My name is Thomas Mayfield. I actually wear two hats. I am the Head of Decentralized Trusts at the Cardano Foundation and I'm going on a new venture now as the founding CEO of a company called Veridian. This is an organization building on KERI and ACDC. This is the verifiable identity layer that sits below authorization and I'm going to talk to you about a few things here today and try and frame the conversation for you. Essentially what you see here on screen are three problems, three stories. I'd like to break them down for you based on humans, machines and agents.
In that first category, humans, there's a huge problem happening online and a lot of this actually isn't discussed in the enterprise audience but that problem is actually with our children. The internet is a very dangerous place and there is a lot of content that is age gated but unfortunately those gates are controlled by a birth date that the child can set themselves.
So when you speak to tech companies in Silicon Valley, they'll tell you that they don't have anybody under on their platforms that's under the age of 13 but the reality is that they do and the reason that is is because there is no verifiable identity piece that can be leveraged here to actually ensure that you are keeping children safe online. The second element there is less emotional but more financially bearing and that's the reality of deep fakes.
Millions, millions and millions of dollars are lost from a simple deep fake video call, typically coming from a CFO. One such case that has happened just recently with the company on screen there Arup and that happens in one interaction, one video call, one bulk transfer and the money is gone. Now the good news in regards to this is verifiable identity is a way forward. There is also regulation and legislature that's now catching up to protect our children and some of those are listed on screen but that is one surface area and I'd like to move on to machines.
What we see in industry today is industrial IoT are ubiquitous. These cheap sensors are easy to make, easy to ship and companies are starting up and closing down very quickly, selling a whole bunch of these things, getting them out into the wild and moving on to the next venture but what this means for us is we have sensors in our industry that have certificates on them that can't be rotated. When those companies shut down there is no way to effectively change the authority behind that ticket and those devices sit in the wild for a long time.
They become single attack vectors and this is a huge problem. You have a 10-year operational life for a sensor in the market but the company shuts down after five years. That's a problem that happens today. I would argue that there are sensors in this very building that came from a company that is no longer active with certificates sitting on them that are no longer controlled by the keys that initially onboarded that device. And finally and where all the money is right now is agentic AI.
One of the challenges we have with agentic AI is employees, individuals are using dozens of agents day to day but the human role approach to identity doesn't work for agents. You need the ability to delegate authority, to create cryptographic chains of trust and you need to know who implemented the agent, who gave it its authority and you also need a way to revoke it in real time. And these are all problems but I would argue that they are problems that all come from the same factor.
Before I tell you about the stack that Veridian is bringing to the market to solve these solutions, I want to tell you exactly what that stack has to do to cover this gap that you saw on the last screen. There are four properties on here and I'm going to read them through for you. That first one is a self-certifying identifier. This is where the identifier is not just a public key. This is an identifier that is derived by keys and attributes that is owned by the individual or the organization. This is an identifier that does not change based on the cryptographic keys that control it.
So this is an identifier that you can use for the foreseeable future of a company or an individual's life. At the moment the way this works is if your keys are compromised that control the identifier, you throw that identifier away and you start again. Typically public keys are what is used to identify individuals, machines and data. This is a new approach and I'm going to get more into that for you in the following slides. The next is cryptographic provenance.
If you are not able to actually establish a chain of trust between the credentials that you issue or the attestations that are made, if they are single tokens that anyone can pick up and clone from a system and masquerade and represent you, if there is no solid verifiable identity key binding to those cryptographic provenances, then what you have there effectively is a system that is extremely weak and it is why we are seeing growing trends in all of the cyber attacks across systems today.
It is why IBM says it takes 258 days for an attack to be identified and resolved because there is no cryptographic provenance, there is no trust chain. The trust has to sit with the issuer and you have to trust that domain you are working in. The next element here is a threat model that is speeding up on us and that's the quantum reality. We need to have quantum ready key rotation for our identifiers and we need to be able to do this in such a way that we don't have to have all of the verifiers re-onboard with their cryptographic algorithms.
NIST says this timeline is coming very soon and systems are now being adapted with cryptographic algorithms that have not been battle tested. What we will propose to you today is a quantum strategy that is effectable today out of the box and allows you to leverage an identifier regardless of the cryptographic algorithms behind it. And finally, there's a notion of phoning home the way existing identifier systems work is they require a central authority to provide the verification proof to a system and this works in closed systems.
If you're working within your organization, you're leveraging something like OpenID or a federated identity system. This is a fantastic approach but the challenge here is once you start working outside of that ecosystem, the other challenge is data correlation. If I have to call back to one central repository to get a verification of an attestation or an identity, I'm creating a honeypot for data correlation and this is what the whole data correlation market is today. Millions of dollars are made off of your and our identity and how we leverage those identities.
Just logging into the apps that we are using for this conference for example, your data has been harvested and has been sold and that is all because there is a phone home activity leveraged behind the identifier that you chose to register with this platform and ultimately this can all be removed from our markets and our ecosystems. What I'm going to talk to you about today is KERI, key event receipt infrastructure. This is not another DID method. DID stands for a decentralized identity if you aren't familiar. Effectively there are three components here to KERI.
The self-serting identifier as I mentioned before, this is a long-living identifier that does not change based on the cryptographic keys that control it. There is an assumption event that takes place when you create your identity and the derivation is a combination of cryptographic keys and attributes but they are not solely dependent on the keys that control it at one particular time. This allows you to self-attest, self-certify your identifier and to build reputation on that identifier even in the event where your keys are compromised and you have to rotate out and regain control.
You don't have to throw away the reputation you have built. Temper evidence logs are a key factor in KERI. This is how you do not have the phone home attribute. You have a cryptographic chain of all of the events that your identifier conducts whether that's its inception event, whether that's credentials that are issued to it, key rotations, revocations. What exactly each identifier carries with it is a ledgerless blockchain.
It is a cryptographic structure that is hash chained together that gives you a log that you can work your way through to verify the consistency of an identifier and you can say irrefutably that something has been presented to me with the current controlling keys of this identifier. So you would know if someone stole the keys five minutes ago. This is something that at the market today does not exist. And then pre-rotation, this is how you get post-quantum protection.
When you create an identifier in KERI, you establish the current keys that you are using to do signing and you establish the next keys you will rotate to. You do not broadcast those public keys which means they can't be fed into a quantum computer, they can't be broken. You do publish a hash of that public key so when you do rotate, you can verify that you are in fact the authentic owner of the identifier. But you do not publish the public key, that's key here.
This feature set is known as key rotation or sorry pre-rotation and it is how KERI provides post-quantum protection today even with elliptic curve algorithms. For those of you that are looking at post-quantum, I highly encourage you to engage on this topic with me or research for yourself KERI and pre-rotation.
Now ACDCs, not the band, are authentic chain data containers. These are the verifiable credentials that sit on top of KERI. They are the same wallet and verifier shape that you would be familiar with from the W3 space known as SDJOT or Java web tokens and they are effectively built on top of that concept of the W3C verifiable credential from a format perspective. Where they really are different is you actually can have a delegated chain of authority through these credentials.
This is the ability to chain one credential to the other cryptographically, delegate authority down through that chain and verify the whole way up the chain. You have graduated and selective disclosure of credentials and the attributes within them. But what you are forming here is a graph, a DAG, a directed acyclic graph with your credentials. For those of you that are familiar with those cryptographics, you will understand how powerful this is. This isn't just a single token or bearer credential.
This is a truly verifiable cryptographic chain that can be used to delegate from a company to the people that work at that company, to the machines in that company's workshop floor, to the contractors that company uses, to the AI models that company deploys. And all of that can be verifiable up a delegated trust chain all the way back to the legal registry. This is an extremely unique approach that is being missed by a lot of enterprise architects at the moment. And finally, revocation. Revocation propagates through those key event logs that I mentioned before.
There is no longer the 30-minute, 5-minute, 24-hour wait time for revocation. It persists in real time and every event where a credential or an attestation is made in KERI requires the signatures to be produced by the current controlling keys of the identifier. So I've talked about the protocol. I've talked about the stack. I want to talk now about the root of trust. For those who aren't familiar, GLIFE stands for the Global Legal Entity Identifier Foundation. And what they have done is they have created an anchoring of a company in a register.
This came out initially in 2008 when we had the financial crisis. And it started with what is known as the LEI, the Legal Entity Identifier. This has evolved now to a cryptographic credential format built on top of the ACDC that I mentioned previously. And it is known as the VLAI. What you get from GLIFE's root of trust starts with GLIFE at the top level, establishing a root of trust recognized by the Financial Stability Board as well as the Financial Action Task Force. From there, that trust chain goes down to a qualified VLAI issuer.
So the authority is delegated down through that same acyclic graph that I mentioned to the QVI, who then has to comply with the extremely intense governance framework to go through the due diligence process of then issuing a company a legal entity credential. In order to achieve a legal entity credential, this is a multi-signature identifier and credential that is created once you have proven control of a company listed on the actual business registry. You then will receive this VLAI credential.
And from there, you can issue credentials chained below that to all of the representatives within the company, as high up as CEOs and directors and as low down as administrative staff. What is really interesting here, especially in the context of where we are today, is this same trust chain can now evolve into agentic AI. So this is not bearer tokens. This is actually a verifiable identity that is cryptographically verifiable through a trust chain of delegation from a legal entity all the way down to those agents that are representing it. This is extremely powerful technology.
Now, the VLAI is not a pilot. You may not be familiar with it, but the LEI, there are more than three million in the wild. If you want to register in certain derivative markets, you must have an LEI. So if you're from the financial space, you will be familiar with the LEI. And in all honesty, you might not even recognize exactly what Elsec Life offers. But the VLAI is a production-grade verifiable credential built on top of Cary and ACDC. The VLAI itself is active across 235 jurisdictions. It is a global identifier leveraged by organizations and those who represent the organization.
What is unique here, it is one cryptographic trust chain for all of those identities. And there are zero bilateral integrations. You are not working across different service providers, integrating across numerous stacks and platforms when you need to do an integration with a new product. And we are seeing this friction occurring now with agentic AI. Organizations want to start leveraging agents, but they also have compliance teams who want to know what exactly these agents are doing. And how do I make sure my staff are not going to be in the way of my agents?
And how do I make sure my staff are not going to delete our entire client table? With the VLAI, with the cryptographic delegation, with the ACDC credential, you can integrate this same delegated authority into these platforms by leveraging something as simple as a plugin. But what I'd like to talk to you about now is specifically Viridian.
Cary, ACDC, VLAI, and what is in production today from Viridian. So my work at the Karana Foundation started three years ago, and we started building out a digital identity system that was different than what every other blockchain was doing. We wanted an identity that didn't require you to buy cryptocurrencies to have one. We wanted an identity that worked outside of our blockchain, that worked across networks, that was established off-chain, because there's this great thing called GDPR, and anybody who has an on-chain identity system and says it's GDPR compliant, it isn't. It can't be.
Even if it's encrypted, it cannot be. So what we built out was an off-chain, on-chain solution to solve our problems in our blockchain ecosystem. And in doing so, we discovered that this work had already been happening in the financial markets within Glyph and the VLAI. And what we have created today is Viridian. Viridian is production grade infrastructure. It allows you to self-host or leverage a service level agreement. It is purely open source, so you can pull the code, review it, run it, audit it.
It has been audited, it has been penetration tested, and it provides you with the ability to not only build up your own identity within your organization, but to also leverage the Glyph VLAI, because it's built on the same protocols and primitives. Viridian Wallet is working on Android, iOS, as well as the privacy-preserving Graphene OS, and is in app stores available today. There is sandbox infrastructure if you would like to start demonstrating with the tech. But what is really unique about how this all works is actually the infrastructure itself.
So I've spoken about the cryptographics, I've spoken about the protocol, but the infrastructure around witnesses and watches is how anybody can verify a digital signature from a carry identifier without relying on a central registry or a verifying service provider. This is what makes it a truly decentralized identity, where anyone can verify the validity without having to phone home to a central authority. So where does this land in the market today? Where the money is at the moment is AI agents. You need provenance. You need the ability to delegate authority.
You need to know exactly what information your agent has provided. You need to know exactly where the training models exist for those agents. Believe it or not, you put a prompt into one agent, it isn't necessarily that agent that comes up with the answer. There is a whole chain of agent architecture that is happening below that, that you don't see, that is never logged, cannot be audited. All of that changes with the VLAI. All of that changes with Viridian, and it's available today.
We're having some very interesting conversations with certificate authorities, because after all, this session on screen, your apps, they're all protected by X.509 certificates. X.509 certificates that are controlled by key pairs. X.509 certificates that have to be revoked when you change those key pairs. With a carry-based identifier system and decentralized public key infrastructure rollout, you can change the keys without having to revoke and reissue certificates. This is a game changer for certificate authorities.
It's also a game changer for actually how you onboard a device into an ecosystem. So the way it works today, you have a manufacturer that creates a device, and on that device goes an X.509 certificate that gets set up for where it is going to. One of the most common protocols is known as Brewski, which is a bootstrapping protocol that allows you to know that when that device left the manufacturer and arrived at my warehouse, it hadn't been tampered with, and only I can onboard with it.
The challenges there with IoT devices is these things are stuck out in the wild, and you have to change these certificates. You have to do over-the-air key rotation, revocation of certificates. You need to then propagate those through networks, and in the meantime, you have a huge attack vector. This is also assuming it wasn't the scenario that I mentioned before where the manufacturer closes down business and moves on to something else.
So with Carry, with ACDC, with VLAI, you now have the ability to protect those IoT devices by replacing X.509s with ACDCs, and this is work that is ongoing right now with some of the largest certificate authorities in the world. And finally, cross-border, cross-organization trust. If you want to have business-to-business trust, you need to be able to verify the authenticity outside of the confines of your organization.
If you are using a federated identity system or an OpenID protocol or something that was designed for a closed network, that works within your organization, but it doesn't work as soon as you want to do business outside of it. Today, we are looking at EIDIS frameworks where we are establishing identity within Europe, but half of the products, if not more of them, have a relationship outside of the European Union. We need to be able to verify identity and data far beyond the confines of our organization and our borders.
A protocol like Carry, a route of trust like GlyphsVL AI, is available today and is designed specifically to do that. I'm running out of time, so I'm going to skip forward to a one-minute video for me to explain exactly what Freudian is doing today. Can you trust who's on the other side? Institutions cannot verify who they're transacting with. Children connect with strangers. AI agents execute without authority.
Today, we cannot answer the most basic questions. Who is on the other side and who authorized them to act? Viridian was built to answer both. Identity you can verify. Trust that travels with every transaction.
Auditable, traceable, compliant. Governments endorse identities. Citizens own and control. Age verified without sharing a name, a birthdate, or an address. Both sides of every transaction verified instantly before anything moves. As AI agents take over decisions, organizations retain control over automated actions. Authorized on record before anything happens.
Viridian, the digital trust every industry needs. So I'll leave you with this. The trust gap that I just mentioned is one problem that is spread across three layers.
Humans, machines, and agents. The same primitives, one stack, already running, shipped by Viridian, solves this today. It is open source. You don't have to use Viridian, but I encourage you to think about the identity that is underlying the systems you are authorizing on top of. This is where the risk will sit for the next decade. Thank you.
Thanks, Thomas.