And welcome to the audience in the room and online. Thank you for being here on a Friday. The title of the presentation was already introduced, From Trusting The Channel To Verifying The Source And The Content, Using GLEIF's VLEI in a Production Environment. So I will cover a bit the background of the global LEI system for those who are not aware of it yet.
And of course the Verifiable Legal Entity Identifier, VLEI, and then show one use case where we use decentralized access management with the help of a partner organization, Esatus AG, who also had their booth out there the last three days and they have created a product which makes this very easy to use. But let's begin with the global LEI system.
So it was in 2011 when the leaders of the G20 states after the financial crisis, Lehman Brothers, you all remember it, decided to create what they called a legal entity identifier to uniquely identify organizations on a global level just because there was this missing opportunity to really understand the risk that the other banks had towards Lehman when they became bankrupt based on the fact that Lehman is not just one organization but it's actually hundreds of legal entities which were all connected with each other and owned each other but didn't have Lehman in their names partially.
So nobody knew what Lehman actually is and this is when the legal entity identifier was created to not only uniquely identify organizations but also capture ownership structures between these organizations on a global level. And it says here parties to financial transactions because that's where it was motivated from but LEIs do really cover any organization on the planet, it's not limited to the financial space. And the ecosystem has three pillars.
There is a regulatory oversight committee that consists of public regulators, for example here in the EU it's the European Commission, the European Central Bank in Germany, the Bundesbank, the BaFin and many other organizations globally and then the Global LEI Foundation which I represent which is organizing the whole system together with a federated system of partners which are the LEI and the VLEI issuers which serve LEIs and VLEIs for every country on the planet.
GLEIF itself is a Swiss non-for-profit foundation created by the Financial Stability Board at the Bank for International Settlements in Basel and it is overseen by this regulatory oversight committee I mentioned already which consists in total of 68 regulators and 24 observers from above 50 countries. And the foundation has also itself an independent board of directors consisting of 19 persons also globally distributed for promotion and oversight purposes and we now have 39 partners worldwide for LEI issuing and eight partners for VLEI issuing and both numbers are growing.
We still receive applications from organizations who want to become part of the system and currently there are a bit more than 3.3 million LEIs issued globally. What is the LEI? The LEI is a lifelong identifier owned by the respective legal entity and why do we highlight this? It is important to understand that this identifier is really unique and any organization globally receives only one of these identifiers when they apply for one.
The numbers are not reused and they are also never deleted so once an LEI is created it stays forever even if the organization stops to exist the LEI persists and can be used for tracking of past activities and the like.
And it's not only a number of course it also connects to important reference data as you can see here in this Nestle example at the top you see it's a bit small the LEI code this is a 20 digit long string which is globally unique and then you of course have the name and the local registry of the organization the local register number addresses and on the left and right hand side here the parent and the children information which I mentioned at the beginning so you can also see who is this organization owned by and which other organizations does this organization own if these organizations also have legal entity identifiers.
And then the VLEI is not an alternative to the legal entity identifier it is an extension that we created to give LEI holders more value when they have an LEI and it's a cryptographic digital credential that helps organizations to prove who they are and as organizations themselves of course don't act but it's persons in a capacity for a legal entity it's this triple very simple data model that we have created so it's always an organization that we represent with its legal entity identifier of course a person and a role that this person has towards this organization packaged in a VLEI role credential as you can see here and that then allows for digital representation.
The VLEI ecosystem comes with what we call a trust chain and that allows that a verifier who receives a person credential here at the bottom of this chain not only to verify the authenticity and the fact that the credential had not been revoked of this person representing the organization but also verifying the whole trust chain up so verifying that the organization has a valid organization VLEI credential which has been issued by an authentic VLEI issuer that has been qualified by Glive and then back to the root of trust with Glive to basically also check that it's not just using the same protocols that we're using but that is really connected to the Glive VLEI ecosystem.
And then we have two types of VLEI role credentials on the left hand side you can see official organizational role or short OOR credentials and on the right hand side engagement context role credentials short ECR what's the difference OOR credentials are for official representatives of organizations which are legally considered and there's also an ISO standard ISO 5009 for This is roles like a CEO, a managing director, a CFO, a board member, an external auditor and officially recognizable roles that can also be independently verified and this is why these types of credentials must by our ecosystem governance work be issued by a qualified VLEI issuer and then on the right hand side the ECR credentials look exactly the same it's also organization role person but the roles are more flexible that can be any string that an organization would like to define and they can be self-issued for more flexible purposes and one of these credentials I will show you for the use case that we have now implemented for logging into a customer portal.
The ecosystem is governed by a governance framework which covers The ecosystem is governed by a governance framework which covers of most more than just the technical and format aspects everything that you see around this right circle here and we didn't just pull that out of thin air we used a standard for ecosystem governance frameworks created by the trust over IP foundation which is hosted by the Linux foundation and the VLEI ecosystem is the most comprehensive implementation of this VLEI and of this trust over IP ecosystem governance framework meta model that has ever been built it's more than 20 documents that basically cover all the aspects that are important for such an identity framework and life is of course the governing body of the VLEI ecosystem.
All right a decentralized access management use case.
So classically when you look at large organizations then of course there are a number of applications and services operated some self-implemented some purchased from externally and they all have their access management systems usernames passwords everything of course sometimes they're single sign-on so some are put together but today also in practice there's usually many of them and that leads to the fact that clients of such organizations still have to receive multiple sets of access credentials which of course is a very high management effort so you have a low scale but you do have a high control because it's everything under the control of the organization itself in-house.
And then of course we have these identity providers mostly cloud-based that allow for reusing of identities which brings a much better scale but also lowers the control because now neither the offerer the provider of the service nor the consumer of the services controls the identity that is used to basically access these services. But luckily we also have the advent now of decentralized identity systems for example in the EIDAS context in Clive's VLEI of course that gives the control over the identity to the users and the consumers of the services.
So they bring their own identity and that brings on the one hand side a high scale because the providers of the services don't have to manage all these user accounts anymore, don't have to reset passwords if something is lost, if there is a new person onboarded the user organization can authorize their staff to have certain roles and don't have to request this with the provider of the service and at the same time there's a high control because the control is with those who should have it which is the users of the platforms of course.
Now I would yeah and this allows for decentralized identity and credential management cross-platform data networks. And I mentioned already at the beginning we have worked with Esatus who have a product called Soul which exists already for a couple of years and it allows to basically convert any verifiable credential presentation into a classical IAM access protocol like OAuth or SAML or all the things that are around it as a list of standard protocols that is supported. And why is that important?
Well because organizations won't redo their whole IT infrastructures just because there's now a better way of access management around the corner and that allows basically to bridge this new access world into the existing infrastructures. And we have used this tool and worked with them together to also support the VLEIs. It's called the VLEI Authenticator and that allows to connect VLEI presentations to exactly as accessing any standard software. What you see here on the screen is Glyph's communications portal.
It's based on a standard software called Nextcloud and what we have changed now is that from using a username and a password there is now also this login with VLEI button and I'll shortly show you through the user experience here. So the user basically just opens that login screen like before but instead of using the username and the password they select login with VLEI. Then they are redirected to the VLEI Authenticator service which is locally hosted. That means the provider has it under control and clicks on select credential. Selects then the login method credential.
Selects their VLEI role credential that they want to use to authenticate themselves and clicks on sign in and that's basically it. The user is logged in and authenticated and that without basically requesting first with us a new user or the right role that is predefined and based on the role in the credential it is identified what is the authorization of the person then in the portal. And that brings a number of benefits both for the service providers and also for the using organizations.
So first of all for the providers of course the effort walks away to create new user accounts, reset passwords, all these efforts that the service desk usually has to deal with. There are no scaling issues because it can be used across multiple systems or even the same credentials can be used to authenticate the same person from the same organization to multiple of these technical applications and services. There is a unique identification of users based on the three items that I showed earlier in the VLEI credential, the LEI code, the name on the role.
That means the service provider knows exactly which organization and person and which role they are dealing with. The role of course allows a clear authorization but also permissioning based on the role. So depending on the role the rights that a person has in the service can be derived. And with such tools like the one that ISRTOS provides there's also no change really needed to existing systems because the established protocols inside the network of the provider can be leveraged.
For users or respectively user organizations there is no dependency from service providers anymore to make changes to register new persons or to change permissions or even to revoke credentials. There's of course full control on the authorization and permissioning of users in real time because these credentials can be issued and revoked and effectively immediately updated.
And lastly there is this opportunity to reuse these credentials not only across multiple applications of the same service provider but also across various service providers and that allows for these data networks across company boundaries. And coming back to the title of the presentation from trusting the channel to verifying the source and the content.
So this is how organizations can basically switch to verifying the source because they don't have to trust anymore that let's say a username and a password has not been shared with somebody else and that it really ended up with the right user because they're verifying with each authentication the identity of the person in the organization. And VLEIs also allow for digital signatures to any data content and that is basically the next step that we're looking at.
That the content that is exchanged on this partner platform is also digitally signed and that means even once the content any files leaves the platform and is for example transferred via an insecure channel an email for example by that digital signature you can always trace back who originates this from is it valid has it been modified and all the advantages that you get with digital signatures. And that brings me to the end of the presentation. Thank you very much. If you have a question I'm happy to take them. Thank you very much. So we have one question, two questions right now.
Let's double check the other one. Does VLEI fundamentally change the role of traditional identity and access management systems? That's a very broad and good question. So I mean as I mentioned the existing identity and access I mean as I mentioned the existing identity and access management protocols don't have to be changed. That's the beauty of such bridges like the Hisatos VLEI Authenticator slash sole product because it leverages these. But of course it changes the role of identity providers from an organizational space.
So if you remember the slide with the three circles the middle one is of course something that you can consider if you require that and if that really brings value if you can have self-sovereign identity really with organizations. Perfect. The other one is a bit too complex for stage so maybe the person asks just afterwards. Thank you very much for presenting. Very interesting. Thank you.