I'll ask my panelists up to the stage, which are Stina Ehrensvärd from Yubico Zeroes Foundation, which is Nick Lambert from Dock Labs, and which is Florin. Okay, it's a fair argument. Stina says we better stand around because otherwise we are not really visible in the room. That's fair. I think there are some microphones hopefully around. I think there's one here.
One, two, here we go. And we have Florin Coptil from Bosch.
Maybe, Florin, you come a bit closer to us here. Yeah, so I would say before we come back to your question and to maybe other questions we have, maybe we start with some quick introductions of you.
So, who are you and why are you interested or why do you feel you have to say something about this topic? Ladies first, Stina.
Oh, thank you. I'm the co-founder of Yubico. We are the leading driver and innovator behind the FIDO-PASCIs open authentication standard. And I am super excited what Europe is trying to do now. Combining digital identities with PASCIs is for me the solution. And in serious foundation that I created with some of my peers in the open identity industry, we are aiming to build the Linux for wallets. You're absolutely right what David said. We shouldn't make money on wallets. But we need to build a stack of open source, open standard components for all the use cases.
And then other organizations and businesses can build their red hats on top of that. So, that's just sort of my intro.
Hi, I'm Nick Lambert, co-founder and CEO of DocLabs. I think what interests me most about this is I actually don't think I've seen it as a major barrier to adoption globally, the lack of ways for companies, organizations to make money. I think decentralized identity has definitely been much slower to adopt because of that. We're asking often complex organizations to adopt new business models, change the way they work, integrate new systems. And there's absolutely no reason for them to do that. There's some regulation coming down from EIDAS, which is a bit more stick than carrot.
And I think we need to give them some carrot to help it along. So, that's my interest in this topic. I think it's essential for the industry to really kick off. Florent Kopter is my name. I am from Robert Bosch GmbH. This is a company in Germany, also known as Bosch, and responsible for the digital identity and organizational wallet. And one of my main topics is how we can use the organizational wallets for different use cases, especially in corporates in the first area, but also go beyond that.
So, how we can use these wallets or this identification for assets, manufacturing, or other processes, which are available on the market. Which I think is very interesting because we are talking here about the use cases number 7 to X or to N, because these are some of the business models I haven't covered. And that might be one of the interesting questions to discuss. Maybe this is where we have the entry path into organizational adoption. Way easier than maybe when we look at trying to get all citizens to use it and all other organizations to be a relying party.
So, I think that will be one of the themes we should look at, because maybe our perspective is, in some sense, depending on where you are. But I think when we look at just the large scale pilots of the UDI wallet, then if I count healthcare more on the government side, then I think four out of six are government use cases. And maybe we need to look at the other side much more. And that's, I think, something where we then truly should talk about.
So, thank you for the introductions. And I'd like to pick up that question, because I think it's an important one.
So, there was an agreement on if we can improve a business process by that technology, we have a huge potential, because it's been about real money. So, business process costs is something that resonates very well with the non-IT part of the organization. And that's what I understand. If we talk about verifiable credentials, they will look at us as we just freshly arrived from Mars or so, and don't have a clue about what we are talking about. And I think that's a fair point. What about the regulatory side? There are two things, I think, in that I believe.
The one is how trustworthy are verified or verifiable credentials. They are not verified, they are verifiable, from a name at least. That's the one thing. And the other thing is might regulations become the roadblock for certain use cases? Any opinions on that?
Nick, do you have an opinion on that? Yeah, I mean, for me, they are definitely a big roadblock. I think like where we've pitched as a company that's kind of working and building in this space, I'm trying to commercialize it as well. An easier use case for us to explore is with very large companies. But there's an umbrella company, and then there's multiple business units that sit underneath that.
And they would benefit from business efficiency, because often an end customer goes into that organisation, maybe they're signing up for a bank account or something like that, and they go through a KYC process. And then they go to the credit card part of that same company, and then they have to go through that entire process again. But what if they got a credential the first time that they onboarded with the current account, reuse that credential with the credit card company?
In that instance, the other business unit can, I think, rely on the credential from the other business unit, because it's part of the same company, and they know the processes. So I think that's an easier way to think about it. But I think across other industries, particularly high assurance, there's definitely a legal roadblock there for sure. But it's an interesting point you raise, because basically you say, okay, in that case, because you stay within the organisation, you're less affected by the regulatory side. You did it within your organisation to prove, and then you just reuse it there.
And even that can save in large financial services, for instance, that can save huge amounts of money in process costs. And it's also business silos, Martin, as well. If you think about a large company, they have multiple instances of dual blogs. There's 20 business units, they have 20 dual blogs, and they actually don't know who Joe is across the organisation. And Joe has a terrible experience every single time.
So it's not only about business value from that sense, but Joe, who I keep referring to now, who's obviously made up, has a much, much better experience, because he's not having to fill out endless forms all the time. So I think that's another benefit that's often missed. Florian first, and then Stina.
Yeah, so I totally agree. So what we saw it in the last pilot, so where we are participating, so like the AVC consortium, and we are going there also in the WeBuild, there are exactly these two use cases, like New York customer, New York supplier, which for us, we are playing the board roles. And there we see for two categories of the benefits, one short term, so where we have exactly these benefits inside the corporates, but we have the big benefits afterwards when we go to the external market.
For example, we want to make a KSC with a bank, and there is coming exactly this regulation, how we can use this attestation, which are already available, and what is the legal binding behind. And for that, I can recommend to reach the AVC consortium, there are already right rule books in this direction, how they can provide the technological and regulatory framework for that, but also how we can make this legal foundation that this attestation can be used afterwards, for example, in cross-border cases over the company digital law directive.
So I would like to put up an even bigger number than the hundreds of millions saved in KYC. Cybercrime today is 10 trillion dollars globally, the world's third largest economy, and 80 percent of this crime is due to stolen logging credentials and identities. If the current identity siloed identity system had worked, we would not have an eight trillion dollar problem.
But if we, with the help of EU, who's really brave and cool and bold, saying, hey, we're going to solve this problem, but because we are going to lay the roads and we're going to pay for the roads together with the different countries who are going to issue the identities that we can link to and reuse for organizations, for payments, you know, for everything we need, you know, take the cost for the roads so other can drive the cars. So if they do that, we actually have a new blue ocean. You said this is a little red thing, it's a little blue thing, it's a huge thing.
It is the next generation secure internet. I think I wish it relates a bit with what I had in the final slide on in a bigger scheme and I think I brought it up in one of my other talks that I think what we a very nice thing, and I think we had it also in your podcast recently, a pretty nice thing with decentralized identity is that if your wallet is hacked, it's one. If this silo with two million or five million identities is attacked and hacked, it's two or five million. So it makes it, at the end of the day, way more difficult to run attacks at scale.
So all this business around reselling stolen passwords, credentials, other stuff will disappear at the end of the day. Probably they will figure out new ways, but it's way harder to do that.
And yes, there's at least a cost model behind. The question is a bit, I think for an organization, it's a bit of an indirect thing. That's the other side of it. So an organization says, okay, that's cool because I reduced my risk, but if they can save both business process costs, then it's even more attractive to them at the beginning, initially, at least. And we need to build on pass keys because it's the only authentication technology proven to stop account takeovers at scale for the modern web for mobile. It's built into all computers and phones and browsers. So we already have it.
And you can, for some use cases, use external security keys, but the underlying technology is already approved by the tech giants. Because what I see in this whole project that we're now discussing, we need to get the tech giants with us and we need to get the regulators. And there is a war now between the tech giants and Europe. And how do we mitigate that?
Well, we mitigate that by just building on the existing standards and technologies that all the tech giants have already approved on. So we don't have to ask them to do too much. And then we have a close dialogue between the tech giants and Europe and say, where can we give and take? If Europe and the tech giants doesn't agree on what we're going to build, we're going to fail. So that's unfortunately, that's the reality.
I think it also comes from another end, which is, you know, at the end, if I have something which works for most use cases, and the UDI wallet is mandated to be used for government use cases, I may end up with saying I just use it for the government use cases. So if we make it interoperable, we will make it much more valuable, much more successful. I think this is the other side of it. So we need to definitely think about it.
Nick, you're definitely looking at like you want to add something here. Yeah, I was going to say as well, and this is probably not specific to just the UDI and the topic was decentralised identity broadly. And I think the other thing that we see, like we have, like companies like Amazon, the e commerce company, not the not AWS.
And they're really excited about, about, you know, reusable ID, and digital identity is because they at the moment are what they see as verifiers of individuals coming onto their platforms, they don't really care about who you are, but they care about how old you are, in many cases, they're talking about age restriction. And it's expensive for them to actually verify how old someone is.
But they're excited about things like MDLs, mobile drivers licenses in the US that are in digital form now, because it basically turns them into what they call a being an acceptor, which we would probably call being a verifier. So they're actually really reducing a lot of cost and able to prove and have a liability placed somewhere else that's not them and bring customers onto their platform really quickly, and really, really cheaply. And they are not going to liable for it. And that's happening this year. Anything to add here? You said the UDI wallet. So we said UDI wallets.
Yeah, when we discuss in the business context, normally, so according to what we saw till now, is the UDI business wallet cannot live alone. You need always an interaction. There are very, very less use cases where the UDI wallet, so the business wallet, your business wallet can interact alone with other agents and so on. But normally, you always need a trigger. And this trigger, it's a person. And that's why you need a personal wallet. And that's why this interaction, we hope that will also scale also the usage of the UDI personal wallet in this direction.
I love this because that really sort of fosters a point I make for a really long time. Latest, when you think about the employee in an organization, you are in a multi-wallet use case. So there's no such thing as a single wallet approach, because this is exactly the point. Latest then, you inevitably have more than one. And I think that's really important that we think in everything we do in multi-wallet and also different routes of the wallets, different providers potentially of wallets use cases. I'd like to come back to a point you've made, Nick.
And basically what you said is, no, so Stina made it, I think probably both. I think what you said basically is implicitly at the end, we need standards and interoperability to make all this a huge ecosystem, not some silos. Did I get this correct? Amen. Okay.
No, but hey, this is such a huge effort. If this is really going to work, if we're going to solve the $8 trillion problem, it has to be everywhere. And how can you get everywhere? It has to be standards. It has to be beyond EU. The tech giants need to agree or not. It needs to solve the range of use cases and you need to get everyone on board. It's almost impossible, but what is the alternative? The alternative is the internet will fail and we'll go back to carving things in caves. So that's not the option.
The option here is actually close collaboration with the tech giants and EU and innovation companies and any of these organizations trying to solve this huge problem. But I am absolutely, I'm so optimistic that it's possible because most of the buildings blocks are already there because OpenID is there, it's already approved by everyone. Taskies is there, it's already approved.
You know, ADAS have put in out some pieces that says that makes sense. And then, you know, their ISO standards to pull information from a phone into a wallet. If all the governments also now agree on doing that, if EU agree to build the roads for this European digital identity wallet sort of ecosystem, and all the countries go out and refine their processes for their passports and driver licenses to work, that is the major investment done. And on top of that, there will be innovation and new business cases being born.
Yeah, the only thing I'd say, the standard stuff is definitely the case, but it moves at a pace which is understandably slow, because everyone needs to be, it needs to be socialized and people need to get on board with it. But if you're then trying to create some of these business models, if you follow the standards, there is no standards right now to monetize credentials. And so if you wait for these standards and you stop innovating and wait for them, which I think we're probably prone to doing somewhat in the EU, we maybe could be a little bit more risky in what we do.
I think you need to follow standards as much as possible. But if you're looking for some of these new features, you need to sometimes leave those standards behind. So I'd agree fundamentally with what Sten is saying there, but I think there are cases where you can't just be all about standards all the time. I agree that we need to have standards and we need to continue to innovate and just show, hey, what about this? So every organization who's in this wallet ecosystem shouldn't just sit and wait for EU.
I think it's an opportunity to do a lot of pilots and tests and put out blogs and demos and say, what about this? And then everyone has an opportunity to look at the innovation and start making decisions on what are these innovations that actually would work. And I think it's also important.
I think you, Florian, you already brought up some initiatives that are running in the world, which is maybe not as much of the focus of the people who spend a lot of time or many of the people who spend time around decentralized UID wallet, which is more the organizational side of things, the business wallets, et cetera. And I think we also have other things that are going on there, like take GLIFE, the Global Legal Entity Identity Foundation. So there's a lot of identity stuff, which is not just around a human already going on.
And I think early in July, July 1st and 2nd, there will be an event in Geneva where some 30 non-governmental organizations meet and where you have whatever World Health Organization looking at prescriptions and stuff like that and the way that can be used in this context. So I think we see a lot of things going on there, which are very global. And I have to say, I'm fully with you. I think it will only, the world is global. So things will work when they are global, not when they are limited to reach.
On the other hand, I think a bit of the thing behind the UDI wallet is this foster the digital economy, the business in the EU. So in that sense, clearly there might be always a bit of fear, again, the tech giants will rule all.
Well, if we build it in a mindful way, we can give a little to the tech giants, but we can have some control here in Europe too. It is possible to get there.
Right now, if we don't do anything, the tech giants, they'll continue to innovate and it may not actually be. I'm a little scared of that future. Okay. We need to rein them back a little. Okay. There seems to be a question that came in. First of all, I started a poll that is in the background and he's blinded by the QR code.
Oh, yes. That's what I said. You can go over there much better. If you scan the QR code, you can take part in the poll. You can leave your questions. We have two already just for you from the moderation standpoint, whenever you want to bring in questions from the audience that's there. And once you've scanned the QR code, you can add your questions. So if there are questions. Yeah. Okay. Maybe one is maybe for the enterprise use case or for the business wallet. What about the problem that for adopting DID inside our enterprise for workforce in the broad, we can't force them to use own devices.
So this work with this, this workers council issues, how do you deal with that to make sure that everybody who needs access to this employee business wallet actually has access to them, to these applications with the proper device? Yeah. So this is a good question. So it's go more in the direction like Martin said. So we need to support this interoperability. That's why, for example, in, uh, we write interoperability tests.
So, and this is not an easy job. We can see that in a VC, we run this interoperability test between the countries, especially for only check the identity of the organization, cross-border in cross-border cases.
Now, imagine that we have an employee, which sitting in another country and he was, and has another wallet, which is another conform, how we can be sure that everything is working. That's can be done, but, um, it's a lot of stuff to test the interoperability conformance test and so on. Right. Okay.
So I just want to add also, we need to build systems that are not only dependent on phones because not everyone have a phone and there are areas where you don't, cannot come in with a phone because of, and there are areas where you don't cannot, or don't want to use your personal phone or the phone is, is lost. You need to build a system that works across computers, phones, across platforms, across browsers, and, um, but allowing for the past keys, um, Fido ecosystem, then you can also bring in external cards and keys that can help solve those.
I think the point you make is speaking to my heart. Um, I don't have it. I have the other phone in the back, but when I talk about it, I always start with pulling out my two phones, the personal and the business phone. And then I say, okay, and I have on the one side, I have an iPad on the other side, I have a notebook, I have two desktop computers. And in business, a lot of stuff will be done from desktop computers, from rock devices, from whatever else, uh, or, or in some restricted environments, we still need to do certain things depending on what you do.
And then it means very clearly, yes, there's again, more than one wallet. And even verifiable credentials will sometimes need to reside on more than one of these devices.
So, which, which means we need to, to have the sufficient openness to really support the real world use case. On the other hand, I think it's also totally normal when we have an evolution like that.
Uh, we start with definitions, we start with ideas, we start with standards, then they hit the reality, which I think the first contact tends to be tough. And then we learn from that, we improve.
And just, I think what is definitely already happening, we, we are starting to, to improve, but, um, I think we also really, but it was a thing we discussed more yesterday. Um, but, um, here, if we talk about the use case, I think we also need the division for that. What is the story we can tell that everyone or the right people understand like your story that is resonates with the business story. It's easy to relatively easy to tell in the business, because there's a real problem you can address better than without. Right.
Just, just as a reminder, also to you, the poll is about the question, um, would you be willing to pay for identity verification or the use of wallets? That's the question with three options. And maybe I'll give the answer or the feedback afterwards. So whenever you want to bring it in, but there's another question that's quite nice. It's a bit, I don't know if it's tongue in cheek, but can you compare the business model, which Google has with signing with Google to the verifiable credentials use case? Where's the difference? Where do you add to it? Why is it better?
I don't Hopefully, hopefully it would be different. Uh, because obviously they've got kind of surveillance as a business model. And I think what we're trying to move to here is a world where the individual is actually holding and controlling that data.
Of course, once they use it, it's gone, but I would hope that it's radically different from the way that Google sees the world. Right. So it's a totally different value, right? This is totally agree with that.
So, uh, for the consumer area, there are all the regulation, which specify in specific sectors, for example, finance, they must to approve, uh, they must to support the wallets. It doesn't matter what kind of policy is there for the natural, the heuristic person, but there are also other laws which, which are coming right now and which enforce to use these digital wallets. For example, the digital act, which, which exactly specified to have a secure environment, the transportation and logistic that you have a transport system, which must to be secure.
And also in the direction of digital product passport, how you can identify consumer organization in a digital form, very easy. So that's exactly this informal enforcement of the using of the wallets. It doesn't matter if it's a personal wallet, natural organizational, it may be future asset wallets. You don't know.
But, but there, there, there are two types of scenarios of that. The one is very obliged to, to use it, um, product, um, passports and the other is where a relying part is obliged to accept it. The second one differs from the first one in that, yes, they may be obliged to accept it, but it still doesn't mean that the users are using it because there will still be alternative ways. So I think there are the, the ones where you, you are restricted to that, which will need to be adapted.
Um, if there are sufficient regulatory pressure behind it, they're the ones where it's, um, an option that must be provided, but where the user at the end of the decides, do I want to do it or not? And their, their usability in other things will win. Yes. Not regulation. Totally agree with that. But that's why we said that using the organizational wallets, you involve also the personal wallets and then it's here. Imagine that it's there. You must use it because you are a business.
So you interact anyway, every day with businesses, then you can scale it maybe for exactly because you're used to it because it's convenient. It's like with most of new technologies, once you get used to it, uh, and it's, it's good to use, uh, so I was a cash person very long. I have to admit, so I'm older and so on.
Uh, I'm a, I'm an Apple pay person nowadays. I have to admit. So most of the payments I make is that way. And finally, the introduction point was my local bakery, uh, which, which, uh, introduced this, uh, way of payment.
I said, Hey, let's try it. So until then I, I didn't do it.
So yes, once it's convenient, we tend to use it. I mean, what we are aiming to build should be as convenient and as the Apple and the Google payment, and they are leading the way in terms of UX. I'm also in Sweden where the Swedish bank ID, I think you said like we interact with our governments like 10 times a year, but in Sweden we interact indirectly where a banker with our governments almost every day, because majority of all payments are verified through the Swedish bank ID system.
And that's a very easy and sort of established user experience, uh, that has sort of laid the way for this, whatever we're, you know, this wallet cool thing we're building, uh, to look at. So we, so is inspired by Google and Apple, like amazing, great user experience that you've agreed on. And then the Swedish bank ID that is also a good user experience. And then how do we then take those, that experience and see that both of those have actually scaled enormously? Why cannot this also succeed based on all that experience? And I am absolutely a possible, I'm an optimist that it will.
Ask me again in one year. Okay. Yeah. So just to make my point, for me, a government use case is when I really want something from the government.
So, so if it's the, if I pay something using the bank ID, I wouldn't count it as a government use case. It's linked. Yes. I go to my bank where it's a link. It's not a derived, but a linked identity. And I think that is the secret sauce here that all these wallets will be linked with identities provided by a government. If the government doesn't step up and do that job, it will be very difficult.
Honestly, I, I'm sure we have a couple of wallets probably, hopefully not too many, but we don't care. Hopefully at some day what we have. So it is trust that, um, the right, verifiable credentials, credentials picked from the right wallet for the use case needed. That's pretty simple for me as a user. That's what I want. You could almost have like one wallet where for this government or private company, it doesn't matter, but you could have like a bunch of, of SDKs just feeding into that wallet and you maybe have multiple wallets that you don't even know about.
But as a user, you've effectively got one wallet on your device or in your, whatever glasses are going to come out and you're going to effectively be using that, but you potentially have multiple wallets behind it. So I think it's the combination of public and private wallets is going to be key.
Yeah, exactly around that. There are two, two questions. First of all, um, maybe that wasn't really completely clear. What is the business case of a business wallet?
A and B, why different wallets for use cases where in physical life you only have one. Okay.
So, uh, first question I can answer in 20 minutes where we describe where we show exactly how it's working for, uh, know your supplier and know your customer use cases. These are these short benefits, but we see for the corporate perspective, why? Because they're not covering the complete identification process with actual regulation and actual, uh, legal foundation, which is now we can cover only half of them, but we'll come.
And regarding the second question, um, so it's more, um, when, when you say, okay, we want to integrate the persons we want to integrate organization, how we can do that in a very easy form. And the most important point is the interoperability there. And with this one, we can achieve the, the, the use case from this perspective, the targets. Okay.
Um, yeah, go ahead. I am really excited about this three types of identities. This is new wallet system will allow one, which is basically it's the same information that's on our passport. One where we, um, give what is needed for that service.
You know, maybe I just have to share that I'm a woman or I'm over 20 or I am in whatever for that game or, you know, and with that, I'm not sharing any more information that's needed for that service. So that can't be misused and hacked. The third one is however, even more interesting because 60% of all identities on the internet are fake or bots and it's driving our democracy and free world into disaster. So if we have a way where people can actually be anonymous yet verified, I am a real human.
Now, when I go in on social media, I testify that this is not a fake robot. That is a new kind of identity opportunity that we haven't had in the past that the government doesn't do. The Googles of the world doesn't do, but Europe has set up and said, we're going to do it. And that is a big paradigm shift. Maybe short question. You said before, why don't you use one wallet for the natural person? Right. I'm the proxy. I'm just handing over the question.
Um, we analyze that. So if it's exactly, was this question, can a small company, a small medium company use a wallet for an onboarding process? They can use it. But at a specific level, for example, knowing in the KSC process, you must make these periodic reviews, changes, uh, your company, uh, for example, suddenly has changed your form or your address is changing how you want to inform that. And officially we have a definition for that.
So in the moment that the pit is stored in the wallet, we discussed about personal wallet in the moment that the legal pit, which attests the existence of the company, according to the national register, you discuss about a legal entity wallet or a business wallet. And that is going exactly in the direction. What's happening with tomorrow. I have an asset, which is an agent, how I can give his identity ownership facility services, which can be provided and can be used for, uh, for other businesses. Models. I wonder it's also a bit about context as well.
Like we might have an email address that we only use for personal stuff for various reasons. Like it's probably an address you're going to have for longer than maybe if you, if you change jobs every few years. And I wonder if the kind of differences that you might have different wallets for, you might have one for your personal life and you might have one for your business life as well. It's like to your kind of example of two phones, uh, Martin. So I kind of wonder if context will also dictate how we use wallets as well.
I think there, there, there are a lot of things we need to learn and, and maybe also back to the question, why, why should we have more wallets if they have a physical app only one, because there's more in depth. I've talked about tens of thousands of verifiable credentials. If you try to squeeze them in one wallet, it might be a bit small.
Anyway, we had this question, would you be willing to pay? Um, for some reason, the, the, the survey tool we are using comes up with, um, pretty weird numbers. So the data seems to be good, but it translates it. So there are currently 18 responses and the results are two 0.67 and 0.44. If I do the mathematics, it basically means around 60% said, no, we are not willing to pay around 23% maybe said, yes, the value of decentralized identity for myself is obvious. And we need to be very clear. We are in a totally biased group here. So in the real world, it probably is way less than 23%.
Um, and then the remaining, whatever, 16, 17% said, yes, if this part of a powerful value adding app like travel, health, finance, et cetera, we would be willing to pay. So, um, paying for that itself is relatively limited. So I think we have, um, two or three minutes left. What I'd like to get from you is a short concise 20 second closing statement from each of you.
Um, Florian, do you want to stop a start? So I want to stay next year here and say, okay, uh, the business use case so that we have it planned two years ago, started, uh, are running, uh, in the cross-border cases with a rebuild, for example, next year. And that will be okay. I would say decentralized identity, uh, adoption is being hugely constrained by a lack of business opportunities and business models. And I think until we fix that, we won't expect to move the needle too much more.
I also want to come back next year and I invite everyone in here in this stage to the open source, open standards efforts that it's huge foundation is leading as S I R O S.org. Um, um, thank you. Thank you. That is very uncommon. I think it's probably the first panel in 18 years. He's also set very short, concise closing statements and all three did it. Usually at least one takes at least three minutes out of it. So great applause to the panelists. Thank you.