デジタルIDウォレットの相互運用面では、OpenID FoundationのOpenID for Verifiable Presentations(OpenID4VP)およびOpenID for Verifiable Credential Issuance(OpenID4VCI)のコンフォーマンステスト整備と併走しており、DID Resolutionの安定化はVC発行・提示フローの実装容易性を高めます[2]。
注目すべき点
注目すべき部分はこちらです。
W3C invites implementations of Decentralized Identifier Resolution (DID Resolution) v1.[1]
標準化プロセスの観点では、CR Snapshotは実装経験を通じた仕様の最終整備ステージです。仕様の文言と実装の相互作用から曖昧さや余白が洗い出され、テスト可能性や相互運用メトリクスが磨かれます。IETFのTechnical Deep Diveでのプロトコル相互運用議論と歩調を合わせるように、実装者・プロファイル策定者・メソッド管理者が同じ用語と入出力で議論できる「共通言語」としての効果が見込めます[3]。
Self-Sovereign Identity (SSI) empowers individuals and organizations with full control over their data. Decentralized identifiers (DIDs) are at its center, where a DID contains a collection of public keys associated with an entity, and further information to enable entities to engage via secure and private messaging across different platforms. A crucial stepping stone is DIDComm, a cryptographic communication layer that is in production with version 2. Due to its widespread and active deployment, a formal study of DIDComm is highly overdue.
We present the first formal analysis of DIDComm’s cryptography, and formalize its goal of (sender-) anonymity and authenticity. We follow a composable approach to capture its security over a generic network, formulating the goal of DIDComm as a strong ideal communication resource. We prove that the proposed encryption modes reach the expected level of privacy and authenticity, but leak beyond the leakage induced by an underlying network (captured by a parameterizable resource).
We further use our formalism to propose enhancements and prove their security: first, we present an optimized algorithm that achieves simultaneously anonymity and authenticity, conforming to the DIDComm message format, and which outperforms the current DIDComm proposal in both ciphertext size and computation time by almost a factor of 2. Second, we present a novel DIDComm mode that fulfills the notion of anonymity preservation, in that it does never leak more than the leakage induced by the network it is executed over. We finally show how to merge this new mode into our improved algorithm, obtaining an efficient all-in-one mode for full anonymity and authenticity.
先日書いた通り、DIF(Decentralized Identity Foundation)がDWN(Decentralized Web Node)に関するイベントを日本時間の19日のAM1時からやりました。
DWNの説明図(DIFより)
その中で大きな発表がありました。
The Decentralized Identity Foundation (DIF) today announced a Free Managed Decentralized Web Node service for developers, operated by DIF leveraging Google Cloud technology.
ベース・レジストリの整備に関しては単なるインフラ整備だけでなく、実際のユースケースや国⺠・行政機関等のニーズを明らかにした上で、取組の実現可能性を精査した上で整備を進める必要がある。この際、登記情報を保有する法務省等、ベース・レジストリの整備・運用に必要となるデータオーナーである各府省は、ベース・レジストリに登録されるデータが適時適切にアップデートされるようデジタル庁との機能的連携が可能となる仕組みを構築すべきである。また、ベース・レジストリにおけるデータ整備については、国立印刷局の持つノウハウを活用し、品質の高いデータを整備することで、情報連携の仕組みに係る全体のコストが効率的なものとなるよう留意する。加えて、⺠間企業に対する登記情報 API の開放について、制度所管省庁である法務省とデジタル庁で検討を行うべきである。
ベースレジストリについても触れられています。少なくとも法人KYCなど法人登記情報をAPI等で民間事業者から参照できる仕組み作りは必要になってくると思います。UKにおけるCompany Houseなど登記情報をAPIで取得できる形が最低限必要となると思いますし、OpenID Connect for Identity Assuranceのプロファイルとして今後策定が進むAuthority Claimsなども考慮に入れることが期待されます。
4.4. VC/DID の利活用促進
web3 技術を応用した VC及び DIDは分散型デジタルアイデンティティを実現する技術であり、国際標準化及び諸外国でのプラクティスが積み上げられつつある。我が国においても⺠間主導で実証やルール整備の検討が進められているが、国内サービスの濫立を避けるため、所管省庁を中心に官⺠が連携し、国内での早期実装に向け、国際標準化をはじめとした議論への参画、実装に当たっての制度的・技術的課題の整理等を進めるべきである。また、VC 及び DID の社会実装を促すため、行政における先行的なユースケースの創出にも、所管省庁を中心に関係省庁が連携して取り組むべきである。
また、VC/DID を活用した分散型アイデンティティの実現に向けて、欧州をはじめとした各国で DIWの議論が進められている。本人を介した情報連携のハブ機能となる DIWがデジタル社会の新たなチョークポイントになり得ることを踏まえ、産業振興や競争政策の観点も含めた政策検討を所管省庁において実施するべきである(VC 及び DID に関するより詳細な提言について web3PT の提言を参照されたい)。
国際的なデータ流通の仕組み(データ連携基盤)に関しては、EU における実装が進展する中、我が国においても海外との相互運用性を確保しつつ EU 主導でのルール形成に対抗していくため、官⺠が連携した枠組みでの議論とデータ連携基盤の構築が急務である。企業や業界、国境をまたぐ我が国のデータ共有やシステム連携の仕組みであるウラノス・エコシステムでは、欧州電池規則への対応のため既に蓄電池を先行ユースケースとしてデータ連携基盤が構築されているが、取組領域・ユースケースを拡充し、官⺠を挙げて我が国のデータスペースエコノミーを構築すべきである。
did:webに限らずdid全般において言えることですが、結局did、Decentralized Identifiersはつまるところ識別子なのでどうやってメソッド内の名前空間におけるユニークネスを担保するのかがポイントになります。ユニークネスを担保するためには多くの場合においてレジストリ(Trusted Data Registry)を構築し重複レコードがないことを管理することが必要となります。その際の登録〜管理プロセスを特定の管理主体(群)を通して行うモデルが従来のDNSやCA局などが取ってきたモデルです。一方で衆人環視の元、あらかじめ合意されたコンセンサスアルゴリズムに則ってレジストリへの登録〜管理を行うモデルがいわゆるブロックチェーンベースのレジストリ管理のモデルです。
論文内で言及されるWeb2.0における世界観における信頼は既存のアカウント管理システム(例えばNFTマーケットだったらOpenSeaやTwitterなど)によって裏打ちされたアイデンティティがベースでしたが、本論文内においてSBTはレピュテーションをベースに信頼を構築することが考えられています。いわゆるブロックチェーンにおけるコンセンサスアルゴリズムのProof of Workのモデルそのものだな、と感じているのですが多くのアクティビティがあり、他のソウルとの関連があり良い評判が得られているソウルの信頼性は高く、必ずしも現実社会におけるエンティティとの紐付きをベースとしてお墨付きを必要としないという考え方です。
少し脇道に逸れますが、そもそも論としてDIDに関してもIssuer DIDとHolder DIDは分けて考えるべきではないか?と思います。VCの文脈における典型的なIssuer/Holder/Verifierのモデルは原則事業者と消費者のモデルがベースとなっており、Issuerは事業者、Holderは消費者となることが想定されていますが、このモデルではいかにしてIssuerの信頼性を高めることができるのか?が焦点となります。この点はDIFのWell Known DID ConfigurationによるDNSのガバナンスへの依拠などにより解決をしてきた問題です。
Thank you. Hello I'd like to talk to you about digital transformation of a different kind than we normally discuss. The world, the technology world has certainly been full of discussion of digital transformation of the enterprise. But my thesis will be that when the enterprise changes the way it treats individuals. It creates a digital transformation for the individual, the lives of people change when the way enterprises treat them changes.
So in getting to that discussion I'd like to look at what we've actually achieved as identity professionals.
Well, really we’ve achieved some great things. We've satisfied all of the basic requirements of digital transformation in which enterprises redefine themselves to deal digitally with us as individuals. We've streamlined and we've professionalized the technology for distinguishing us. If you go back 10 years, that technology was really a catastrophe of amateurism and we have professionalized the way it is written, the way it is run and the way it appears. We've transitioned the world from raw authentication where only based on secrets to one where whether it be SAML or OpenID connect. We're talking about the transmission of claims. I will come back to that in a second but this is one of the most fundamental changes we've brought about. We've enabled a reliable identity dial tone for the internet and interoperability between diverse systems all of which was just a pipe dream 15 years ago. In addition we can even say we have increased dramatically the security of the internet in spite of all the work that remains to be done. I remember the day when we sat and talked about the fact that we needed to change our paradigm from attributes to claims. Attributes was the word for characteristics in a closed world of single enterprise and we realize that when you open the world and go between domains. It isn't simply a question of attributes, it's a question of who says what about whom. Attributes are spoken by an entity and you must decide whether you actually believe that entity. In other words that's where we came to the concept of claims where claims are attributes that are in doubt and you need technology to decide what you trust for which purposes. This was a fantastic change in technology without which we couldn't have moved out into an actual internet identity we would have been stuck with this prison of the individual enterprise. So I don't say all of this to puff us up and make us overly proud of ourselves. I say this to remind us all that we can do really difficult and almost unthinkable things. Claims which the notion of claims began as something which was almost impossible to explain and now the entire world bases its technology on the concept of claims of assertions that are in doubt. So we were able to transform technology on a scale that was unimaginable if you at the time. And the reason I say this is because we must bear in mind that we can do that again, we can do that now. We mustn't look at the current state of technology and say that's what it is. Our role as professionals is to actually go beyond that.
So at the same time that we congratulate ourselves let's look at how we failed.
We’ve failed to recognize that the digital transformation of enterprise created the digital transformation of individual people and we left them really in a situation of chaos. You know the thing about this is we haven't seen the fact that when all of the enterprise's digitalize then the individual faces a new problem of scale. Instead of having to deal with one enterprise or five enterprises of 20 enterprises they have to deal with hundreds and I would say thousands at this point. In addition it isn't simply a scale in terms of the number it's the question of intensity. And by intensity I mean the frequency of dealing with the services and the immersiveness of the relationship with the services. So this is a change which is really significant and further despite the hopes of the telcos who I love of course. The fact remains that people will require multiple different devices in order as it come more intensive and we're using devices in more parts of our lives for more things we need more kinds of devices and we need multiple devices and we all have Alexas now and we all have tablets and we have phones so there's not one single device and this is our we have devices in our cars and devices are propagating. And we've left people in a world where all the technology is device-specific and there is no interoperability between devices really because of the control of the operating system of the device manufacturers. And lastly well of course we have left people with all the problems of privacy and profiling and we have created a need for technological longevity and this may be one of the most difficult problems. In other words you don't just have a device you have a device that one day a terrible thing happens and you have to move to a you have to upgrade to a new device or you lose your device or whatever. So there's longevity in terms of as more is concentrated in the device the need to be able to move the device to other devices becomes greater and we have no answer for this. And similarly we have no answers to help people cope with changing service providers. When one service provider begins to disappoint us or fail us or betray us, how do we transfer our digital life to another service provider? And finally there's the problem of accommodating aging. I speak with experience about what happens when one's memory begins to fade. All of our technology depends on remembering passwords. So basically you are cut from the digital world just through the process of aging and at the point of death the process of inheritance in the digital world of your digital assets is just a chaos.
So let me ask if we've been so clever about all the things we've achieved, how could we fail in so many ways. I would say the reason is because the problems of the personal digital transformation are very gradual and they grow very very slowly. You know you don't get all of your thousands of relationships in one day. You don't have the need for multiple devices all of a sudden everything is very gradual. It's like the lobster who is putting cold water in and the water is heated slowly and the lobster doesn't complain until it's too late. This gradualness has allowed us to escape the recognition that at a certain point. That change in quantity will become a change in quality and becomes something which really causes deep social resistance.
So I have the thesis that PDT(Personal Digital Transformation)’s gradual changes are eventually making our systems usable. And that our organizations do not understand the coming social disjuncture. That is implicit in personal digital transformation. I also think that only those of us who have expertise in identity have the ability to perceive the underlying dynamics and to sound the warning bell and to adjust course within our enterprises. Only we can take the leadership recognizing and addressing the emergent realities.
Now you know in the physical world people have been expertly handling human identity for many millennia. But there has been no attempt to replicate those abilities in the digital world. The creators of digital services we the enterprises and governments have scoped our efforts to solving our own problems as enterprises. And forgetting about the requirements really of the individuals as long as they could cope incrementally with what we were dishing out to them. So the systems that we build cause rather than solve the problems of the personal digital transformation. Because they have been one-sidedly built solely from the point of view of the enterprise. So my thesis is that personal digital transformation requires us to transpose human identity in all of its brilliance and subtlety into the digital world.
Now if you look at let's look at the pattern by which digital reality has been created. I propose that what has happened is that things begin with a deep understanding of a phenomenon. Then there is innovation in order to bring about what I called transposition by transposing. It's like in music where you move from one key to another key. And here this is moving from one part of reality physical to another part of reality digital. And this pattern leads to a holistic digital equivalent. So if we think about digital audio.
People, scientists had a very good understanding of what audio was. They knew audio was a form of sound waves. And the innovation was to take those waves and sample them to see different amplitudes and then be able to say okay we can express those amplitudes as digital data and produce a holistic equivalent of the sound so that the process could be reversed to create the digital audio. And so now the end result is 50 million songs for $9.95 a month from Amazon. I mean this is a fundamental thing that was done through a holistic approach to solving the transposition problem.
But if you look at the rest of the internet this problem of transposition has been solved in a similar way. Let's take the case of just digital banking. It began with people who had a deep understanding of the phenomenon of banking, then analysts came in and understood the processes and the aspects and the things that had to be replicated. And then innovators built the visual experiences that allowed this to be used by millions and hundreds of millions and billions of people.
So what about digital identity? Where are the experts in what human identity has been for these thousands of years? Who are they? What is the invitation? What is innovation? Where's the transposition? What's the holistic digital equivalent?
Basically I have been looking at this for almost 50 years. It is impossible to find an equivalent in terms of scientists or sociologists or psychiatrists. The only thing that has been studied really is basically identification in other words for example the way that governments have handled identity you know during the last hundreds of years. And not only that when on the internet when you read about identity you read all kinds of things when you read about digital identity. And basically people just make up words and use them in ways that they just pull them out of the sky. So I believe we have to realize there are tools that can help us. One of them is in English and I'm curious to know if there are similar tools that can help us in Japanese culture, Chinese culture and other cultures. But the European because you say the whole notion of identity, it actually comes from French. So it isn't simply English, it's sort of the European experience that has been studied, and in great detail by the Oxford English Dictionary.
You may not know that dictionary, because you are not that involved in studying the details of English Origins. But you actually have not only the definition, but the uses of these words throughout time since they were first recorded in writing. And so you really can have an understanding if you look up something like identity there is great wisdom in what is expressed. I'm going to leave this with my slides but these notions that are really the essence of the Oxford English Dictionary definition are hugely accurate and important and worth reading and I would love you to share other things from your culture that would lead us to greater insights.
But I have actually distilled this my reading of the dictionary into two concepts one is selfness and one is who-ness. So selfness is the sameness of the person, the thing at all times, the condition of being a single thing, the fact that a person is itself and not something else. That's the self and selfness. Who-ness is what is said about people, the characteristics of the person, the ability to recognize the person. And I called this selfness and who-ness and somebody may think gee Kim you just said you shouldn't make up words now you're making up words but the words. Selfness originated in 1574. And the word who-ness originated in 1611. People have been thinking about these problems for a really long time.
So to make it simpler, selfness is the aggregate of all the attributes and experiences of a person through their life. Who-ness is what you share in individual relationships.
Perhaps the most important concept is that this aggregate is never visible in the physical world. To the people in your relationships they never see the whole, only you, only the self has a visibility on to all that has happened, but it has that visibility and that is fundamental to the way it exists. Privacy is the fact that the who-ness are not convertible into selfness, all right and that's what creates the distinction you know our own individuality is distinct.
So now I imagine you’re asking, okay but how do these concepts map onto current digital technology.
Well, the truth is digital identification which is what we have. We don't have digital identity yet , we have digital identification so far. Which is the who-ness from the point of view of enterprises and governments. We actually have made some progress in who-ness and that's what we've achieved as I discussed at the beginning of this presentation. But there's virtually zilch you know zero in terms of technology for selfness.
So to solve the problems of personal digital transformation, we have in order to do an MVP for digital transformation. We need massive new construction in order to build technology for selfness and we need major renovation so that who-ness can be made compatible with selfness.
Selfness is technology, you know basically the self needs its own technology just as we've automated the enterprise we haven’t automated the self and you know Ian spoke about this in terms of his concepts like active clients and so on. We need to be able to remember and manage our relationships. We need digital technology to do that for us. We need to have digital technology that handles the problem of recognition without our consciousness just as happens in this world in the physical world. We aren't conscious of meeting each other and this is an identity relationship it's simply an identity relationship. Our technology must do the same and provide this recognition layer. We must be able to move between devices from any manufacturer and use new devices without perceiving any change. And I will assert that regardless of what the device manufacturers want to do, the need to do these things as so significant that there will be social and governmental intervention in order to make just as there was around privacy in order to solve these problems of having a self across multiple devices without being prisoners of powerful corporations, and so on. We need to be able to use the services to fill in its memory to fill in the self’s memory as people age. The services can guide them and take over the problem, automate the problems of aging so that they can continue to be part of their digital world. And the digital world at the digital who-ness must evolve in the sense that we have to separate the problem of recognition of ID from the problem of characteristics of claims. So that we don't have to be conscious of all of the ID work and can achieve a world similar to the physical world.
Now to bring this down to something concrete with respect to current technology. In who-ness we need to separate the layers and and I was so pleased I was at the OpenID (Foundation) Japan meeting today and the the leaders of OpenID (Foundation Japan) are perfectly aware of this problem and are working two separate the problem of recognition and distinct impression from the problem of characteristics by splitting up ID technology from the actual claims provider technology. And we have these things. We have many initiatives here DIDs, OpenID SIOP and FIDO2. Any characteristics, we have two phenomena, one is verified credentials and one is aggregated and distributed claims. Now the important thing here is that we not unleash 10 different technologies on the people who are already victims of the personal digital transformation. So between us we as technical people must ensure the convergence of these technologies. So that they're interoperable with each other ,for example a key recognition that is that I can have when I'm using OpenID and recognition I can have when I'm using FIDO those should be once it's established in one it should be established in the other and it should automatically be because it's part of the self be shared between those different ways of doing who-ness. In terms of selfness we have been one I think an important innovation which is this notion of authenticators. The authenticators, Google has done a very good job actually of initiating this notion of authenticator. Google has done an excellent job here, but this is all very very primitive and as Ian pointed out we need to have much more advanced technology for the self.
So I'll just give my conclusions. A bullet train is headed straight for us in the form of personal digital transformation. We need to see it coming and get out of its way by evolving a holistic digital identity. OIDC which you're here to celebrate today the most promised I think it's undoubtedly the most promising deployed identification technology should be triaged and is being triaged to determine how it can fit into holistic digital identity. Then self sovereign identity, OpenID Connect SIOP and FIDO should be rethought so they fit together to solve the problems of the personal digital transformation. Otherwise they'll just make things worse, wasting everyone's time and money. This requires a great deal of careful thought. I have some examples but I've gone on too long so I'll leave the examples for people who would like to look at the slides later. So thank you very much.
そこで私は、PDT(Personal Digital Transformation)の緩やかな変化によって、最終的にはシステムが使えるようになるのではないか、という仮説を立てました。そして、私たちの組織は、来るべき社会的断絶を理解していません。それがパーソナル・デジタル・トランスフォーメーションの暗黙の了解です。また、アイデンティティに関する専門知識を持っている私たちだけが、根底にあるダイナミクスを察知し、警鐘を鳴らし、企業内で軌道修正することができると思います。私たちだけが、出現した現実を認識し、それに対処するためのリーダーシップをとることができるのです。