The Spanish government has a new objective: to prevent minors from accessing websites with pornographic content. The project follows the line of other previous efforts in the European Union, and it is extremely complex to make it effective.
Technical specificationsThe first challenge, the technical one, is simply colossal. The technical specifications for the age verification tool are available at the Ministry for Digital Transformation and Civil Service. The verification system follows the standards of the European Regulation on Electronic Identification and Trust Services for Electronic Transactions (eIDAS2).
Digital Wallet BetaThe age verification system will work through the Cartera Digital Beta mobile application, an electronic wallet that can also be used for other purposes such as requesting and submitting the census, checking the absence of a criminal record for sexual crimes, and also checking what university and non-university qualifications the user has.
Credential of age. The Digital Wallet Beta app “will securely store the adult identification card issued by the Government of Spain.” When accessing adult content platforms, a double authentication system will be used for two reasons. First, to prevent minors from accessing such content from their devices. And second, to prevent them from trying to do so through adult devices.
Anonymity and privacy. According to the specification for the use of the “Age of Majority” credential, the Government’s solution ensures the user’s anonymity during the process, “thus preventing the monitoring of the different operations that the user carries out with his or her wallet.” The credential “does not contain any type of information that can be linked to the user, except for a public key generated on the device itself.”
![Cartera3](https://i.blogs.es/3f3e79/cartera3/450_1000.jpeg)
![Cartera3](https://i.blogs.es/3f3e79/cartera3/450_1000.jpeg)
How the internal check will be carried outFor verification, the system will check the user’s age using the electronic ID, but other administrative records may also be used, such as the Cl@ve system (permanent, mobile, PIN) in which, of course, we must register beforehand. The process will consist of three main parts:
- Content Provider Validation: Before presenting the adult credential, the system verifies that the content provider (the platform with adult content) is a trustworthy entity. To do this, the white lists that the Government will configure are consulted, and in which each platform will be able to identify itself as a provider of such content.
- Credential Selection: From the batch of 30 credentials, the mobile app will assign a maximum of three to each content provider. These credentials will be used randomly within the same provider a maximum of 10 times, and never between multiple services. When 30 uses are made, 10 for each of the 3 credentials, another subset of 3 credentials will be selected from the batch of 30. A history of the use of these subsets of credentials is not kept.
- Presentation of evidence:The user will confirm the presentation of the credential and send it as “evidence” to the content provider using the OpenID4VP protocol.
![Screenshot 2024 07 02 at 10 57 35](https://i.blogs.es/cad020/captura-de-pantalla-2024-07-02-a-las-10.57.35/450_1000.jpeg)
![Screenshot 2024 07 02 at 10 57 35](https://i.blogs.es/cad020/captura-de-pantalla-2024-07-02-a-las-10.57.35/450_1000.jpeg)
Communication flow of the “actors” involved in the entire age verification process when accessing adult content. Source: Government of Spain.
But how will it work for the user? The process for the user will be more transparent and will resemble other verification processes used on web platforms. The process will be as follows:
- The user accesses an online platform with adult content
- The platform will ask you to prove that you are of legal age. To do so, it will display a QR code.
- The user will have to scan the QR code with their mobile phone, and this will launch the verification process through the Beta Digital Wallet.
- If the user has an adult credential, he or she will be able to access the content. Otherwise, the content will be blocked.
Credential packs. After successful verification, the user will be provided with a pack or batch of 30 anonymous credentials. Each of these credentials is a public/private key pair generated within the device. As mentioned, subsets of three credentials will be used that will be valid for the same content provider and will be valid for one month. This “subset” will not be reusable between several providers, which according to the specification reduces user traceability.
![Cartera4](https://i.blogs.es/477f0f/cartera4/450_1000.jpeg)
![Cartera4](https://i.blogs.es/477f0f/cartera4/450_1000.jpeg)
Running out of credentials? No problem. These batches of credentials can be renewed “if they have less than 3 days of validity left or if there are less than 10% of unused credentials.” If these conditions are met, it will be possible to make this renewal request, which will allow the user to have a new batch and, at the same time, the elimination of the credentials belonging to the old batch from the wallet to avoid the accumulation of unnecessary credentials.
Only for porn platforms hosted in Spain. The system will be limited to online adult content platforms that are hosted in Spain. Even so, the Government explains, the National Cybersecurity Institute (INCIBE) will manage “with the collaboration of other actors” a list of websites of this type not subject to Spanish jurisdiction “with the aim that browsers can verify the age of majority before presenting their content.”
Other platforms will be able to take advantage of the systemAs Carmen Cabanillas, Director General of Governance at the Ministry of Digital Transformation, explained, “if you are using Telegram and you are exchanging adult content, Telegram has the option to call our application and verify that you are of legal age before you broadcast or consume that content, it is voluntary.” Thus, the age of majority credential can be consulted by other platforms that implement this type of control.
Available in SeptemberAccording to the Minister for Digital Transformation and Public Service, José Luis Escrivá, the development and testing phase will last for about two months. The Digital Wallet beta is expected to be available at the end of summer, in September.
At WorldOfSoftware | What we know about ‘internet porn’ and its influence on the sexuality of men and women