SlideShare une entreprise Scribd logo
1  sur  49
Télécharger pour lire hors ligne
#identiverse
Architecture & Standards
What is a Verifiable
Credential, and Why
Does it Matter?
#identiverse
Identity Standards Architect
Kristina
Yasuda
Microsoft
#identiverse
This talk is NOT about W3C Verifiable Credentials
Data Model, JWT-VC,s JWT-VPs, LDP-VCs, LDP-VPs,
etc.
It’s about…
(you’ll see)
#identiverse
How do we normally present
Identity?
(notice that it does not say “digital identity”)
#identiverse
Plastic Cards in a Physical Wallet
Source: Unsplash
#identiverse
What is the emerging way to
present Identity?
(that we have been so excited about)
#identiverse
Digital Cards in a Digital Wallet
+
…and other things
Caveat: digital wallets can
also hold…
#identiverse
Let’s experience
a digital wallet.
(is it really that exciting?)
Imagine when you checked into a
hotel to attend Identiverse.
#identiverse
Issued to Me
Physical Wallet Digital Card
Cards are issued to me (owner of the
wallet)
1. Physical wallet and emerging digital wallet
+
#identiverse
Issued by the Authoritative Issuer
Cards are issued by the authoritative
issuer
Plastic Card Digital Card
1. Physical wallet and emerging digital wallet
+
#identiverse
Cards are Portable
I can carry the cards with me (for
example, in a wallet)
Physical Wallet Digital Card
1. Physical wallet and emerging digital wallet
+
#identiverse
Multi-Use of a Single Credential
I can use the same card multiple times
Physical Wallet Digital Card
1. Physical wallet and emerging digital wallet
+
#identiverse
Combine Multiple Cards in One Transaction
I can show multiple cards at the same
time
Physical Wallet Digital Card
1. Physical wallet and emerging digital wallet
+
#identiverse
Issuer Might Not Know When and Where the
Card is Used
Issuer of the card might not know
when and where I use the card
Physical Wallet Digital Card
1. Physical wallet and emerging digital wallet
#identiverse
Similarity in the Experience and Features
Issued to?
Issued by?
Portable?
Multi-Use?
Combining multiple cards?
Issuer knows?
Yes
Yes
me
the authoritative
issuer
Might not
Yes
Physical Wallet Digital Card
1. Physical wallet and emerging digital wallet
+
#identiverse
What are benefits of
“Digital Cards”?
#identiverse
Use-Case: Digital Driving License*
Everything is moving
into the phone
Reducing human error
during verification
Unlocking online Use-
Cases
* Same value propositions will apply to the other credentials such as University Graduation Credentials for example
1. Physical wallet and emerging digital wallet
#identiverse
How are “Digital Cards”
different from the way we
are used to presenting
identity online?
#identiverse
Yes, Federated Sign-in
* Each company has offerings in both Consumer and Enterprise spaces
Consumer* Enterprise*
#identiverse
A new artifact introduced in the “Digital
Cards” model*
* Some “Digital Cards” use-cases do not require user signed artifact.
Issuer-signed Card
(what is issued)
User
Signature
User-signed Card
(what is presented,
only in digital cards model)
- Claims about the
User
- User Identifier
- User’s Public Key
Issuer
Signature
- Claims about the
User
- User Identifier
Issuer
Signature
Not Bearer! Owned by a user who controls
the private key tied to a public key.
Claims inside can be about another user, if
delegated
#identiverse
Not everything changes,
but some important differences
Issuer
(Website)
Verifier
(Website)
Holder
(Digital
Wallet)
Federated Sign-in Digital Cards model
Identity
Provider
(Issuer)
Relying
Party
(Verifier)
Issuer-
signed
Sign
Issuer-
signed
Sign
User-signed
Sign
User
Agent
#identiverse
Issued to?
Federated Sign-in Digital Card
Cards are issued
to me (owner of
the wallet)*
Issuer signed
card is issued to
the Relying Party
(via the User
Agent)
*Issuer only has limited technical means to control at which verifier the user is going to use a digital credential. Not
talking about delegation/guardianship scenarios here.
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
#identiverse
Issued by?
The authoritative
issuer (Identity
Provider)*
Federated Sign-in Digital Card
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
* Ratio of the Issuers to the Verifiers varies, too.
#identiverse
Portable?
(Identifier is what would allow Card portability)
Globally unique
identifier - not
namespaced and
is portable.*
User identifier
namespaced to
the Identity
Provider
Federated Sign-in Digital Card
* Depends whether the Verifier accepts non-namespaced identifier brought by the User.
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
#identiverse
Multi-Use?
Same card can
be used multiple
times*
ID Token is one-
time use
Federated Sign-in Digital Card
* Same Issuer-signed credential, different user signature per presentation
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
#identiverse
Combining multiple cards from multiple
issuers in one transaction?
I can show
multiple cards
from multiple
issuers in one
transaction
RP receives one
ID Token from
one IdP in one
transaction*
Federated Sign-in Digital Card
* IdP can aggregate claims from multiple issuers, but authority of the original issuer is gone
* Focus is on the deployed features of the Federated sign-in
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
#identiverse
Issuer knows about my usage?
Depends on the
use-case whether
Issuer of the card
knows when and
where I use the
card*
Issuer of the ID
Token knows
when and where I
used it, always
Federated Sign-in Digital Card
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
* Some use-cases require the Issuer knowing where the card is used.
#identiverse
Certain Differences
-> can address different use-cases
Issued to?
me
Relying Party
Issued by?
Authoritative Issuer
Portable? (Identifier)
Possible
Within IdP
Multi-Use?
Yes
One-Time
Combining multiple cards?
Yes
Not used
Issuer knows?
Depends
Yes
Federated Sign-in Digital Card
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
#identiverse
When are the use-
cases enabled by the
differences of
“Digital Cards”?
#identiverse
Use-Case: Identity Governance
Attribute-level
Attestation
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
3. Use-Cases when digital wallet is useful
#identiverse
Use-Case: Authentication at the Edge
No Account Creation *
* Need a verifier who is ok not to create an account
#identiverse
Use-Case: Supply Chain
Scale across
thousands of
organizations
+ independent from the
Issuer Availability
+ Ad-Hoc Trust* Possible
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
3. Use-Cases when digital wallet is useful
* When decision whether to trust a source of a request/response can be made when receiving that request/response (at a runtime)
#identiverse
Beyond Technical Integration:
Legal Agreements, Compliance, etc. (not a new problem)
Digital Cards
model
Issuer
(Website)
Verifier
(Website)
Holder
(Digital
Wallet)
Legal
agreement*
Legal
agreement*
Legal agreement*
Federated Sign-in Identity
Provider
(Issuer)
Relying
Party
(Verifier)
End-
User
Legal agreement
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
3. Use-Cases when digital wallet is useful
* Can be ad-hoc trust or a legal agreement.
#identiverse
Use-Case: Digital Driving License
Public Perception
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
3. Use-Cases when digital wallet is useful
#identiverse
Benefits of Digital Cards
Public Perception
Scale Cross-
Organization
Trust
+ independent from the
Issuer Availability
No Account Creation
(e.g. Authentication
at the Edge)
Attribute-level
Attestation
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
3. Use-Cases when digital wallet is useful
#identiverse
Isn’t this talk about “Verifiable
Credentials”?
#identiverse
Meet Verifiable Credentials
The idea of Verifiable
Credentials is to design
components and
mechanisms necessary
to use “Digital Cards”.
Multiple design choices
possible.
#identiverse
Data-Models and Credential Formats of
Verifiable Credentials
* ISO/IEC 18013-5 mDL provided by Zetes Industries S.A.
Verifiable Credentials
W3C Verifiable Credentials
Data Model
JWT-VC LDP-VC
AnonCreds mDL data model
CBOR-
encoded,
COSE
signed
JSON-
encoded,
JSON
signed*
SMART
Health
Cards
…
…
#identiverse
Standards that enable Verifiable Credentials
Component Standards
Exchange Protocol OpenID for VC Issuance, OpenID for VPs
Subject-Signed
Authentication
Self-Issued OpenID Provider v2
Credential Formats W3C JWT-VC, W3C LDP-VC, ISO mDL, IETF SD-JWT, etc.…
Entity Identifier DID methods, Raw keys, X.509 certs, etc.
Cryptography EdDSA, ES256K, etc.
Revocation Status List 2021, Revocation List 2020, Accumulators, etc.
Trust Frameworks Trusted Registries, Ledgers, etc.
#identiverse
How to find your peaceful spot for your use-case
inside a Verifiable Credentials ecosystem?
- Scope
- Enterprise / Consumer / Government
- Market
- Established / Emerging
- Use-Cases
- High Assurance / Low Assurance
- Identity of
- Individual / Legal Entity / Machine
Key Slide
#identiverse
Food for thought
- Attestations to prove security of a digital wallet?
- Usage of the Cloud components?
- Will Verifiers request digital cards more often than needed?
- Attributes of each user in one place – higher risk for hacking?
- Maturity of the Trust Frameworks?
…
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
3. Use-Cases when digital wallet is useful
4. Verifiable Credentials: Pros and Cons
#identiverse
What we did not talk about
- Revocation
- Selective Disclosure
- Refresh
- Delegation / Guardianship use-cases
- Unlinkability
- (Web3 – digital cards are possible without blockchain/DLT)
…
1. Physical wallet and emerging digital wallet
2. Federated sign-in and emerging digital wallet
3. Use-Cases when digital wallet is useful
4. Verifiable Credentials: Pros and Cons
#identiverse
Now that you know what
verifiable credentials are good for…
Where in a verifiable credentials
ecosystem does your use-case belong
to?
What aspects need a deep-dive to realize
your use-case?*
* Business? Legal? Technical? Standards? else?
#identiverse
* Session may be called “Building Secure, Trusted and Interoperable Self-Sovereign Identity with
OpenID Connect” in some parts of the Identiverse website.
*
#identiverse
Yes, flexibility of verifiable
credentials is both exciting and
confusing.
#identiverse
But with a little bit of imagination
your use-case will find a cool spot.
#identiverse
Thank you!
#identiverse
Some Real-life Examples
mobile Driving Licence Vaccination QR Code
#identiverse
Why these two are moving forward?
mobile Driving Licence Vaccination QR Code
• One large Verifier – TSA
• No usage of Advanced Cryptography for
Selective Disclosure or Predicates
• Not doing Holder Binding
• Make choices across technical stack to ensure interoperability (e.g. exchange
protocols, credential format, data model, crypto suites, etc.)
• Finding a verifier that does not require account creation
• Focus on the existing ecosystems
Mutual to both

Contenu connexe

Tendances

IDA,VC,DID関連仕様 最新情報 - OpenID BizDay #15
IDA,VC,DID関連仕様 最新情報 - OpenID BizDay #15IDA,VC,DID関連仕様 最新情報 - OpenID BizDay #15
IDA,VC,DID関連仕様 最新情報 - OpenID BizDay #15OpenID Foundation Japan
 
S13_レガシー ID 管理者でも分かる Verifiable Credentials のセッション [Microsoft Japan Digital D...
S13_レガシー ID 管理者でも分かる Verifiable Credentials のセッション [Microsoft Japan Digital D...S13_レガシー ID 管理者でも分かる Verifiable Credentials のセッション [Microsoft Japan Digital D...
S13_レガシー ID 管理者でも分かる Verifiable Credentials のセッション [Microsoft Japan Digital D...日本マイクロソフト株式会社
 
Self-issued OpenID Provider_OpenID Foundation Virtual Workshop
Self-issued OpenID Provider_OpenID Foundation Virtual Workshop Self-issued OpenID Provider_OpenID Foundation Virtual Workshop
Self-issued OpenID Provider_OpenID Foundation Virtual Workshop Kristina Yasuda
 
OpenID 4 Verifiable Credentials + HAIP (Update)
OpenID 4 Verifiable Credentials + HAIP (Update)OpenID 4 Verifiable Credentials + HAIP (Update)
OpenID 4 Verifiable Credentials + HAIP (Update)Torsten Lodderstedt
 
SSIとDIDで何を解決したいのか?(β版)
SSIとDIDで何を解決したいのか?(β版)SSIとDIDで何を解決したいのか?(β版)
SSIとDIDで何を解決したいのか?(β版)Naohiro Fujie
 
次世代 KYC に関する検討状況 - OpenID BizDay #15
次世代 KYC に関する検討状況 - OpenID BizDay #15次世代 KYC に関する検討状況 - OpenID BizDay #15
次世代 KYC に関する検討状況 - OpenID BizDay #15OpenID Foundation Japan
 
OpenID Connect 4 SSI (at EIC 2021)
OpenID Connect 4 SSI (at EIC 2021)OpenID Connect 4 SSI (at EIC 2021)
OpenID Connect 4 SSI (at EIC 2021)Torsten Lodderstedt
 
新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向FIDO Alliance
 
Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装Haniyama Wataru
 
The European Union goes Decentralized
The European Union goes DecentralizedThe European Union goes Decentralized
The European Union goes DecentralizedTorsten Lodderstedt
 
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...Torsten Lodderstedt
 
自己主権型IDと分散型ID
自己主権型IDと分散型ID自己主権型IDと分散型ID
自己主権型IDと分散型IDNaohiro Fujie
 
SAML / OpenID Connect / OAuth / SCIM 技術解説 - ID&IT 2014 #idit2014
SAML / OpenID Connect / OAuth / SCIM 技術解説  - ID&IT 2014 #idit2014SAML / OpenID Connect / OAuth / SCIM 技術解説  - ID&IT 2014 #idit2014
SAML / OpenID Connect / OAuth / SCIM 技術解説 - ID&IT 2014 #idit2014Nov Matake
 
Getting Started With WebAuthn
Getting Started With WebAuthnGetting Started With WebAuthn
Getting Started With WebAuthnFIDO Alliance
 
Verifiable Credentials, Self Sovereign Identity and DLTs
Verifiable Credentials, Self Sovereign Identity and DLTs Verifiable Credentials, Self Sovereign Identity and DLTs
Verifiable Credentials, Self Sovereign Identity and DLTs Vasiliy Suvorov
 
SSI DIDs VCs 入門資料
SSI DIDs VCs 入門資料SSI DIDs VCs 入門資料
SSI DIDs VCs 入門資料KAYATO SAITO
 
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~Tatsuo Kudo
 
OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜
OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜
OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜Masaru Kurahayashi
 

Tendances (20)

IDA,VC,DID関連仕様 最新情報 - OpenID BizDay #15
IDA,VC,DID関連仕様 最新情報 - OpenID BizDay #15IDA,VC,DID関連仕様 最新情報 - OpenID BizDay #15
IDA,VC,DID関連仕様 最新情報 - OpenID BizDay #15
 
S13_レガシー ID 管理者でも分かる Verifiable Credentials のセッション [Microsoft Japan Digital D...
S13_レガシー ID 管理者でも分かる Verifiable Credentials のセッション [Microsoft Japan Digital D...S13_レガシー ID 管理者でも分かる Verifiable Credentials のセッション [Microsoft Japan Digital D...
S13_レガシー ID 管理者でも分かる Verifiable Credentials のセッション [Microsoft Japan Digital D...
 
Self-issued OpenID Provider_OpenID Foundation Virtual Workshop
Self-issued OpenID Provider_OpenID Foundation Virtual Workshop Self-issued OpenID Provider_OpenID Foundation Virtual Workshop
Self-issued OpenID Provider_OpenID Foundation Virtual Workshop
 
OpenID Connect 4 SSI
OpenID Connect 4 SSIOpenID Connect 4 SSI
OpenID Connect 4 SSI
 
OpenID 4 Verifiable Credentials + HAIP (Update)
OpenID 4 Verifiable Credentials + HAIP (Update)OpenID 4 Verifiable Credentials + HAIP (Update)
OpenID 4 Verifiable Credentials + HAIP (Update)
 
SSIとDIDで何を解決したいのか?(β版)
SSIとDIDで何を解決したいのか?(β版)SSIとDIDで何を解決したいのか?(β版)
SSIとDIDで何を解決したいのか?(β版)
 
次世代 KYC に関する検討状況 - OpenID BizDay #15
次世代 KYC に関する検討状況 - OpenID BizDay #15次世代 KYC に関する検討状況 - OpenID BizDay #15
次世代 KYC に関する検討状況 - OpenID BizDay #15
 
OpenID Connect 4 SSI (at EIC 2021)
OpenID Connect 4 SSI (at EIC 2021)OpenID Connect 4 SSI (at EIC 2021)
OpenID Connect 4 SSI (at EIC 2021)
 
Hyperledger Aries 101
Hyperledger Aries 101Hyperledger Aries 101
Hyperledger Aries 101
 
新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向
 
Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装
 
The European Union goes Decentralized
The European Union goes DecentralizedThe European Union goes Decentralized
The European Union goes Decentralized
 
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
 
自己主権型IDと分散型ID
自己主権型IDと分散型ID自己主権型IDと分散型ID
自己主権型IDと分散型ID
 
SAML / OpenID Connect / OAuth / SCIM 技術解説 - ID&IT 2014 #idit2014
SAML / OpenID Connect / OAuth / SCIM 技術解説  - ID&IT 2014 #idit2014SAML / OpenID Connect / OAuth / SCIM 技術解説  - ID&IT 2014 #idit2014
SAML / OpenID Connect / OAuth / SCIM 技術解説 - ID&IT 2014 #idit2014
 
Getting Started With WebAuthn
Getting Started With WebAuthnGetting Started With WebAuthn
Getting Started With WebAuthn
 
Verifiable Credentials, Self Sovereign Identity and DLTs
Verifiable Credentials, Self Sovereign Identity and DLTs Verifiable Credentials, Self Sovereign Identity and DLTs
Verifiable Credentials, Self Sovereign Identity and DLTs
 
SSI DIDs VCs 入門資料
SSI DIDs VCs 入門資料SSI DIDs VCs 入門資料
SSI DIDs VCs 入門資料
 
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
パスワード氾濫時代のID管理とは? ~最新のOpenIDが目指すユーザー認証の効率的な強化~
 
OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜
OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜
OpenID Connect 入門 〜コンシューマーにおけるID連携のトレンド〜
 

Similaire à Verifiable Credentials_Kristina_Identiverse2022_vFIN.pdf

Digital Identity Wallets: What They Mean For Banks
Digital Identity Wallets: What They Mean For BanksDigital Identity Wallets: What They Mean For Banks
Digital Identity Wallets: What They Mean For BanksEvernym
 
What is self-sovereign identity (SSI)?
What is self-sovereign identity (SSI)?What is self-sovereign identity (SSI)?
What is self-sovereign identity (SSI)?Evernym
 
apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...
apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...
apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...apidays
 
Digital certificates
Digital certificates Digital certificates
Digital certificates Sheetal Verma
 
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...Torsten Lodderstedt
 
CASE STUDY ON PKI & BIOMETRIC BASED APPLICATION
CASE STUDY ON PKI & BIOMETRIC BASED APPLICATIONCASE STUDY ON PKI & BIOMETRIC BASED APPLICATION
CASE STUDY ON PKI & BIOMETRIC BASED APPLICATIONPankaj Rane
 
Re-using existing PKIs for online Identity Management
Re-using existing PKIs for online Identity ManagementRe-using existing PKIs for online Identity Management
Re-using existing PKIs for online Identity ManagementMartijn Oostdijk
 
Money pad future wallet report
Money pad future wallet reportMoney pad future wallet report
Money pad future wallet reportrmangal
 
Money pad future wallet report
Money pad future wallet reportMoney pad future wallet report
Money pad future wallet reportrmangal
 
Money pad future wallet
Money pad future walletMoney pad future wallet
Money pad future walletrmangal
 
Electronic Payment Fundamentals: When Tech Embracing Payment Industry
Electronic Payment Fundamentals: When Tech Embracing Payment IndustryElectronic Payment Fundamentals: When Tech Embracing Payment Industry
Electronic Payment Fundamentals: When Tech Embracing Payment IndustryGoutama Bachtiar
 
The future of digital identity initial perspective
The future of digital identity   initial perspectiveThe future of digital identity   initial perspective
The future of digital identity initial perspectiveFuture Agenda
 
What is Digital Signature, Digital Signature FAQ - eMudhra
What is Digital Signature, Digital Signature FAQ - eMudhraWhat is Digital Signature, Digital Signature FAQ - eMudhra
What is Digital Signature, Digital Signature FAQ - eMudhraeMudhra dsc
 
Indjic fintech module 3
Indjic fintech module 3Indjic fintech module 3
Indjic fintech module 3Drago Indjic
 
R.Grassi - P.Sardo - One integration: every wat to pay
R.Grassi - P.Sardo - One integration: every wat to payR.Grassi - P.Sardo - One integration: every wat to pay
R.Grassi - P.Sardo - One integration: every wat to payMeet Magento Italy
 
Technologies for Self-Sovereign Identity
Technologies for Self-Sovereign IdentityTechnologies for Self-Sovereign Identity
Technologies for Self-Sovereign IdentityMarkus Sabadello
 
Digital signature & PKI Infrastructure
Digital signature & PKI InfrastructureDigital signature & PKI Infrastructure
Digital signature & PKI InfrastructureShubham Sharma
 
Presentation on digital signatures & digital certificates
Presentation on digital signatures & digital certificatesPresentation on digital signatures & digital certificates
Presentation on digital signatures & digital certificatesVivaka Nand
 

Similaire à Verifiable Credentials_Kristina_Identiverse2022_vFIN.pdf (20)

Digital Identity Wallets: What They Mean For Banks
Digital Identity Wallets: What They Mean For BanksDigital Identity Wallets: What They Mean For Banks
Digital Identity Wallets: What They Mean For Banks
 
Digital signature
Digital signatureDigital signature
Digital signature
 
What is self-sovereign identity (SSI)?
What is self-sovereign identity (SSI)?What is self-sovereign identity (SSI)?
What is self-sovereign identity (SSI)?
 
apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...
apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...
apidays LIVE Paris 2021 - Identification & Authentication for Individuals wit...
 
Digital certificates
Digital certificates Digital certificates
Digital certificates
 
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
How to Build Interoperable Decentralized Identity Systems with OpenID for Ver...
 
CASE STUDY ON PKI & BIOMETRIC BASED APPLICATION
CASE STUDY ON PKI & BIOMETRIC BASED APPLICATIONCASE STUDY ON PKI & BIOMETRIC BASED APPLICATION
CASE STUDY ON PKI & BIOMETRIC BASED APPLICATION
 
Re-using existing PKIs for online Identity Management
Re-using existing PKIs for online Identity ManagementRe-using existing PKIs for online Identity Management
Re-using existing PKIs for online Identity Management
 
Money pad future wallet report
Money pad future wallet reportMoney pad future wallet report
Money pad future wallet report
 
Money pad future wallet report
Money pad future wallet reportMoney pad future wallet report
Money pad future wallet report
 
Money pad future wallet
Money pad future walletMoney pad future wallet
Money pad future wallet
 
Digital Signature.pptx
Digital Signature.pptxDigital Signature.pptx
Digital Signature.pptx
 
Electronic Payment Fundamentals: When Tech Embracing Payment Industry
Electronic Payment Fundamentals: When Tech Embracing Payment IndustryElectronic Payment Fundamentals: When Tech Embracing Payment Industry
Electronic Payment Fundamentals: When Tech Embracing Payment Industry
 
The future of digital identity initial perspective
The future of digital identity   initial perspectiveThe future of digital identity   initial perspective
The future of digital identity initial perspective
 
What is Digital Signature, Digital Signature FAQ - eMudhra
What is Digital Signature, Digital Signature FAQ - eMudhraWhat is Digital Signature, Digital Signature FAQ - eMudhra
What is Digital Signature, Digital Signature FAQ - eMudhra
 
Indjic fintech module 3
Indjic fintech module 3Indjic fintech module 3
Indjic fintech module 3
 
R.Grassi - P.Sardo - One integration: every wat to pay
R.Grassi - P.Sardo - One integration: every wat to payR.Grassi - P.Sardo - One integration: every wat to pay
R.Grassi - P.Sardo - One integration: every wat to pay
 
Technologies for Self-Sovereign Identity
Technologies for Self-Sovereign IdentityTechnologies for Self-Sovereign Identity
Technologies for Self-Sovereign Identity
 
Digital signature & PKI Infrastructure
Digital signature & PKI InfrastructureDigital signature & PKI Infrastructure
Digital signature & PKI Infrastructure
 
Presentation on digital signatures & digital certificates
Presentation on digital signatures & digital certificatesPresentation on digital signatures & digital certificates
Presentation on digital signatures & digital certificates
 

Dernier

在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查ydyuyu
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdfMatthew Sinclair
 
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdfMatthew Sinclair
 
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...SUHANI PANDEY
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftAanSulistiyo
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableSeo
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...nirzagarg
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...SUHANI PANDEY
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubaikojalkojal131
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Call Girls in Nagpur High Profile
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...nilamkumrai
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...roncy bisnoi
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...Escorts Call Girls
 
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...SUHANI PANDEY
 
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.soniya singh
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...SUHANI PANDEY
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...SUHANI PANDEY
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceDelhi Call girls
 

Dernier (20)

在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
 
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
20240510 QFM016 Irresponsible AI Reading List April 2024.pdf
 
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
 
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck Microsoft
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men  🔝mehsana🔝   Escorts...
➥🔝 7737669865 🔝▻ mehsana Call-girls in Women Seeking Men 🔝mehsana🔝 Escorts...
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
 
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...(+971568250507  ))#  Young Call Girls  in Ajman  By Pakistani Call Girls  in ...
(+971568250507 ))# Young Call Girls in Ajman By Pakistani Call Girls in ...
 
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
 
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
valsad Escorts Service ☎️ 6378878445 ( Sakshi Sinha ) High Profile Call Girls...
 
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort ServiceCall Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
Call Girls in Prashant Vihar, Delhi 💯 Call Us 🔝9953056974 🔝 Escort Service
 
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
Call Now ☎ 8264348440 !! Call Girls in Green Park Escort Service Delhi N.C.R.
 
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
Ganeshkhind ! Call Girls Pune - 450+ Call Girl Cash Payment 8005736733 Neha T...
 
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
VVIP Pune Call Girls Sinhagad WhatSapp Number 8005736733 With Elite Staff And...
 
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort ServiceBusty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
Busty Desi⚡Call Girls in Vasundhara Ghaziabad >༒8448380779 Escort Service
 

Verifiable Credentials_Kristina_Identiverse2022_vFIN.pdf

  • 1. #identiverse Architecture & Standards What is a Verifiable Credential, and Why Does it Matter?
  • 3. #identiverse This talk is NOT about W3C Verifiable Credentials Data Model, JWT-VC,s JWT-VPs, LDP-VCs, LDP-VPs, etc. It’s about… (you’ll see)
  • 4. #identiverse How do we normally present Identity? (notice that it does not say “digital identity”)
  • 5. #identiverse Plastic Cards in a Physical Wallet Source: Unsplash
  • 6. #identiverse What is the emerging way to present Identity? (that we have been so excited about)
  • 7. #identiverse Digital Cards in a Digital Wallet + …and other things Caveat: digital wallets can also hold…
  • 8. #identiverse Let’s experience a digital wallet. (is it really that exciting?) Imagine when you checked into a hotel to attend Identiverse.
  • 9. #identiverse Issued to Me Physical Wallet Digital Card Cards are issued to me (owner of the wallet) 1. Physical wallet and emerging digital wallet +
  • 10. #identiverse Issued by the Authoritative Issuer Cards are issued by the authoritative issuer Plastic Card Digital Card 1. Physical wallet and emerging digital wallet +
  • 11. #identiverse Cards are Portable I can carry the cards with me (for example, in a wallet) Physical Wallet Digital Card 1. Physical wallet and emerging digital wallet +
  • 12. #identiverse Multi-Use of a Single Credential I can use the same card multiple times Physical Wallet Digital Card 1. Physical wallet and emerging digital wallet +
  • 13. #identiverse Combine Multiple Cards in One Transaction I can show multiple cards at the same time Physical Wallet Digital Card 1. Physical wallet and emerging digital wallet +
  • 14. #identiverse Issuer Might Not Know When and Where the Card is Used Issuer of the card might not know when and where I use the card Physical Wallet Digital Card 1. Physical wallet and emerging digital wallet
  • 15. #identiverse Similarity in the Experience and Features Issued to? Issued by? Portable? Multi-Use? Combining multiple cards? Issuer knows? Yes Yes me the authoritative issuer Might not Yes Physical Wallet Digital Card 1. Physical wallet and emerging digital wallet +
  • 16. #identiverse What are benefits of “Digital Cards”?
  • 17. #identiverse Use-Case: Digital Driving License* Everything is moving into the phone Reducing human error during verification Unlocking online Use- Cases * Same value propositions will apply to the other credentials such as University Graduation Credentials for example 1. Physical wallet and emerging digital wallet
  • 18. #identiverse How are “Digital Cards” different from the way we are used to presenting identity online?
  • 19. #identiverse Yes, Federated Sign-in * Each company has offerings in both Consumer and Enterprise spaces Consumer* Enterprise*
  • 20. #identiverse A new artifact introduced in the “Digital Cards” model* * Some “Digital Cards” use-cases do not require user signed artifact. Issuer-signed Card (what is issued) User Signature User-signed Card (what is presented, only in digital cards model) - Claims about the User - User Identifier - User’s Public Key Issuer Signature - Claims about the User - User Identifier Issuer Signature Not Bearer! Owned by a user who controls the private key tied to a public key. Claims inside can be about another user, if delegated
  • 21. #identiverse Not everything changes, but some important differences Issuer (Website) Verifier (Website) Holder (Digital Wallet) Federated Sign-in Digital Cards model Identity Provider (Issuer) Relying Party (Verifier) Issuer- signed Sign Issuer- signed Sign User-signed Sign User Agent
  • 22. #identiverse Issued to? Federated Sign-in Digital Card Cards are issued to me (owner of the wallet)* Issuer signed card is issued to the Relying Party (via the User Agent) *Issuer only has limited technical means to control at which verifier the user is going to use a digital credential. Not talking about delegation/guardianship scenarios here. 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet
  • 23. #identiverse Issued by? The authoritative issuer (Identity Provider)* Federated Sign-in Digital Card 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet * Ratio of the Issuers to the Verifiers varies, too.
  • 24. #identiverse Portable? (Identifier is what would allow Card portability) Globally unique identifier - not namespaced and is portable.* User identifier namespaced to the Identity Provider Federated Sign-in Digital Card * Depends whether the Verifier accepts non-namespaced identifier brought by the User. 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet
  • 25. #identiverse Multi-Use? Same card can be used multiple times* ID Token is one- time use Federated Sign-in Digital Card * Same Issuer-signed credential, different user signature per presentation 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet
  • 26. #identiverse Combining multiple cards from multiple issuers in one transaction? I can show multiple cards from multiple issuers in one transaction RP receives one ID Token from one IdP in one transaction* Federated Sign-in Digital Card * IdP can aggregate claims from multiple issuers, but authority of the original issuer is gone * Focus is on the deployed features of the Federated sign-in 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet
  • 27. #identiverse Issuer knows about my usage? Depends on the use-case whether Issuer of the card knows when and where I use the card* Issuer of the ID Token knows when and where I used it, always Federated Sign-in Digital Card 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet * Some use-cases require the Issuer knowing where the card is used.
  • 28. #identiverse Certain Differences -> can address different use-cases Issued to? me Relying Party Issued by? Authoritative Issuer Portable? (Identifier) Possible Within IdP Multi-Use? Yes One-Time Combining multiple cards? Yes Not used Issuer knows? Depends Yes Federated Sign-in Digital Card 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet
  • 29. #identiverse When are the use- cases enabled by the differences of “Digital Cards”?
  • 30. #identiverse Use-Case: Identity Governance Attribute-level Attestation 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet 3. Use-Cases when digital wallet is useful
  • 31. #identiverse Use-Case: Authentication at the Edge No Account Creation * * Need a verifier who is ok not to create an account
  • 32. #identiverse Use-Case: Supply Chain Scale across thousands of organizations + independent from the Issuer Availability + Ad-Hoc Trust* Possible 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet 3. Use-Cases when digital wallet is useful * When decision whether to trust a source of a request/response can be made when receiving that request/response (at a runtime)
  • 33. #identiverse Beyond Technical Integration: Legal Agreements, Compliance, etc. (not a new problem) Digital Cards model Issuer (Website) Verifier (Website) Holder (Digital Wallet) Legal agreement* Legal agreement* Legal agreement* Federated Sign-in Identity Provider (Issuer) Relying Party (Verifier) End- User Legal agreement 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet 3. Use-Cases when digital wallet is useful * Can be ad-hoc trust or a legal agreement.
  • 34. #identiverse Use-Case: Digital Driving License Public Perception 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet 3. Use-Cases when digital wallet is useful
  • 35. #identiverse Benefits of Digital Cards Public Perception Scale Cross- Organization Trust + independent from the Issuer Availability No Account Creation (e.g. Authentication at the Edge) Attribute-level Attestation 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet 3. Use-Cases when digital wallet is useful
  • 36. #identiverse Isn’t this talk about “Verifiable Credentials”?
  • 37. #identiverse Meet Verifiable Credentials The idea of Verifiable Credentials is to design components and mechanisms necessary to use “Digital Cards”. Multiple design choices possible.
  • 38. #identiverse Data-Models and Credential Formats of Verifiable Credentials * ISO/IEC 18013-5 mDL provided by Zetes Industries S.A. Verifiable Credentials W3C Verifiable Credentials Data Model JWT-VC LDP-VC AnonCreds mDL data model CBOR- encoded, COSE signed JSON- encoded, JSON signed* SMART Health Cards … …
  • 39. #identiverse Standards that enable Verifiable Credentials Component Standards Exchange Protocol OpenID for VC Issuance, OpenID for VPs Subject-Signed Authentication Self-Issued OpenID Provider v2 Credential Formats W3C JWT-VC, W3C LDP-VC, ISO mDL, IETF SD-JWT, etc.… Entity Identifier DID methods, Raw keys, X.509 certs, etc. Cryptography EdDSA, ES256K, etc. Revocation Status List 2021, Revocation List 2020, Accumulators, etc. Trust Frameworks Trusted Registries, Ledgers, etc.
  • 40. #identiverse How to find your peaceful spot for your use-case inside a Verifiable Credentials ecosystem? - Scope - Enterprise / Consumer / Government - Market - Established / Emerging - Use-Cases - High Assurance / Low Assurance - Identity of - Individual / Legal Entity / Machine Key Slide
  • 41. #identiverse Food for thought - Attestations to prove security of a digital wallet? - Usage of the Cloud components? - Will Verifiers request digital cards more often than needed? - Attributes of each user in one place – higher risk for hacking? - Maturity of the Trust Frameworks? … 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet 3. Use-Cases when digital wallet is useful 4. Verifiable Credentials: Pros and Cons
  • 42. #identiverse What we did not talk about - Revocation - Selective Disclosure - Refresh - Delegation / Guardianship use-cases - Unlinkability - (Web3 – digital cards are possible without blockchain/DLT) … 1. Physical wallet and emerging digital wallet 2. Federated sign-in and emerging digital wallet 3. Use-Cases when digital wallet is useful 4. Verifiable Credentials: Pros and Cons
  • 43. #identiverse Now that you know what verifiable credentials are good for… Where in a verifiable credentials ecosystem does your use-case belong to? What aspects need a deep-dive to realize your use-case?* * Business? Legal? Technical? Standards? else?
  • 44. #identiverse * Session may be called “Building Secure, Trusted and Interoperable Self-Sovereign Identity with OpenID Connect” in some parts of the Identiverse website. *
  • 45. #identiverse Yes, flexibility of verifiable credentials is both exciting and confusing.
  • 46. #identiverse But with a little bit of imagination your use-case will find a cool spot.
  • 48. #identiverse Some Real-life Examples mobile Driving Licence Vaccination QR Code
  • 49. #identiverse Why these two are moving forward? mobile Driving Licence Vaccination QR Code • One large Verifier – TSA • No usage of Advanced Cryptography for Selective Disclosure or Predicates • Not doing Holder Binding • Make choices across technical stack to ensure interoperability (e.g. exchange protocols, credential format, data model, crypto suites, etc.) • Finding a verifier that does not require account creation • Focus on the existing ecosystems Mutual to both