A personal identity authenticating system where the registrant/cardholder
and the registrar are assigned specific identifiers and secret keys and
public keys that are mapped to the identifiers at the authentication
support station (ASS). Personal identity to which the registrar
identifier is attached is encrypted wit the registrant/cardholder's
secret key. Personal identity data is embedded as an encrypted watermark
image data by means of the registrar's secret key. Both encrypted
identity and watermarked image data are recorded on the IC card. When
authentication is required, the identity data with the registrar
identifier is decrypted with the cardholder's public key that is supplied
by the ASS. The registrar's public key is obtained from the ASS by using
the decrypted registrar identifier. The registrar's public key permits
the personal identity to be retrieved from the watermarked image data.
Internal authentication is executed by matching between personal identity
strings and image data.