Identosphere 203: How Self-Sovereign Identity Could Lose Its Way • New ID & Discovery Work Items • Post-Quantum Verifiable Credentials
A weekly digest on self sovereign identity: events, policy, organizational updates, standards development and more!!! Thanks for your support!
Identosphere’s Weekly Highlights
We Gather, You Read!
We’re still aggregating industry info.
Thanks for supporting our efforts by a PayPal, or Patreon
Upcoming
New Event Listings
Notice of Vote for Proposed Final OpenID Connect for Identity Assurance Specifications 9/23-30
Summer of Protocols Symposium 9/17-27. closing with an unconference. Kaliya is presenting her research on the IETF on Sept 19th.
[fediverse] Open Call: Join the Open Social Incubator Deadline: 10/4
The Media Economies Design Lab at the University of Colorado Boulder is launching a 5-month process of mentorship and peer-to-peer learning, empowering veteran community builders to adopt emerging open social networks. h/t werd.ioPre-registration Now Open for DIF’s 2024 Hackathon! 10/1-11/4th blog.identity.foundation
Veridium Joins IGEL at Disrupt 2024: Elevating Security for the Edge - Implement Strong Passwordless Authentication 2024-09-10 Veridium
We’re excited to announce that Veridium will be joining forces with our strategic partner IGEL at IGEL Disrupt 2024! [...] Special Offer: Use coupon code DISRUPT24EXCLUSIVE to get your ticket for just 120 Euros!t
Previously Listed
NIST 800-63 Feedback Sessions 09/19-20
[South Africa]DID UnConf: Africa *an IIW Inspired Regional Event09/25-27Postponed to the New year[Berlin, Global Trust Foundation] EU Digital Identity Wallets Forum 10/09
DIF Hackathon 10/1-11/4
[California] Internet Identity Workshop #39 10/29-31
[New Orleans] Hybrid Identity Protection Conference (HIP Conf) 11/13-14
Shared Signals Interop Event at Gartner's IAM Summit 12/9-11
Government
Philippines Authorities Warn Against Digital ID Printing 2024-09-11 FindBiometrics.com
The Digital National ID, launched in June, is an official digital version of the physical National ID card. It can be accessed online through computers or smartphones and obtained via a dedicated website or mobile app. It requires face-based biometric verification for identity confirmation and serves as a valid proof of identification for various transactions.
Coming full circle: How Self-Sovereign Identity Could Lose Its Way 2024-09-13 Georg C. F. Greve (Verisign)
Quality content
The first version of eIDAS was an adoption failure. While it was not providing privacy by design, technologically it was sufficiently correct to function. It did so by giving a central role to Trust Service Providers (TSPs) and Certificate Authorities (CAs).
These intermediaries sought to exploit their government issued monopoly and consequently choked off adoption for the first version of eIDAS.
Web Standards
DIF Announces Two New Work Items in Identifiers & Discovery Working Group 2024-09-10 blog.identity.foundation
"I am excited about the two latest work items in our working group - DID Traits and Trust DID Web. Both will be extraordinarily useful in our continued quest to build strong and useful identifier systems that other technologies and protocols can rely on." Markus Sabadello
QUBIP - Post-Quantum Verifiable Credentials 2024-09-12 qubip.eu
VCs are the top layer (Layer 3) of the Self-Sovereign Identity (SSI) reference model; see Figure 1. Layer 1 is used to store information about public identities and is implemented by a Verifiable Data Registry (VDR), while Layer 2 is used to initiate peer authentication and employs Decentralized Identifiers (DIDs)
Invitation to comment on two KMIP specifications 2024-09-13 www.oasis-open.org
OASIS and the KMIP TC are pleased to announce that KMIP Version 3.0 and KMIP Profiles Version 3.0 are now available for public review and comment. [...] The OASIS KMIP TC works to define a single, comprehensive protocol for communication between encryption systems and a broad range of new and legacy enterprise applications, including email, databases, and storage devices.
Organization
Welcome to Linux Foundation Decentralized Trust! 2024-09-16 www.lfdecentralizedtrust.org
LF Decentralized Trust encompasses the entire Hyperledger ecosystem, the Trust Over IP (ToIP) community.
Web3
Introducing Hiero: Bringing Hedera’s Core Network Software to Linux Foundation Decentralized Trust 2024-09-16 Alex Popowycz; www.lfdecentralizedtrust.org
Introduction to Hiero, an LF Decentralized Trust project, a contribution of entire codebase by Hedera. This new project includes a collection of key modules necessary to run and interact with a fully decentralized network
Web3 ID
Firmar: Legally Compliant Digital Signatures in Web3 LitProtocol
Using Lit Protocol’s distributed threshold cryptography, Firmar creates a decentralized Certificate Authority, ensuring secure and decentralized signature verification. This system eliminates the vulnerabilities associated with centralzed key management and sets a new standard for secure, globally compliant digital signatures.
[web3id] Money, the Metaverse and David Birch (Making Data Better EP15) 2024-09-10 Lockstep
He told us about being at an industry event with lots of people “walking around as avatars and meeting each other”. That all seemed real enough until he wanted to buy something. He had to come out of the metaverse and undergo an all-too-real payment rigmarole—scanning a QR code, then another website, typing in card details—before he could rejoin the virtual fun.
Explainer
[business] Council Post: The Changing Future Of Digital Identity: What Does It Mean For Businesses? www.forbes.com
If you currently rely on only one kind of identity for user login, you may need to make allowances for other types of identifiers. Decentralized identity brings a new customer login method that doesn't involve a user filling in a form to create an account. Users may expect to provide their identity from their digital wallet to engage with online services. Digital wallets will include decentralized identifiers that could vary from user to user.
From federated to decentralized identity: Why Verifiable Credentials are the next step in identity management 2024-09-10 Helen Garneau; Indicio
Unlike federated identity, decentralized identity doesn’t rely on any single provider. This dramatically reduces the risk of losing access to services in the event of an account compromise or a provider outage. The use of distributed ledger technology means there is no central database that can be breached
Differences Between Centralized and Decentralized Identifiers 2024-09-06 everycred.com
Decentralized Systems\
Authority: Individual users
Data Storage: Distributed network
Security: Resilient and tamper-proof
Privacy: User-controlled data sharing
Interoperability: Open standards and protocols
Trust: Establishes trust through cryptographic proofs
User Experience: May require additional steps
From federated to decentralized identity: Why Verifiable Credentials are the next step in identity management 2024-09-10 Helen Garneau Indicio
Even though federated identity reduces the need for multiple login credentials, it still relies on centralized identity providers.
Decentralized Identity: Potential for Breakthrough Innovation KuppingerCole
DCI, also referred to as SSI (Self-Sovereign Identity), is a concept that differentiates fundamentally from established models. [...] DCI builds on a concept of issuers that issue VCs, holders – commonly the individuals – that hold VCs, and verifiers that consume VCs.
Digital ID Wallet: Comprehensive Guide 2024-09-13 www.identity.com
Governments around the world are adopting digital ID wallets, linking them to official identification documents such as driver’s licenses, national IDs, and passports.
[short video] What are Verifiable Credentials? 2024-09-10 shiftmag.dev
Company Stories
[France] IDnow’s YRIS solution obtains Substantial Level of Assurance 2024-09-10 www.idnow.io
With their reusable digital identities, end users in France will be able to open a bank account or carry out any banking operation, perform a qualified electronic signature, open an online gaming account, or send or receive an electronic registered letter. We are at a pivotal moment in the digital identity ecosystem in France and Europe overall and IDnow is proud to lead the way with our expertise and our proven solutions
Development
TBD DWN | Vidos Digital Identity Hack Pack vidos.id
Web apps enhanced with decentralized identity and data storage capabilities. Using TBD DWN, part of the Vidos Digital Identity Hack Pack. Get started building today!
Thoughtful
[user research] Staying on Track 2024-09-10 blog.weareopen.coop
User research is a journey, and like any journey, it doesn’t always go exactly as planned. We’ve written previously about starting your own user research journey and questions to ask that can help get you off on the right foot.
An Introduction to Systems Thinking - Part 3: Identifying leverage points 2024-09-16 blog.weareopen.coop
Leverage points are specific areas within a system where a small change can produce a significant impact on the entire system. These points often require careful analysis and a deep understanding of the system’s structure and behaviour, as they are not always immediately obvious.
ID not SSI
OAuth 2.0 Protected Resource Metadata draft addressing reviews since IETF Last Call Mike Jones: self-issued
Aaron Parecki and I published a new version the “OAuth 2.0 Protected Resource Metadata” specification that addresses the review comments received since the IETF Last Call. Per the history entries, the changes were...