Identosphere 217: BBS Blind Signatures • SSI Over before it Started? • Markets Talk •
Upcoming events, standards development, specifications, company news, organizational updates; and deep thoughts on everything related to decentralized identity and verifiable credentials
Happy New Year from Identosphere
We Gather, You Read!
End of the year gifts via PayPal, or Patreon are appreciated if you love what you read here.
We are taking a two week holiday break and will publish again the first week of January.
Coming Up
[online] CA mDL Community Hackathon Public Briefing 1/10
The two hackathons, participated by 20+ teams, 40+ organizations, and 200+ attendees
The CA DMV is hosting this briefing to share with the broader mDL ecosystem[Berlin] European Cloud and Identity Conference [Call for Proposals] Until 01/31
[Cape Town] DID:Unconf Africa 2/18-20
[Zurich] Digital Identity Unconference Europe - Ecosystems 3/4-5
New -> [Manila] MOSIP Connect - March 11-13
[Orlando] Gartner Identity & Access Management Summit 2025 3/3-5
[London] Future Identity Finance 3/19
[Netherlands] IDM Europe 4/1
[California] Internet Identity Workshop #40 4/8-10
[Washington DC] IAPP Global Privacy Summit 2025 4/21-24
[San Francisco] RSA Conference 2025 4/28-5/1
[Berlin] European Identity and Cloud Conference 2025 5/6-9
[London] Future Identity Customer 5/13
[Ethiopia] ID4Africa 2025 5/20-23
[Las Vegas] The Identity Engine - from Identiverse 6/3-6
[Netherlands] Identity Week Europe 2025 6/17-18
Featured
Self Sovereign Identity: Over before it started? 2024-12-22 Georg C. F. Greve
Web based DID methods belong to the family of federated identity methods, not Self Sovereign Identity Using the web for Decentralized Identifiers (DIDs) violates some of the basic principles of Self Sovereign Identity, and effectively restricts the possible properties of the system to that of a classic federated identity protocol, such as OpenID.
Funding
Vendor Opportunity! $70K CAD 2024-12-24 Charles Macpherson; BC Gov
BC Gov is looking to enhance our ability to create demonstration systems for digital credentials. If you are familiar with the BC Wallet Showcase demo, we're expanding that.
Implement an Interactive Digital Credential Showcase Builder Closes 1/10; Code With Us
Markets
Understanding the digital identity market: key insights 2024-12-21 gov.uk
Investment rates are a further indicator of a resilient market: UK digital identity firms have raised £826 million in external investment since 2015, with £148m raised across 34 deals in 2023.
The figures highlight a highly productive sector, with an average revenue per employee of £189,867 and Gross Value Added (GVA) per employee of £79,366—about 42% higher than the average in the wider UK economy.
Biometrics and digital identity M&A in 2024 2024-12-24 Biometricupdate
In the Goode Intelligence market analyst report, “Travel Digital Identity – Seamless Travel Powered by Digital Identity” we forecast that the market will grow to $4.6 billion by 2029 with a CAGR of 22 percent. It is no surprise that suppliers of biometric and digital identity technology are aware of this opportunity and are growing their business and product portfolio through acquisition.
The Crucial Role of ID Verification in the Digital Economy 2023-09-19 Harvard Business Review
At its core, ID verification tools prove your information – name, address, age, phone number – is valid and linked to you. Many different technologies can be used to achieve that one goal. The author, the CEO of Mastercard, explores how the technology works, where it’s used, and the potential pitfalls of digital IDs.
Organizations
OpenID Foundation calls for collaboration on mDLs between private, public sectors 2024-12-27 Biometricupdate
The hackathons co-hosted by OIDF and the California Department of Motor Vehicles brought in a range of participants from the public and private sectors, addressing 25 real-world use cases. They were successful in demonstrating the value of mDLs as secure digital credentials for use cases in financial services, retail, healthcare and entertainment, OIDF says.
DIF Technical Leaders Engage Korean Students at MegaStudy Academy 2024-12-18 Decentralized Identity Foundation
DIF Identifiers & Discovery WG Guest Lecture at Gangnam MegaStudy Academy
Markus Sabadello (co-chair) and Kyoungchul Park (chair) delivered a guest lecture on December 10, 2024.
Students demonstrated deep understanding through challenging questions about DID-Web3 relationships, VC proof mechanisms, underlying trust models.
Established alongside Ministry of Science and ICT's Self-Sovereign Identity Technology Project, the SIG bridges DIF's technical standards with Korea's digital identity ecosystem
The Night Before Digital Trust: A Holiday Tale 2024-12-24 John Jordan; BC Gov
‘Twas the night before Christmas, and through BC’s realm,
The wallets were buzzing, all safe at the helm.
The Person Credentials were stored with great care,
In hopes that secure access soon would be there.
DIF Newsletter 47 2025-01-02 blog.identity.foundation
DIF Labs Beta Cohort Launch: New initiative brings together leading projects on Bitcoin Ordinals, Linked Claims, and privacy-preserving verification through VerAnon.
CFRG Adoption of BBS Blind Signatures and Pseudonym Specifications: Major progress towards standardized, privacy-protecting digital credentials.
DIF Technical Leaders Engage Korean Students: DIF extends educational outreach in Asia with a session on decentralized identity technologies at Seoul's MegaStudy academy
Web Standards
BBS Blind Signatures 2024-12-12 blog.identity.foundation
BBS Signatures: Mature working group document, ongoing review by CFRG
Blind BBS and BBS Pseudonyms: On their way to adoption, public support encouraged
Voice your support for Blind BBS and BBS Pseudonyms specifications before December 20th, 2024.
Proposed Second Candidate Recommendation for Securing Verifiable Credentials using JOSE and COSE 2025-01-02 Mike Jones; self-issued.info
One significant change since the First Candidate Recommendation was splitting the Controller Document text out into its own specification called Controlled Identifier Document 1.0. Publishing a Candidate Recommendation Snapshot for it is planned for next week. Part of why it became its own specification is so that it can be referenced by the planned update to the W3C DID specification
2024 PKI and Digital Certificates: Challenges and the 2025 Roadmap 2024-12-31 Israr Ahmed
Resolution & Roadmap for 2025:
✅ Automation: Implement certificate lifecycle automation tools to reduce human error and ensure timely renewals.
✅ Centralized Management: Deploy unified PKI platforms to gain visibility and control over all certificates.
✅ Quantum-Ready PKI: Start adopting hybrid cryptographic solutions to future-proof systems against quantum attacks.
✅ Continuous Monitoring: Invest in real-time monitoring solutions to detect vulnerabilities proactively.
✅ Training & Awareness: Upskill teams on the latest PKI trends, standards, and technologies.
Unlock the Secrets of OAuth 2.0 Tokens (and Have Fun Doing It!) 2024-12-19 ; Heather Flanagan; Spherical Cow Consulting Founder
Analyzes security implications of short-lived vs long-lived tokens within OAuth 2.0 framework; benefits include mitigating token replay attacks, limiting attack window, and reducing impact of compromise.
Literature
[Gaia-X] [TRAIN] Digital Calibration Certificate in a trusted quality infrastructure federated data space: A proof of concept Tomasz Sołtysiński, Jens Niederhausen, Sascha Eichstädt; ScienceDirect
a framework of verifiable presentations realized by applications of W3C decentralized identifiers and verifiable credentials in a federated international data spaces approach. To realize a verifiable presentation of DCC content on demand between two federations, a trust and identity work package of the Gaia-X along with its new trust management infrastructure (TRAIN) framework has been adapted. The proposed approach is readily scalable, extendable, and accessible to any authorized body and industrial partner or company.
mDL
[linkedin] Puerto Rico joins U.S. states that let driver’s licenses go in Apple Wallet 2024-12-24 Wayne Chang
PRITS' announcement of federally accepted IDs on Apple Wallet
Link to Apple's mDL announcement: https://lnkd.in/eDtZXwKg
Map of TSA checkpoints accepting mDL: https://lnkd.in/e-WMhctk.
[Linkedin] The NCCoE has set up a new page to follow along on our mDL build progress. 2024-12-24 Ryan Galluzzo; NIST
We will post material for feedback as we go. First items for review are the build requirements. Please send us your thoughts via email or GitHub issues!
Privacy
[Regulation] Colorado's new biometric privacy law may strain small businesses, says lawyer 2024-10-29 Keely Quinlan; StateScoop
Colorado passed a law regulating biometric data privacy, one of the first states to do so
Requires businesses to provide notices of collection, create retention schedules, and establish mandatory deletion guidelines
Includes facial scans, fingerprints, voiceprints, and retina scans
Does not include data from photographs or audio recordings
Surveillance
Secret Service Admits It Didn’t Check if People Really Consented to Being Tracked 2024-12-31 Ben Werdmuller
Private Services and Data Brokers: Contracts and relationships between law enforcement and federal agencies, private services, and data brokers seem to be based on a "nudge and a wink."
Secret Service's Justification Challenged: The email undermines the Secret Service's and other U.S. federal agencies' justification for monitoring movements without a warrant based on user consent from apps.
Apple to settle claims Siri collected user data without permission SCWorld.com
$95 million payout unlikely to make significant dent in Apple's cash reserves
Net profit: $27 billion
Net income: $95 billion.
Threats
What Does the Dark Web Facial ID Farm and Users Selling Their IDs Mean for the Rise of a New “Natural Person Wallet Engineering” Threat? ; Dr. Carsten Stöcker, Mirko Mollik
Wallet engineering creates highly convincing wallets with real documents & biometrics. These wallets mimic legitimate users and can easily bypass traditional verification methods. Soon, such fraud-ready wallets (together with authentic smart phones) may be bought & sold on the dark web, enabling large-scale impersonation fraud.
Now Appearing At Your Local Security Theatre: Know-Your-Customer 2024-12-11 Forbes.com
Remember the good old days when people used to rob banks for money? At least there was no contagion. Apart from anything else, thanks to fungibility, it wasn’t your money that was being stolen anyway, it was the banks’ money. Today though, smart criminals rob banks for identity, which is much more valuable (and not at all fungible).
Company Stories
Digital wallet for farmers developed by Indicio and Anonyome wins SuperNova award 2024-12-20 Biometricupdate
The paper, presented in collaboration with the Queensland University of Technology (QUT), argues that digital identity wallet applications can feasibly support the EUDI Wallet technical Architecture and Reference Framework (ARF), but with some tradeoffs in terms of algorithmic compatibility, user experience and performance.
Reflecting on 2024: Highlights from SpruceID’s Year 2024-12-20 Spruceid.com
Utah's Division of Technology Services
California DMV
Department of Homeland Security
ISO/IEC18013-7 Release: remote use of mobile driver's licenses (mDLs)
Collaboration with NCCoE at NIST
Digi Yatra achieves major milestones in 2024 2024-12-27 bwhotelier.com
In 2024, Digi Yatra, a Self-Sovereign Identity (SSI) ecosystem using face biometric technology for seamless airport processing, reached over nine million active users and expanded from three to 24 airports across India. The platform has facilitated 42 million contactless journeys and sees an average of 30,000 downloads daily.
New Social
The open social web is the future of the internet. Here's why I'm excited 2024-12-13 Ben Werdmuller
The open social web puts control back in your hands. Unlike big social media platforms, it’s not run by a single company — it’s made up of independent, connected communities where you decide how and with whom you interact. It respects your privacy, avoids intrusive ads, and gives you the freedom to truly own your online experience. It’s like the internet used to be: open, personal, and community-focused.
Web3
NFT vs. Verifiable Credentials: Which to Choose and Why? 2024-12-25 Fabio Budris Klaz
Verifiable Credentials and NFTs are complementary solutions rather than direct competitors. While VCs excel in contexts where privacy, data updates, and regulatory compliance are paramount, NFTs shine in certifying authenticity, exclusivity, and transparent trading of unique assets.
ENS Labs and Dentity are Bringing Real-World Identities Onchain to Connect Web2 and Web3 2024-08-21 La Rédaction Cointribune
For the first time, ENS users can now securely link their onchain identity with their real-world identity. They can define the scope of the information they wish to share, and maintain complete control over what Personally Identified Information (PII) is publicly accesible, while preventing the need for any PII to be stored onchain. Similarly, Dentity users can now link their identity credentials to their ENS domain using the newly created integration pathway.
Revolutionizing Digital Identity: ENS Labs and Dentity Join Forces 2024-08-21 ; Kelly Cromley; www.cointrust.com
ENS Labs Teams With Dentity to Advance Real-World Credentials via Crypto - Decrypt 2024-08-21 ; Decrypt, Vismaya V; decrypt.co
We’re excited to partner with Dentity to bring real-world identities onchain. 2024-08-21 ens.eth