Skip to main content

Why bother with the blockchain for identity?

As my former colleague Salome Parulava rather succinctly described last year, we must distinguish between two different areas of overlap between 

First, “Identity for Blockchain”, assumes that if blockchain platforms… gain adoption that is at least 10% as widespread as the industry’s attention to them today, there will be a need for a robust and reliable identity layer to manage KYC, AML, authentication and authorisation processes for shared ledger applications.

From “Identity for Blockchain” vs “Blockchain for identity”. What’s in it for Airbnb? | Consult Hyperion

xxx

xxx

Second approach could be called “Blockchain for Identity” and it formulates a separate self-sustained class of use cases. It assumes that blockchain technology can enable solutions to known identity problems

From “Identity for Blockchain” vs “Blockchain for identity”. What’s in it for Airbnb? | Consult Hyperion

It’s this latter category that interests me at the moment. As Sally pointed out last year, there are some specific problems to do with interoperability and discoverability that might be approached in a different way. Let’s to pause to clarify a couple of definitions. First, I want to distinguish between attributes (such as IS_OVER_18) and credentials (such as dave.birch!Barclays#IS_OVER_18).

Oh wait. As you can see here, I’ve invented a new shorthand. So the attributes are facts about me (the first party) that you (the second party) want to know. Credentials are attributes about me that are not useful to you unless they are attested to by a third party and they can be presented by the first party for verification by the second party. So you, the pub, want to see an IS_OVER_18 credential and I present you with an identity dave.birch!Barclays (that’s a public key of mine signed by Barclays private key) and you can check that identity, see that it includes the IS_OVER_18 attribute and then (assuming that the identity hasn’t expired ) you can serve me a drink. In the case of some other credentials (IS_A_UK_RESIDENT) you might want to ping Barclays to make sure that the identity has been cancelled (because I’ve moved out of the UK). So you get the general idea.

Note one particularly interesting aspect of this architecture. In the example I used, my identity was dave.birch!Barclays but it could just as easily have been mr.x!Barclays and that wouldn’t make any different whether you serve me a drink or not. As I have written here approximately monthly for a decade or so, we need to make our transactional space one where attributes, not identities, are transaction enablers.

My good friends at Meeco along with a group of people I take very seriously in this space have just published their report “The Rise of the Attribute Economy 2.0” that explores and examines this kind of thinking.

Now, suppose all of the banks issue these credentials to their customers. This would be immensely useful for several reasons. 

 

I could store the CRUD on my phone or on my laptop. But then I might lose it. So instead, let’s assume that the banks get together a create a shared ledger to hold all of their CRUD in one place. Now, when I want to open a new bank account or start internet dating or put a monkey on Man City half way through a game courtesy of noted actor Ray Winstone, all I have to do is point to a relevant piece of CRUD. Now the pointers to the CRUD will easily fit on my phone so no problem - I can download them from my bank whenever I get a new phone, it’s no big deal -

Let’s try a worked example. I want to start internet dating. I go to Ashley Match and click to open an account. Ashley Match Asks for a virtual identity. I choose Mr X at Barclays, an identity that contains only two facts about me: that I’m over 18 and I am resident in the UK. The fact that the credentials are attested to by Barclays also tells Ashley match that Barclays know who I am, which as I have mentioned before, means that I cannot misbehave behind my pseudonym. Ashley match now go to the chain and look for this identity. They find the Mr X creation records and look along the ledger to see if that identity has been updated or deleted (they don’t care if it’s been read by someone else). It hasn’t. But now they need to know that I am the actual owner of Mr X so to speak

Comments

Popular posts from this blog

new survey results from USA Technologies (USAT) suggest. The payments technology company, which enables electronic payments for self-service machines, compared consumer spending activity at 35 of its vending machines in urban areas with a high concentration of iPhone users between week one and week four of the installation of new digital signage promoting Apple Pay. Consumers made more contactless purchases: The vending machine providers saw an average contactless transaction revenue increase of 89%, implying that consumers are making more mobile payments. This was likely driven by the clear advertisement of Apple Pay. Total transactions increased: Consumers made more purchases overall. This was probably driven by an uptick in mobile payments, given the major increase in contactless transaction revenue. And the vending machines may have attracted many first-time users who were drawn in by the digital advertising of Apple Pay. Boosting awareness is key to unlocking pent-up demand amon...

David | LinkedIn

Alex Todd rather kindly called this a “most lucid explanation of digital identity management” I would highly recommend this presentation to anyone interested in understanding prospective blockchain based identity architectures From David | LinkedIn This is very kind, but as I said in the link, this is thinking out loud and far from a fully-developed solution. We’re working on parts of this for different clients and I can see that there is something there - a genuinely new way of solving some old problems - but it’s early days.

Financial Cryptography: Corda Day - a new force

Forum friend Ian Grigg, who I always take very seriously indeed on any such topic, wrote about Corda on his blog and concluded with a powerful statement. Bitcoin told the users it wanted an unstoppable currency - sure, works for a small group but not for the mass market. Ethereum told their users they need an unstoppable machine - which worked how spectacularly with the DAO? Not. What. We. Wanted. Corda is the only game in town because it's the only one that asked the users. It's that simple. From Financial Cryptography: Corda Day - a new force xxx It seems to me, however, what Ian is pointing to as the greatest strength of their approach is also the greatest weakness. A staple feature of unimaginative management consultants presentations about innovation is some variation on the statement by Henry Ford that if you had asked users what they wanted, they would have asked for faster horses coupled with some variation on the statement by Steve jobs that it was pointless ask...