[00:00.000 --> 00:01.300] And now to our next speaker. [00:02.660 --> 00:13.480] Once mass immunization campaigns begin, whether it was smallpox in 1947, polio in 1955, or COVID more recently, governments and people want means to verify vaccination status. [00:13.900 --> 00:27.060] Our next speaker will discuss modern proof of vaccination credentials, how the document and issuers protect the underlying information, and how governments and industry work together to create an inter-jurisdictionally interoperable document. [00:27.320 --> 00:28.940] Please welcome Dr. Greg Newby. [00:33.690 --> 00:34.250] Thanks, Jen. [00:34.430 --> 00:35.250] Thanks for everyone showing up. [00:35.370 --> 00:39.290] I don't know if you've seen me before at the conference, but I'm actually doing a talk, believe it or not. [00:39.890 --> 00:43.670] Blind refereeing, no nepotism, nothing like that. [00:43.930 --> 00:46.590] So proof of vaccination technologies and standards. [00:46.970 --> 00:51.010] So let me just start out by saying I'm not officially representing someone. [00:51.190 --> 01:00.330] I'm going to do my best not to mention my employer in Canada, not representing them, not representing any provincial or territorial government, federal government, anything like that. [01:00.550 --> 01:02.530] And I'm not telling you any secrets. [01:02.530 --> 01:04.010] I was not exposed to secrets. [01:04.010 --> 01:04.390] I was not exposed to any secrets. [01:04.850 --> 01:14.430] We have a little bit of a, not a non-disclosure, but a little bit of a terms and use or a use agreement, not violating any of that stuff. [01:15.830 --> 01:23.610] At the same time, this is stuff I'm going to talk about is kind of opaque, I found, even learning a lot about it as I've been working with this. [01:23.710 --> 01:28.190] So I thought it would be a good, a good topic to share here at the Hackers on Planet Earth. [01:28.750 --> 01:31.510] For the record, I pasted the abstract. [01:31.870 --> 01:33.830] You don't need to spend too much time on that. [01:33.950 --> 01:36.670] And we got a nice summary that went beyond the abstract. [01:36.970 --> 01:38.510] And this is a little bit about me. [01:39.070 --> 01:46.610] People know, I think here at this time, that I'm involved with the Hackers on Planet Earth conference, done some writing for 2600 magazine. [01:46.870 --> 01:49.590] This is all, from my point of view, sort of a hobby and interest. [01:50.230 --> 02:04.750] But as do many of us, I have a pretty strong IT background, do some work in InfoSec, and I'm also into eBooks, which I've talked about on the HOPE stage a couple of times. [02:04.970 --> 02:09.790] So you can refer to those previous talks if you want to know about some of my other distractions. [02:10.210 --> 02:14.730] But today, it's actually, as I said, it's a story about something that I was involved with in my workplace. [02:14.730 --> 02:25.350] And more or less, I was a technical lead for one of the 13 provinces or territories of Canada, the country to our north. [02:25.670 --> 02:32.630] And what we did was something that worked across Canada in a very standardized way, which I think is interesting. [02:32.830 --> 02:40.610] And even though the U.S. has nothing like the same scope or scale of standardization, the same standards are used in Canada. [02:40.610 --> 02:44.950] So I'll mention it again probably, but the Excelsior Pass uses the exact same technology. [02:45.110 --> 02:49.350] The New York Excelsior Pass uses the exact same technology that I'm going to talk about. [02:49.470 --> 02:51.850] So it's relevant to the U.S. as well. [02:52.250 --> 02:56.810] The rest of the world, most of the rest of the world is using a somewhat different standard. [02:57.050 --> 02:58.470] There's maybe two or three other ones. [02:58.570 --> 03:01.690] But it's the same concept, and I'll go into that in a little more detail. [03:02.810 --> 03:06.590] So the idea here... I'm going to make this just a little bigger. [03:06.790 --> 03:07.050] Excuse me. [03:08.210 --> 03:08.950] Give me a sec. [03:13.210 --> 03:16.250] I just need to make my view, my presenter view, a little bigger. [03:16.430 --> 03:19.630] So the idea here is we want to issue a credential. [03:19.990 --> 03:23.710] So we didn't call... for some reason, they didn't call it a certificate. [03:23.710 --> 03:24.670] They called it a credential. [03:24.910 --> 03:29.430] So a proof of vaccination credential, or PVC, is what we call it in Canada. [03:29.430 --> 03:36.670] And so we wanted something that, as Jen mentioned, would let people demonstrate that they are vaccinated. [03:36.910 --> 03:41.490] It would be privacy-preserving and minimally disclosing of information. [03:41.490 --> 03:49.470] So, for example, you might consider, rightly, your proof of vaccination or your vaccination status to be part of your health record. [03:49.630 --> 03:55.730] Well, we don't want someone to hold up a piece of paper with your proof of vaccination and have your whole health record on it. [03:55.730 --> 03:59.990] We wanted to just do what it needs to do, which is demonstrate the vaccine proof. [04:00.190 --> 04:04.030] But it did need to be something that would work across jurisdictions. [04:04.290 --> 04:11.450] We wanted something that would be what you call self-sovereign, which is like your driver's license in your wallet, which means that you only show it to people when you want to. [04:11.930 --> 04:13.930] It doesn't require a remote database. [04:15.270 --> 04:22.650] It's not something that needs to be protected beyond what the information is that is on it. [04:22.650 --> 04:26.430] We also wanted to make it reasonably fraud-proof and tamper-evident. [04:26.610 --> 04:28.250] So, in other words, can you fake one? [04:28.390 --> 04:34.210] Can you make one that looks the same but you made it yourself and have that pass the validation checks? [04:34.210 --> 04:36.630] The answer is qualified no. [04:37.110 --> 04:40.790] And will it be evident if you take a valid one and make a change? [04:40.850 --> 04:43.150] Say, did you put your name in instead of someone else's name? [04:43.270 --> 04:44.790] And again, the answer is a qualified no. [04:46.070 --> 04:49.770] Qualified because if you're reading it digitally, then the answer is no. [04:49.770 --> 04:52.810] You can't fake these things very easily because they're digitally signed. [04:53.050 --> 04:56.610] And that gives you a lot of tamper-evidence and validation that we'll talk about a little bit. [04:57.070 --> 05:07.950] But if you're just reading the thing, reading the words on it as opposed to using a technical solution, then yeah, you could, you know, Photoshop and change the name easily enough. [05:08.190 --> 05:12.230] So, on the digital side, tamper-evidence and anti-fraud were very important. [05:12.510 --> 05:17.310] We wanted to be able to validate these things with apps, you know, with phone apps for a variety of reasons. [05:17.310 --> 05:23.370] You know, getting on planes, getting into venues, getting into supermarkets, whatever the jurisdictional requirement was. [05:23.490 --> 05:25.370] And the same sort of thing happened in the U.S. [05:25.410 --> 05:27.550] when they used these same technologies. [05:28.010 --> 05:31.310] We wanted to leverage an emerging de facto standard. [05:31.390 --> 05:39.610] By de facto, I mean it's not an actual standard like an ISO standard or one of the other standard bodies, standards, W3C, what have you. [05:40.030 --> 05:43.170] But it's a de facto standard in that a lot of places are using it. [05:43.290 --> 05:47.010] And therefore, it becomes a standard in practice. [05:47.570 --> 05:49.630] Oh, and by the way, there's no blockchain involved. [05:50.070 --> 05:53.590] A couple of times I talked to people about this, the anti-fraud, anti-tamper-evidence. [05:53.710 --> 05:56.550] I said, oh, you need a ledger, right? [05:56.550 --> 05:58.430] You need to be able to have an immutable ledger. [05:58.430 --> 06:04.290] And that is not a completely incorrect statement, but it's a mostly incorrect statement. [06:04.370 --> 06:10.630] Because one of the goals with a self-sovereign certificate and the app is that these should not need to call home. [06:10.770 --> 06:12.650] They should not need to verify externally. [06:12.830 --> 06:17.450] Because if you do that, then, you know, what if you're in a place with no mobile network? [06:17.590 --> 06:20.230] You know, or in a place where the Internet's down or something like that. [06:21.330 --> 06:22.850] And that's a practical thing. [06:22.970 --> 06:25.970] But, and we don't want to have a central database of this stuff. [06:25.970 --> 06:33.370] You want to have a document that someone can show, in the case of Canada, that someone can get their document issued in New Brunswick, one of the provinces. [06:33.690 --> 06:36.690] And they can show it in Northwest Territories, one of the territories. [06:37.130 --> 06:42.110] And it's fully interoperable without Northwest needing to know where the New Brunswick database is. [06:42.190 --> 06:43.250] So everything's self-contained. [06:43.550 --> 06:48.730] So yeah, no blockchain, despite, you know, maybe having a little bit of a conceptual appeal. [06:49.710 --> 06:55.730] The practical issues with an immutable stored ledger just don't match up with the requirements. [06:55.730 --> 06:56.570] of this application. [06:57.430 --> 06:59.290] So we've lived through COVID-19. [06:59.450 --> 07:01.130] We're still living through COVID-19. [07:01.290 --> 07:03.950] I just picked four, you know, sort of, sort of milestones. [07:04.170 --> 07:07.250] But just to give you an idea of how quickly some of this has occurred. [07:07.450 --> 07:09.650] Even though, of course, it feels like it's moving very slowly. [07:09.830 --> 07:10.690] It feels like it's forever. [07:12.330 --> 07:19.290] But March of 2020 was when the World Health Organization declared COVID-19 to be a global pandemic. [07:19.290 --> 07:20.710] That was a pretty big deal. [07:20.870 --> 07:24.770] It had appeared a few months earlier in China, of course, as everyone knows. [07:25.750 --> 07:27.770] First arrived in the United States. [07:27.770 --> 07:28.610] I think it was February. [07:28.750 --> 07:28.990] I'm not sure. [07:29.110 --> 07:30.750] It might have been January of 2020. [07:30.750 --> 07:32.910] And then it was declared a pandemic in March. [07:33.470 --> 07:36.270] By April, vaccine programs were announced. [07:36.390 --> 07:37.170] So this was interesting. [07:37.170 --> 07:38.390] And I remember as someone... [07:38.390 --> 07:48.030] I'm not a medical doctor, but I remember as someone with a scientific background thinking, okay, there are almost no effective vaccines against viruses. [07:49.490 --> 07:50.290] Very few. [07:50.810 --> 07:53.330] And most of those are a live vaccine. [07:53.930 --> 07:56.170] And they were talking about mRNA vaccines. [07:56.850 --> 07:57.870] So it's like, oh, this is pretty cool. [07:57.970 --> 07:58.970] So maybe they'll come up with it. [07:59.010 --> 07:59.770] Maybe they won't. [07:59.910 --> 08:01.730] Of course, now we know that they did. [08:01.830 --> 08:05.430] But this was announced in April of 2020. [08:05.430 --> 08:10.690] And then by December of 2020, which again, in retrospect, that seems insanely fast. [08:10.850 --> 08:13.350] But if you remember what we were doing in 2020, it was miserable. [08:13.610 --> 08:14.050] Right? [08:14.150 --> 08:23.210] It was like, you know, masking and double masking and all these songs about how to wash your hands for 25 seconds and six-foot distancing and not knowing. [08:23.310 --> 08:23.830] Remember this. [08:23.950 --> 08:31.630] We didn't know at the start of this period whether it was aerosol transmission, whether it was waterborne transmission. [08:31.630 --> 08:33.470] We had a lot of questions about this. [08:33.870 --> 08:35.530] You know, if it took residence in your lungs. [08:35.730 --> 08:50.090] So, you know, by the end of that year, just a year, because of the effort involved across the country, across the world, I mean, we had some vaccinations that were, you know, through with the early clinical trials. [08:50.270 --> 08:53.670] We got the emergency use authorization from FDA in the U.S. [08:53.670 --> 08:56.030] And then that happened in other countries, including Canada. [08:56.570 --> 09:01.450] And vaccines started going out by very late December and then into early January. [09:01.750 --> 09:03.130] And that was, again, both the U.S. [09:03.130 --> 09:05.090] and Canada were pretty close in lockstep. [09:06.110 --> 09:07.990] And then it was April 2021. [09:08.330 --> 09:15.870] So a few months later, when you started to see, and it might have been plus or minus in April, but you started seeing proof of vaccination requirements. [09:16.110 --> 09:29.350] So if people need to prove that they're vaccinated in order to get on a cruise ship, get on a plane, go into a supermarket, retain their job, which often happened, these other types of purposes, then you needed a proof. [09:29.350 --> 09:31.170] You got vaccinated, you needed a proof. [09:31.830 --> 09:35.710] So some of the reasons why you might want it, some of the opportunities here. [09:36.030 --> 09:37.510] Citizens, of course, want to be vaccinated. [09:38.330 --> 09:39.630] Some people are hesitant to be vaccinated. [09:39.630 --> 09:42.270] But if you're vaccinated, you'd like to be able to prove that. [09:42.850 --> 09:55.590] And also, if you're hesitant about getting vaccinated or for whatever reason, good reasons, you don't want to be among people that might be sick, you might want to know that other people can prove that they're vaccinated. [09:55.590 --> 09:57.610] So you have confidence, just like we did in this venue. [09:57.610 --> 10:01.590] You have confidence that the people in the venue have been vaccinated. [10:02.190 --> 10:06.010] Businesses, we just said, might demand to verify vaccination. [10:06.510 --> 10:09.710] Governments might require vaccination in various settings. [10:10.050 --> 10:12.790] And health professionals want to see more vaccination. [10:13.130 --> 10:17.850] But if you're going to require vaccination, then you want to also be able to protect against fraud. [10:18.030 --> 10:25.610] If it's trivially easy to have a fraudulent proof of vaccination, then you're not getting what you'd like out of the vaccination program. [10:25.610 --> 10:30.530] So a lot of reasons to have a, you know, one of these sort of robust proof of vaccination credentials. [10:31.270 --> 10:36.570] So what we did is, and this is across the board, not just in Canada and the U.S. [10:36.610 --> 10:53.690] with this particular standard I'm talking about, but with all the implementation sort of similarly for the proof of vaccine you get around the country and around the world, is you don't want to store a lot of information because people are sophisticated enough in the health profession especially about oversharing information. [10:53.690 --> 10:56.170] They don't want to disclose more than they need to. [10:56.350 --> 10:59.470] So what that means is if you're going to approve vaccination, what do you really need? [10:59.730 --> 11:04.530] One is you need to know what the vaccines were because there's different policies in different places. [11:05.310 --> 11:07.170] For example, sometimes there's a new... [11:07.170 --> 11:14.150] They're not as often now, but there used to be new vaccines that got approved in one place and it took time for it to be approved in the other place. [11:14.230 --> 11:23.250] So there might be a period where your proof of vaccination has you showing up as fully immunized, meeting the immunization requirements in one place but not in another place, right? [11:23.330 --> 11:24.790] So you have to know about the vaccinations. [11:24.990 --> 11:29.330] You also have to know the identity, right? [11:29.430 --> 11:42.290] So if I provide my proof of vaccination and it has my name on it, it has, you know, the vaccines on it, that's great, but does this pertain to me or is it, you know, someone else's proof of vaccination? [11:42.290 --> 11:45.630] So you also need identification and that's usually provided separately. [11:45.630 --> 11:47.070] Again, just like we did here at HOPE. [11:47.210 --> 12:00.470] You show your proof of vaccination, whatever form that may take, and then you provide your proof of identity and the job is to make sure that the identity matches the vaccination and that the vaccination meets whatever the requirements are for that particular venue. [12:01.310 --> 12:03.710] And we want to be standardized for the reasons I mentioned before. [12:03.830 --> 12:07.710] You want to be able to take a proof of vaccination from one place, read it in another place. [12:07.850 --> 12:11.950] And as you can imagine, a pretty good way of doing that is with automation. [12:11.950 --> 12:13.850] And that's really what we're going to be talking about today. [12:14.450 --> 12:20.190] And again, I mentioned self-sovereign, the idea that individuals determine when to present this. [12:20.730 --> 12:22.590] Individuals might... I have mine here. [12:22.790 --> 12:25.090] I'll show it again in a little more detail. [12:25.290 --> 12:32.110] But individuals might, you know, fold, spindle, mutilate, and just show you the QR code and not show you the birth date, right? [12:32.170 --> 12:34.750] Because you don't need to know the birth date, especially if you're scanning it. [12:34.910 --> 12:38.350] So there's a little bit of control even over the physical side. [12:38.530 --> 12:40.510] So let's get into what this thing looked like. [12:40.510 --> 12:45.850] So I just showed you mine briefly, and we'll dig into it on the slide show so you can see a little bit better. [12:46.330 --> 12:50.890] I'm going to be showing dominantly examples from Canada, mostly because... [12:50.890 --> 12:53.910] Well, mostly probably because those are the ones I'm most familiar with. [12:54.070 --> 12:57.990] But also because Canada came up with a standard for the whole country. [12:58.250 --> 13:00.570] In the U.S., there's a... we'll talk about this a little more. [13:00.630 --> 13:03.650] There's a real mixture of how they're presented, the look and feel. [13:04.470 --> 13:12.170] But if they're machine readable, they use the exact same QR code specification, this de facto specification that I talked about. [13:12.350 --> 13:21.470] So the QR code part and the associated payload, you know, the standard for the payload in the QR code content, are exactly the same in the U.S. [13:21.470 --> 13:21.830] and Canada. [13:22.010 --> 13:27.070] So this is just one of the examples that are from, you know, from the Canadian websites. [13:27.070 --> 13:31.150] And what I'll do, this is the front and back page. [13:31.330 --> 13:35.490] Generally, in Canada, the front page is the standard. [13:35.730 --> 13:40.870] The back page is whatever that particular jurisdiction wanted to add for their purposes. [13:41.030 --> 13:45.170] So, for example, they might say, here's where to go to get more information. [13:45.170 --> 13:47.030] And that's going to be different depending on the issuer. [13:47.410 --> 13:52.070] In the United States, there are some states, including New York, that centralize. [13:52.590 --> 13:56.450] You know, they have a reasonably centralized health database. [13:56.950 --> 13:59.250] There are a lot of places in the U.S. [13:59.690 --> 14:01.230] where there's no centralization. [14:01.230 --> 14:06.590] So these are issued by, you know, Walmart, for example, gave tons and tons of vaccinations. [14:07.110 --> 14:08.650] But in Canada, they're pretty standardized. [14:08.650 --> 14:10.650] And the second page was for the local information. [14:10.930 --> 14:11.830] I'm zooming in. [14:11.930 --> 14:13.970] It actually changed from one, I think, from the Yukon. [14:14.130 --> 14:15.590] And here's one from Ontario. [14:17.550 --> 14:21.070] And what you can see here is up top, it's the issuer, right? [14:21.070 --> 14:27.030] And this is sort of an arbitrary standard, but in a whole country, it's nice to have a common look and feel. [14:27.270 --> 14:29.010] I think it would have been nice for the U.S. [14:29.130 --> 14:34.590] to do that, but there's just so much resistance on the political side for willingness to do that. [14:34.590 --> 14:39.670] So there's a buy-in to the technical part of the QR code, but not at all to the look and feel. [14:40.350 --> 14:41.050] Well, a little bit. [14:41.110 --> 14:43.850] We'll talk about that momentarily, but not for the digital PVC. [14:44.550 --> 14:47.070] So anyway, you see up top the issuing jurisdiction. [14:47.270 --> 14:51.670] In this case, country Canada, province or territory of Ontario. [14:52.430 --> 14:57.090] And then you can look a little further, and you see that there's a little personal identifying information. [14:57.270 --> 15:00.610] And all it is is name and date, name and birth date, right? [15:00.790 --> 15:04.790] So you're not providing stuff that isn't necessary to verify identity. [15:04.790 --> 15:09.530] You're not doing, I don't know, address or citizenship or... [15:09.530 --> 15:12.590] In Canada, it's called the social insurance number, U.S. [15:14.690 --> 15:15.950] Social Security number. [15:16.190 --> 15:18.010] You know, you don't need that stuff to verify. [15:18.010 --> 15:23.210] So it's privacy protecting or minimally disclosing of personal information. [15:23.490 --> 15:25.230] We'll talk a lot about the QR code. [15:25.610 --> 15:30.850] This is the machine-readable payload, you know, the content of the PVC. [15:30.850 --> 15:33.950] And then also the human-readable version. [15:34.090 --> 15:39.710] Because the idea here is if it's only machine-readable, then you go to a place and they just drop their... [15:39.710 --> 15:45.870] You know, you're going into a bar or a venue and they just drop their phone and they can't verify digitally using the app. [15:45.950 --> 15:49.270] Well, you want them to be able to read visually what's going on. [15:49.310 --> 15:51.450] And as I said earlier, visually is great. [15:51.610 --> 15:52.810] The same information is there. [15:52.970 --> 15:55.770] Almost the exact same information as is in the QR payload. [15:56.190 --> 15:58.030] Slightly less, but almost the exact same. [15:58.030 --> 16:02.210] But it doesn't have any anti-fraud capabilities, right? [16:02.250 --> 16:06.410] In other words, you could have Photoshopped or whatever a document that looks just like this. [16:06.970 --> 16:13.190] And for someone reading it verbally, visually, they wouldn't be able to know that it was faked. [16:13.230 --> 16:14.850] You need the digital piece to do that. [16:16.230 --> 16:16.710] All right. [16:16.910 --> 16:18.550] So, and these are a couple of URLs. [16:18.550 --> 16:23.530] I'll post these slides on my website, which I have at the end of the talk. [16:23.530 --> 16:25.810] And if you want them, you can email me. [16:25.890 --> 16:26.690] I'm happy to share them. [16:27.610 --> 16:30.630] But these are a couple of places where you can find sample repositories. [16:31.290 --> 16:32.910] Canada has a nice repository. [16:33.410 --> 16:39.110] The U.S., they have a CDC page that talks about a couple of the different standards. [16:39.350 --> 16:43.870] And also, if you look a little further, you know, New York State has their own page, which I think is this right here. [16:44.650 --> 16:48.530] And Maryland and a couple other states do a pretty good job of these pages. [16:49.230 --> 17:01.670] So, in New York State, the equivalent of what I'm showing you, the proof of vaccination credential that Canada came up with, is the Excelsior pass, where an individual... [17:01.670 --> 17:04.610] I don't know if someone in New York probably knows for sure. [17:04.630 --> 17:09.650] I don't know that they were issuing, like, a paper version of this or not, or if this is printable. [17:09.830 --> 17:17.450] But I know that it's basically an app, and you're getting your QR code and the payload from the New York State Department of Health. [17:17.450 --> 17:19.090] So, they have a, you know, centralized database. [17:19.330 --> 17:26.770] So, if you get a vaccination in CVS in New York, then that can be fed up to New York State, get it into the app. [17:26.930 --> 17:35.450] And then you're able to show this QR code, just like on my piece of paper here, to someone that wants to verify your status. [17:36.270 --> 17:40.170] So, very, very similar, but, you know, obviously a somewhat different look and feel and some different details. [17:40.890 --> 17:43.610] And here's some other examples. [17:44.090 --> 17:44.950] This is from Walmart. [17:45.230 --> 17:50.930] So, you know, biggest retailer in the U.S., has a lot of pharmacies, gave a lot of vaccinations, millions and millions of vaccinations. [17:51.410 --> 17:53.810] Exact same QR code, right? [17:53.970 --> 17:57.050] And again, different look and feel, but the payload is the same. [17:57.270 --> 17:58.950] The QR code payload is the same. [17:59.690 --> 18:12.330] And the advantage over the, you know, printed card, a lot of us got a printed card when we got the vaccination and then needed to get the digital one, you know, go online somehow and get the digital one and download it or print it. [18:13.670 --> 18:22.210] The non-digital card, the printed version, is standardized, which is nice, so easy to see what's there, but extremely easy to fake, right? [18:22.330 --> 18:32.510] I mean, all you have to do is get someone else's card, make a copy, do a little digital editing, and you can have something that looks just the same and says that you're vaccinated, but it's fake, right? [18:32.530 --> 18:33.950] It's a forgery. [18:36.210 --> 18:40.370] As I just mentioned, in the U.S., there's a whole lot of variety in how this is done. [18:43.810 --> 18:53.030] I'll show you the list, maybe I'll spin out in a moment, I think I'll spin out to a web browser and I'll show you just a little bit of the list of those that are using the same standard. [18:53.450 --> 18:56.370] So it's, I believe it's 17, did I say, might have said 13. [18:56.790 --> 18:57.530] It's something like that. [18:57.590 --> 19:00.330] I think it's 17 states adopted this. [19:00.430 --> 19:02.190] We've mentioned New York because we're here in New York. [19:03.870 --> 19:06.030] And that sounds like not that many, right? [19:06.030 --> 19:06.450] I mean, it's not. [19:06.590 --> 19:08.330] It's fewer than half of the United States. [19:08.610 --> 19:21.130] However, hundreds of healthcare providers, HMOs, pharmacies, these types of places adopted the standard, which means that because the state is not usually the one that's immunizing you, right? [19:21.130 --> 19:24.250] You don't go to like a New York State clinic or something to immunize. [19:24.250 --> 19:26.350] You go to CVS or something like that. [19:27.230 --> 19:34.170] That actually the coverage for this standard, you know, the QR code standard, is actually quite great. [19:34.270 --> 19:45.750] I haven't seen any kind of statistics, but certainly there's a pretty good chance that if you were vaccinated in the U.S., you can get a digital, either an app or a paper or something that looks more or less like what I'm talking about. [19:47.830 --> 19:53.710] Okay, so let's talk about... actually, let's spin out to the web browser just for a moment. [19:54.030 --> 19:55.210] I'm going to do this a few times. [19:55.290 --> 19:56.050] Hopefully, it'll work okay. [19:56.370 --> 19:57.210] This is what I just mentioned. [19:57.310 --> 19:58.830] This is the... oh, wait a minute. [19:58.910 --> 19:59.990] Sorry, I have to go back here. [20:00.830 --> 20:01.830] I have to press escape. [20:02.350 --> 20:03.510] Now I have to go out to the web browser. [20:03.510 --> 20:10.450] So this is the list from the smart health... smarthealth.cards is the URL. [20:10.870 --> 20:15.610] But in Canada, there's all the provinces and territories. [20:15.670 --> 20:19.030] And then there's like the armed services and stuff like that. [20:19.190 --> 20:22.550] And then the U.S., there's 17 or so states, which doesn't sound like a lot. [20:22.750 --> 20:25.130] But then you keep... and there's a couple of other countries that are using this. [20:25.310 --> 20:28.590] And then you keep scrolling and say, okay, here's pharmacies. [20:28.590 --> 20:34.350] And as we said, you know, Walmart, CVS, Walgreens are dominant in the U.S. [20:34.490 --> 20:38.510] And so you're talking about millions and millions of doses of vaccinations. [20:39.270 --> 20:47.510] And you keep going and you get to all these other dozens and dozens, scores and scores of different organizations of different types, right? [20:47.690 --> 20:50.950] So it really is the dominant standard in the U.S. [20:50.970 --> 20:55.990] and Canada, even though it's much more centralized in Canada than it is in the U.S. [20:58.230 --> 21:02.190] And that thing is in the deck. [21:02.930 --> 21:04.090] Oops, what did I just do? [21:04.230 --> 21:06.530] I just did a slide sorter. [21:07.110 --> 21:07.790] Ooh, and we're back. [21:07.950 --> 21:11.050] So let's talk about the QR code in a little bit more detail. [21:12.290 --> 21:14.370] And these are just some of the various points. [21:14.650 --> 21:18.570] But more or less, it's the basics, as we said. [21:18.710 --> 21:22.390] Privacy preserving by not including information that doesn't need to be included. [21:22.390 --> 21:23.650] This is pretty reasonable. [21:23.870 --> 21:30.850] Any reasonable organization that was working on a health card standard to disclose information would make the exact same decision. [21:31.690 --> 21:50.310] Whatever you can say about health problems and insurance issues and HMOs and all these folks, when you're sitting around the table with the policy people and the technical people, always the conversation is about privacy, always. [21:50.570 --> 22:00.310] It's like how can we make sure that whatever we're doing with our technology is not inappropriately disclosing information that's personal health information. [22:00.310 --> 22:13.910] So what's in the content, the payload, as I said, is just a little bit of information about the individual, name, date of birth, some information about the vaccination given, which is more or less what we call the trade name or the brand name, you know, [22:13.950 --> 22:17.130] the name like Moderna, Spike Vax, these types of things. [22:17.510 --> 22:25.390] The dose, where it was administered, the lot number, and also a little bit of information about validity. [22:25.390 --> 22:34.570] There's a situation where, interesting thing I learned, a situation where you can get a vaccination, and then it turned out it was invalid, which is kind of a weird thing. [22:34.570 --> 22:35.550] So why did you get that shot? [22:35.770 --> 22:38.150] Well, it might have been that the lot was bad, for example. [22:38.410 --> 22:42.050] You know, the lot that the vaccine came in was found out later to be bad. [22:42.330 --> 22:44.510] So they have a thing about validity. [22:46.350 --> 22:50.610] And then this stuff we'll spend a little more time on digital signature by the issuer. [22:50.610 --> 22:52.530] So this is public key cryptography. [22:56.350 --> 23:03.630] And then on the implementation side, as I mentioned before, it doesn't contain things like social security number, your insurance card number, or things like that. [23:03.730 --> 23:08.190] It does include where you got the vaccination, at least at the jurisdiction level. [23:08.330 --> 23:12.410] I think probably in Canada it's going to say something like Ontario. [23:13.030 --> 23:14.010] In the U.S. it's going to say something like CVS. [23:15.530 --> 23:16.810] You know, it's like where you got this thing. [23:16.810 --> 23:21.870] And then another characteristic, as I said, is there's... [23:21.870 --> 23:23.350] Well, in New York State, I guess there is. [23:23.450 --> 23:27.990] But in Canada, the healthcare provider is the province or territory. [23:28.250 --> 23:32.730] And so there is a central database for, say, Ontario or for, say, Quebec. [23:33.210 --> 23:36.350] In the U.S., usually these are distributed. [23:36.570 --> 23:37.690] So Walmart has a database. [23:37.810 --> 23:38.630] CVS has a database. [23:39.410 --> 23:44.190] In the case of New York, as I said before, it seems like records do flow up and other people might know more... [23:44.190 --> 23:48.290] I mean, I'm sure more people know more details, including in the audience here. [23:50.310 --> 23:55.830] But that flows up to the New York State Health Department so that they're the ones that are issuing the Excelsior pass. [23:56.890 --> 23:58.170] But no database lookups. [23:58.250 --> 24:04.250] And also, and this is important, is that you don't need to call home to verify the document. [24:04.310 --> 24:05.630] And we'll talk about that in a little bit more. [24:06.390 --> 24:11.870] And here's just a URL that has a little bit of the detail, the technical detail, the specification. [24:12.310 --> 24:24.350] When you look at the decoded information from the QR code, which we'll do together momentarily, you see that it's an SHC colon slash slash data type as opposed to like HTTP or something like that. [24:24.430 --> 24:29.210] So this is the, you know, protocol or the data type definition, smart health card standard. [24:29.210 --> 24:36.930] And then that's a particular encoding that tells your, you know, whatever you're looking at it with the browser, how to decode what's there. [24:40.170 --> 24:47.150] The specific format of the payload is a JWS, Compact Serialization JSON Web Signature, JWS. [24:47.790 --> 24:50.430] And the decoded payload is signed. [24:50.530 --> 24:52.090] And we'll talk about that in a little bit more detail. [24:52.090 --> 24:58.270] But it's signed with a SHA-256 hash of an elliptic curve key. [24:58.870 --> 25:00.230] So pretty strong crypto. [25:00.370 --> 25:05.130] Not the strongest, but pretty strong crypto in the public key sense. [25:05.570 --> 25:12.750] And what this does, because it's SHA plus EC, what you're doing is you're able to, you're making a, I think they would call it a hash or a digest. [25:13.050 --> 25:14.730] So what you're doing is actually two things. [25:15.230 --> 25:19.610] One is that you're able to verify that it's not been tampered with. [25:19.610 --> 25:34.410] So when you have the hash, the SHA-256, you know, the one-way hash, if someone changes even one bit in the digital payload, then the hash won't match what's in the payload, right? [25:34.550 --> 25:36.470] So tamper evident or tamper resistant. [25:36.770 --> 25:42.570] And then with the digital signature, what that means is you can use the public key signature. [25:44.310 --> 25:58.630] I'm sorry, you can use the URL that goes to the public key signature, and you can verify that the issuer, as long as you're trusted it hasn't been tampered with, that the issuer out there on the Internet, the key matches what the payload is. [25:58.750 --> 26:01.950] So that is a validating factor. [26:01.950 --> 26:05.310] So that's kind of interesting to me because it's both. [26:05.610 --> 26:09.370] The ability to... and that's sort of typical of PKI, right? [26:09.470 --> 26:18.110] With verified email, whatever it is, is that you're tamper evident, and you're also able to validate the issuer with the same technology. [26:18.790 --> 26:21.890] So we'll do a quick little show-and-tell with this. [26:23.390 --> 26:25.350] We're going to look at the portal. [26:25.550 --> 26:26.910] Let's... I think maybe first thing... [26:27.550 --> 26:28.670] No, I'll just... I'm sorry. [26:28.730 --> 26:32.970] I'll just zoom out to the web page, to the web browser again. [26:33.130 --> 26:33.630] Let's do that. [26:35.610 --> 26:37.110] So this is a web page. [26:37.170 --> 26:37.970] Anyone can go to it. [26:38.090 --> 26:40.890] It's a verifier portal for the SHC. [26:41.830 --> 26:43.850] I think it can maybe do a few things other than that. [26:44.010 --> 26:45.870] And so what I think I'll try... [26:45.870 --> 26:52.610] I'm just going to try this, but I've done presentations before, so I also have the output stored in another web window. [26:53.250 --> 26:56.910] But... so this, as I showed before, this is my personal proof of vaccination credential. [26:57.410 --> 26:58.750] Why am I showing it to you? [26:58.810 --> 27:02.170] Because there's very little in here that's not readily available. [27:02.290 --> 27:03.070] You already know my name. [27:03.330 --> 27:06.310] You don't know my date of birth, but it's not that hard to find my date of birth. [27:06.490 --> 27:08.570] And then everything else is what vaccines I got. [27:08.670 --> 27:11.170] And I'm not really very sensitive to people knowing that. [27:11.350 --> 27:13.110] I'm happy for you to know what vaccines I got. [27:13.390 --> 27:14.150] And boosters. [27:15.210 --> 27:15.610] Vaccines. [27:15.850 --> 27:16.110] Boosters. [27:17.410 --> 27:19.170] So the QR code is over here. [27:19.170 --> 27:21.570] So what we're going to do here, we'll try this. [27:22.290 --> 27:24.010] Is we're going to say, scan the code. [27:26.670 --> 27:27.970] And we'll try this. [27:28.110 --> 27:29.450] It might not work because of the lighting. [27:37.610 --> 27:38.550] Not too happy. [27:38.870 --> 27:39.930] I didn't think it would be. [27:39.990 --> 27:41.910] That's why I did this before. [27:42.270 --> 27:42.830] Oh, there it goes. [27:42.990 --> 27:43.170] Okay. [27:43.370 --> 27:43.710] Excellent. [27:44.150 --> 27:44.730] So, yeah. [27:46.690 --> 27:47.710] I take no credit. [27:48.090 --> 27:49.410] So, yeah. [27:49.450 --> 27:53.290] Like I said, I had stored a copy just in case I wasn't able to scan it. [27:53.290 --> 27:54.030] But... [27:54.570 --> 27:55.670] So this is... [27:56.170 --> 27:57.770] It shows it in a couple different ways. [27:58.930 --> 28:01.590] And it's more or less the same thing, just presented in a few different ways. [28:01.810 --> 28:03.410] So this is the raw data here. [28:03.590 --> 28:06.050] And you can see shc colon slash slash, right? [28:06.850 --> 28:10.390] And then the JWS encoded, which is... [28:10.390 --> 28:14.590] I don't know exactly how it's different than Base64, but it's that same type of thing. [28:16.370 --> 28:20.210] And then they decode numerically, which we're not going to dwell on. [28:20.490 --> 28:25.490] They decode the compact JWS, but it's compact, so it's not well presented. [28:25.710 --> 28:30.330] And then they just do a nice little unrolling down here, which we'll look at together. [28:31.130 --> 28:35.210] One thing here, part of the payload, is a public key URL. [28:35.810 --> 28:37.110] So this is... [28:37.110 --> 28:38.290] A lot of you have seen this. [28:38.410 --> 28:45.290] If you're in the technology world, it's a pretty common approach for validating that the issuer is legit. [28:45.290 --> 28:56.090] So you have a sort of a standard of saying it's a domain slash well-known slash something. [28:56.090 --> 29:02.250] You know, and it's a JSON file, so all you're doing is going on the public web with HTTPS to a site. [29:02.470 --> 29:04.830] And what this is is a public key, right? [29:04.890 --> 29:05.890] With a little bit of extra stuff. [29:05.930 --> 29:07.150] I don't think I... [29:07.150 --> 29:09.130] I might have a slide that shows a little bit of that. [29:09.190 --> 29:10.230] I'm not going to dwell on that too much. [29:10.270 --> 29:13.550] It's just a JSON that has a public key and a little bit of additional information. [29:13.890 --> 29:14.990] So that's part of the payload. [29:15.450 --> 29:17.090] And you scroll down. [29:18.910 --> 29:20.170] And, yeah, actually, I'm sorry. [29:20.230 --> 29:21.650] This is actually what I just talked about. [29:21.710 --> 29:23.490] This is the public key itself. [29:25.170 --> 29:28.050] Plus, as I said there, a little bit of additional information about it. [29:28.190 --> 29:29.610] The format and whatnot. [29:30.010 --> 29:31.230] The standard that they're using. [29:33.590 --> 29:35.050] And then keep going. [29:35.210 --> 29:35.910] Verify signature. [29:36.150 --> 29:36.330] True. [29:36.630 --> 29:36.730] Right? [29:36.890 --> 29:37.910] So, again, you could test this. [29:37.990 --> 29:38.810] You could change a bit. [29:39.290 --> 29:40.530] Make a new QR code. [29:40.670 --> 29:42.250] It's pretty easy to generate a QR code. [29:42.430 --> 29:43.590] A lot of software that can do that. [29:43.730 --> 29:45.650] And then you can demonstrate that it says false. [29:45.890 --> 29:46.090] Right? [29:46.150 --> 29:48.330] Which is what you want to happen if you tamper with it. [29:48.450 --> 29:52.850] And then here, it's sort of long because they unpacked it before it was compact. [29:53.410 --> 29:53.810] Presentation. [29:53.950 --> 29:55.530] Here, they've nicely formatted it. [29:55.630 --> 29:57.970] And so you can see that this is just the... [29:57.970 --> 30:01.050] More or less just what's on the PVC document itself. [30:02.070 --> 30:05.210] Except that it has a little bit more detail about the vaccination. [30:05.430 --> 30:07.550] I can't remember exactly what it is right now, actually. [30:07.670 --> 30:10.670] But there's a tiny bit more information. [30:10.870 --> 30:11.170] I think... [30:11.170 --> 30:13.270] Well, it has the validity, which is not part of the printout. [30:13.270 --> 30:19.170] But it's more or less the same as the human readable payload. [30:19.370 --> 30:27.870] Except that it has this cool public key ability to do the anti-fraud, anti-tampering. [30:28.970 --> 30:29.410] Okay. [30:29.710 --> 30:30.910] So that was a nice little demo. [30:31.170 --> 30:31.710] Very good. [30:32.030 --> 30:34.530] And we'll talk about the standard a little bit. [30:34.630 --> 30:36.230] In other words, what you saw just now. [30:36.230 --> 30:39.670] And then we'll also talk about the apps to verify these things. [30:39.970 --> 30:45.710] So, as we said, the JSON payload, the QR code has all the printed information. [30:45.710 --> 30:46.230] A little more. [30:46.350 --> 30:46.910] I've said that already. [30:47.430 --> 30:49.210] The embedded public key signature. [30:49.470 --> 30:50.170] I've said that already. [30:50.290 --> 30:53.690] We showed you where the public key is. [30:53.790 --> 30:57.990] And so the document doesn't need to store the public key or shouldn't store the public key. [30:57.990 --> 30:58.310] Why? [30:58.510 --> 31:07.830] Because if you put the public key in the document, then in order to commit fraud, all you have to do is put your own public key in the document. [31:08.010 --> 31:08.150] Right? [31:08.250 --> 31:11.390] So that it doesn't work to have the public key be part of the document itself. [31:11.390 --> 31:12.330] It has to be remote. [31:12.510 --> 31:16.390] And we'll talk about how the apps handle that in a fascinating way momentarily. [31:17.110 --> 31:17.550] Yeah. [31:17.650 --> 31:18.370] And it's standard. [31:18.570 --> 31:22.730] The smart health card is a, like I said before, a de facto standard. [31:22.730 --> 31:28.070] This we actually already talked about and I showed you the different places that have adopted it. [31:28.930 --> 31:30.230] Just a couple of other countries. [31:30.390 --> 31:34.790] As I said, Europe is doing the exact same thing, but they chose a somewhat different standard. [31:34.890 --> 31:37.150] Just like for electricity and some other stuff. [31:37.950 --> 31:39.090] Let's talk about apps. [31:39.550 --> 31:47.990] So, in New York, you have the Excelsior app, which is where your PVC lives. [31:48.130 --> 31:49.670] Your proof of vaccination credential lives. [31:49.670 --> 31:50.170] Right? [31:50.210 --> 31:53.130] As I said, I don't know if you get a paper one like that or not, actually. [31:53.270 --> 31:59.450] But the app itself has a QR code and it has a little bit of additional information, very similar to what I'm showing you on paper. [32:00.270 --> 32:02.610] And by the way, this paper you can also get as a PDF. [32:02.650 --> 32:05.690] It's not like you only get a piece of paper. [32:05.810 --> 32:07.390] You know, you get a digital thing and you can print it. [32:09.250 --> 32:19.550] So, in New York, though, if you're, say, a business and you want to validate a bunch of people's PVCs because they're coming into your store, they're coming into your bar, they're getting on your plane, something like that. [32:19.770 --> 32:21.530] You need an app to read these things. [32:21.750 --> 32:26.670] So, we're not going to talk about the Excelsior app for displaying them. [32:26.850 --> 32:29.270] But we'll talk about, in New York, I think it's called... [32:29.270 --> 32:30.450] Oh, now I forgot. [32:30.730 --> 32:32.810] It's the Excelsior something else app. [32:33.110 --> 32:38.770] The Excelsior app that, like I said, a bar or something that needs to demonstrate proof of acts would use. [32:38.770 --> 32:43.830] So, these apps, you want to be privacy-preserving, which means that they're not recording. [32:44.070 --> 32:44.190] Right? [32:44.370 --> 32:50.170] And that's surprisingly easy to get the Android Store and Google App Store to verify. [32:50.170 --> 32:51.490] They actually look at your code. [32:51.610 --> 32:55.270] And if you say it doesn't record anything, they will know if it does. [32:55.470 --> 32:55.750] Right? [32:55.810 --> 32:56.550] So, that's actually cool. [32:56.650 --> 33:03.390] In other words, if it's in the official store for Android or Apple, then if you say it can't record, then it can't record. [33:03.390 --> 33:15.650] So, you know, essentially no access to local storage, only the access determined for the camera and, you know, limited use of the Internet, all these types of things. [33:16.310 --> 33:17.370] So, it's not recording. [33:18.390 --> 33:20.870] You also want it to be policy-enforcing. [33:20.890 --> 33:21.790] And this is the trick. [33:21.790 --> 33:24.750] And I'm not going to dwell on this a lot, but it's really an important concept. [33:24.990 --> 33:27.530] And I'll describe it in the Canadian context. [33:27.630 --> 33:28.770] And I'll describe it in the U.S. context. [33:29.070 --> 33:48.790] So, if you're a bar owner in New York and you are required, and we know you're not anymore, but when you are required to get proof of vaccination for people going into that bar or restaurant or supermarket or something like that, there's not a uniform universal policy on what a fully vaccinated person is. [33:49.070 --> 33:49.490] Right? [33:49.610 --> 33:58.670] So, if you're... and that's not only just the case between countries, because they have some differences between countries, but even across states, they had different laws. [33:58.670 --> 33:59.810] And we lived through this, right? [33:59.890 --> 34:02.170] They weren't that different, but there were some differences. [34:02.630 --> 34:08.330] And that also includes... we're not going to dwell a lot, but that also includes various exemptions or deferrals. [34:08.530 --> 34:26.550] So, if someone got a note from their doctor that says they cannot be vaccinated, then in some places you can get a PVC issued and it's supposed to flash green or, you know, come up as being affirmative as someone that meets the requirements of that jurisdiction. [34:26.550 --> 34:36.910] But you bring that to another jurisdiction, maybe they don't have exemptions, or maybe your medical exemption is different from the list of medical exemptions permitted in the jurisdiction. [34:36.910 --> 34:38.550] And we saw this all the time in Canada. [34:38.690 --> 34:42.250] Quebec had, I think, 17 medical exemptions. [34:42.770 --> 34:44.830] Yukon had six, for example. [34:45.250 --> 34:45.430] Right? [34:45.590 --> 34:48.190] And so, what that means is that exemptions were tricky. [34:48.290 --> 34:49.690] I'm not going to dwell on that anymore, though. [34:49.690 --> 34:55.630] But the fact is that the policy would differ even for people that got the vaccination and also would evolve over time. [34:55.790 --> 34:59.390] So, you have the World Health Organization that would authorize vaccinations. [34:59.390 --> 35:04.270] So, for example, the India or the Sinovacs, the China one, they would come up with a vaccine. [35:04.730 --> 35:10.290] WHO would say, yes, we've confirmed this is a good vaccine against COVID-19. [35:10.290 --> 35:18.270] And therefore, as long as you have two shots 28 days apart or, you know, something similar, then you should be considered vaccinated. [35:18.510 --> 35:21.970] But the FDA might take a little while to confirm that. [35:22.130 --> 35:31.050] And so, there would be a period where a valid vaccine from, you know, whatever, China, India, Europe, or even Canada is valid in that place, but not valid someplace else. [35:31.210 --> 35:37.690] And in the U.S., of course, a lot of this was actually at the state level rather than being at the federal level. [35:38.430 --> 35:40.670] So, anyway, policy enforcing is important. [35:40.830 --> 35:55.730] And what that means, because of the policy enforcement, is that you have to, you would have to have an app for every jurisdiction, whether it's a state or even a municipality, I suppose, that has its policy. [35:57.570 --> 36:00.430] So, last thing to mention is independently operating. [36:00.570 --> 36:01.690] I alluded to this before. [36:01.810 --> 36:03.470] You don't want to have an app that has to be on the Internet. [36:03.470 --> 36:05.350] You're not going to have a centralized database. [36:06.610 --> 36:11.550] Your app should be able to resist fraud, even if it has no network connection. [36:11.730 --> 36:15.250] And as I showed you before, the hash does that, right? [36:15.450 --> 36:16.510] It's tamper evidence. [36:16.910 --> 36:20.790] And then the public key, you need to demonstrate the validity. [36:21.030 --> 36:23.030] And so, you say, okay, what do you do about that, newbie? [36:23.170 --> 36:26.590] How do you, you know, how do you do that if your app is offline? [36:26.590 --> 36:28.150] And the answer is caching. [36:28.410 --> 36:35.830] So, periodically, what will happen is your app from a given jurisdiction will have a list internally in another one of these JSON files. [36:35.870 --> 36:41.790] And it will go and refresh the list of what the public keys are. [36:41.830 --> 36:44.170] And it will cache them locally on the app. [36:44.170 --> 36:51.330] So, the app can actually verify a public key signature as long as the, you know, signature hasn't... [36:51.330 --> 36:54.130] The public key hasn't been changed or revoked or something since then. [36:54.290 --> 36:55.610] But they can do that offline. [36:55.750 --> 36:56.550] So, that was a requirement. [36:57.350 --> 36:58.550] There's a reference app. [36:58.730 --> 36:59.630] We won't talk about that. [37:00.070 --> 37:01.370] Let me show you how it works. [37:01.670 --> 37:03.810] As I said, in Canada, each... [37:03.810 --> 37:06.530] Literally, each of the 13 provinces and territories made their own. [37:06.710 --> 37:09.690] In the U.S., I don't know how many made their own app. [37:09.690 --> 37:12.970] I'm not sure that all of them did, even though they were using the same standard. [37:13.090 --> 37:14.410] That doesn't mean they had to make an app. [37:14.810 --> 37:22.070] But certainly, there were a number of different apps going around, including the one I mentioned in New York, the Excelsior app. [37:22.390 --> 37:25.570] So, here, I have the Android version. [37:26.090 --> 37:29.010] This is a Yukon vaccination validator. [37:31.230 --> 37:32.790] And there's not much to see here. [37:32.890 --> 37:34.790] But it's just an app that uses your camera. [37:34.950 --> 37:36.310] I didn't initialize it just now. [37:36.310 --> 37:37.110] I already had it running. [37:37.250 --> 37:39.290] But when you first fire it up, it says a regular thing. [37:39.290 --> 37:40.130] Can you use your camera? [37:40.430 --> 37:43.030] It's Canada, so it lets you select English or French. [37:43.310 --> 37:47.670] And then all you got to do is point it at your document, your QR code, and press the button. [37:47.870 --> 37:48.890] So, I'll do that now. [37:49.070 --> 37:50.090] So, what you see... [37:50.090 --> 37:50.490] I don't know if... [37:50.490 --> 37:51.770] You probably won't be able to see too well. [37:51.990 --> 37:53.650] But the camera is just in the middle. [37:53.830 --> 37:55.570] The camera is just showing whatever it's looking at. [37:55.810 --> 37:56.910] So, I'll have to... [37:56.910 --> 37:58.070] I have to look at it. [37:58.130 --> 38:01.170] So, I can't do it quite facing you. [38:01.170 --> 38:04.170] I don't know, but nothing up my sleeves. [38:07.010 --> 38:07.530] See? [38:07.710 --> 38:08.130] There it goes. [38:08.650 --> 38:09.350] Meets requirements. [38:10.350 --> 38:11.290] Thank you very much. [38:11.790 --> 38:16.650] So, that concludes the live demo portion of our day here. [38:16.790 --> 38:24.910] So, that flashed up green, which meant that whatever is on my PVC meets the jurisdictional requirements of wherever the app came from. [38:24.910 --> 38:32.710] And the app is periodically, when it runs, it's going to go and check and get the latest version of whatever that policy is. [38:32.850 --> 38:34.270] So, the policy is... [38:34.270 --> 38:35.590] And there's no standard for this. [38:35.670 --> 38:36.910] It's unique to the app. [38:37.030 --> 38:42.150] But the policy is basically another JSON file that says, here's a list of vaccinations. [38:42.570 --> 38:44.750] Here's a list of time between vaccinations. [38:44.990 --> 38:49.710] In some provinces or territories, it might say, here are the types of codes for things like medical exemptions. [38:51.390 --> 38:56.910] And then the app says, okay, whatever I read either meets that policy or does not meet that policy. [38:56.910 --> 38:58.430] And it shows up green or red. [38:58.690 --> 39:02.410] And when we first started doing this, we also had, I think, an orange or something like that. [39:02.490 --> 39:04.910] Because there was a situation where you might have... [39:04.910 --> 39:06.650] If you might recall, there's a... [39:07.090 --> 39:08.270] I'm sure you do recall. [39:08.790 --> 39:11.210] There was a time when one vaccine was enough. [39:11.650 --> 39:15.350] And then, you know, because you had to allow time between, and then they wanted to have two. [39:15.350 --> 39:16.250] Right? [39:16.430 --> 39:18.970] So that's a period where maybe you'd flash green because you had... [39:18.970 --> 39:22.490] Flash green if you had two, but flash orange if you only had one. [39:22.850 --> 39:23.070] Right? [39:23.130 --> 39:24.110] So partially vaccinated. [39:24.650 --> 39:24.910] All right. [39:24.950 --> 39:26.310] We're just about done here. [39:26.450 --> 39:29.150] So there's a screenshot in case my demo didn't work. [39:29.750 --> 39:30.950] And why Yukon? [39:31.050 --> 39:35.350] Because most of the provinces and territories have now shut off their validator. [39:36.170 --> 39:38.390] Because, you know, these aren't required anymore in most situations. [39:39.150 --> 39:46.090] Interestingly, though, they're preparing for a fall surge and saying, oh, maybe we're going to be doing a booster campaign. [39:46.090 --> 39:47.890] Or maybe there'll be more requirements for this. [39:49.810 --> 39:50.030] Okay. [39:50.330 --> 39:55.030] Within the app, and I have just a couple of little screenshots of this, but there's a public key I've mentioned, which is cache. [39:55.490 --> 39:55.850] There's... [39:55.850 --> 39:56.250] I didn't... [39:56.250 --> 39:57.750] I'm not going to talk about replication lists. [39:57.850 --> 40:02.290] But if you know about PKI and other sorts of situations, you know, you have to have a replication list. [40:02.290 --> 40:14.250] So if the key becomes compromised, or even, say, a batch of PVCs becomes compromised, maybe an individual PVC becomes compromised, or was false, you know, was fraudulently issued, you want to have a replication list. [40:14.350 --> 40:15.070] We won't dwell on that. [40:15.250 --> 40:22.530] The policy that I talked about just now, and as I said, we need to have these work online, and maybe periodically go there. [40:22.690 --> 40:27.430] And this is just a little example of an issuer. [40:27.710 --> 40:29.190] So who issued this thing? [40:29.190 --> 40:35.990] And this normally would be a list, but for, like, demo application purposes, there might just be one, so you can test it out. [40:36.570 --> 40:39.310] This we saw momentarily before. [40:39.630 --> 40:43.330] This is the public key field, which is... [40:43.330 --> 40:48.270] I think it's truncated here, but we saw that also in the verifier decoder. [40:48.990 --> 40:50.790] And that's what I wanted to talk about. [40:50.910 --> 40:54.270] So what we've seen here is that we have a de facto standard. [40:54.270 --> 41:01.390] We're leveraging a lot of free software and certainly a lot of open standards with public key infrastructure. [41:01.790 --> 41:03.950] And we had a lot of collaboration in Canada. [41:04.670 --> 41:09.670] U.S. collaboration, you know, as you know, not so good on a variety of things. [41:09.890 --> 41:15.470] And so even though the states were individually choosing the same standard, there wasn't a national-level collaboration. [41:15.910 --> 41:18.290] And there was probably a lot of, like, state-to-state collaboration. [41:18.290 --> 41:23.130] You have, you know, the organizations like CVS, Walmart making similar decisions. [41:23.290 --> 41:26.310] But nothing that was federally orchestrated. [41:26.930 --> 41:27.870] The U.S. really opted out of that. [41:28.170 --> 41:29.490] Trump opted out really clearly. [41:29.650 --> 41:33.350] And then Biden continued to opt out of forcing a federal standard. [41:33.630 --> 41:40.570] But the outcome, though, is because we're all using SHC, the smart health card standard, is essentially interoperability. [41:40.730 --> 41:44.270] And so in Canada, for example, they have something called the Arrive Can app. [41:44.270 --> 41:46.450] You can show up with a PVC from anywhere. [41:46.450 --> 41:48.590] You can show up with one from the U.S. [41:48.810 --> 41:50.010] And they'll scan it. [41:50.110 --> 41:54.150] And they'll be able to parse it and apply their policy and determine whether you're fully vaccinated. [41:54.670 --> 42:01.970] In their case, at a federal border protection level case, they also can read standards that are different standards, you know, from Europe and elsewhere. [42:02.830 --> 42:04.070] So this worked pretty well. [42:04.470 --> 42:08.430] The global pandemic made things happen a lot quicker than they probably would have. [42:08.710 --> 42:11.510] And the privacy by design, I think, was really key. [42:11.570 --> 42:13.350] And we've talked about that quite a lot. [42:13.350 --> 42:21.830] And as I said, if you're in the room with, you know, government employees, health professionals, privacy is really top of mind. [42:21.830 --> 42:26.630] And I realize that's not obvious, you know, without being part of it. [42:26.690 --> 42:28.350] But I can report that's the case. [42:29.290 --> 42:33.550] So we do have a short-term solution, but also we have sort of longer-term prospect. [42:33.550 --> 42:36.150] We didn't need blockchain. [42:37.650 --> 42:42.250] It's interoperable, works offline, is privacy-preserving, is self-sovereign. [42:42.350 --> 42:43.670] So there's a lot of good things about this. [42:43.730 --> 42:45.250] And that's part of why I wanted to talk about it. [42:45.490 --> 42:51.090] So we're probably almost at the end of my time, but I'd be happy to entertain a couple of questions before we wrap up. [42:51.090 --> 42:53.590] This is my email, my name. [42:53.810 --> 42:56.370] I'm gbnewby at petascale.org. [42:56.550 --> 42:59.390] Happy to correspond, send out the slides, anything like that. [43:07.820 --> 43:09.960] Please feel free to walk up to the mic for questions. [43:10.200 --> 43:12.570] I'd like to start with one from the Matrix chat. [43:13.320 --> 43:17.050] You did mention that there was a possibility for key revocation in this. [43:17.340 --> 43:20.800] But do the public keys and certificates themselves expire? [43:20.800 --> 43:24.260] And what happens to old credentials once that happens? [43:24.500 --> 43:24.680] Right. [43:25.110 --> 43:30.550] So the recommendation that accompanies this de facto standard is that you make a new signing key every year. [43:30.590 --> 43:38.320] And that's just generally good practice, because the signing key more or less is a password plus, you know, an algorithm that makes the key pair, the public and the private key. [43:38.680 --> 43:41.960] So the recommendation is make a new one every once in a while. [43:42.200 --> 43:51.260] But the certificates themselves, we decided in Canada that they wouldn't expire because they're a point-in-time document. [43:51.420 --> 43:55.400] In other words, yeah, you got these vaccinations, and that's true always. [43:55.680 --> 44:02.400] The only thing that might change, as I mentioned, relevant to a revocation list is if one of those vaccines turned out to be bad, you know, a bad lot, something like that. [44:03.400 --> 44:12.200] Or if, and this happens a lot in Canada, it happened a lot in Ontario in particular, maybe the record, maybe the source of truth was false. [44:12.200 --> 44:24.800] So yeah, so a revocation list is going to be for either a unique ID associated with a PVC document itself, or it's going to be for a whole key, and that hasn't happened in Canada. [44:24.960 --> 44:31.700] I don't know if it's happened in the U.S., but if your private key is compromised, then your public key is suddenly no good anymore. [44:31.700 --> 44:35.840] So you can actually revoke huge swaths of these things, which would be a big inconvenience. [44:35.840 --> 44:42.740] So that's kind of the story on revocation list, at the individual item level, at the key item level. [44:43.900 --> 44:45.540] And you can also have groups. [44:45.660 --> 44:49.660] You can also have vaccine lots, things like that. [44:49.780 --> 44:54.780] And this actually, this was an extension to the SHC standard that Canada did. [44:55.580 --> 44:56.360] Yeah, it's in there. [44:56.440 --> 44:57.460] It's in the, I just saw it before. [44:57.580 --> 44:58.660] It's in the technical documentation. [44:59.100 --> 45:03.140] But the revocation list was not part of the SHC like a year ago. [45:03.280 --> 45:04.240] It got added recently. [45:04.860 --> 45:05.680] There's a question there. [45:06.180 --> 45:10.260] That mostly answers what I was thinking of, like an example of bad lots. [45:10.360 --> 45:14.600] In this case, you're saying the validator app would just flash red saying it's no longer a valid vaccination, right? [45:15.120 --> 45:15.280] Yeah. [45:15.440 --> 45:19.270] Well, I mean, so the app is not telling you about a particular shot. [45:20.040 --> 45:22.960] So you might have, and it's interesting because they're corner cases. [45:23.340 --> 45:27.160] Let's say you got a shot and then the hospital called and says, oh, it was a bad batch. [45:27.200 --> 45:28.280] You have to come get another shot. [45:28.660 --> 45:33.820] Your record might actually show the bad one and say two good ones, and then you meet requirements. [45:33.820 --> 45:38.020] But if it shows a bad one and nothing else, then maybe you don't meet requirements. [45:38.360 --> 45:47.500] So the fact of it being invalid, you know, more or less means that the app is going to ignore it for your, you know, for your status being green or red or something else. [45:48.900 --> 45:48.940] So. [45:49.960 --> 45:50.800] Thanks for your talk. [45:51.280 --> 45:51.600] Yeah, thanks. [45:51.600 --> 45:55.320] Have you seen malicious keys out in the wild? [45:55.520 --> 46:00.800] People trying to, you know, say, oh, yes, I am a legitimate government and just not me. [46:01.000 --> 46:03.440] No, these are, these are really fricking locked down. [46:03.580 --> 46:05.680] Maybe I should have made that, made that clearer. [46:05.680 --> 46:17.040] So the, and again, I don't know about the U.S. other than, I don't know about the standardization, centralization approach if it's outside of this context. [46:17.040 --> 46:18.920] But there's really two things that happen. [46:19.180 --> 46:27.780] One is the SHC people themselves, the Smart Health Card Standards, which is basically a consortium based out of Boston. [46:29.210 --> 46:30.940] They retain the canonical list. [46:31.500 --> 46:35.400] And to get on that list, it's a little like getting in the app store with a health app. [46:35.500 --> 46:37.060] You have to jump through a number of hoops. [46:37.240 --> 46:41.760] So they have a list that includes all those people I scrolled through before, all those places I scrolled through before. [46:42.560 --> 46:45.540] And their, their URLs, their issuer URLs. [46:45.820 --> 46:48.480] And when you go to that issuer URL, you get the list of keys. [46:48.720 --> 46:56.540] So the issuer stores the keys, but the list of valid issuers is stored in the Smart Health Card official repository. [46:56.540 --> 47:00.840] So yeah, that could get hacked, but, you know, it's centralized and it's highly protected. [47:00.880 --> 47:03.160] So, you know, some advantages there. [47:04.500 --> 47:09.420] In Canada, most of the provinces and territories opted to use a, just a Canadian list. [47:09.580 --> 47:20.040] So it's sort of the same thing, but rather than going to the whole Smart Health Card list of hundreds, they just had the Canadian list of about fewer than 20, 15 or so different issuers. [47:20.400 --> 47:27.380] So yeah, that's the solution to that, is that the list of those well-known locations where you go in to get the JSON is tightly controlled. [47:27.560 --> 47:37.440] So that's, and that's sort of a typical thing when you're trying to come up with a solution like this, is sooner or later you'll have a couple of single points of failure, and then you just protect the heck out of those. [47:38.420 --> 47:43.600] I do know someone who made a fraudulent one, but he got stopped by what you just described, that it won't scan correctly. [47:44.140 --> 47:44.700] Yeah, yeah. [47:44.800 --> 47:49.760] Yeah, and there's a certain, there's, I guess you'd call it bureaucracy or trust or validation or whatever it is. [47:49.760 --> 47:57.560] I mean, sooner or later you have to decide how you can determine whether you trust the issuer and you trust that you got a valid key from that issuer. [47:57.700 --> 48:03.460] Oh, and by the way, there's a little more to it, which is the JSON that lists the issuer keys is also signed. [48:03.600 --> 48:05.580] So you're trusting the source of that as well. [48:05.660 --> 48:06.900] So there's a couple different layers in there. [48:07.080 --> 48:07.840] It's reasonable. [48:08.080 --> 48:11.180] I was going to ask, what's the machinations? [48:11.180 --> 48:17.020] I assume, like, this can support multiple other diseases like yellow fever and the childhood stuff. [48:17.220 --> 48:17.240] Yeah. [48:17.240 --> 48:17.340] Yeah. [48:17.440 --> 48:19.640] Like, what's the progress on instrumenting those? [48:21.460 --> 48:22.440] I haven't seen it. [48:22.500 --> 48:27.820] Yeah, and that's what I mentioned in my last point there, that this seems like a sound basis for that type of thing. [48:28.540 --> 48:40.140] And the fact that we needed to come up with a standard for various, you know, basically because you're doing billions and billions and billions of these in all these different situations, you say, how can we do it efficiently, you know, anti-fraud and so forth. [48:40.960 --> 48:47.660] So the technology would certainly work for other types of vaccinations, but I don't know if there's the same will or imperative to do that. [48:47.880 --> 48:49.060] But it may be the case. [48:49.060 --> 48:52.560] And the smart health card standard can encode. [48:52.800 --> 48:54.120] It's not... it was invented. [48:54.120 --> 48:55.900] It was around before COVID came along. [48:55.920 --> 48:58.360] So it can encode your whole vaccination record. [48:58.500 --> 49:06.060] But sort of the rest of the stuff that I talked about, just like just now, the replication infrastructure, lists of issuer IDs, stuff like that, that's pretty unique to COVID. [49:06.420 --> 49:08.280] And I know I'm out of time, but thanks for your questions. [49:10.140 --> 49:10.640] All right. [49:11.320 --> 49:11.980] Appreciate it.