Tap and Prove
Identiverse 2021 SWILSON Why Isnt Identity Easy (1.1.1) HANDOUTS

Tap and Prove

We should be able to “tap and prove” any important fact and figures about ourselves – as easily as we tap and pay with a mobile phone at any one of 100s of millions of terminals globally.?

And I mean exactly as easily.?With the same security, privacy and speed.?With the very same gadgets.?

We should be able to move verified copies of our personal information around the data economy as safely as we move our money.?

Look at the innovation in mobile credentials. With our phones now we can carry and present secure copies (tokens) of payment accounts, boarding passes and even virtual hotel room keys.?

In digital life and work, we are constantly needing to show things about ourselves – typically discrete pieces of important data each in a particular context. Under the covers, transaction systems also consume special metadata used to prove the origin of the credential, the origin of each authorised transaction, consent of the user to the transaction, signs of compliance with conditions of use, regulatory commitments, and so on.?

If we generalise from credit cards ― leveraging the networks, terminals and smart data carriers, and the business arrangements of standardised contracts and service fees― we could build truly global infostructure for verifying everything we routinely need to prove about ourselves: professional memberships, trade licences, qualifications & grades, age, government IDs, other pieces of KYC, health IDs, medical data, vaccination records and so on.?

State governments in Australia are well advanced in digitising all manner of citizen credentials so they can be conveyed peer-to-peer from mobile phones.?The user experience is evolving from QR codes through to instantaneous radiofrequency interfaces (of exactly the same type used in mobile phone payment wallets). And this digitisation is taking place without changing any of the meaning or the rules around the credentials. There’s no fuss, and there’s little or no complication around “identity”.?The mission is simple: progressively digitise all the things we routinely need to know and show.?

Conceptually simple data wallets are leaving federated identity for dead.??While digital services have developed ever more rapidly, digital identity – which was supposed to be the essential underpinning – has laboured.?We made digital identity too hard by solving for the wrong problem.?Personal human identity is always going to be rich and relative and analogue, but the challenges in the digital domain are simpler, and boil down to truth in data.?We know how to solve for data reliability, by blending cryptography with established governance.?Look at how credit cards have evolved from paper through magnetic stripe to chip cards and mobile wallets.?They’re all just data carriers, each carrying exactly the same data, but modernised over time, with cryptography now built in to prove that data is true.??

The digital identity industry has arrived at cryptographically Verifiable Credentials.?This technology can be married to existing rules frameworks to create infostructure to verify any data anywhere across cyberspace and the digital economy. We’ve done it for credit cards; now let’s do it for data.?

This is an edited extract from my recent speech at the Identiverse 2021 conference "Why Isn’t Identity Easy?".

We seem to be on exactly the same page! Thanks for this great piece, we really respect your work.

I'm a little cautious about extrapolating from financial applications (where someone attacked can be made whole by reimbursement) to other applications where the harms might not be so easy to remedy. Some applications require strong assurance that the person doing the "tap" is in fact the subject of that information, to a greater extent than might be available from entering a PIN. We also need to be concerned about things like replay attacks, especially if something like a QR code is involved.

Baber Amin

Chief Product Officer at Anetac Inc. Senior Executive - Strategy, Product, GTM, CyberSecurity, Digital Experience & Identity. ? Entrepreneur, Investor, Advisor ? Enterprise Leadership ? Global Transformation

3 年

I like that Steve. Going to start using this phrase also :)

Curious to hear your take on the monetization model and how the identity exchange system will get bootstrapped.

回复
Drummond Reed

Director, Trust Services at Gen Digital

3 年

Steve, I think you are right on the money. "Tap and prove" has just entered my vocabulary.

要查看或添加评论,请登录

Stephen Wilson的更多文章

  • The digital wallet wars will not be over wallets

    The digital wallet wars will not be over wallets

    An edited version of my 2024 Identiverse speech, The History and Future of Digital Wallets. Executive Summary Digital…

    21 条评论
  • Australians becoming familiar with verifiable credentials

    Australians becoming familiar with verifiable credentials

    The Reserve Bank of Australia (RBA) recently released the 2024 Payments System Board Annual Report. It shows that…

    3 条评论
  • Back to the Future with Verifiable Credentials

    Back to the Future with Verifiable Credentials

    I recently co-authored a white paper about verifiable credentials, with Richard Mallam, founder and CEO of the exciting…

  • What do verifiable credentials verify?

    What do verifiable credentials verify?

    An extract from my new Lockstep blog post. What exactly does a verifiable credential verify? And while we’re on the…

    8 条评论
  • Making data valuable

    Making data valuable

    In the latest episode of our podcast Making Data Better, George Peabody and I are joined by the former NSW Chief Data…

    3 条评论
  • A governance regime for all data

    A governance regime for all data

    I’ve been speaking and writing a lot recently about the newly legislated Australian Government Digital ID System…

    5 条评论
  • Why are there so many digital identities?

    Why are there so many digital identities?

    With Mitchell Landrigan and Hamish Fraser I co-authored a paper recently published in the open access journal Law…

    8 条评论
  • Think global; act local

    Think global; act local

    We all love to think globally, especially in digital identity, where the problem space is huge and the long standing…

    7 条评论
  • How to regulate Generative AI

    How to regulate Generative AI

    There are calls for new legislation to control Large Language Models and generative AI, but new laws are hard to craft.…

  • WHO goes there? Vaccination Certificates Technology and Identity

    WHO goes there? Vaccination Certificates Technology and Identity

    The World Health Organisation (WHO) has released the first of a series of design documents concerning digital proof of…

    12 条评论

社区洞察

其他会员也浏览了