Thank you and good morning everybody. Thank you for joining me here. I'm Nishant Kaushik. I'm the CTO at the FIDO Alliance and you can find my socials through my website. I would love to hear from you as we discuss this topic about how we're finally, finally, finally going to get digital identity that we can trust. Question mark? Maybe? You know. Are we going to get digital identity we can trust? I don't know. If you were in the keynote yesterday by Elizabeth, it may have raised some questions in your minds, so I think we should explore those. But why is the FIDO Alliance talking about trust?
Isn't the FIDO Alliance purely about getting rid of passwords? Yes, we are about getting rid of passwords, but that was just the start. This was the FIDO Alliance mission up until a month ago. And as of a month ago, we have a new mission statement. A new mission statement is that we enable identity technologies that put trust and simplicity at the center of interactions among people, services, and devices. Pretty big statement, especially about the trust part. Why do we care about trust?
Well, the promise of digital identity is easy to describe, especially if you think about it from the perspective of the individual. Every person should be able to prove who they are or what they are entitled to without being forced to reveal more than they need to about themselves. Giving up choice or control, memorizing fragile secrets, or repeating the same onboarding process over and over again with every organization that they have to interact with.
And for every business or public service, they should be able to verify trustworthy claims and engage with their customers quickly, securely, and at scale. But the promise of digital identity has been surprisingly hard to deliver. People do not trust systems simply because they are digital. They trust systems when the experience is fair, when the choices that they are provided are real, when their privacy boundaries are clear, and the security holds up under pressure.
The system has to actually work where life happens, whether it's at the bank, at checkout, at the border, at the pharmacy, or the hiring desk, or even in emergency conditions, right? That's when you can trust. And on the technology front, we see three foundational capabilities that are converging.
The first, obviously, is phishing-resistant authentication that we've been working on for so long. We now also have portable verifiable credentials. And we have browser and wallet mediated exchange. Individually, each of these is very powerful. But together, they form the foundation of a digital identity system and ecosystem that can actually be trusted. And that foundation is a layered architecture that makes up the digital identity wallet stack. At the interaction layer, you have the wallet UX and platform APIs that recognize the browser as a key mediator of wallet-based credential exchange.
And phishing-resistant domain-bound authentication that is responsible for helping users understand requests, choose credentials, share them intentionally, and receive credentials from issuers or create passkeys for relying parties. At the data layer, you have VDCs that are a common model for portable, tamper-evident credential and presentation. While credential formats such as ISO and DOC and SDGOTVC allow for selective disclosure-friendly presentation of documentation.
At the issuance and presentation layer, you have standardized protocols from OpenID Foundation and ISO that provide increasingly practical and verifiable ways to issue credentials and request presentations using patterns that are familiar to the broader identity industry. And at the access layer, you have passkeys and biometrics that offer authentication methods that are materially stronger than passwords and many legacy MFA approaches. But trust is not a feature. It is an outcome.
And despite having these building blocks, we know that technical capability is not sufficient because trust has been limited by fragmentation. Even when the underlying cryptography has been sound, the ecosystems are often lacking consistent profiles, wallet behavior, verifier expectations, and browser support that is needed to make cross-system exchange practical and predictable. That is happening because what we have lacked is a framing that helps guide policy, governance, and implementation.
And I believe that this identity ecosystem needs to be framed against six key concepts, at least six key concepts, in my opinion, that cut across standards, policy, product design, and ecosystem governance. They are design tests that any digital identity ecosystem must meet in order to rise above mere digitization of existing processes and actually become the infrastructure that people and institutions truly trust. I'll start with human dignity.
Anybody who's seen me talk is not going to be surprised that this is where I'm starting, as I've been talking about this concept for the last few years. Identity systems shape how people are seen, sorted, included, and excluded. And the World Bank's principles on identification for sustainable development begin from that premise, the premise that every person should be able to participate fully in society and the economy, and that identification systems should be inclusive, trusted, and useful. That is why I love the direct principle of voluntarism. Voluntariness. Voluntariness.
Probably saying that five times. They argue that digital identity adoption must be genuinely voluntary and with equivalent non-digital alternatives that are available without penalty. A system is not meaningfully optional if the non-digital alternative or the non-digital route means three-hour waits, extra fees, unsupported payment providers, shrinking branch access, or staff that who no longer know how to support you. Trust erodes quickly when digital choice becomes practical coercion.
And this equally applies when we start thinking about the digital pathways we follow, when we talk about preferred pathways or pathways that require paying a premium as an individual. Centering dignity also demands data minimization.
People should not have to hand over their full identity just to prove a digital fact, a single fact, whether it's proving that they're over 18, whether it's claiming a resident discount without having to provide their full address, whether it's proving their purchase ability without reporting or exposing a full account number, or whether it's collecting a package without revealing unrelated personal data. That is why selective disclosure and privacy by design are critical. With selective disclosure, the user is no longer the raw material of the transaction. They are a person with agency.
Dignity also requires pluralism. Public sector systems are important, especially when it comes to foundational identity. But trust is often strengthened when we have clear choices offered by the private sector. And people can choose between providers and interaction models. Trusted identity ecosystems can emerge and thrive through different institutional models, provided they have user rights, accountability, and privacy boundaries at the center of them.
This has been proven out in private sector schemes such as Bank ID in Sweden and Norway, ITSME in Belgium, and is at the heart of the concepts behind things like the state endorsed digital identity initiative. It has some really interesting and good ideas about how to extend and provide a path forward.
Now, where dignity asks whether a system respects the person, resilience asks whether it can be relied upon when conditions are imperfect. And this is where the convergence of pass keys, wallets, and verifiable credentials becomes especially important. Pass keys improve resilience because they, at the authentication layer, remove the shared secrets that make passwords easy to phish, exploit, replay, and stuff into credential attacks. But equally critical in that model was addressing things like recovery, portability, and usability.
And that's where the work on things like synced pass keys, cross-device authentication, and secure credential portability between credential providers has emerged. With pass keys, authentication becomes not just stronger, but structurally resilient. And when it comes to VDCs, they introduce resilience at the data layer. Instead of relying on a single identity provider at the center or at the moment of a transaction, VDCs can be verified independently. They can be verified offline if needed, without round trips to issuers, and without central system dependencies.
These are critical elements from resilience perspective and are at the heart of the concept of decentralization. Resilience also depends on architectural layering. If you look at the digital wallet identity stack that I described earlier, it is deliberately avoiding forcing one component to do every part of the equation or do every job. Pass keys handle authentication. Credentials carry the signed claims. Wallets mediate the content and storage, consent and storage. Presentation protocols govern the exchange. And trust frameworks determine which issuers and verifiers should be relied upon.
So when each layer is well-defined, the ecosystem becomes easier to secure, evolve, and recover. Separation of concerns creates a more fault-tolerant system overall. And resilience is not only technical, but it's actually institutional. You have to think of it from the perspective of the fact that ecosystems need fallback paths. They need clear liability. They need lifecycle management, revocation, or status checking where appropriate. Governance must survive changes, platform changes, or, as we heard yesterday, political cycles.
The European digital identity wallet architecture and reference framework is a good example that reflects that thinking. It reflects the broader understanding that by combining legal governance, technical, and operational dimensions in one coordinate architecture, we can improve resilience. Institutional support becomes even more important when we are trying to remove barriers to cross border and private sector interoperability. Barriers like regulatory fragmentation, lack of mutual recognition, and insufficient harmonization of technical standards.
Now, of course, trust requires security, right? Kind of obvious. But when we think of security, we must not only think of more defenses or stronger defenses, but we actually have to think about fewer vulnerabilities. The traditional identity systems that we have today create large attack surfaces. They create centralized credential stores, reusable secrets, and over-collection of personal data. This is even larger when you think of traditional payment systems where you have reusable card numbers that can be stolen and transactions that can be manipulated.
The modern layered identity stack is trying to reduce risk at multiple levels. And the authentication layer PASCs eliminate reusable credentials and eliminate phishing risk and password theft. Biometric certification work, like what we do at the FIDO Alliance, is helping ensure that consistent performance, security, freedom from bias, spoof resistance, and interoperability exist.
At the identity verification layer, you have identity verification programs like what we have at the FIDO Alliance with document authenticity and face verification, helping create measurable assurance around identity proofing systems. But that translates then into the data layer, where you have cryptographic verification through VDCs preventing tampering and spoofing, where issuer signatures ensure authenticity. Selective disclosure minimizes data exposure.
And credential-centric payment systems cryptographically bind the transaction, the intent, and the relying party in one authenticated ceremony. At the device layer, you have authentication layer leveraging trusted hardware, such as secure enclaves, DPMs, secure elements, and hardware security keys. And in the system architecture, you have decentralized verification reducing high-value targets. Even advanced threats, like deep fakes, become less effective when identity is cryptographically bound, device protected, and verified through trusted issuers.
Fundamentally, I just think it's cool that we're improving security not by adding more controls, but actually redesigning the systems from the ground up to remove weaknesses. Interoperability is the hinge on which digital identity swings from local success to systemic values. It is easy to see this when we look at how this operates in lived experience. A person crossing borders should not discover that a digitally stored credential, like a license, a permit, a qualification, or entitlement, becomes unusable at the moment it crosses a border or a sector boundary.
When systems speak different languages, people are pushed back towards paper, manual review, and exclusion. Open standards and shared protocols are what are preventing fragmentation from becoming permanent. The standards landscape is now substantially more mature than it was even a few years ago. But an important element that is now getting introduced is the need for profiling to support interoperability.
Real ecosystems still need agreements on optional features, acceptable credential formats, metadata, trust anchors, encryption requirements, and so much more, especially when you think about user experience and user experience conventions. It's important to remember that the wallet is not a taco. It's not an app. It is actually an ecosystem. It consists of platform wallets, third-party wallets, issuer-specific apps, and government wallet applications.
Interoperability requires that all of these wallets must coexist and interoperate through a healthy trust model that assumes pluralism and that makes that pluralism work predictably. Interoperability at scale will require bridges across trust models and forced uniformity. That's why the FIDO Alliance has consistently approached interoperability as both a technical and an ecosystem problem.
By collaborating closely with organizations like the W3C, ENVCO, the OpenID Foundation, and ISO, we work to operationalize the standards and to close operational gaps in certification, deployment, developer experience, security, and privacy. Think of it as ecosystem engineering instead of pure standards development. I mentioned scalability, right? Scalability means you think about everything works in a pilot, but scalability is where good architecture meets operational reality.
So things must work repeatedly, affordably, inclusively across large populations and many different service providers over billions of interactions and transactions. Scalability therefore demands simplicity. It must be simple for users, trusted by businesses, implement privacy by design, and usable in the real world. Scalability is achieved when ordinary people can use it confidently without training manuals or repeated failure.
And this requires making that integration problem simpler, reducing the integration burden on the ecosystem by requiring open standards, implementation profiles, conformance testing and certification, sustainable governance, and shared assurance languages. This ensures that every new verifier, issuer, and wallet does not have to negotiate everything from first principles. The browser in this context acts as a very important scaling mechanism because it is a universal interface that standardizes how credentials are requested and shared across the dimensions, across websites, across the systems.
The combination of wallet, browser, and open protocols creates a distribution model that scales naturally with the web and across mobile ecosystems, irrespective of industry or geography. Scalability requires utility. It doesn't really matter whether the systems work if there's no use for it, right? Not every interaction needs to look like opening a bank account.
We need to think about how wallets should support many common low-friction and high-frequency journeys, such as proving age, collecting parcels, activating a SIM card, claiming a local benefit, accessing healthcare, verifying your qualifications. If digital identity only supports a narrow range of high-ceremony use cases, it will struggle to become socially normal. And trust only scales when adoption scales.
So, scaling adoption is about enabling participation and unlocking opportunity. The strongest argument for trust in digital identity is not that it makes existing systems more efficient, but actually that it unlocks access to services, to finance, to technology, to to finance, to mobility, to education, and to participation. A trustworthy ecosystem unlocks opportunity in two directions at once. It reduces friction for industries and institutions, and it expands agency for individuals. Commercial motivations are a powerful engine for deployment.
Digital identity activity is being driven globally by organizations that are seeking to expand markets and reduce onboarding. But one of the things the FIDO Alliance learned is that we have to remove friction by providing implementation guidance, deployment playbooks, and user-first design. And identity is not merely implementation in administrative infrastructure, but is a precondition for accessing rights, protections, and opportunities. And that requires having guardrails and safeguards, which are increasingly important in this age of AI.
So, this is where we look at how the EUDI wallet and broader identification principles from folks like the World Bank demonstrate that digital identity trust depends on inclusion, governance, and accountability. And with that framing in mind, we recognize that we have all the pieces, and it's not waiting on a missing invention, but on the need for disciplined assembly. The components are here, the standards are here, and what we need today is an identity stack that is capable of serving the deepest social purpose that identity has always carried.
And that sounds like digital identity we can trust. Thank you.