Liberté, Égalité, Fraternité in digital identity technologies

Will we have these values in the EU Digital Identity Wallet?

peacekeeper 19 de junio de 2024
Liberté, Égalité, Fraternité in digital identity technologies

👋Dear NGI-ers:

In my recent NGI Talk, I tried to argue that overlapping/competing technical standards in the decentralized digital identity community should not only be explained by technical features but also by the "values" and "worldviews" inherent to specific technologies.

At the recent European Identity Conference, with my long-time colleague and friend Nat Sakimura, we gave a keynote presentation called "Les Miserables of the Cyber Frontier: The Dueling Narratives of Decentralized Identities".

In this presentation, we examined the role of technology in initiatives to build and maintain decentralized systems. One of the narratives in the "Les Miserables" story is an uprising by a group of revolutionaries against an authoritarian regime, driven by ideas of the Age of Enlightenment and its fundamental values of ✨ "liberté, égalité, and fraternité"✨.

In our keynote, we concluded that combinations of technical architectures and operational/legal controls are needed and that the three values should guide us in designing them.

In my previous article, "Technology is not neutral: the worldviews behind digital identity standards", I have provided "superficial explanations" about the differences between competing technologies and potential "deeper explanations" about the values inherent to them.

I would now like to explore this a bit further, and I will re-use the same sets of technologies I have already examined, but this time attempt to relate them to the three values liberté, égalité, and fraternité⬇️⬇️⬇️

W3C VCDM vs. SD-JWT VC:

These are two different data models for digital identity credentials. I would argue that W3C VCDM has more liberté than SD-JWT VC.

Why? - ✨The former is based on an open-world data model that allows anyone to define the semantic meanings of statements instead of requiring centralized authorities for that.✨

Besides control over data, control over semantics can also create power asymmetries and dependencies in the digital and physical world:

  • If you issue a Verifiable Credential that includes a claim called "family", then maybe that term means something different to me than it means to you.
  • Or what about a hypothetical claim called "follower of a religion"?

Who gets to decide what the exact meaning of these claim names is?

One of the two technical choices provides decentralized freedom in defining such meanings; the other does not.

DIDs vs. the "cnf" claim

These are two ways to bind a digital identity credential to a Holder. I would argue that DIDs have more égalité than the "cnf" claim.

Why? - ✨Suppose you use the "cnf" claim in a Verifiable Credential to express the binding between a Holder and their device, and you use "JWT Issuer Metadata" to discover a VC Issuer's public keys. In that case, there is a strong asymmetry between the technical constructs used for the Holder and Issuer sides.✨

If, on the other hand, you use DIDs to identify both the Holder and the Issuer, then the same technical construct is used to express the association of cryptographic material with both sides.

One consequence of this, for example, is that it becomes much easier for the different roles to change, i.e. a Holder can become an Issuer, and an Issuer can become a Holder, and their means of identification would be equal.

DIDComm vs. OID4VC

These are two different protocols for digital identity wallets. I would argue that DIDComm has more fraternité than OID4VC.

Why? - ✨Similar to the previous argument, there is more symmetry in DIDComm than OID4VC. In the former, all network participants are identified by DIDs. In contrast, in the latter, you have to deal with different mechanisms for identifying the parties of an OID4VC transaction (e.g. Credential Issuer Metadata and Client IDs).✨

But beyond that, in OID4VC, you always assume individual transactions that follow a request/response pattern and terminate after that. In DIDComm, on the other hand, one fundamental design principle is connections between peers.

In other words, while one of the two technologies continues to be based on a mindset of clients and servers (or providers), the other technology can enable symmetric, persistent relationships, like those between brothers and sisters.

👉 And what about the EU Digital Identity Wallet?

The EU Digital Identity Wallet is a fantastic initiative that we can all be proud of, and it has the potential to bring significant benefits to EU citizens and other people.

Nevertheless, it makes me slightly uneasy that the technical choices that currently seem to be favoured by the experts are those that have less liberté, less égalité, and less fraternité than their alternatives.

---

Important News: NGI Talk 📢

Are you curious about decentralized digital identity and want to learn everything about it, or are you just wondering about its complexities?

✨Join me in this NGI Talk: Technology is not neutral: the worldviews behind digital identity standards.✨

Let's uncover the essence of digital identity technologies together in this exciting activity!

👉 Watch it now by clicking here.