Thank you all for staying until we have lunch. My name is Annet Steenbergen and I'm an independent advisor on digital identity wallets and a strong focus on travel. I'm moderating a panel with a very simple question. Global Trust at Scale, are we finally interoperable? Just a tiny little question. And all the panels and presenters leading up to this in this room were discussing around this. We will deep dive into how do we get there. And to quote Heather, we have three digital identity diplomats here because that's what indeed I think we all need to be. I fully agree with her.
So before we start the discussion, please introduce yourselves. Graham.
Hi, my name is Graham Francis. I am the head of international in the UK Office for Digital Identities and Attributes, OfDIA. Our job as a whole is to enable the use of digital identities across the UK, including by setting trust standards and assuring these standards are met through our certification system. And my job within that is to explore how we can achieve international interoperability while still meeting those trust standards. That's just a small job.
Yes, Rachel. So I am Rachel Salung. I am a researcher at Fraunhofer Institute in Germany. I've been doing research in trust frameworks for almost a decade, where I've worked on various EU projects and currently working with the City Hub program. And Fedra.
Yes, hello. My name is Fedra Lalic. For the purposes of today's discussion, I'm wearing a hat of Digital Identity Advisor for the United Nations University Digital Government Research Unit. Great.
So, to dive right into it. Why is a global scale interoperability so such a difficult challenge? Who wants to go first? We're going right to the top. The ideal situation. It is a challenge.
I mean, it's really difficult to say what Heather's just said. Less eloquently than that. And I'm just really grateful we've got thought leaders like her in the space. I think often part of the challenge is the word interoperability itself. Because that often kind of gets in the way. And as well as being quite hard to say, it's quite a technical word that implies technical solutions. It sort of implies that you can geek away and plug systems into each other. And if you get the APIs right, it'll just work. And that's you interoperable. And obviously, we know that's not the case.
We know that while technical interoperability is important, it's not the only thing you need to solve if you want to do cross-border recognition of identities and attributes. And you need to look at things like existing laws and standards, data flows, privacy. From our point of view, it's critical that we know that when people's data leaves the UK, they can still trust it's going to be protected to the same standards as in our country. And equally, when we take data into the UK, we need to trust that we know where it comes from. It'll work within our ecosystem.
It involves things like finding real-life use cases. There's no point in being technically interoperable if you've got no relying party with an incentive to be at the other end. And political ambition. In particular, if like the UK, you're trying to achieve interoperability outside the context of an established regional partnership, you're sort of dependent on what sort of policy you want. So I think to finish off, then the challenge is with that bigger scope, interoperability becomes like everything, everywhere, all at once.
And so the challenge is then how you break it down and how you established common methodologies and frameworks. And so going back to what the World Bank was saying earlier on, it's actually how you can break things down into components that can move you towards the goal in a manageable way. I like what you said about the word interoperability.
Indeed, you're right. I think it sounds very technical. It's like if we connect the technical dots, we'll be there.
Rachel, of course, that's not enough. And you've done a ton of research, 10 years of research on this. So what is your view on how we can get there?
Yeah, that's a big question, of course. I definitely agree with the challenges that you've stated. And I mean, there is no universal standard of how to do trust frameworks.
So, of course, it creates a more pragmatic approach. But I think that also is how it should be. And I think if you would provide the tools to facilitate, to be able to verify or translate or to work with the trust frameworks, this is probably a more likely to be successful strategy. Let's see. We've done a lot of research that have tried to create such a tool.
But, of course, like it's important to have these kind of environments and exchanges outside of research to talk to the stakeholders themselves, talk to the governments, to the industry, to kind of bring it outside of research and make it more applied and more used. And I think that that's something that we personally are trying to do more often to help this endeavor to actually create something that's more interoperable. Like POCs and just Nike principle, just do it. You have to start.
Yeah, you have to start. Yeah, that's an important one.
Vedran, do you agree? Yeah, and I think actually EIDAS is the kind of proof of concept right now that is, I think, gaining traction globally. And I think for me, the way I see the way towards global interoperability, I think it's going to happen via regional integration first. My hypothesis would be that regional integration is sort of the model that enables the scale necessary for these interoperability proof of concepts to be validated. And I think regional integration also offers the scale necessary for the uptake of digital identity and trust services.
I think no individual country today is well placed to do this alone. I think really cross-border by default is something that every country should consider as part of their approach to digital identity. And I think also, you know, if you look at EIDAS 1, we saw that, you know, it failed to deliver results for almost 10 years. So obviously framework alone is not, especially voluntary frameworks alone, are not sufficient. I think where EIDAS still made sort of a quantum leap forward was by mandating the acceptance of wallets in the private sector as well.
And I think this is really what's going to kind of deliver the scale and different use cases that will sort of organically evolve from that point on. And I think also in the case of the EU, you know, really what's driving the demand side is the commercial and administrative aspects. So I think as more and more Europeans are mobile and travel and work across borders, the wallet in itself becomes really a practical tool that, you know, helps you on a daily basis. So I think that's part of the appeal. It becomes more than just, you know, age verification or something abstract.
It really becomes a practical tool. And I think, you know, we're showing, I think the EU in that respect is a good sort of a template for other similar frameworks that are now evolving both in the Asia-Pacific region, in Africa, in Latin America. I think increasingly we're seeing sort of similar models emerging, of course, being adopted to the specificities of those regions. But definitely I see like now EIDAS becoming a global model that others will follow. So from regional, you say we should go to global and we have the practical use cases that are actually driving the adoption.
But if we then take it at the maximum level, so what are the synergies? What challenges are shared and where could those synergies push towards interoperability? Because I'm thinking, again, going to that.
Well, I think right now one of the key sort of inhibitors of, you know, moving towards global interoperability, which is, I think, a long-term process. It will take time to get there. I think right now, from my perspective, it's the question of sovereignty. Because really, you know, digital identity is something very different than payments or child credentials. It's a sensitive political issue for most nation states because it really goes down to the question of who controls the identity, you know. It's cultural.
It's cultural, but I think it's also institutional in a sense that, you know, member states, I'm talking in EU-specific language, the governments are very sensitive when it comes down to sharing data of their citizens. I think this is sort of the, from the political perspective, from the political economy perspective, one of the key inhibitors as to why, you know, we are inching very slow and making progress at a slow pace.
Of course, EU is advancing, but of course, again, in the EU, it was a result of, you know, political consensus among 27 member states that this is, in fact, the direction that they want to go in. And Graeme, going back to the basics, we saw the presentation yesterday from your CEO, fantastic. UK is moving ahead with the digital identity framework as head of international. What is the UK doing to prepare for interoperability and what are the trust anchors you're focusing on?
Yes, thanks. And, you know, as you implied in the question, it is all about trust at the base of interoperability.
I mean, I think we've probably done about four really important things to build trust at a national level that can then be extended internationally. They're things that are probably fairly standard, you know, different countries have got different ways of doing them, but I think they're all really important. The first is to actually set the standards.
You know, we've got a digital identity trust framework, a UK version of it, which sets our standards for secure, trusted digital identity in the UK. And that includes things like privacy, security, technical standards. And we've built it in the open. I think that's quite, quite important. So we've built it through iteration and consultation so that we can be sure that the standards are robust and they'll be used, they'll actually work in practice. And we've also built them in partnership with our data regulator because, you know, privacy obviously needs to go through it like a, you know.
But then it's sort of not enough to just write the rules. You need to make sure they're being followed. And so independent certification is also at the heart of our system. So we've got a network of conformity assessment bodies who independently assess services against our trust rules. There's 60 or more of those services that have been assessed, including government's own verification services, because it's quite important to show that we follow the same rules as everybody else. And then finally, I think it's not good enough for us to know what's being checked.
It's important for other people to know that too. And so we've got a digital verification service register, which is a digital service that displays all those certified services and a trust mark so that people, normal people can see at a glance, like what's trusted without needing to look through hundreds of pages of technical information. And so we've got law, new UK law as a sort of foundation for all of that. And as I was saying at the start, these things all absolutely lay the foundation of a trusted domestic system, a transparent one.
So then it can be sort of allow the foundations for us to extend that globally. Yeah, that's fantastic. And it's exciting times to be working on this. And Rachel, I'm really interested to learn about the research you've done and especially the tool you've developed to translate between trust frameworks, because that could be a really crucial tool to speed things up and create understanding and with understanding you also create trust.
Yeah, absolutely. So I think we've developed a few different tools that could be helpful in this space. I also think that the City Hub program, they've really taken on an initiative to kind of branch out, creating tools or like material for countries all over the world.
I mean, we've heard a lot about like Western established countries that have had existing trust frameworks and have done a lot in this space, but I mean, it shouldn't just stop there, right? So I mean, they're working with African countries and Asia and all over and I think that's a really important initiative to have and to have these kind of tools that have been made or that hopefully will be made to facilitate that everywhere can have this interoperability opportunities. But of course it's important that we have more established trust frameworks as well.
So the, yeah, one of the main tools that we've, we've made is basically something that would be able to verify and translate between trust frameworks according to their own preferences in the lightest project. However, that ended in 2019 and since then we've had various use case projects with the UNDP, with the UNHCR, T-Systems, EPSI and very different use cases.
However, like we are really trying to find a way to bring those kind of technical solutions to life. But I think one thing that we are working on currently with the City Hub program is to create material or other tools like a compatibility check, where new trust frameworks or existing ones can kind of see at a glance, first a high level perspective of a gap analysis of what things do they align on, what things should be further considered and yeah. So those are some of the, some examples. Some examples and you're continuing developing this?
Yes, yes, yeah. And where will it be? What use cases are you working on or is it deployed anywhere?
You know, if we, I have a talk on Friday at 10.30. So if you want to know more about the work that we're doing there, I would suggest to go to that session. It's more of a winded response.
So, for the sake of time, I think we have just one final question. If we talk about trust frameworks and trust anchors, those are basically usually legally translated in regional or national law. If we have to come together to get to that interoperability, we need to be able to cross jurisdictions. And I think, you know, Heather's diplomats are called for again. But what do you see? How should this start? Is it the geopolitical situation currently?
I see, you know, the EU is really actively working together with a lot of larger countries right now. So is that it? Or is it meetings like this? Or is it trade negotiations? I think it's a combination of a lot of different things. I think in terms of, you know, keep it short. I think there's an interesting template that we have at our disposal, which is called European Interoperability Framework. And it lists four different areas that are important for interoperability. And I think it can be also, you know, used as a global template. So one is legal interoperability. Another one is semantic.
So the workflows. The other one is organizational. And the third one looks also at interoperability at the level of systems. So I think, you know, these are kind of the building blocks that we need to have both at the national, regional, interregional, exactly, to make this really feasible at the global level. And Graham, it resonates with you? These building blocks for interoperability as a diplomat, digital identity diplomat?
Yeah, I mean, I think certification and assurance is really important. I mean, one thing that we hear quite a lot from companies, companies want their product to work globally. One of the things they're saying, well, why should we have to do the same tests again and again and again in different jurisdictions when we're proving the same things? So I think there's something quite interesting about as the sort of international certification, independent certification processes evolve and mature.
Is there anything stopping different auditors accepting and building on the results of sort of different certifications that have been performed already? So that's something that might be interesting. So final word for Rachel.
Yeah, I can only agree with what you've said, but I think all or both of you have said, but I think just, yeah, having open transparency about these decisions. I think this is definitely a key factor to, yeah, everything going forward and being able to be open and having these discussions on every level. So these building blocks, and then we have the certifications that are globally trusted.
And then, of course, without transparency, nothing happens. So we have our diplomatic work cut out for us. Thank you so much. Thank you for joining.