SlideShare ist ein Scribd-Unternehmen logo
1 von 27
Downloaden Sie, um offline zu lesen
lBM Trusted Identity
Towards Self-Sovereign Identity
2 5/21/18
Inclusive of principles from
• NIST's Trusted Identities Group
• A Blueprint for Digital Identity: The Role of Financial Institutions in Building
Digital Identity, World Economic Forum, 2016
• http://www.coindesk.com/path-self-sovereign-identity/
Key Elements of a Trusted Digital Identity Framework
• The user is the ultimate authority
over his/her identity (Self-Sovereign)
• Privacy-enhancing and voluntary
• Decentralized/Distributed Trust
• Trusted Identity for Individuals,
Enterprises and Things
• Open and flexible
• Interoperable and portable
• Viable and sustainable
3 5/21/18
Trusted Digital Identity Network: Benefits
INDIVIDUALS BUSINESSES GOVERNMENTS
•Convenience and simplified
experience for identity
verification
•Full control and consent
over identity usage and monetization
•Reduced costs, and risk of data
breach/theft
•Efficient compliance
management and monitoring
•New revenue streams
•Rapid on-boarding
•Better personalized
customer services
•Distributed trust and increased
protection of identity data
•Reduced counterfeiting, alteration,
and theft
•Reduced risk and cost of identity
issuance and management
•Increased efficiency in compliance
control, monitoring, and quality
4 5/21/18
Trusted Digital Identity Use Cases
The benefits of blockchain technology include almost everything from more secure
financial transactions, improved access to personal healthcare information, and
more efficient and effective government and private-sector services -
MIT Summit Commission For Enhancing National Security – July 2016
Know Your Customer
(KYC)
Government Identity for
citizens and services
Identity Verification Network
across Industries
IBM Trusted Identity Solutions | © Copyright IBM Corporation 2017 5
– The Technical Foundations of the Sovrin Architecture
“A globally shared ledger can enable true self-sovereign
identity, where every person, organization, or thing can have its
own truly independent digital identity that no other person,
company, or government can take away.”
Open Solution Architectures: Independent identity on
distributed ledgers
Hyperledger Indy is a distributed ledger purpose-built for decentralized
identity. It provides tools, libraries and reusable components for providing
independent digital identities rooted on blockchains or other distributed
ledgers so that they are interoperable across administrative domains,
applications, and any other “silo”.
Independent Identity
You
IBM Trusted Identity Solutions | © Copyright IBM Corporation 2017
• Sovrin Ledger
• The foundational component—a globally distributed
ledger of root identity records maintained by trusted
institutions around the world. Analogous to the internet
itself, the structure and operation of this layer is
operated as a non-profit global public utility governed
by the Sovrin Foundation.
• Sovrin Agents
• Network services that give Sovrin identity owners
(people and organizations) a permanent, privacy-
protecting way to perform identity and data
management transactions. Sovrin agents are not strictly
required by Sovrin architecture; they simply make a
Sovrin identity much easier and more productive to use.
• Sovrin Clients
• Apps used by Sovrin identity owners (typically on local
devices like smartphones and laptops) to communicate
with Sovrin agents and the Sovrin ledger to conduct
identity transactions of all types. From a security and
encryption standpoint, Sovrin clients are the “key” to
Sovrin key management.
Open Solution Architectures: Independent identity on distributed ledgers
8
•Hyperledger Indy provides tools, libraries, and reusable components for providing digital identities
rooted on distributed ledger technology (DLT) so that they are interoperable across administrative
domains, applications, and any other silos.
Evernym
Contributor of open source Sovrin Trust Framework
Sovrin Foundation
Non-profit organization managing Sovrin Trust Framework
Hyperledger Indy
Open source community project for Sovrin Trust Framework
Sovrin Trust Framework
IBM Trusted Identity Solutions | © Copyright IBM Corporation 2017
Open Solution Architectures: Sovrin Trust Framework
9
As with DNS, LDAP, and other large-scale identity systems, read requests are typically an order of
magnitude more numerous than write requests so pools of nodes have different roles.
System of Ledgers
• Identity ledger: Primary ledger that is the system of record for all identity records written by Sovrin identity owners.
• Pool ledger: System of record for what Sovrin nodes are permitted to serve as validator or observer nodes.
• Voting ledger: System of record for historical governance decisions (votes) among trustees within the public utility network.
• Config ledger: holds network-wide configuration data set by the Sovrin Foundation Technical Governance Board and approved by the Board of Trustees.
• Validator nodes
• Validate new Sovrin transactions. Every
“write” to the Sovrin ledger must be sent
to a validator node.
• Observer nodes
• Required as the network scales. From the
standpoint of Sovrin clients, an observer
node is simply a read-only copy of the
Sovrin ledger.
IBM Trusted Identity Solutions | © Copyright IBM Corporation 2017
• Stewards
• Ensure that the network runs effectively, security and reliably.
• Granted Trust Anchor status
• Can be any organization that serves in a position of public trust, such as:
• Financial institutions
• Healthcare providers
• Universities
• NGOs
• Government agencies
• Utilities and telecom providers
• Sovrin infrastructure or service providers
• Trust Anchor
• A specialized person or organization that is known to the Sovrin Foundation as an authoritative
entity for which trust is assumed and not derived. These entities are able to help bootstrap
others into the ecosystem (i.e: Government DMV or Vital Records).
• Citizen Agents
• Provide discovery of people, places and things
• Enable connections that improve your status in the reputation economy.
• Provide management of the identity owner’s off-ledger “container” of Sovrin identity data.
• Citizen “Wallets”
• Device Application UX
• ID and agent provisioning
• Key management
• Management of decentralized secure data storage synchronized across the owner’s clients.
Open Solution Architectures: Sovrin Trust Foundation
10
Stewards, Agents and Clients.
sovrin
I’m a
doctor
You’re now
a doctor.
University
Verifiable claims
sovrin
University
X
Blind verification
sovrin
University
Scales to any number of consumers
sovrin
Scales to any number of issuers
sovrin
I have a
job.
You work
for us.
Bank
Scales to any number of claims
sovrin
Gov’t
University
Handles complex claims
sovrin
Gov’t
Insurance Companies
Supports selective disclosure
Sovrin Claims
Real-time claims verification
– without direct connections to issuers
Revocable (anonymously)
▪ Multi-Issuer
– credit score + mortgage balance + income
▪ Predicates
– over 18: false vs. birthdate: 16 Jan 2001
Privacy-respecting
– Anonymous, Anti-correlation, Selective disclosure
What is written to the Ledger?
• Only uncorrelated data → Never PII
– When public ledgers are broken, they are broken forever
Types of data:
• Decentralized IDs
• Public keys
• Service Endpoints
• Accumulators and Anchoring Hashes
Sovrin Token
•Every exchange of verifiable claims reduces risk for the verifier
and reduces friction for the owner
•This reduction has value
•Sovrin Token provides a way to monetize this value by
supporting a flow either from verifiers to issuers—or indirectly
from verifiers to owners to issuers.
For example, your mobile carrier could help you prove
your location at any point in time—and be paid for it
Fully open architecture
Open Standards (under development)
W3C Decentralized ID
W3C Verifiable Claims
https://www.w3.org/TR/verifiable-claims-data-model/
Decentralized Key Management (DKMS) http://bit.ly/2FpQZJL
Open Source Projects
Decentralized Identity Foundation (DIF) http://identity.foundation
Hyperledger Indy https://github.com/hyperledger/indy-sdk
IBM Announcements / Participation
• DIF Member (http://identity.foundation)
• Sovrin Foundation Members (http://sovrin.org)
• Hyperledger Founding Member (Fabric and Indy)
• W3C Member
Recommended Reading
Sovrin White Paper – Published in January 2018
A Protocol and Token for Self-Sovereign Identity and
Decentralized Trust
https://sovrin.org/wp-content/uploads/Sovrin-Protocol-and-Token-White-Paper.pdf
Thank you!
Schemas and Semantics
Schemas can be published to the ledger for use in claims and
proofs as well as for supporting the extensible APIs of agents.
Allows the identity ledger to function as a marketplace for
semantic meaning and a basis for reputation combining
identity, schema and code.
DIDs (Decentralized Identifiers)
• DIDs are a new type of digital identifier
• DIDs were invented to enable a new type of long-term digital
identity that does not require centralized registry services
• DIDs can also be verified using cryptography, enabling a digital
“web of trust”
Schema and Service Discovery
Service endpoints with the DID Descriptors service block
API enumeration service at a well-known URL that responds
based on mutual authentication of DIDs
OpenAPI (fka Swagger) with an EventedAPI extension (based
on eventedapi spec) being defined and developed now.

Weitere ähnliche Inhalte

Was ist angesagt?

Hyperledger Sawtooth Lake Intel's OSS Contribution to Enterprise Blockchain
Hyperledger Sawtooth Lake Intel's OSS Contribution to Enterprise BlockchainHyperledger Sawtooth Lake Intel's OSS Contribution to Enterprise Blockchain
Hyperledger Sawtooth Lake Intel's OSS Contribution to Enterprise Blockchain
Altoros
 

Was ist angesagt? (20)

Hyperledger Sawtooth Lake Intel's OSS Contribution to Enterprise Blockchain
Hyperledger Sawtooth Lake Intel's OSS Contribution to Enterprise BlockchainHyperledger Sawtooth Lake Intel's OSS Contribution to Enterprise Blockchain
Hyperledger Sawtooth Lake Intel's OSS Contribution to Enterprise Blockchain
 
Machine identity - DIDs and verifiable credentials for a secure, trustworthy ...
Machine identity - DIDs and verifiable credentials for a secure, trustworthy ...Machine identity - DIDs and verifiable credentials for a secure, trustworthy ...
Machine identity - DIDs and verifiable credentials for a secure, trustworthy ...
 
Introduction of Hyperledger Fabric & Composer
Introduction of Hyperledger Fabric & Composer Introduction of Hyperledger Fabric & Composer
Introduction of Hyperledger Fabric & Composer
 
Blockchain for Business
Blockchain for BusinessBlockchain for Business
Blockchain for Business
 
Hong Kong Hyperledger Meetup January 2018
Hong Kong Hyperledger Meetup January 2018Hong Kong Hyperledger Meetup January 2018
Hong Kong Hyperledger Meetup January 2018
 
How does hyperledger fabric blockchain work
How does hyperledger fabric blockchain work How does hyperledger fabric blockchain work
How does hyperledger fabric blockchain work
 
Hyperledger
HyperledgerHyperledger
Hyperledger
 
Hyperledger Fabric in a Nutshell
Hyperledger Fabric in a NutshellHyperledger Fabric in a Nutshell
Hyperledger Fabric in a Nutshell
 
Anatomy of a hyperledger application
Anatomy of a hyperledger applicationAnatomy of a hyperledger application
Anatomy of a hyperledger application
 
Hyperledger Fabric - Blockchain for the Enterprise - FOSDEM 20190203
Hyperledger Fabric - Blockchain for the Enterprise - FOSDEM 20190203Hyperledger Fabric - Blockchain for the Enterprise - FOSDEM 20190203
Hyperledger Fabric - Blockchain for the Enterprise - FOSDEM 20190203
 
Hyper ledger febric
Hyper ledger febricHyper ledger febric
Hyper ledger febric
 
Blockchain explained FIATA Congress 20180910
Blockchain explained FIATA Congress 20180910Blockchain explained FIATA Congress 20180910
Blockchain explained FIATA Congress 20180910
 
Introduction to Ion – a layer 2 network for Decentralized Identifiers with Bi...
Introduction to Ion – a layer 2 network for Decentralized Identifiers with Bi...Introduction to Ion – a layer 2 network for Decentralized Identifiers with Bi...
Introduction to Ion – a layer 2 network for Decentralized Identifiers with Bi...
 
Ethereum vs fabric vs corda
Ethereum vs fabric vs cordaEthereum vs fabric vs corda
Ethereum vs fabric vs corda
 
An introduction to blockchain and hyperledger v ru
An introduction to blockchain and hyperledger v ruAn introduction to blockchain and hyperledger v ru
An introduction to blockchain and hyperledger v ru
 
What is corda
What is cordaWhat is corda
What is corda
 
Hyperledger Fabric Update - June 2018
Hyperledger Fabric Update - June 2018Hyperledger Fabric Update - June 2018
Hyperledger Fabric Update - June 2018
 
The Hyperledger Indy Public Blockchain Node
The Hyperledger Indy Public Blockchain NodeThe Hyperledger Indy Public Blockchain Node
The Hyperledger Indy Public Blockchain Node
 
Wwc developing hyperledger applications v4
Wwc  developing hyperledger applications v4Wwc  developing hyperledger applications v4
Wwc developing hyperledger applications v4
 
Deja vu Security - Blockchain Security Summit - Adam Cecchetti
Deja vu Security - Blockchain Security Summit - Adam CecchettiDeja vu Security - Blockchain Security Summit - Adam Cecchetti
Deja vu Security - Blockchain Security Summit - Adam Cecchetti
 

Ähnlich wie Towards Self Sovereign Identity 20180508

Introduction to Decentralized Finance (DeFi)
Introduction to Decentralized Finance (DeFi)Introduction to Decentralized Finance (DeFi)
Introduction to Decentralized Finance (DeFi)
101 Blockchains
 

Ähnlich wie Towards Self Sovereign Identity 20180508 (20)

Webinar-Dubai DeFi Series-Webinar 1-The Basics of DeFi
Webinar-Dubai DeFi Series-Webinar 1-The Basics of DeFiWebinar-Dubai DeFi Series-Webinar 1-The Basics of DeFi
Webinar-Dubai DeFi Series-Webinar 1-The Basics of DeFi
 
Blockchain-Anchored Identity -- Daniel Buchner, Microsoft
Blockchain-Anchored Identity -- Daniel Buchner, MicrosoftBlockchain-Anchored Identity -- Daniel Buchner, Microsoft
Blockchain-Anchored Identity -- Daniel Buchner, Microsoft
 
Development of Digital Identity Systems
Development of Digital Identity Systems Development of Digital Identity Systems
Development of Digital Identity Systems
 
How to Integrate Blockchain Technology into Your Applications
How to Integrate Blockchain Technology into Your ApplicationsHow to Integrate Blockchain Technology into Your Applications
How to Integrate Blockchain Technology into Your Applications
 
Financial Event Sourcing at Enterprise Scale
Financial Event Sourcing at Enterprise ScaleFinancial Event Sourcing at Enterprise Scale
Financial Event Sourcing at Enterprise Scale
 
Smart Identity for the Hybrid Multicloud World
Smart Identity for the Hybrid Multicloud WorldSmart Identity for the Hybrid Multicloud World
Smart Identity for the Hybrid Multicloud World
 
Introduction to Mydex CIC Personal Data Stores - 7th March 2013
Introduction to Mydex CIC Personal Data Stores -  7th March 2013Introduction to Mydex CIC Personal Data Stores -  7th March 2013
Introduction to Mydex CIC Personal Data Stores - 7th March 2013
 
SSO IN/With Drupal and Identitiy Management
SSO IN/With Drupal and Identitiy ManagementSSO IN/With Drupal and Identitiy Management
SSO IN/With Drupal and Identitiy Management
 
Introduction to Decentralized Finance (DeFi)
Introduction to Decentralized Finance (DeFi)Introduction to Decentralized Finance (DeFi)
Introduction to Decentralized Finance (DeFi)
 
How Cloud-Based Service Providers Can Integrate Strong Identity and Security
How Cloud-Based Service Providers Can Integrate Strong Identity and SecurityHow Cloud-Based Service Providers Can Integrate Strong Identity and Security
How Cloud-Based Service Providers Can Integrate Strong Identity and Security
 
Building blockchain applications using Java
Building blockchain applications using JavaBuilding blockchain applications using Java
Building blockchain applications using Java
 
Building open source identity infrastructures
Building open source identity infrastructuresBuilding open source identity infrastructures
Building open source identity infrastructures
 
[Meetup 4] Nuit de la Blockchain, Anna Shugol, IBM
[Meetup 4] Nuit de la Blockchain, Anna Shugol, IBM[Meetup 4] Nuit de la Blockchain, Anna Shugol, IBM
[Meetup 4] Nuit de la Blockchain, Anna Shugol, IBM
 
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
Digital Identity Landscape for Vancouver IAM Meetup 2017 12-19
 
Federated and fabulous identity
Federated and fabulous identityFederated and fabulous identity
Federated and fabulous identity
 
Value proposition of SSI tech providers - Self-Sovereign Identity
Value proposition of SSI tech providers - Self-Sovereign IdentityValue proposition of SSI tech providers - Self-Sovereign Identity
Value proposition of SSI tech providers - Self-Sovereign Identity
 
Public Digital Identity as a Service
Public Digital Identity as a ServicePublic Digital Identity as a Service
Public Digital Identity as a Service
 
Blockchain, Biometrics, and the Future of Financial Services
Blockchain, Biometrics, and the Future of Financial ServicesBlockchain, Biometrics, and the Future of Financial Services
Blockchain, Biometrics, and the Future of Financial Services
 
Trust and identity in the Géant project - Networkshop44
Trust and identity in the Géant project - Networkshop44Trust and identity in the Géant project - Networkshop44
Trust and identity in the Géant project - Networkshop44
 
Blockchain and Cybersecurity
Blockchain and Cybersecurity Blockchain and Cybersecurity
Blockchain and Cybersecurity
 

Mehr von Arnaud Le Hors

Mehr von Arnaud Le Hors (12)

Hyperledger Fabric Application Development 20190618
Hyperledger Fabric Application Development 20190618Hyperledger Fabric Application Development 20190618
Hyperledger Fabric Application Development 20190618
 
Hyperledger Fabric Technical Deep Dive 20190618
Hyperledger Fabric Technical Deep Dive 20190618Hyperledger Fabric Technical Deep Dive 20190618
Hyperledger Fabric Technical Deep Dive 20190618
 
Hyperledger Fabric update Meetup 20181101
Hyperledger Fabric update Meetup 20181101Hyperledger Fabric update Meetup 20181101
Hyperledger Fabric update Meetup 20181101
 
Hyperledger Overview - 20181024
Hyperledger Overview - 20181024Hyperledger Overview - 20181024
Hyperledger Overview - 20181024
 
Hyperledger fabric 20180528
Hyperledger fabric 20180528Hyperledger fabric 20180528
Hyperledger fabric 20180528
 
Hyperledger community update 20180528
Hyperledger community update 20180528Hyperledger community update 20180528
Hyperledger community update 20180528
 
Hyperledger community update 201805
Hyperledger community update 201805Hyperledger community update 201805
Hyperledger community update 201805
 
Hyperledger Fabric EVM Integration Feb 20, 2018
Hyperledger Fabric EVM Integration Feb 20, 2018Hyperledger Fabric EVM Integration Feb 20, 2018
Hyperledger Fabric EVM Integration Feb 20, 2018
 
Hyperledger Cello Feb 20, 2018
Hyperledger Cello Feb 20, 2018Hyperledger Cello Feb 20, 2018
Hyperledger Cello Feb 20, 2018
 
Hyperledger community update Feb 20, 2018
Hyperledger community update Feb 20, 2018Hyperledger community update Feb 20, 2018
Hyperledger community update Feb 20, 2018
 
W3C Chair training Focus & Poductivity 2014102
W3C Chair training Focus & Poductivity 2014102W3C Chair training Focus & Poductivity 2014102
W3C Chair training Focus & Poductivity 2014102
 
WWW2014 Overview of W3C Linked Data Platform 20140410
WWW2014 Overview of W3C Linked Data Platform 20140410WWW2014 Overview of W3C Linked Data Platform 20140410
WWW2014 Overview of W3C Linked Data Platform 20140410
 

Kürzlich hochgeladen

Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girlsRussian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Monica Sydney
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
pxcywzqs
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
ayvbos
 
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi EscortsIndian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Monica Sydney
 
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
ydyuyu
 
75539-Cyber Security Challenges PPT.pptx
75539-Cyber Security Challenges PPT.pptx75539-Cyber Security Challenges PPT.pptx
75539-Cyber Security Challenges PPT.pptx
Asmae Rabhi
 
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
gajnagarg
 
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi EscortsRussian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Monica Sydney
 
PowerDirector Explination Process...pptx
PowerDirector Explination Process...pptxPowerDirector Explination Process...pptx
PowerDirector Explination Process...pptx
galaxypingy
 

Kürzlich hochgeladen (20)

Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girlsRussian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
Russian Call girls in Abu Dhabi 0508644382 Abu Dhabi Call girls
 
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
一比一原版(Offer)康考迪亚大学毕业证学位证靠谱定制
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck Microsoft
 
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
一比一原版(Curtin毕业证书)科廷大学毕业证原件一模一样
 
Power point inglese - educazione civica di Nuria Iuzzolino
Power point inglese - educazione civica di Nuria IuzzolinoPower point inglese - educazione civica di Nuria Iuzzolino
Power point inglese - educazione civica di Nuria Iuzzolino
 
APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53APNIC Updates presented by Paul Wilson at ARIN 53
APNIC Updates presented by Paul Wilson at ARIN 53
 
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi EscortsIndian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
Indian Escort in Abu DHabi 0508644382 Abu Dhabi Escorts
 
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
原版制作美国爱荷华大学毕业证(iowa毕业证书)学位证网上存档可查
 
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
20240509 QFM015 Engineering Leadership Reading List April 2024.pdf
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
Trump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts SweatshirtTrump Diapers Over Dems t shirts Sweatshirt
Trump Diapers Over Dems t shirts Sweatshirt
 
Vip Firozabad Phone 8250092165 Escorts Service At 6k To 30k Along With Ac Room
Vip Firozabad Phone 8250092165 Escorts Service At 6k To 30k Along With Ac RoomVip Firozabad Phone 8250092165 Escorts Service At 6k To 30k Along With Ac Room
Vip Firozabad Phone 8250092165 Escorts Service At 6k To 30k Along With Ac Room
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf
 
75539-Cyber Security Challenges PPT.pptx
75539-Cyber Security Challenges PPT.pptx75539-Cyber Security Challenges PPT.pptx
75539-Cyber Security Challenges PPT.pptx
 
Best SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency DallasBest SEO Services Company in Dallas | Best SEO Agency Dallas
Best SEO Services Company in Dallas | Best SEO Agency Dallas
 
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
Top profile Call Girls In Dindigul [ 7014168258 ] Call Me For Genuine Models ...
 
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime NagercoilNagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
Nagercoil Escorts Service Girl ^ 9332606886, WhatsApp Anytime Nagercoil
 
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
best call girls in Hyderabad Finest Escorts Service 📞 9352988975 📞 Available ...
 
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi EscortsRussian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
Russian Escort Abu Dhabi 0503464457 Abu DHabi Escorts
 
PowerDirector Explination Process...pptx
PowerDirector Explination Process...pptxPowerDirector Explination Process...pptx
PowerDirector Explination Process...pptx
 

Towards Self Sovereign Identity 20180508

  • 1. lBM Trusted Identity Towards Self-Sovereign Identity
  • 2. 2 5/21/18 Inclusive of principles from • NIST's Trusted Identities Group • A Blueprint for Digital Identity: The Role of Financial Institutions in Building Digital Identity, World Economic Forum, 2016 • http://www.coindesk.com/path-self-sovereign-identity/ Key Elements of a Trusted Digital Identity Framework • The user is the ultimate authority over his/her identity (Self-Sovereign) • Privacy-enhancing and voluntary • Decentralized/Distributed Trust • Trusted Identity for Individuals, Enterprises and Things • Open and flexible • Interoperable and portable • Viable and sustainable
  • 3. 3 5/21/18 Trusted Digital Identity Network: Benefits INDIVIDUALS BUSINESSES GOVERNMENTS •Convenience and simplified experience for identity verification •Full control and consent over identity usage and monetization •Reduced costs, and risk of data breach/theft •Efficient compliance management and monitoring •New revenue streams •Rapid on-boarding •Better personalized customer services •Distributed trust and increased protection of identity data •Reduced counterfeiting, alteration, and theft •Reduced risk and cost of identity issuance and management •Increased efficiency in compliance control, monitoring, and quality
  • 4. 4 5/21/18 Trusted Digital Identity Use Cases The benefits of blockchain technology include almost everything from more secure financial transactions, improved access to personal healthcare information, and more efficient and effective government and private-sector services - MIT Summit Commission For Enhancing National Security – July 2016 Know Your Customer (KYC) Government Identity for citizens and services Identity Verification Network across Industries
  • 5. IBM Trusted Identity Solutions | © Copyright IBM Corporation 2017 5 – The Technical Foundations of the Sovrin Architecture “A globally shared ledger can enable true self-sovereign identity, where every person, organization, or thing can have its own truly independent digital identity that no other person, company, or government can take away.”
  • 6. Open Solution Architectures: Independent identity on distributed ledgers Hyperledger Indy is a distributed ledger purpose-built for decentralized identity. It provides tools, libraries and reusable components for providing independent digital identities rooted on blockchains or other distributed ledgers so that they are interoperable across administrative domains, applications, and any other “silo”.
  • 8. IBM Trusted Identity Solutions | © Copyright IBM Corporation 2017 • Sovrin Ledger • The foundational component—a globally distributed ledger of root identity records maintained by trusted institutions around the world. Analogous to the internet itself, the structure and operation of this layer is operated as a non-profit global public utility governed by the Sovrin Foundation. • Sovrin Agents • Network services that give Sovrin identity owners (people and organizations) a permanent, privacy- protecting way to perform identity and data management transactions. Sovrin agents are not strictly required by Sovrin architecture; they simply make a Sovrin identity much easier and more productive to use. • Sovrin Clients • Apps used by Sovrin identity owners (typically on local devices like smartphones and laptops) to communicate with Sovrin agents and the Sovrin ledger to conduct identity transactions of all types. From a security and encryption standpoint, Sovrin clients are the “key” to Sovrin key management. Open Solution Architectures: Independent identity on distributed ledgers 8 •Hyperledger Indy provides tools, libraries, and reusable components for providing digital identities rooted on distributed ledger technology (DLT) so that they are interoperable across administrative domains, applications, and any other silos. Evernym Contributor of open source Sovrin Trust Framework Sovrin Foundation Non-profit organization managing Sovrin Trust Framework Hyperledger Indy Open source community project for Sovrin Trust Framework Sovrin Trust Framework
  • 9. IBM Trusted Identity Solutions | © Copyright IBM Corporation 2017 Open Solution Architectures: Sovrin Trust Framework 9 As with DNS, LDAP, and other large-scale identity systems, read requests are typically an order of magnitude more numerous than write requests so pools of nodes have different roles. System of Ledgers • Identity ledger: Primary ledger that is the system of record for all identity records written by Sovrin identity owners. • Pool ledger: System of record for what Sovrin nodes are permitted to serve as validator or observer nodes. • Voting ledger: System of record for historical governance decisions (votes) among trustees within the public utility network. • Config ledger: holds network-wide configuration data set by the Sovrin Foundation Technical Governance Board and approved by the Board of Trustees. • Validator nodes • Validate new Sovrin transactions. Every “write” to the Sovrin ledger must be sent to a validator node. • Observer nodes • Required as the network scales. From the standpoint of Sovrin clients, an observer node is simply a read-only copy of the Sovrin ledger.
  • 10. IBM Trusted Identity Solutions | © Copyright IBM Corporation 2017 • Stewards • Ensure that the network runs effectively, security and reliably. • Granted Trust Anchor status • Can be any organization that serves in a position of public trust, such as: • Financial institutions • Healthcare providers • Universities • NGOs • Government agencies • Utilities and telecom providers • Sovrin infrastructure or service providers • Trust Anchor • A specialized person or organization that is known to the Sovrin Foundation as an authoritative entity for which trust is assumed and not derived. These entities are able to help bootstrap others into the ecosystem (i.e: Government DMV or Vital Records). • Citizen Agents • Provide discovery of people, places and things • Enable connections that improve your status in the reputation economy. • Provide management of the identity owner’s off-ledger “container” of Sovrin identity data. • Citizen “Wallets” • Device Application UX • ID and agent provisioning • Key management • Management of decentralized secure data storage synchronized across the owner’s clients. Open Solution Architectures: Sovrin Trust Foundation 10 Stewards, Agents and Clients.
  • 11. sovrin I’m a doctor You’re now a doctor. University Verifiable claims
  • 13. sovrin University Scales to any number of consumers
  • 14. sovrin Scales to any number of issuers
  • 15. sovrin I have a job. You work for us. Bank Scales to any number of claims
  • 18. Sovrin Claims Real-time claims verification – without direct connections to issuers Revocable (anonymously) ▪ Multi-Issuer – credit score + mortgage balance + income ▪ Predicates – over 18: false vs. birthdate: 16 Jan 2001 Privacy-respecting – Anonymous, Anti-correlation, Selective disclosure
  • 19. What is written to the Ledger? • Only uncorrelated data → Never PII – When public ledgers are broken, they are broken forever Types of data: • Decentralized IDs • Public keys • Service Endpoints • Accumulators and Anchoring Hashes
  • 20. Sovrin Token •Every exchange of verifiable claims reduces risk for the verifier and reduces friction for the owner •This reduction has value •Sovrin Token provides a way to monetize this value by supporting a flow either from verifiers to issuers—or indirectly from verifiers to owners to issuers. For example, your mobile carrier could help you prove your location at any point in time—and be paid for it
  • 21. Fully open architecture Open Standards (under development) W3C Decentralized ID W3C Verifiable Claims https://www.w3.org/TR/verifiable-claims-data-model/ Decentralized Key Management (DKMS) http://bit.ly/2FpQZJL Open Source Projects Decentralized Identity Foundation (DIF) http://identity.foundation Hyperledger Indy https://github.com/hyperledger/indy-sdk
  • 22. IBM Announcements / Participation • DIF Member (http://identity.foundation) • Sovrin Foundation Members (http://sovrin.org) • Hyperledger Founding Member (Fabric and Indy) • W3C Member
  • 23. Recommended Reading Sovrin White Paper – Published in January 2018 A Protocol and Token for Self-Sovereign Identity and Decentralized Trust https://sovrin.org/wp-content/uploads/Sovrin-Protocol-and-Token-White-Paper.pdf
  • 25. Schemas and Semantics Schemas can be published to the ledger for use in claims and proofs as well as for supporting the extensible APIs of agents. Allows the identity ledger to function as a marketplace for semantic meaning and a basis for reputation combining identity, schema and code.
  • 26. DIDs (Decentralized Identifiers) • DIDs are a new type of digital identifier • DIDs were invented to enable a new type of long-term digital identity that does not require centralized registry services • DIDs can also be verified using cryptography, enabling a digital “web of trust”
  • 27. Schema and Service Discovery Service endpoints with the DID Descriptors service block API enumeration service at a well-known URL that responds based on mutual authentication of DIDs OpenAPI (fka Swagger) with an EventedAPI extension (based on eventedapi spec) being defined and developed now.