Complete Package), however, are not publicly downloadable. Due to the critical and sensitive nature of identity infrastructure, access to the generator and the Wallet is granted through a controlled onboarding process to ensure security, compliance, and operational alignment.
For demo requests or partnership inquiries, please contact us at demo@internetidentitycard.com.
Released 3 July 2026. v9.0 introduces hybrid post-quantum signing — ECDSA P-256 combined with ML-DSA-65 (FIPS 204) — an embedded offline verification engine in every exported card, and a deterministic modular build.
“PQC-ready” denotes FIPS 204 algorithmic conformance in code; it is not a FIPS 140 CMVP validation or an ANSSI qualification.
Step-by-step instructions to create your first card, choose between Quick and Secure modes, share your identity safely, understand SHA-256 page integrity, and answer common questions about Memorable Words, Card Passphrases, and recovery. Updated for v9.0.
Architecture, cryptography and verification flows — including the hybrid post-quantum signature suite introduced in v9.0: ECDSA P-256 combined with ML-DSA-65 (FIPS 204), crypto-agile suite registry, hybrid receipts v3.0, deterministic modular build, and the embedded offline verification engine.
Provenance, engineering innovations and standards compliance: single-file zero-dependency architecture, offline self-verification, hybrid post-quantum signing, multi-zone canonical neutralization, and the complete prior-art and registration record since 2013.
Security analysis, trust assumptions and residual risks — with the quantum adversary now explicitly addressed: harvest-now/decrypt-later and harvest-now/forge-later scenarios, STRIDE analysis of the hybrid posture, and a candid statement of what remains out of scope.
How to install and use the IIC Wallet — the optional offline PWA that collects and organizes your cards. Unchanged since v8.4.1: the v1.0 edition and its blockchain anchor of 7 June 2026 remain current.
The Complete Package is a single archive (14 files) containing the four official v9.0 documents (User Guide, Technical Specification, Engineering Specification, Threat Model), the Wallet User Guide v1.0, the IIC generator application v9.0 (~493 KB, hybrid post-quantum signing), the IIC Wallet PWA (offline card viewer, with manifest, service worker and Apache config), the README, and a SHA256SUMS checksum file. Because it includes the generator and the Wallet, this download is provided through the controlled onboarding process described above.
🔒 Request access — demo@internetidentitycard.comOnce granted, you can verify the authenticity of the archive against the published SHA-256 hash.
Superseded by v9.0 on 3 July 2026. These editions remain published and fully verifiable: their blockchain timestamp proofs are permanent.
Step-by-step instructions to create your first card, choose between Quick and Secure modes, share your identity safely, understand SHA-256 page integrity, and answer common questions about Memorable Words, Card Passphrases, and recovery.
Full cryptographic architecture and API reference. Covers AES-256-GCM, Argon2id RFC 9106 (96 MiB, t=4, p=4) for both cards and backups, ECDSA P-256, the dual-passphrase architecture, SHA-256 page integrity (Mode A), IIFE module isolation, threat model, and storage format.
System architecture, provenance timeline (2013–2026), defensive publications (TDCommons #10079, #10167 and #10394), standards compliance, and version history. Documents NIST, RFC, GDPR alignment and the registration timeline of Https Card — Internet Identity Card Ltd. Reference document for procurement, due diligence, and compliance reviews.
Realistic security analysis: trust assumptions, assets, adversary model (A1–A4), STRIDE analysis, ten concrete attack scenarios, and an honest account of residual risks and out-of-scope threats (compromised devices, generator authenticity, coercion, quantum). Companion to the Technical & Engineering Specifications.
Complete step-by-step guide to the IIC Wallet: installation (desktop and mobile, local use or PWA), first-launch consent dialog, three methods to add cards (drag-drop, file picker, auto-open .iic), opening cards, removing cards, the six-layer security model, troubleshooting common dialogs, and a full FAQ.
The Complete Package is a single archive containing the five official documents (User Guide, Technical Specification, Engineering Specification, Threat Model), the IIC generator application (~338 KB), the IIC Wallet PWA (offline card viewer, ~31 KB, with manifest, service worker and Apache config), the README, and a SHA256SUMS checksum file. Because it includes the generator and the Wallet, this download is provided through the controlled onboarding process described above.
🔒 Request access — demo@internetidentitycard.comOnce granted, you can verify the authenticity of the archive against the published SHA-256 hash and ECDSA P-256 signature.
The IIC Wallet is an optional offline application that lets you collect and organize all your IIC cards in one place. It runs entirely in your browser, stores nothing on any server, and works without an internet connection. The Wallet never sees the unencrypted content of secured cards — each card retains its own cryptographic protections (Argon2id key derivation, AES-256-GCM encryption, SHA-256 page integrity, ECDSA P-256 signatures).
Distribution model: the Wallet is included in the IIC Complete Package — the same controlled-access archive that contains the generator. It is never hosted publicly. After receiving the package, you choose how to use it: locally on your desktop, or by hosting it on your own private server for mobile use.
.iic files.iic card opens it directly in the Wallet.Once you have received the IIC Complete Package, the Wallet is in the wallet/ folder. You can use it two ways:
wallet/iic-viewer.html in Chrome, Edge, Brave, Safari or Firefox..iic or .html cards into the Wallet, or use the file picker.wallet/ folder on any HTTPS server you control (local Apache, nginx, or a private cloud)..iic auto-open support.wallet/ folder on an HTTPS server you control..html or .iic files — this is an Apple OS-level restriction that applies to every web-based app. On iOS, the Wallet still works fully, but each card must be added manually via the file picker or drag-and-drop inside the Wallet. The other platforms (Android, macOS, Windows, Linux with Chromium browsers) support full auto-open.
The cryptographic constructions underlying the Internet Identity Card are disclosed as open prior art on Technical Disclosure Commons (operated by Elsevier), released under the Creative Commons Attribution 4.0 license with explicit patent waivers from the inventor. They are indexed by Google Scholar, Semantic Scholar, and the bepress Digital Commons Network. Two further disclosures — covering the v9.0 multi-zone canonical neutralization and in-file stapled freshness constructions — were blockchain-anchored on 3 July 2026 and are in publication.
Discloses the canonical neutralization ordering (v2) by which one self-serialized document simultaneously embeds hybrid classical + post-quantum signatures, a self-referential SHA-256 integrity digest, and a blockchain anchor written after signing — collapsing the triple circular dependency to a single deterministic fixed point verifiable fully offline.
Discloses Zone F: successive Micali-style hash-chain freshness tokens stapled by the holder into a dedicated length-preserving zone of an immutable self-verifying document — excluded from both signature and integrity coverage — giving an offline verifier a FRESH / STALE / INVALID ruling with no re-signing, no server, and no PKI.
Discloses the TOTP-derived symmetric key system, dual-domain PBKDF2 architecture, AES-256-GCM encryption, IIFE module isolation, ECDSA P-256 signatures, and single-file HTML distribution model for offline issuer-mediated access control.
Discloses two new constructions: (i) the SHA-256 page integrity scheme (Mode A) with fail-closed lockdown, and (ii) the dual-passphrase key architecture using Argon2id RFC 9106 (96 MiB, t=4, p=4) for per-export recipient passphrases.
Discloses the ecosystem-wide defense-in-depth architecture: multi-marker structural validation, bidirectional filename-identifier verification with triple checkpoint, the non-degrading optional offline launcher pattern (PWA), and bundled access-controlled distribution with universal blockchain verifiability — combined with the prior two publications into six independent fail-closed verification layers.
Pick the one that matches your role and what you want to do.
In addition to file verification, you can verify the SHA-256 integrity of every HTML page on this site in real time — directly in your browser, using the W3C Web Crypto API. Nothing is uploaded.