All right. Hello, ladies and gentlemen. I'm Jeff. This is my third sharing today.
So, talk a lot for today. And luckily, it's the last session, so all of us can go for dinner later. For today's topic, I know I put the advanced on it. But actually, after reviewing all the deck that I put it, it's more like introductory.
So, if you don't feel like it's advanced, you can ask advanced questions, and then we can discuss. All right.
So, what we're going to talk about today is the future of digital identity, but I'm going to walk you through also the past and present, and then talk about the future. And this is me. And the reason why I use the photo in the United Nations is because it's nearly impossible for any Taiwanese to be in the United Nations.
So, I'm kind of sneaking and taking a photo. And I'm going to use the same number from the World Bank.
Thank you, Jay. 1.1 billion people today, they don't have a way to prove their identity. The way to prove they are the person they claim to be. And the number is going to grow higher if we don't have a solution nowadays. I'm going to give a very introductory definition about what is digital identity. I know right here, everyone is experts, but if we are honest, people have different explanations and definitions about digital identity.
Usually, by three ways. The first, to prove you are you, we will ask you your password. And we're guessing you're the only person in the world who knows and memorizes your password.
So, if you can spell it, if you can put a password out in the input, that means you are yourself. That's the first way. We're testing what you know.
Second, we check what you have. If you are the person you claim to be, you must have the mobile phone of yourself in your pocket. Which means when I send a text message to your mobile phone, you are the only person in the world who can know the information on the text message, which is a 2FA.
So, it's about what you have. The third way, what you are. When we look at your fingerprints, look at your facial, you are that physical body person as a human.
So, when we verify it, we know the person with the fingerprint are you. So, usually, if you're talking to our parents or something, they will recognize your identity as what you know, what you have, and what you are. And I'm going to start from a very long time ago.
So, in the past history, how do people prove who they are? Around 100,000 years ago, people, when they want to prove they are from a rich family, in the tribes, they actually have this kind of different wearable beads and jewelry saying, okay, with that bead, with this kind of decoration, I'm from that family, I'm from this family. And it's about what you have, right? You have that necklace, you have that decoration, means that you are from this family. And notice we have the dot tag for soldiers, so we can recognize when you wear it, when you have it, that means you are you.
And then, 1046 BC, this is actually in my textbook. So, in the Chinese Zhou dynasty, a long time ago, one of the originality of a tattoo isn't for real fancy decoration nowadays, it was for prisoners.
So, at a time when someone do something bad, have a crime, the dynasty would put the tattoo on the face of the prisoner. So, when you go out to shopping in the markets, in the old style of the markets, everyone sees you, oh, that person is a prisoner, that person is a criminal, so people will stay away from you.
So, that is for what you are, right? The thing on your face proves that you are a bad guy.
And then, 1415 AD, one of the first passports in the world is from King Henry of England. It's because there are a lot of travelers around the globe, so they issue this kind of paper-based document for you. When you bring it, when you have it, when you're at the gate of the castle, you can show it to the people, to the soldier, and then they say, oh, because you have it, so I can let you pass through.
So, this is another example of what you have. You have that paper document. Until 1915, one of the spy scandal, a guy named Lody, at the time, people only had the paper documents with all the information, but without photos.
So, this is a spy from Germany who was spying in the UK, and he got this kind of paper document as an American passport, and he basically spied for seven years without being noticed. And this is because if we only examine what you have, but we don't examine what you are, we don't really know you are the person really you claim to be.
So, we start adding photos to the passport right after this one. Okay, that's a brief history about identity. And back to what you know, what you have, and what you are, the basic definition of digital identity. Here we come with the credential, right?
So, all of us, in our pocket nowadays, we have the wallet, the pass, with the physical cards, we call credential. On the credential, we have a photo showing, okay, when I look at the credential, it's from one nationality, and with a photo on it, and it looks like a real one, which proves that you're from that country, like that.
And then, if the credential is real, all the information recorded on the credential, I will regard it as real. So, that is nowadays. Before the successful of EIC, right before, in the past 2020, all the people used credential, physical card, to recognize who are you, who are the person you claim to be.
And then, by credential, we have the password. So, if you hold the card, you have the card, you know the password, you look alike to the photo, that means you are the person you claim to be.
So, this is how things go nowadays. And it can come with different kind of challenges, all right? The first challenge is, when we are verifying your credential, do we get access to too much information? For example, in Taiwan, we don't have a driver license, but we have the ID card.
So, when you got stopped by the traffic transportation officer on a highway, when they look at your ID card and then turn around, they will know your spouse's name. They will know your permanent address. They even know your birthday, right?
So, they can congratulate you if today is your birthday. So, that's the thing nowadays about the credential. All the information are easily revealed to the party who don't really need that much access to your personal information. The second is, if you remember your password, are you really the person you claim to be? How do I know you never share your password information with your friends, your family? How do I know you didn't put the sticker notes on your computer writing your password out there?
So, the person who remembers the password doesn't mean that person 100% need to be the person he or she claims to be. The third one, biometric data. A lot of you might have heard the false positive effect on the fingerprints. Out of the 30 million to 40 million people, there will be one false positive result on the fingerprints.
So, if the world population nowadays is 40 million, it's okay. We can still use fingerprints, but we are not, right?
So, the fingerprints will be much, much more useless with this type of false positive exists in the world. So, we need to look at different types, like face recognition, and also, like, iris and retina, different types of biometric recognition. And this is the thing that every one of us know about.
So, I'm going to skip this slide. And as I mentioned, like, if you know the password, even though if you know the one-time password, nowadays, we have so many ways that we can attach something to your phone with an app, and that will simply listen to your text message, and a hijacked message will be able to receive it and send it back to the LTP app, and then someone can hack into your bank account. And nowadays, people talk about, what if, like, fingerprints doesn't work in the future? Are we going to use face recognition?
But face recognition, people find it even easier to fake by creating an image with the gen-ai nowadays. So, when a defender increases in saying, okay, now you need to shake your hats, and an attacker finds a new way to create a, like, shaking hats, gen-ai image, the defender finds a better way to defend and then recognizes the fake one, and the attacker finds a better way to sneak in the system.
So, it's come, like, always an attacking defense within the recognition system. And also, for iris and the retina recognition, the device is just too not portable, sometimes about the cost. Not everywhere we have the eyeball recognition device out there, right?
So, how can we balance out the trade-off between having a high recognition on the biometric information, but at the same time, not too costly is also the problem nowadays. And then, I'm going to talk about the impact of the dual identity. And Jay already mentioned a lot of the negative things.
Nowadays, I'm going to talk about more. So, one thing is, if you just put too much data into one place, the data breaches might happen. India is one of the largest ID databases in the world, but it actually accounts for two huge data breaches in the past few years.
You know, 800 million percent data has been linked to dark web in the past 10 years. So, you can basically go to dark web, and you can search anyone's name, address, phone number, password information, and also the Aadhaar number on the dark web. And it's with very low price to get it.
Second, statelessness. So, Pakistan, they have a CNIC identity, but the issue is, when you want to register for the CNIC identity, you need to present your father's card. What if you don't have access to your father's card, or your father's just not with you?
So, there's a few cases about women that cannot obtain the ID card because she was abandoned when she was a child. And with this kind of presenting the father's card, no identity can be registered. No identity means no right to vote, no right to get educated, no right to go to hospital, and then no access to bank accounts, and so forth.
So, does identity actually really create the convenience of the world, or it just creates convenience for partial of the people nowadays, but also creates trouble for the rest of the world? We don't know. The third one, surveillance. By everything digitalized, it actually increases the right for sometimes the country, the nations, to take control of the system if they don't use it in the right direction.
So, in Saudi Arabia, the Apsha app, they have a functionality that the male user can actually track the female dependent within the family. So, you can imagine when your female dependent within the family go abroad, all the information will be tracked.
So, they will get notified, and then they can do something called revoke. Revoking the travel permits, so none of your dependents in your family can travel outside of the country.
So, digital identity is a neutral tool. We can use it in the right way, and we can design it in a bad way as well. What's next, right?
So, if there are so many problems, are we going to still research this technology, or are we going to stop it because it's going to create more trouble in the future? People always imagine, like, can we use one identity that's virtually, and then use it in every scenario in the world?
So, we don't need to. In the future, like, nowadays, we have the wallet. In a wallet, usually two things, right? The cards. ID cards and credit cards. The credit card and cash are replaced by mobile payments. ID cards are replaced by all the technology we developed right here, all together, the DID.
So, in the future, maybe the terminology of the purse might disappear. It becomes history in a museum.
So, by ID in a mobile phone, people always want to rent a car. Nowadays, for Taiwanese to go to South Korea to rent a car, you need to have an international driver's license. The application process is two weeks. You need to pay around $50 to $800 to get a license, and when you bring it there, without a complete documentation, they will just reject you, and they will not return your booking fee.
So, if you book ahead for $200, and then without a complete document, they will reject you, so you will never get a car and never get the money back. So, that's the situation nowadays.
So, how can we make your local ID document easily accessible and recognizable across all the countries in the world? That will be one of the first topics to be discussed. The second is for opening a bank account. Each country has their own anti-money laundering rules, and also the KYC document list.
So, for example, Taiwanese opening a bank account in Japan is usually nearly impossible. Like, by the right endorsement, you need to spend half a year to get a bank account set up.
So, can we match the Japanese KYC list of documents and the Taiwanese list of documents in the air, so the person only needs to grant the access and then get a bank account set up within 24 hours? That's one of the projects that we're undergoing within the Asia-Pacific Digital Identity Consortium.
So, trying to make local identity globally recognizable. So, I think that's the key thing for the future. And some more introduction about myself. Taiwanese is also difficult to get in WHO, so I also take a picture right there of our collaboration. Because WHO, they said they need to issue 12,000 e-certificate of volunteer in 150 countries. They used to do it on paper, but they realized that nowadays we go for sustainable, right?
So, zero carbon emission. They say, is there a way we can deliver in the PDF format, but still real? Real PDF format is how they understand the digital identity.
So, that's how we help them issue to a lot of different countries. And also, another picture in the UN talking about how can we use in digital trust framework with collaboration like country to country, collaboration on traveler, students, and migrant workers.
So, another topic to talk about. And this is us, the Turing Space. We are having a few issuers in 12 countries, around 550 people there. Organization, they're issuing certificate every day, and they issue to 168 countries for now.
So, even though a few countries only have a small number of users, but they are kind of using Turing Space and giving us feedback. And our office is in four places.
Recently, we set up in Netherlands, and we have the other two offices in Japan and Taiwan, and also one office in the U.S. As we're talking about, like, the database isolation, we're trying to make Asia one database, Europe one database, and U.S. one database, so people wouldn't think about the privacy issues.
So, back to the topic, like, definition of a digital identity. In the future, how can we increase the accuracy about all of this, right? Because I mentioned, like, password is not accurate. The 2FA might have problems. Biometric also have problems. To know what you know, can we just look into your conscience, right? Some scientists might think about, like, everyone thinks in a different brainwave. Can we recognize you by your brainwave? We show you an image. When you think about it, you have a pattern of thinking about it. Can we recognize by your conscience?
That's one of the topics we can talk about. Second, if having a mobile phone means losing it, can we put that chip inside your body?
So, there's quite a few experiments nowadays, but it's kind of, like, maybe not ethical. Can we have an in-body chip, like, in your hands, in your elbow, or some other places?
So, it's also for, like, mobile payment, like that. So, is it a future for humans, or is it not? We don't know, right?
Third one, if the biometric data have this kind of, like, false positive, can we look into your gene data, right? People might say twins have the same genetic data, but can we use your gene data as a conscious in-body chip to recognize a real, alive human? That's also another topic to talk about.
So, there's still a large room for technology to advance, and technology is always neutral. Choosing which to use it in what place are what we're going to discuss about in the future.
So, today, I don't have the answer. I don't have the solution. I'll just bring more questions to you, and then we can all think about together for the bright future of the humanity. And this is me. Thank you so much. I'll see you in another identity conferences soon. Thank you.