Revised Laws of Identity
Copyright 123RF

Revised Laws of Identity

This article is my homage to Kim Cameron. He was a visionary identity thought leader in the 90's and 2000's creating the "Laws of Identity" who sadly recently died. However, since he created the laws, over the last two decades, much has changed in the identity world including:

Here's my main point - legal identity is different than that of "identity". A legal identity must have the ability, in a court of law, to legally differentiate that it’s Jane Doe 1 who’s involved, and not Malicious Sally who’s masquerading as her, nor it’s not Jane Doe 2,3,4.5 etc. who are DNA identical human clones of Jane Doe 1.

Thus, in homage to Kim, I believe the laws of identity need to be updated.?So, I’ve sat down and created 18 principles covering identity.?It’s out of the box thinking, for out of the box times.?

Note: At the end of the principles, I have referenced different architecture, cost and problem docs laying it all out. Since I'm very passionate about learning, you'll see me leveraging the rethought human and AI system/bot legal identities to rethink learning.

Principle 1

A human and/or AI system and bots can have multiple identities.?

Principle 2

From birth on, a human can only have one legal physical identity and at least one legal digital identity. Multiple digital legal identities are possible.?

Principle 3

A human’s legal physical identity MUST be biometrically tied to their legal identity registration using forensic biometrics (which are not able to profile a person like DNA) e.g., fingerprints and iris.

Principle 4

A person’s biometrics used in legal identity SHOULD be revocable and re-issuable.

Principle 5

A human legal identity MUST use forensic biometrics able to legally and scientifically differentiate human clones e.g., Jane Doe 1,2,3,4,5 etc.

Principle 6

The authoritative sources for a human’s legal identity i.e., the CRVS (civil registration vital statistics) system, MUST be to global data standards and able to be queried to confirm a person’s legal identity.

Principle 7

A person’s death, after confirmation by the local coroner, should result in death notifications being digitally sent out to either registered parties or, to a global notification system.

Principle 8

The legal identity of each person MUST be in control by them e.g.,

  • SOLICT (Source of Legal identity & Credential Truth) which in turn feeds
  • LSSI (Legal Self-Sovereign Identity) devices (e.g., different types of LSSI devices; physical id card, digital legal app, biometrically tied physical wristband or chips inserted into people).?
  • These MUST be able to mitigate the risks of digital death, and/or a malicious state deleting their legal identity from all its databases

Principle 9

A person must be able to provide claims about their legal identity, biometric, behavioral and neuro-data, from their SOLICT/LSSI devices, which are digitally signed by an authority.?The person should be able to choose which portions of the above to produce in a claim.

Principle 10

A person, or a bot, MUST have the ability to prove portions of their legal identity and some types of credentials anonymously (e.g., above or below age of consent, human or bot, Covid vaccinations, etc.), either physically or digitally.

Principle 11

Not all digital identities require legal identity registration. However, where risk requires it, a person’s smart digital identities of them MUST be legally registered and tied to the underlying legal physical identity of the person.

Principle 12

All consents given by a person, from cradle to grave, MUST be recorded in their SOLICT, which they control.?This gives the person the ability to later go back, determine which consents they gave and, if local laws apply, request removal from the databases.

Principle 13

A person/bot should have a PIAM (Personal Identity Access Management) system able to create legal consent agreements on the fly, between the person/bot and other third parties.

Principle 14

Depending on risk, different levels of informed consent for releasing portions of a person’s legal identity, biometric, behavioral and neuro-data should be used.

Principle 15

An AI system/bot legal identity must be able to be created, checked, and verified instantaneously on the planet i.e., it requires a global legal framework locally managed.

Principle 16

To mitigate the risk caused by this curve - https://hvl.net/pdf/PatScannellHockeyStickShapedCurve.pdf, the legal identity framework (i.e., governance, business processes, tech infrastructure and end users), must be continually threat assessed, by a global, independent, non-profit, The non-profit will continuously issue threat assessments which, depending on severity, MUST be responded to by all parties in a similar manner e.g., a very high risk MUST be responded to within hours.?This brings industry best practices to the world of legal identity.

Principle 17

The global, independent, non-profit MUST have mechanisms to prevent malicious parties from accessing or affecting their internal data.?As well, it must have governance mechanisms to in effect watch and check the non-profit i.e., watching the watchers.

Principle 18

A person MUST have the ability to live privately in a non-private world.?This requires laws and regulations requiring a person’s consent for their legal identity, biometric, behavioral and neuro-data to be used to identify them.?It also requires the technical infrastructure the laws above spell out i.e., SOLICT, LSSI Devices, PIAM that allow a person to control their legal identity and their forensic biometrics.

About Guy Huntington

I'm an identity trailblazing problem solver. My past clients include Boeing, Capital One and the Government of Alberta's Digital Citizen Identity & Authentication project. Many of my past projects were leading edge at the time in the identity/security space. I've spent the last eight years working my way through creating a new legal identity architecture and leveraging this to then rethink learning.

I've also done a lot in education as a volunteer over my lifetime.?This included chairing my school district's technology committee in the 90's - which resulted in wiring most of the schools with optic fiber, behind building a technology leveraged school, and past president of Skills Canada BC and Skills Canada.

I do short term consulting for Boards, C-suites and Governments, assisting them in readying themselves for the arrival of AI systems, bots and AI leveraged, smart digital identities of humans.

I've written LOTS about the change coming. Skim the?over 100 LinkedIn articles?I've written,?or my webpage?with lots of papers.

Quotes I REALLY LIKE!!!!!!:

  • We cannot solve our problems with the same thinking we used when we created them” – Albert Einstein
  • “Change is hard at first, messy in the middle and gorgeous at the end.” – Robin Sharma
  • “Change is the law of life. And those who look only to the past or present are certain to miss the future” – John F. Kennedy

Reference Links:

An Identity Day in The Life:

My Message To Government & Industry Leaders:

National Security:

Rethinking Legal Identity, Credentials & Learning:

Learning Vision:

Creativity:

AI Agents:

Architecture:

AI/Human Legal Identity/Learning Cost References

AI Leveraged, Smart Digital Identities of Humans:

CISO's:

Companies, C-Suites and Boards:

Legal Identity & TODA:

Enterprise Articles:

Rethinking Enterprise Architecture In The Age of AI:

LLC's & AI:

Challenges With AI:

New Security Model:

DAO:

Kids:

Sex:

Schools:

Biometrics:

Legal Identity:

Identity, Death, Laws & Processes:

Open Source:

Notaries:

Climate Change, Migration & Legal Identity:

"Human Migration, Physical and Digital Legal Identity - A Thought Paper

Fraud/Crime:

Behavioral Marketing:

AI Systems and Bots:

Contract Law:

Insurance:

Health:

AI/AR/VR Metaverse Type Environments:

SOLICT:

EMP/HEMP Data Centre Protection:

Climate:

A 100,000-Foot Level Summary Of Legal Human Identity

  • Each person when they’re born has their legal identity data plus their forensic biometrics (fingerprints, and later when they can keep their eyes open – their iris) entered into a new age CRVS system (Civil Registration Vital Statistics - birth, name/gender change, marriage/divorce and death registry) with data standards
  • The CRVS writes to an external database, per single person, the identity data plus their forensic biometrics called a SOLICT “Source of Legal Identity & Credential Truth).?The person now controls this
  • As well, the CRVS also writes to the SOLICT legal identity relationships e.g. child/parent, cryptographically linking the SOLICTs.?So Jane Doe and her son John will have cryptographic digitally signed links showing their parent/child.?The same methodology can be used for power of attorney/person, executor of estate/deceased, etc.
  • The SOLICT in turn then pushes out the information to four different types of LSSI Devices “Legal Self-Sovereign Identity”; physical ID card, digital legal identity app, biometrically tied physical wristband containing identity information or a chip inserted into each person
  • The person is now able, with their consent, to release legal identity information about themselves.?This ranges from being able to legally, anonymously prove they’re a human (and not a bot), above or below age of consent, Covid vaccinated, etc.?It also means they can, at their discretion, release portions of their identity like gender, first name, legal name, address, etc.
  • NOTE: All consents granted by the person are stored in their SOLICT
  • Consent management for each person will be managed by their PIAM “Personal Identity Access Management) system.?This is AI leveraged, allowing the person, at their discretion, to automatically create consent legal agreements on the fly
  • It works both locally and globally, physically and digitally anywhere on the planet
  • AI systems/bots are also registered, where risk requires it, in the new age CRVS system
  • Governance and continual threat assessment, is done by a new, global, independent, non-profit funded by a very small charge per CRVS event to a jurisdiction to a maximum yearly amount.

A 100,000-Foot Level Summary Of The Learning Vision:

  • When the learner is a toddler, with their parents’ consent, they’ll be assessed by a physical bot for their learning abilities.?This will include sight, sound, hearing and smell, as well as hand-eye coordination, how they work or don’t work with others, learning abilities, all leveraging biometric and behavioral data
  • All consents given on behalf of the learner or, later in the learner’s life by the learner themselves, are stored in the learner’s SOLICT “Source of Legal Identity & Credential Truth
  • This is fed into a DLT “Digital Learning Twin”, which is created and legally bound to the learner
  • The DLT the produces its first IEP “Individualized Education Plan”, for the learner
  • The parents take home with them a learning assistant bot to assist the learner, each day, in learning.?The bot updates the DLT, which in turn continually refines the learner’s IEP
  • All learning data from the learner is stored in their LDV “Learner Data Vault”
  • When the learner’s first day of school comes, the parents prove the learner and their identities and legal relationship with the learner, via their LSSI devices (Legal Self-Sovereign Identity)
  • With their consent, they approve how the learner’s identity information will be used not only within the school, but also in AI/AR/VR learning environments
  • As well, the parents give their consent for the learner’s DLT, IEP and learning assistant bot to be used, via their PIAM (Personal Identity Access Management) and the learner’s PIAM
  • The schools LMS “Learning Management System” instantly takes the legal consent agreements, plus the learner’s identity and learning information, and integrates this with the school’s learning systems
  • From the first day, each learner is delivered a customized learning program, continually updated by both human and AI system/bot learning specialists, as well as sensors, learning assessments, etc.
  • All learner data collected in the school, is stored in the learner’s LDV
  • If the learner enters any AI/AR/VR type learning environment, consent agreements are created instantly on the fly with the learner, school, school districts, learning specialists, etc.?
  • These specify how the learner will be identified, learning data use, storage, deletion, etc.
  • When the learner acquires learning credentials, these are digitally signed by the authoritative learning authority, and written to the learner’s SOLICT.
  • The SOLICT in turn pushes these out to the learner’s LSSI devices
  • The learner is now in control of their learning credentials
  • When the learner graduates, they’ll be able, with their consent, to offer use of their DLT, IEP and LDV to employers, post-secondary, etc.?This significantly reduces time and costs to train or help the learner learn
  • The learner continually leverages their DLT/IEP/LDV until their die i.e., it’s a lifelong learning system
  • IT’S TRANSFORMATIONAL OVER TIME, NOT OVERNIGHT

?

?



要查看或添加评论,请登录

社区洞察

其他会员也浏览了