The Identity Fabric is presented as an architectural concept for managing access of everyone and everything to every digital service, replacing reliance on a disappearing network perimeter. With employees working from many locations and devices, accessing applications across internal, partner, supplier, and customer environments, identity becomes the primary security perimeter and requires dynamic access management. Consumers need more explicit, portable digital relationships, and devices performing critical work require unique identities for differentiation and lifecycle management. Because the Identity Fabric is a set of connected enabling components rather than a single product, it can be implemented in many ways, with decentralized identity offering advantages such as higher identity assurance, more confident ecosystem interactions, and reduced onboarding and verification administration.
A key characteristic is the coexistence of many identity types and technologies—eIDs, social logins, federation, directories, and Verifiable Credentials—making an API layer essential to provide consistent access to identity services (authentication, authorization, auditing, federation) across varied apps and identity methods. Decentralized identities often reside on user devices, with proofs anchored in a decentralized ledger, requiring secure API-based exchanges. Interoperability is emphasized: wallet/authenticator apps must integrate into Zero Trust flows, verify incoming credential requests, and use decentralized identifiers (DIDs) to validate request integrity and the requester’s identity via public keys. Integration should also align with common enterprise standards (OAuth, OpenID Connect, SAML, LDAP, AD), including issuing and authenticating Verifiable Credentials via OpenID Connect using existing IdP claims.
Organizations adopting decentralized identity typically need both issuance and verification capabilities, potentially including document proofing or biometrics. Cryptographic verification occurs on every presentation, enabling consumption of credentials from other issuers without formal trust relationships. In the IAM Reference Architecture, decentralized identity strengthens administration (vetting, issuance, self-service), authentication (adaptive methods, acceptance, federation), and supports privacy-centric authorization use cases such as secure attribute sharing and zero-knowledge proofs with explicit consent.
See All Locations
See All Locations