Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Self Sovereign ID and Decentralized ID

Naohiro Fujie
November 03, 2020

Self Sovereign ID and Decentralized ID

Often we associate the word "Self Sovereign Identity/SSI" or "Decentralized Identifiers/DID" to a Distributed Ledger Technology especially "Blockchain". But now we have to understand what SSI/DID is and how DLT/Blockchain technology helps identity system in the future.
This deck was translated from Japanese one which was originally used at a meeting in Japanese Cabinet Secretariat.

Naohiro Fujie

November 03, 2020
Tweet

More Decks by Naohiro Fujie

Other Decks in Technology

Transcript

  1. • Identifier • Identity Japan Osaka Fujie Fujie Fujie Fujie

    Copyright © 2020, Naohiro Fujie, All Rights Reserved 4
  2. Identity https://sovrin.org/faq/what-is-self-sovereign-identity/ recognizes an individual should own and control their

    identity without the intervening administrative authorities Copyright © 2020, Naohiro Fujie, All Rights Reserved 6
  3. Car rental Store Company Hospital User present identity by their

    choice Trust issuers No need to validate identity by accessing issuers Issue identity Copyright © 2020, Naohiro Fujie, All Rights Reserved 7
  4. Aspect Requirements for SSI Issues on current identity model Users

    Do not rely on a specific identity provider Business continuity and availability If the identity provider stop their business, user can not use federated services. Account management All accounts are managed under policies of the identity provider and if they suspend the accounts, users can no longer use federated services. Privacy considerations IdPʼs awareness of users behaviours IdP can know which services the user wants to use by identity federation. Attribute management IdP and RP decide which attributes are provided between them Account linkage by correlation of RPs RP can know unintended attributes by correlation with other RPs Service Provide rs Able to trust identity which was presented by users Trust claim values Based on the identity proofing/KYC process on the IdP Trust issuers Pre-established trust(static trust) Copyright © 2020, Naohiro Fujie, All Rights Reserved 10
  5. Aspect Requirements for SSI Issues on current identity model Users

    Do not rely on a specific identity provider Business continuity and availability If the identity provider stop their business, user can not use federated services. Account management All accounts are managed under policies of the identity provider and if they suspend the accounts, users can no longer use federated services. Privacy considerations IdPʼs awareness of users behaviours IdP can know which services the user wants to use by identity federation. Attribute management IdP and RP decide which attributes are provided between them Account linkage by correlation of RPs RP can know unintended attributes by correlation with other RPs Service Provide rs Able to trust identity which was presented by users Trust claim values Based on the identity proofing/KYC process on the IdP Trust issuers Pre-established trust(static trust) Copyright © 2020, Naohiro Fujie, All Rights Reserved 11 3 1 5 4 2 6 Numbers in The Laws Of Identity in SSI
  6. • How to trust issued claims • How to trust

    the issuer Copyright © 2020, Naohiro Fujie, All Rights Reserved 14
  7. Copyright © 2020, Naohiro Fujie, All Rights Reserved 15 Aspect

    Requirements for SSI Issues on current identity model Users Do not rely on a specific identity provider Business continuity and availability If the identity provider stop their business, user can not use federated services. Account management All accounts are managed under policies of the identity provider and if they suspend the accounts, users can no longer use federated services. Privacy considerations IdPʼs awareness of users behaviours IdP can know which services the user wants to use by identity federation. Attribute management IdP and RP decide which attributes are provided between them Account linkage by correlation of RPs RP can know unintended attributes by correlation with other RPs Service Provide rs Able to trust identity which was presented by users Trust claim values Based on the identity proofing/KYC process on the IdP Trust issuers Pre-established trust(static trust)
  8. Car rental Store Company Hospital User present identity by their

    choice Trust issuers No need to validate identity by accessing issuers Issue identity Copyright © 2020, Naohiro Fujie, All Rights Reserved 17 How to trust the presented identity without asking to the issuer
  9. Car rental Store Company Hospital User present identity by their

    choice Trust issuers Issue identity Copyright © 2020, Naohiro Fujie, All Rights Reserved 18 PKI
  10. Car rental Store Company Hospital User present identity by their

    choice Trust issuers Issue identity Copyright © 2020, Naohiro Fujie, All Rights Reserved 19 PKI Who operates the PKI?
  11. Car rental Store Company Hospital User present identity by their

    choice Trust issuers Issue identity Copyright © 2020, Naohiro Fujie, All Rights Reserved 20 PKI No falsification of the key by the issuer or the operators?
  12. Car rental Store Company Hospital User present identity by their

    choice Trust issuers Issue identity Copyright © 2020, Naohiro Fujie, All Rights Reserved 21 PKI on DLT Register wallet and bind to the identity
  13. Sovrin Foundation’s governance model Holder /Prover Issuer Verifier Verifiable Credential

    Proof Trust Trust Verifiable Credential Governanc e Authority Governance Framework Publishes Holder /Prover Issuer Verifier Verifiable Credential Proof Trust Copyright © 2020, Naohiro Fujie, All Rights Reserved 25
  14. Copyright © 2020, Naohiro Fujie, All Rights Reserved 30 OIDC4IDA

    VC Philosophy IdP centric User centric Focus on Identity verification on IdP Identity verification on RP Provides Verified identity information Verifiable identity information Based on Pre-established trust relationship between RP and IdP Immutability of a DLT
  15. Copyright © 2020, Naohiro Fujie, All Rights Reserved 33 OpenID

    Provider DID SIOP Wallet Holder Wallet Verifier KYC providers SIOP Wallet RP Issuer Presentation Exchange OIDC4IDA VC VC Presentation Exchange JWT VC JWT OIDC4IDA Distributed Claim OpenID Connect DID/VC
  16. Copyright © 2020, Naohiro Fujie, All Rights Reserved 34 Write

    issuing information In university Private sectors Inter universities Verify ceriticates Record students information - Digital student card - Identity proofing at online classes - Portable certificates - Inter universities ID federation - Digitalized certificates - Payment system integration Login with student ID Issue certificates (enrolment, graduates) Students ID federation Registration/Issue Use cases Digital Student Card Certificate Issuing sys ID platform Distributed Ledger Technology keio.jp