The lack of unified global standards for digital and decentralized identities threatens interoperability, security, and user trust. Fragmented frameworks risk inefficiencies, security gaps, and exclusion. As industries and governments adopt these technologies, aligning protocols becomes critical to enabling seamless cross-border interactions and safeguarding user sovereignty in an increasingly interconnected digital landscape.
Modern solutions leverage protocols like FIDO2, OAuth, and OpenID4C to streamline authentication, while decentralized systems empower user-controlled data sharing. AI-driven analytics and zero-trust architectures further bridge gaps, enabling scalable, secure identity ecosystems across industries.
Martin Kuppinger, Principal Analyst at KuppingerCole Analysts, will moderate the discussion featuring top industry experts. Joining him are Katryna Dow, CEO at Meeco; Darrell Geusz, Product Lead at Ping Identity; Kay Chopard, Executive Director at Kantara Initiative; Andrew Hughes, VP of Global Standards at Facetec; and Loffie Jordaan, Business Solutions Architect at AAMVA. Together, they will share valuable insights on the evolving landscape of IAM, focusing on key standards, challenges, and future innovations shaping the industry.
Welcome everyone to our KuppingerCole Analysts webinar Standards in Focus — Shaping the Future of Digital and Decentralized Identity. This webinar is part of our series of the Road to EIC webinars, EIC, the European Identity Conference, taking place in Berlin May 6th to 9th this year and definitely the must-attend event in our space. We have a great number of panelists and really great panelists, most or probably most all I know for many years.
So we have Kay Chopard from the Kantara Initiative, we have Katryna Dow from Meeco, Darrell Geusz from Ping Identity, Andrew Hughes from FaceTec, Loffie Jordaan from AAMVA and me, Martin Kuppinger, I'm one of the founders of KuppingerCole Analysts and Principal Analysts. So from a housekeeping perspective, feel free to ask questions at any time on the lower right edge of the app. You'll find the questions area and you can enter your questions and if time allows we will pick up your questions. So we'll try to bring sort of cover as many questions from the audience as we can.
Aside of that I think we have quite some good ideas of what we like to talk about when it comes to digital and decentralized identities and the role standards are playing. But before we really dive into that I'd like to ask all of my panelists to quickly introduce themselves and maybe have a very brief statement about what do you see as the biggest advancements in standards we've made in the past 12 months because the work on standards has started many years ago.
So we go, we'll take the title slide from left to right. Katie, do you want to start?
Sure, thank you. I'm Katie Schopard. I'm the Executive Director of the Kintara Initiative and as you probably know, Kintara works both in the US and the UK specifically running certification programs against digital identity standards in both of those countries and also provides certification for those who use the same standards that those two countries are using.
And we have liaisons with various standards organizations including ISO and so on and so we're constantly with many of our work groups working towards informing standards or providing I think a basis for what can go into those international standards. In terms of what I see as the biggest advancement, I have to tell you I've gotten multiple things on my list so I'm really struggling about what is the one thing.
I guess that I would say at least from my perspective what I'm seeing is so much more work between countries around the e-wallets and mobile credentials and I'm seeing an impetus to try to make those work across borders. And so I think that's what I am seeing is a lot more effort and a lot more attempts to really make that work. The biggest gap, I think some of the issues later on, let's look at the gaps later on.
Great, that's good for me. Thanks Martin, thanks Kay. Hi I'm Katrina Dow, the founder and CEO of Meeco and we provide enterprise infrastructure, B2B API platform to enable the full life cycle of verified credentials, organisational wallets, holder wallets. But our focus is really on enabling ecosystems and so I'd like to pick up on Kay's point and also point to a EIC last year and it was the first time that we had really put a light on the cross-border collaboration that was starting and so I think the great thing about the EU wallet is that we've got specification and clarity and a timeline.
That's really helped other jurisdictions and at EIC last year we saw DMP together with MUFG Bank and some of the banks in Australia and ConnectID show this cross-border interoperability and I'm excited to say at EIC this year we're going to see some more of that cross-border interoperability into the Asia-Pacific region and then looking at how that might connect up with EU.
So I think what's different is we last year we started to see the building blocks, now we have clarity and now we're starting to see those building blocks come together and it's the standards really that's helped I think that more than anything. Okay Daryl.
Yeah this is Daryl Goy, I'm product lead for NEO at Ping Identity which covers identity verification and creds and digital wallets and about 25 years in the business and I think the most exciting thing for us is we now have production rollouts for digital wallets and credentials and we're not just doing identity verification, we're actually creating digital identities both innate from issuers like banks, healthcare, transportation but also derived from proofing events as a form of a proofing receipt that could be used over and over and over again. So that's the big developments that I've seen.
Okay Luffy. Hi, so I work for AMVA, the American Association of Motor Vehicle Administrators. AMVA is a member organization that represents the issuers of driver license and ID credentials in North America, US and Canada. So we come to it from the issuing side. The biggest advancements I've seen in the last 12 months or two, the first one from a technical perspective is the digital credentials API and how different entities have joined the work and how it has really matured I think over the recent couple of months and also the protocols that run on top of it.
We have ISO WG10 has a document under ballot. We also have the OADF that's protocols that run on top of the digital credentials API. So that is big advancements on a technical level for digital credentials. The other thing more on a logistical organizational level if you would, is the emergence of issuing authority trust lists. AMVA has created a trust list for North America and we're seeing alignment between what's happening here with what's happening in other regions of the world.
Again, talking to the cross interoperability, cross acceptance of the trust of issuers in different regions of the world. So those are the biggest things I saw.
Okay, Andrew. Thanks Martin. My name is Andrew Hughes. I'm the VP of Global Standards at Facetech. We're a 3D liveness and biometric verification company. I work mostly on ISO standardization across biometrics, identity management, and MDOC mobile driver's license. So I have a very strange cross-sectoral view of the world. What's the biggest advancement? Lofi stole one of mine, so thanks Lofi. I would say that we're starting to see enough stabilization in the standards across the board and enough momentum and acceptance of standardized products in the world that certification matters now.
So in previous years, everyone's trying to build and experiment and prototype. Now people are seeking certification of their products according to the standards, and that's new. That hasn't been in existence yet on a large scale. We're seeing large-scale pilots, Cantera with the NIST and UK frameworks, and more and more are seeking that demonstration, the assertion that the product, the solution is fit for purpose and the purpose is useful in the world. So that's my big takeaway from the last 12 months and ongoing.
Okay, so it looks like many of you brought up this interoperability across geographies as something which is really sort of speeding up and where we clearly also have a need because the world is global and so solutions, at the end of the day, the solutions must work globally. I think it makes perfect sense. So this was one of the things. The other thing which came through a bit from what you've said is, I would say there are two aspects.
The one is there are a lot of different layers that are working on standards, and there obviously are many different standards, which I would dare to say makes it relatively complex for someone entering the space and doesn't have the legacy you have being involved in this area for sometimes decades. So when you look at this, if you would need to pick one or let's say two standards where you should look at, which ones would it be? Maybe we start with you, Andrew.
Oh, great. I'm reminded of the SKCD comic. We're doing the 15th standard because the 14 don't cover the problem sufficiently. The real advice I have for implementers is don't pick a standard before the ecosystem. Figure out what your application is, where you need to apply it, and ask your customers, ask your partners what they do because you'll have immediate traction. And you can't choose wrong if your customers want what you're producing. So that's really how I encapsulate it. We have many standards for data formats and security formats and so on.
But if you've got the wrong one for your customers, nothing's going to work. So follow your customers is my advice. Yeah. So what you say basically is the first thing is you need to understand your business case, your use case. You need to understand the ecosystem where this takes place. And then you will need to have some technology in place.
And so me having a bit of an experience in history from an architectural perspective, that would mean that I probably would then recommend building the solutions in a manner that sort of the protocol are basically as isolated as they can so that you concentrate on having some flexibility, especially also in a world that is still, if you are still in a relatively early stage of maturity. So when I think forward maybe 10 or 15 years, then probably a lot of things will look very different. Some things probably still will be around, but we will see this evolution. Would you agree with that?
Maybe Daryl, Katrina? No, I think Andrew's dead on. I think that solving tactical problems come first and getting benefit from the technology. And then the strategic can come in as a future proofing. And what we're saying is that you asked if you had to pick one, I think the OpenID Foundation standards, OIDC and W3C-based standards have been the best received by developers because they can understand it easier because it's based on OIDC extensions essentially.
So OpenID for VP, OpenID for VCI, and even the SciOp V2, which allows the wallets to talk to legacy applications and the applications don't even know they're talking to a wallet. Those have been received the best, but our strategy is do them all. So our platform model is we help abstract that from our customer and we have to bake in everything because we don't know, we're not going to choose the winner. We don't know who the winner is going to be, quote unquote, or how the mashup is going to happen someday. So we have to accommodate both.
So we're doing 18.0.13-7 for MDL verification, but we're also doing the straight up OpenID for VP for other applications. But the customer usually doesn't even know what's working under the covers in our model. The platform takes care of it. Kadria?
Yeah, I would agree completely with what Andrew and Daryl has just said. I think starting with your ecosystem, your use case, the customer value. So what's the job to be done? What's the best route to that? Although I agree with Daryl, there are some clear winners and I familiar. And then what we're seeing also on the MDL side is whether or not it's Australia, Europe or the US, we're seeing some common adoption.
I think the thing that I would add to this, and this is kind of around the future proofing, is that once there's a use case, once you have settled on an implementation, building a sort of profile test suite so that you can constantly keep those doors open to collaboration and starting to join the tactical with the strategic is really important.
So the more you can make it easier for other ecosystem players to join or test or make a decision as to whether or not they might move their profile in some way or incorporate, I think that's also a really important part of stabilizing and growing the ecosystem at the same time. So Kay, you talked about the role of Katara also in interoperability testing, etc. and certifications. This multitude of standards makes it quite interesting for you, doesn't it?
Yes, you're kind of reading my mind. I was sitting here thinking to myself that I think the other thing that's really important and I think that for companies that are trying to address the use cases, looking at their ecosystem, looking at their customers, I think another important piece is to seriously consider having your solutions put through the test, put through conformance assessment, which is obviously what we do.
And I think that we are going to, we're already embarking on expanding what that conformity assessment looks like as we're moving into these other areas and recognizing, and Andrew, who's also a member of Katara will be able to tell you, we're looking at expanding to make sure that our assessment, our audit and certification programs are also speaking to the commercial use case, which is what we're really talking about here. And it's sort of an interesting, though, interplay of both government and commercial.
And I think that one of the best things that you can do, and I've seen many companies do this, is to actually go through that audit process, get those certifications, be able to show how you meet those standards. I think that makes it trustworthy for the entire marketplace in addition to giving you a competitive edge.
And I think the other thing we already see starting is that there are more and more specialist players that basically provide technology that abstracts all the underlying standards and really provides relatively simple tools to developers to consume all the technology while the solution provider then cares for the, so to speak, heavy lifting of all the standards below. Lofi, you brought up another point which I found interesting because you emphasized on the APIs.
So to speak, the API more than the standard itself, which also means basically an API is something which, if done right, is relatively simple to consume for a developer, relatively simple to use. And if done right, it also helps abstracting the underlying world. Is this the reason why you sort of put your emphasis on the API side?
In that particular case, the reason why I brought it up is because speaking from 18.0.13.7 perspective, 18.0.13.7 started off with two different protocols of sharing credentials over the internet, and we realized that it's not optimal and we needed something more generic, if you would, that has this abstraction built in and that works better, essentially. And the digital credential API, we believe, is part of the answer to that. It abstracts things. It means that at the lower layer, you can trust the browser to do certain things on your behalf.
You don't have to try to do it yourself, and you can focus on the presentation that runs on top of it. I do want to jump back just slightly to the discussion around the different standards that are out there and the abstraction perhaps a little bit. I think it's important to keep in mind that you have different domains, and in each domain, you have different credentials, and they have different needs. The issuers of driver licenses have very different needs from the issuers of university certificates of the degree that you get at an institution.
They have different needs, and as such, I think it's natural for them to follow different technical standards. I think trying to say we have to do everything the same everywhere is probably not viable, just because you have, again, different ecosystems, different drivers in the ecosystem, in the mobile driver license ecosystem. We want to make sure that everything is interoperable within the driver license ecosystem. We're not really interested in being interoperable with university certificates. As an analogy, if you look at the physical world, we have driver licenses and we have passports.
They don't follow the same formats. They're very different, even though they both can serve as identity credentials, even. They have different ecosystems, different governance around them, and as a result, do things in different ways.
And so, I think that's a practical reality that we have to recognize in the technical world. We would devise solutions, technical solutions for credentials. Even while we may end up with scenarios where someone then comes up with solutions where you have your passport or your EID card and your driver's license and whatever, your insurance, car insurance, card, et cetera, in the same solution.
And I think this brings me to a discussion I had recently, and it's a thinking I'm still sorting out a bit, but I think we need to probably think in more layers than trust the wallet and issue or hold a verifier on top, because the wallet is basically the place where the credentials reside. But we may have services on top that aggregate also different types of things.
So, I had this example when I'm talking about travel. So, if you want to build a travel app for a certain region, then you have a solution which may rely on a service that helps in sort of integrating UDI wallets, but also, for instance, the passports for non-EU citizens, because the tourists will come from different countries. And then you have different types of identities and wallets below that.
So, it's probably a multi-layered ecosystem where the different level things come together. And then the job of the providers of the various levels to, for instance...
So, when you focus on mobile driver's license specifically, then you focus on that. But if it's a broader solution, then someone needs to care about how can I bring mobile driver's license with their specifics plus passports plus other things with the various specifics into something where then whatever different types of sort of travel solutions or apps can build on, which again are very specific.
So, I think we probably will see an evolution there. There's a lot of place for different types of providers over time. Any thoughts or feedbacks on that?
Martin, I think an interesting conversation at the end of EIC last year with the question of, okay, here's the three-party model and lots of positive things for issuer, verifier, holder. But there was increasingly, when you start to look at the ecosystems, actually, are we going to end up with some sort of agentic or service orchestration four-party model? Not to interfere with the roles of the three, but to be able to have the intelligence to recognise, oh, this is an employee onboarding.
Oh, this is booking an airline ticket. Oh, this is actually health-related. Because one of the problems is, particularly if we have multiple wallets that either are able to have a range of different credentials or specific, specific to driving, specific to state or government-issued identity, is that it will become so cumbersome if there isn't some intelligence to be able to say, I know what kind of credential I want, and I know how to look for it, maybe in a range of wallets, or I actually want to be able to talk to three wallets simultaneously.
I want to pull something that's government, I want to pull something that's commercial, and I want to pull something that's self-asserted, like seat preference or food preference. Yeah, so I think this is going to come through as the ecosystem discussions form.
Andrew, you first. Yeah, so I just want to clarify one thing. So the ISO 18013 Part 5 and Part 7 standards actually specify a mobile document type. We've got profiles for driving licences, but they actually, the structure is set for any types. We have drone licences, vehicle registrations already in production. I think they're in production now. And others are photo ID coming soon. I'm a standards guy, so the world is perfect, right? Fortunately, I don't have to deal with implementation, so, you know. The thing that we're trying to do in provide capability that can be extended.
You know, the standards that lose are the ones that close, and you can't extend them, you can't do anything else with them. There's an ongoing push to be fit for purpose, whatever that purpose is.
And, you know, once we have market feedback on what people actually implement and actually can use, and the ecosystems that establish their trust frameworks and trust networks, then those participants will tell us in the standards bodies what to do next. So we do have the multitude of formats and wallets. Wallets are new in the world. I'm quite pleased to see that the EU has invested in large-scale pilots to discover what wallets should do, can do, might not want to do, sort of thing. Because how you implement from your toolkit of standards, as you mentioned, is critical.
Like, I know that Ping has taken the Swiss army knife, all approaches model, because you're guaranteed to win, right? If the platform doesn't do what you need it to do, it's not fit for your customers. Yeah. Okay. And I'd like to come back to one thing Katrina said, because I think it's very important. So I have to say that the most important sentence I've heard of last year's EIC was, I think it was from Varma, former ATAR chief architect.
He said, keep in mind we are issuing to the holder, not to the wallet, which I think aligns also with this tiered model. I think we have a bit of a tendency, especially in the EU, with the EUDI wallet, to think too much from a wallet and too little from a process perspective, and also maybe from a use case perspective. The other thing is, I think, yes, there's more than a three-legged approach. There are probably, there definitely are two-legged approaches.
So if you want to issue a liveness detection as a VC, then basically the issuer must directly interact with the verifier and not bring it into the wallet over there. So then you could argue it's a two-legged one. Four-legged means you have at least an organization and an individual in the game, or the use case Katrina brought up. So I believe you will see a lot of use cases where information is consumed out of different wallets, and maybe sometimes aggregated into services that then can just interact with different wallets. I'm very confident to see that.
But maybe let's look in the interest of time at a couple of other things. So the one thing is, if you have questions, please put them into the questions area in this application on the lower right edge. There's the questions area. The other thing, maybe a round of questions again to all of you. So we looked at what has been happening last year. We already touched on things we see happening in the future. What is the most important thing that is currently already on the road, so to speak, in the standards bodies? So what do you see in the standards bodies you are looking at?
What do you see as the most important piece of work, so to speak? Maybe, Lofi, you want to start? Certainly. In my mind, it's on-device holder authentication. In the in-person sharing world, where I share a credential in person, identity credentials, at this point, the relying party receives your portrait image, and you check that this portrait image that you have authenticated matches the person that gave me the credential.
In an unattended situation, an over-the-internet situation, we would like to see a future where the relying party is not the one making the match between the person and the data being shared, but where that match is being made by the device or, well, the combination of the wallet, the operating system, and the device. So the relying party only gets, say, a statement that the person sharing this information with you is the person who is older than 18 years old, for example. So the relying party doesn't have to make the match.
The challenge is that that statement, that the information the relying party receives belongs to the person sharing it, is ultimately under the signature of the issuing authority. So the issuing authority has to be able to trust that the combination of the device, the operating system, the hardware does that matching accurately at transaction time. How do you standardize that so that when an issuing authority provisions a credential to a device, it can trust that this combination, the device, etc., will be able to do that in a trustworthy manner at transaction time?
So there's work going on in ISO group WG4 to compile a standard for that. It's very challenging, and I believe it's a challenge that many, many identity credentials will face, is how do you delegate this matching responsibility to the device at transaction time?
Yeah, okay, which I think is, for instance, also a bit related to what I talked about with liveness detection, where you also have a delegation scenario. Darrell, what would be your perspective on the most relevant thing happening today or these days?
Yeah, I think what we're saying now is, you know, what I'll call the perfunctory or functional standards are no longer as much of interest as the profiles and the bringing together of these things into a solution set along with schemas. So we have organizations now where we've got small groups collated, and actually, Andrew, you helped me kick this off when you were here, but we've got organizations within a community of interest building schemas that are going to be standardized, hopefully, right? So for example, banks, what is a wire transfer schema look like?
I mean, if you're going to trust a credential from another bank, what does that need to have in it so that you can conduct a wire transfer to that bank, for example? I think kind of to your point of layers, I'm glad to see we've moved up at least one layer to the schemas now, and we did a lot of work with Microsoft Workday. Andrew helped lead that with the verified employee schema that we launched, like, in 2022. LinkedIn adopted it. That's the only credential right now that Microsoft and us can interoperate with at the moment. So we need more of those.
We need more of those profiles and schemas for various communities of trust that we can interact with. Yes, which is about, at the end, trust frameworks. I don't really...
Yeah, networks of trust. At the end, it's about having the schemes, having the networks of frameworks, the trust, and also having a sort of understanding of level of assurance, etc. On the other hand, I think some of the discussion, before I come to the next one of you, reminds me a bit of when I go back 20-plus years, maybe already, in the early days of identity federation. We had a lot of talks about, oh, how do we handle that, and who takes the liability, etc., etc.?
And it has been basically solved by the practice, by the practitioners, which figure out solutions on how to do it, when to do it, when not to do it. I'm quite positive we will see a similar evolution in this space as well.
Kay, what would be your point on the most relevant thing happening these days? Oh, my goodness. I'm not sure where to start. I really appreciate a comment that you made before, Martin, about we're issuing to the holder. I think that while it's, you know, like Lafey's point about the organizations that issue a driver's license, they have very specific things in mind, but I think to something that Katrina said, it's really what does the user want, and do they want to have to have a wallet for all these different use cases? I think probably not.
And even though the issuers of those may have very specific reasons that they're doing it, things they want it to be able to do, and things to address, I think if you look at the users, ultimately the holders, they're going to want something that's more streamlined and yet controlled all at the same time, so that the example of, you know, I can share just my age verification without having to share all the information is going to become more and more important to the users.
That's what they're going to be looking for, and I think the question will be, can the market really respond to that type of an interest? And at the same time, as long as it takes to create these standards, no offense, Andrew, having sat in now on my fair share of ISO meetings, which I don't know how you do that all your days, is amazing to me, but it takes a long time to get to that place, and yet I feel like the demand is there from the users, and from government, and from commercial entities.
Everybody wants us to make this work, and it is hard, I think, for the standards to sort of maintain that pace, and for us to be able to be responsive to all of these needs, and yet everybody wants it to work together. I don't want to have to have a dozen wallets because of all the different use cases, right? Sorry. That's something, by the way, where I haven't fully made up my mind. So at the beginning, I thought we probably will have maybe two or three or very few wallets, personal, private maybe.
Then I thought about maybe we have a travel wallet with a lot of functionality around, maybe a health wallet, maybe a finance wallet with a lot of wallets. You have aggregating services. You have apps on top of that. I probably won't care about it hopefully soon. So I may have a lot of wallets, which I don't care about because they are just the technical needs, but I care about what I can do in practice with the apps, the services built on top of that.
Andrew, you next. I'll respond quickly to that before getting on to the future. In some circles, and it's widespread thought I think in implementations, there's a confusion between security and reliability of the credential versus security and reliability of the wallet. So if you believe that the security and reliability exists in the credential in and of itself, wallets don't matter. If you don't trust somebody else's wallet, you can build your own. We're going to see an explosion of wallets until it starts consolidating.
In terms of what's going on now, what's coming up in the future, so the evolution of standards. I totally forgot to mention that I'm deeply, deeply involved in Cantera Initiative.
Sorry, Kay. I spend a significant portion of my time in Cantera. So the Privacy Enhancing Mobile Credentials Workgroup in Cantera has just published requirements for issuers and wallet providers and relying parties on good practice for handling information of people. And as that evolves, it may make it into certification down the road. But it's a stake in the ground, dealing with the people and the information, no matter what the conveyance method is, no matter what the trust framework is. It's an extension of privacy principles, as you hopefully expect. But it's a start.
And it's essential because the technologists are dealing with the security and technology and protocols. But what matters to people is the information and how it's managed. I got to put in the biometrics word from the biometrics company. In the ISO standards community, we've got standards for how to test for liveness detection methods. And companies are getting their certifications and evaluations based on that. Work has just started on a similar set of standards for injection attempts, which is the next big threat for remote biometrics. How do you know it's not a fake camera?
How do you know that the OS hasn't been compromised and you're injecting deepfake video in? It's challenging to test. It's more on the security side than the biometrics side. But there's a joint group going on between SC27 for security and SC37 for biometrics to try to figure out what the critical measurement factors are in that. So hopefully in the next couple of years, we'll see a published standard. But along the way, we'll see a lot of trials and prototypes and test methods coming out. Okay.
Katrina, what's your take on the most relevant things going on these days? So I think the next layer of abstraction is this balancing between the risk that you'll accept and the trust. So whether or not it's to Lofi's point about trusting a device, trusting binding, trusting a wallet, trusting an issuer, the ability for those use cases actually to grow and scale will depend on where the risk is mapped and who's prepared to take that risk.
And I think clarity, some additional standards, best practice guidance that will help bilateral, multilateral trust schemes develop where it's very clear where that risk resides and or who is responsible is going to be critical. Because I think what's different for the scaling of this compared to maybe the scaling of credit card schemes is that we saw the credit card schemes join up different schemes over time all around the world. And we've seen many evolutions.
The challenge we have now is that everyone is used to that with their card and they will see their identity in the same way they see cards. So there'll be expectations for these bilateral, multilateral agreements. And if we can't get some clarity around this trust risk model really quickly, I think it's going to slow things down from a commercial implementation point of view. Okay. So before we look at or talk a bit more about our wish lists for what is next, I'd like to look at a couple of questions that came in.
So some of them have been, some of you have already responded, but I think it's good still to look at. So the one question is, and by the way, to all the attendees, you can also upvote the question so that we can pick the ones that are standard for digital wallets. So if you say one, then I probably would say no, because it's more about the way we interact as a wallet.
Even there are a couple of standards, but I would say if we would count all the standards that are relevant in this broader decentralized identity ecosystem, then we probably would be closer to a three-digit and to a two-digit number. Correct me if I'm wrong. What's the perspective of the others? Someone wants to jump in here. I put in the chat about the one standard for digital wallets.
We're talking about the multiplication of the number of concepts about what a wallet is versus the things that might need to be secured and the interoperable layers that might need to exist in every combination, more or less. There may come a day where the number of standards reduces when the functionality is worked out and the number of opinions about what should actually happen between the person, the issuer, and the verifier, what those actions really should be. It's really early days, is my simple answer, I hope.
Okay, then there's an interesting question, and we already had a bit of responses in the chat and in the questions. The question is, does or can or should digital identity discussed here replace existing use cases of authentication and authorization, for instance, via WebAuth on OS2 tokens, etc., or does it sit alongside? I would say the typical answer would be, it depends on, but Daryl, you first.
Sure, I mean, I can tell you right now that the attacks going on are very severe. Adversarial AI is gaming the systems. APIs in the sky are under heavy, attack. CNBC had a great article about this a few weeks ago.
Also, federation is under heavy, heavy attack. And so our customers are already seeing the wallet model, the decentralized integration model, where you snip the wire in the sky and you make the customer, the API, through the wallet can greatly frustrate these attacks. And they're super excited by this from a security perspective. The other cool thing is verifiable credentials are unique to the holder. They're uniquely issued to you and they can contain the biometric data inside, unique to you. Other methods like OS-based biometrics, that doesn't happen. You can enroll five people in Touch ID.
You can enroll 10 people in Android Fingerprint. We've already had workforce customers where children have been logging in as their dad and mom getting access to employee resources, including top secret level stuff. And so even for the biometric models, they're not cutting it anymore. So we have to move. We believe MFA is going to go away eventually. And a model of verified trust and continuous verification is what's emerging now. Who else wants to comment? I'll second Daryl.
I'm not going to go into our products, but we have developed a new protocol that allows you to take the face biometric and embed it in a 2D barcode and then place that inside a verifiable credential or an MDoc. It helps with the holder verification at presentation time. And the credentials that we tend to talk about are authorization at transaction time kinds of credentials. Authentication or authorization were artificially separated many years ago so they can be solved independently. It's great.
But in my view, they're coming back together because sometimes an authentication is the authorization. And sometimes the authorization is very far separated from the authentication event that happened before. So with discussion of digital credentials, you're passing information or signals to the verifier and relying party so they can make a decision. And that is the essence of authorization. Okay. Katrina?
I think one of the points that Daryl's made is really interesting from moving away from what was maybe seen as SSI and a lot of people saying, oh, it can't work and it won't work and some of the negative to this reusable but holder binding to the individual from a security and a fraud management point of view. So I think it's an interesting way to think about the value of the individual and the uniqueness of them, their credential as opposed to an authentication method that can be interrupted or spoofed or whatever the case may be.
So I think it's an interesting way to reset the value of the role of the holder in the ecosystem, particularly if you can help an organization to understand that how they elevate that role might help them to mitigate risk and fraud. I think that's an interesting conversation. But I think it's also a bit about, if I were a cynic, Karina, you know me, I'm a cynic. I think it's also maybe a bit about liability, etc. Because if you move away from a centralized model to a decentralized model, it basically means that the holder is the one who is first sort of being claimed to be liable.
When you have a centralized model, the provider of the centralized identity is the first. And so I think there's also logic, especially in going back to Daryl in an age where we see ever-increasing attacks, identity-based attacks, to say if we can distribute it, there's this advantage around liability. But clearly it's also, such a model might be over time more difficult to attack because you only have, so the individual wallet's not the big silo. So you can't lose 300,000 or 300 million passwords out of a single wallet, at least not under normal circumstances and with normal wallets. Okay.
Interest of time. What I'd like to do next is look a bit at your wish list. What is it what you like to have next? What is what you feel is missing? What we should have? Maybe Lofi, you start.
If I look in my crystal ball, what I'd like to see is, again, speaking purely from the driver license perspective, is a future where you have regional trust lists for issuers so that you can as a relying party, the credentials issued in a different jurisdiction where a local relying party would consult their local trust list, which would include the credentials of or the certificates of issuers elsewhere that are considered trustworthy by their regional ecosystem administrator.
I also see the future where we have a solution for protecting the information of a credential holder after it's been released, especially where such a release is in a different jurisdiction from where I achieved my or obtained my credential. I think that's one of the biggest challenges is how do we get there knowing that we have limited jurisdiction. The legal system has limited jurisdiction. It is limited to the area in which it applies.
And so if I cross boundaries, jurisdictional boundaries, how do I still give the holder a way to have reasonable confidence that my data will not be misused, that the holder will not be surprised by the use to which the data is put, including outside their own jurisdiction? Coming up with a solution to that would be wonderful. Kate? It's an interesting question. We talked a little bit, but not a lot, about also the impact of like AI, which can be applied in good ways when it comes to use of wallets and can also be a source of serious attacks.
And my sense is that when it comes to these kinds of credentials, these types of wallets, there's so many use cases that sort of all come together. And therefore, there's so many different standards that have the potential to have an interplay. And I think that, again, this is sort of from Kentara's perspective, how do we take all of these different pieces and make it into some kind of a cohesive system where we can make sure that the standards that we would want to try to do assessment and conformity testing against are sort of covering all the possibilities?
Because I think the risk can be very high for fraud. I think some of the examples that Daryl gave, it's kind of frightening. And I think being able to come up with something that's going to address all of that is a big challenge for all of us working in the area. Okay. Andrew? Okay. Idealistic standards guy point of view here. One of the steel threads throughout the discussion here is information sharing. One of the purposes of digital credentials is to share relevant information appropriately for different purposes and so on.
In today's world, a lot of fraud happens when remote ID verification is bad. It's just done poorly. It's ineffective. Old thinking is used against modern attacks. So it's a huge area that needs to be improved. The challenge today is every place has their own standard for doing identity proofing or ID verification. There is no unified framework where one jurisdiction, to Walkie's point, can look at a different jurisdiction and evaluate, according to their own risk appetite, how good the verification was.
Right now, we've got three or four levels of identity verification assurance, which has no metadata and no additional information to help a receiving party understand under what conditions that verification was made. There is work going on with an opening foundation, for example, with the name of the standards eludes me right now. It's an ID verification standard where metadata can be communicated. But one of the projects that I've started at the ISO SC27 level is basically modernizing the existing ID proofing framework standard. It's 10 years at least old.
It does not address, I don't think it even has a concept of a mobile device. If you don't enroll the correct person with the correct information, nothing else is trustworthy. That's bottom line, must be fixed. Kadria?
My wish list really is looking at sort of the business challenges that lay ahead and anything that either the standards community or existing regulations can help to manage and mitigate that so whether or not that's, you know, for instance, financial services, that there's a common approach to know your customer or know your business, KYB, KYC, or AML, anti-money laundering, so that we can maybe set some of these rules that don't hold back use cases.
Because I think we're all so happy to be on this call today and know that the technology is working, that it's in the wild and so much of the hard work is paying off. But we've got a whole set of new challenges around us now, which is that legal infrastructure, the risk mapping, the level of assurance or the requirement to suit a use case.
So we want to be able to do that as quickly as possible in order to commercialize or we need to work backwards from that commercial outcome and say this is the financial services or this is health and I know I won't be able to do anything unless I can also fulfill these existing regulatory requirements or step up requirements. And so I think for me my wish list is how we can start to address that business infrastructure. Daryl. I think for me right now the fraud levels that we're seeing is so bad, especially in financial services. Also health care is getting very bad.
I think the thing we need is a sense of urgency in legislative and standards bodies to move faster because I'll give an example of the hackathon that the California MDL team did was fantastic. It allowed us to really come in and be partners with the state government and now I can verify the California MDL on my platform as a result of that hackathon, right. We need more innovative approaches, public-private partnerships, more education and faster movement because the AI threats are moving at such speed.
We actually need this kind of technology as a defensive measure to protect our own identities and also to enable transactions not to become too onerous. Otherwise we're going to have some crazy onerous experiences that we're all going to hate or work around. So my own wish list, I want to bring up two aspects here. The one is payments, micropayments baked into the world of verifiable credentials because that is something we definitely need for a ton of different use cases.
Not only issue to verifier who pays but also for instance if you share certain information maybe you get something back like providing data for clinical trials and stuff like that. Maybe I add even a third point here but okay let's just give you the two in the interest of time. The second one I want roaming or sort of yeah let's call it roaming verifiable credentials. I want to decide about where a credential resides but not only in one wallet because I have a lot of devices I use and I use these devices for different scenarios.
So I don't want to reissue, I don't want to care about recovery by the way because that would solve all of our recovery problems. Currently we think about how can we reduce complexity of recovery. The complexity only exists because we don't have sort of roaming or reusable these verifiable credentials. I think this is something we definitely need to fix which is cryptographically quite interesting but I think we need to start about to think about and to start to work on that.
So we are at the end of the time we have so first of all thank you very much to my panelists today for providing their thoughts, their insights. I think this was very valuable. A ton of topics we've touched, a lot of things we need to dive deeper into. A lot of this will happen at EIC so don't miss to be at EIC this year but also thank you to all the attendants of this webinar for asking the questions. We weren't able to cover all the questions but many have been answered also remotely. So thank you very much and hope to see you soon in Berlin May 6th to 9th. Thank you.
See All Locations
See All Locations