State of the KERI Suite - Samuel Smith

KERICONF26 Day 1 · 50:10

0:00 Samuel Smith | State of the KERI Suite | KERI Conference 2026

0:02 All right. I want to introduce Henk

0:07 van Cann. Right, the KERI

0:09 Foundation (https://keri.foundation) would not exist without him.

0:12 He came out of retirement. He likes to

0:15 play guitar and sing on the streets in

0:18 the Algarve in Portugal, and he could be

0:21 doing that instead of being here with

0:23 you guys. So,

0:24 give him a big round of applause.

0:28 And he's also a financial sponsor of

0:31 the KERI Foundation. So, there's no

0:33 amount of

0:34 thanks that

0:36 is too much for him.

0:37 I want to thank everyone for coming.

0:43 This is KERI Conference 2026.

0:47 Get a t-shirt cuz there'll

0:50 never be another first-ever KERI

0:51 Conference. So, you know.

0:54 And I think they're downstairs, right?

0:55 Yeah. All right.

0:57 And then…

0:59 one more shot for the

1:02 for the sponsors.

1:03 So, I'm going to talk about the state of

1:05 the KERI Suite,

1:07 the journey to adoption.

1:10 and

1:13 I look at 2026. We've been doing KERI

1:16 for a lot of years now,

1:19 and it feels like this is going to be

1:22 the year of KERI. So, mark

1:24 your calendars. This is where the world

1:26 starts to understand and

1:28 and know that KERI exists.

1:32 Some early feats

1:33 that have already happened in 2026.

1:37 The KERI Suite of protocols released

1:39 as Linux Foundation open standards. That

1:42 was a four-year process starting in

1:45 2020.

1:47 And we've got TrustoverIP. Drummond [Reed, red.] who

1:49 is the chairman is here today.

1:52 And then we have a couple of members

1:53 of the steering you know, several member

1:55 at least three members of the steering

1:57 committee here today. They've

1:59 been helpful; Karla, Niko and Drummond.

2:01 We started a funded project to build

2:08 open infrastructure for KERI.

2:10 We received a grant from the Utah

2:13 Governor's Office of Economic

2:15 Opportunity to build a digital

2:17 identity utility for SEDI,

2:20 based on KERI.

2:23 the Telecom Industry's OVC Alliance is

2:28 doing proof of concepts to vet use

2:31 of the KERI Suite of protocols and the

2:33 verifiable voice protocol. And later

2:35 today, you'll have Daniel Hardman

2:37 is here. He'll talk about that.

2:40 We have Utah State passed the SEDI

2:44 implementation law

2:46 funded law to build SEDI.

2:50 There is

2:52 production implementation of

2:57 using those for stopping call spam.

3:00 Healthcare's vital

3:02 Initiative. We'll have a talk later

3:04 today about that with the vLEI, KERI

3:09 and using the KERI for healthcare

3:12 data provenance.

3:14 We just completed the SEDI

3:18 Policy summit the last 2 days. How

3:22 many people are here that were here the

3:23 last 2 days?

3:25 All right, almost everybody. Fantastic.

3:27 So, you so I don't need to tell you any

3:29 more about what happened there.

3:32 And first-ever annual KERI conference

3:35 So, that's just this

3:38 first 4 months of 2026. We're just

3:40 getting started.

3:43 One of the things I want to

3:45 look at is

3:48 what are the chances of broader

3:52 adoption? What are the sort of

3:54 rules? And so, I went back to

3:57 Malcolm Gladwell wrote a book

4:00 called The Tipping Point.

4:01 And he had rules for

4:05 when adoption reaches a tipping point.

4:07 And this is a curve.

4:11 And the tipping point is this inflection

4:12 point down he- down here where

4:16 you sort of go from

4:18 flat adoption to where you start to

4:22 get a significant grow to

4:25 a steeper curve. And the

4:28 the reality is down here, it's not a

4:31 smooth curve. It's really noisy down

4:33 here. And so, really the tipping point

4:35 is when the noise starts to dissipate

4:38 and you start to see

4:41 month over month, week

4:43 over week, year over year growth. And

4:47 where does that tipping point

4:51 happen? How do we get to that

4:53 tipping point? So his three rules

4:57 are the law of the few, the stickiness

4:59 factor, and the power of context.

5:02 So, the law of the few. What does that

5:04 mean?

5:05 Well, if you have a sufficiently

5:07 influential set of early adopters, those

5:10 are the few.

5:12 That means you have to have people

5:14 that recognize the technical

5:16 suitability. And then they have to try

5:19 to get other people to adopt it.

5:22 And so, you guys

5:24 are the few. You're the ones.

5:28 So, let's see what's happened.

5:30 You have to first overcome the seven

5:33 stages of adoption resistance.

5:36 I know there's some people

5:38 in this room that [are in there:] shock,

5:40 denial, anger, bargaining, testing, and

5:42 acceptance, right? Most of you are

5:46 well along. There's still a couple that

5:48 maybe they're in the <i>bargaining</i>

5:50 stage yet. They're still trying to well,

5:52 do we really need KERI or you know,

5:54 does it really solve what we want? We'll

5:55 see.

5:58 What are some adoption vectors

6:03 that the few start; sort of like an

6:05 epidemic, right? What are some

6:07 of those? Well, I sort of hinted at

6:09 those. We have the telecom sector.

6:11 That could be a massive adoption

6:14 vector.

6:15 We have the healthKERI sector. That

6:18 could be a massive adoption vector.

6:20 And we have state entitlements,

6:23 which

6:23 Could be a massive adoption vector.

6:25 Any one of those

6:28 could

6:29 cross the tipping

6:31 point. And since I'm a fault-

6:34 tolerant person, I believe in fault-

6:37 tolerant systems. I got to have three,

6:39 right?

6:40 You got to have three massive adoption

6:42 vectors to make sure one works, right?

6:44 So, that's where we're at.

6:46 Widespread bootstrap vectors. So, the

6:49 difference here is

6:52 in order to have adoption that is

6:55 we had a

6:56 saying in Florida, "What

6:58 comes in over the transom goes out

7:00 over the transom.

7:01 You know, as a wave washes fish in, it's

7:04 junk fish, you don't want it, right? But

7:06 what we want is to have adoptions

7:09 that we didn't plan on. We didn't know

7:12 that they were going to happen. And they

7:13 they just spin up

7:16 spontaneously. And so, we need something

7:18 that will bootstrap those without us

7:20 forcing them. These up here

7:22 are the result of years of work.

7:25 We started working

7:27 with SEDI, three years

7:29 ago. I know how long Provenant and

7:32 healthKERI have been working in their

7:33 sectors. It didn't happen overnight.

7:36 It took lots of time, right? But we want

7:39 to also have vectors that happen

7:41 quickly. So,

7:43 we have two bootstrap vectors,

7:45 organizational Root of Trust, that's

7:47 GLEIF.

7:48 And that's been the thing that has

7:50 been enabling these other ones, right?

7:52 They went to production with

7:54 the vLEI in 2022. That's now

7:57 been 4 years. Seems like it was

8:00 yesterday, but it's been 4 years.

8:03 We're starting to see the

8:06 fruits of that.

8:08 But one of the things that is new this

8:11 year and in the next year is a personal

8:13 Root of Trust. That's never happened

8:15 before, not an organizational root of

8:16 trust, a personal Root of Trust. That

8:18 means lots of businesses

8:22 that wouldn't normally consider using

8:25 digital identity, centralized digital

8:27 identity,

8:29 are going to get for free bootstrapped

8:33 identity assurance that is highly

8:36 trustworthy.

8:37 That means every industry

8:40 has the potential to leverage

8:43 that Root of Trust, which is Utah state.

8:46 And then all scale enablement vector,

8:50 that's open standards,

8:52 open source, and open infrastructure.

8:55 I'm going to talk about what I mean by

8:56 open infrastructure a little bit later

8:57 in this talk.

8:58 So, there's the law of the few. So, I

9:00 feel like

9:02 we've got that.

9:05 The next one is the stickiness factor.

9:06 What makes it stick?

9:08 Well, it needs to be compelling and

9:10 contagious.

9:12 So, we have to think about things that

9:13 make it, right? So, we need to have some

9:16 sort of pathology that's endemic

9:20 that isn't going to go away and it's

9:22 going to stick

9:23 and it's going to keep driving adoption,

9:26 and that is fraud.

9:28 The world is filled with fraud. Every

9:30 business is suffering the cost of fraud.

9:33 And fraud includes identity theft. It

9:36 includes,

9:37 all of the security,

9:39 exploits,

9:42 ransomware.

9:43 But, it includes just normal day-to-day

9:47 business, factoring fraud, PO

9:49 fraud [Purchase Order, red.], those sorts of things.

9:52 And they're getting worse. And one of

9:54 the things that are making them worse is

9:56 the fact that the tooling that enable

9:59 fraud has now reached the point where it

10:02 is better

10:03 than the mechanisms that protect against

10:05 fraud.

10:06 And so,

10:08 that's going to continually push people

10:11 over the edge. They're going to

10:12 say, "Do I really need KERI?" And you

10:14 go, "Well, can you fix fraud without

10:17 KERI?"

10:18 And they go, "Well, no, not really."

10:19 Okay, then you really need KERI.

10:22 Regulator imperatives to

10:25 repress fraud and abuse. Those

10:28 are happening in several industries. For

10:30 example, in the telecom industry, FCC.

10:33 In the healthcare industry ..,

10:34 you see Scott [Scrimshire, red.] nodding his

10:35 head.

10:39 In state endorsed

10:40 digital identity.

10:43 You're you now have regulators that are

10:46 saying, "Hey, we need to we need to

10:49 we need to we have an imperative that

10:51 says we've got to get rid of fraud and

10:53 abuse." And by abuse, I mean

10:55 exploitation of citizens in the case of

10:57 personal identity.

10:59 The malaise of digital exploitation.

11:02 Do any of you feel like you're sick

11:06 of being exploited online?

11:10 Only a few of you. Okay.

11:12 Do you know of anybody that

11:14 feels like they're sick of being

11:16 exploited online? Okay. [laughter]

11:18 Do you have a desire to

11:21 control your digital presence? Yes.

11:24 Absolutely! The

11:26 So that's a stickiness factor. Is

11:28 that desire going to go away?

11:31 Do you know anybody

11:32 wants to have less control?

11:39 I know some.

11:40 Yeah,

11:40 There are few. But most of the ..,

11:42 everybody in this room, I'm pretty sure,

11:43 wants more control over their digital

11:45 presence.

11:46 The other thing that's happening

11:49 is that the technology

11:51 that enables KERI

11:54 is key management.

11:56 And that means the devices, the

11:58 software, the systems, operating systems,

12:01 have to start moving in the direction of

12:04 educating people

12:06 to manage their own keys. And that is

12:08 happening.

12:10 You know, when we started KERI and

12:12 when I started doing digital

12:14 identity in 2015, 2016,

12:17 the people were

12:20 really saying, "There's no way

12:22 you're going to get

12:24 people to manage the private keys."

12:27 The blockchain community had

12:28 already gone there. They had to

12:30 manage private keys to be on the

12:31 blockchain. The technology

12:34 got a got a big boost. Now you're

12:36 seeing it in every system.

12:39 This endemic pathology is pushing

12:42 people to better key management.

12:45 As people become familiar, the

12:48 friction to adoption reduces.

12:52 So, I think we have stickiness.

12:55 The power of context.

12:58 What that means is timing and

12:59 externalities. Is the timing right?

13:06 I think the specter of AI is making

13:09 an unprecedented

13:12 context that says the timing

13:14 is right.

13:15 We are faced with

13:19 the potential for the annihilation of

13:21 trust. There's an impending doom. I

13:23 don't If you guys don't see it, if you

13:26 aren't, go read OWASP 100-page

13:30 report they just

13:31 published

13:33 on how to deal with AI threats to

13:36 security.

13:38 And it is chilling cuz they say

13:41 it has never existed before, it is a

13:44 different type of threat, and we don't

13:46 have a cure. All we can do is mitigate

13:49 some of the symptoms.

13:51 And they're only going to get worse. And

13:52 it's 100 pages long.

13:54 Right. And it's just starting.

13:56 They're going to add 100 pages

13:59 on a regular basis because the threats

14:01 are increasing at an exponential rate.

14:05 So, impersonation,

14:07 been around for a while. AI

14:08 impersonation, deep fakes,

14:11 those, they just barely

14:13 happened.

14:14 When was the ChatGPT moment?

14:19 Yeah, 2023. It's only 3 years around,

14:22 and we're already

14:23 seeing those effects.

14:26 Exploitation, you thought somebody

14:29 could exploit you? Wait till an AI

14:31 exploits you.

14:34 Surveillance, you thought you were being

14:36 surveilled online?

14:39 Just ask an AI to surveil you.

14:42 You know, I've done this test for

14:44 people where I went out and said, "Hey,

14:47 I'm working with X,

14:50 and he needs somebody to manage his

14:52 online presence and reputation, and I'm

14:55 doing that for him."

14:57 And it says, "Okay."

14:59 And after about three prompts, it says,

15:02 "So, would you like me to create an

15:04 interactive dashboard that tracks all of

15:06 the things they say and do online?"

15:09 And I always say "No."

15:11 [laughter]

15:12 It takes

15:14 literally 10 minutes for anybody in

15:17 the world to say, "I want to know

15:18 everything about everything that anybody

15:20 that they know of that they have a name

15:22 for has done.

15:24 And that's just

15:25 starting.

15:27 We're not even close to the

15:28 capability yet.

15:31 Sufficient political will to legislate

15:33 new civil rights. I think you saw that

15:35 the last 2 days.

15:38 Individual control over digital ID data

15:40 and context. That is

15:42 what we need is legislation that gives

15:45 us back control over our internet

15:47 presence.

15:48 <i>Duty of data loyalty</i> is probably the

15:50 most significant legislative initiative

15:54 that we can put in place to enable

15:57 control over

15:59 over our digital ID presence online.

16:02 We can't do it with anything less. It

16:05 inverts the liability equation. And for

16:07 those of you who don't understand the

16:09 difference between

16:12 consumer harm legislation and fiduciary law,

16:16 the standard of proof is different.

16:19 if I have consumer protection,

16:22 I can't

16:24 punish the person abusing, me unless I

16:26 can show harm. The standard of harm is

16:28 pretty high. And it's pretty hard

16:31 to show harm in a diffuse

16:34 internet online where your data gets

16:36 spread out all over the place and you

16:37 can't point to somebody and say, "You

16:39 harmed me." They go, "No, I gave

16:41 the data to this person. They gave it to

16:42 that person." And then you can't show

16:44 harm.

16:45 But fiduciary duty of loyalty says,

16:49 "If the fiduciary

16:51 is self-dealing,

16:53 then you can punish them because your

16:55 interests have to come before the

16:58 fiduciary's interests." That means

17:00 everybody that collects any data about

17:03 you online in Utah now has to

17:07 understand that if they self-deal,

17:11 if they benefit from your data and you

17:14 don't,

17:15 you can go after them.

17:17 That has never happened before. That is

17:19 the way place where it has to be.

17:22 So, that's the stickiness factor cuz

17:24 that's now in law.

17:26 And that stickiness, that's the context.

17:28 And then the last one, the inevitability

17:30 of KERI. You have to have true

17:32 believers who are going to fight through

17:34 the fights, who are going to

17:37 go to the meetings and put up

17:39 with the arguments and make the

17:41 case. And I think we have cadre of

17:45 people that are willing to do that. So,

17:48 people that are willing to do that.

17:49 And the thing is, we have a severely

17:52 constrained solution trade space.

17:54 And what I mean by that is, I spent

17:56 years

17:58 doing the trades. What can we do to

18:00 solve these problems? What tools do we

18:03 have available? And everything every

18:05 time I go, "Well, I could do this, but

18:07 wait, if I do that, then

18:10 here's the tradeoffs, and I don't

18:12 like those tradeoffs. And I do that,

18:13 here's the tradeoffs. I don't like that

18:15 those tradeoffs." And once you do the

18:17 tradeoffs, you realize that there's only

18:20 a very small

18:22 space for a solution, which means, as

18:25 far in my opinion, if it's not KERI,

18:28 it's going to be something that looks,

18:30 smells, walks, and quacks like KERI.

18:32 They just changed the name.

18:34 Because the under the hood, there just

18:36 isn't any other solutions. We have to ..,

18:39 cryptography only gives us

18:41 a handful of things that we can use.

18:43 That means that

18:46 the timing is right. So, anyway

18:51 Persistent problem cascade that

18:52 continually exhausts anything less

18:53 capable.

18:55 It's just every time you look at some

18:57 other system, you look at <i>DNS/CA</i>, you

19:00 look at <i>OAuth, OIDC</i>, you look at these

19:02 systems,

19:04 and they keep failing for the same

19:06 reasons.

19:07 People are starting to recognize that.

19:11 So, what does that mean?

19:14 It's a matter of when, not if. If

19:16 it's not this year, it's next year. If

19:19 it's not next year, it's the following

19:20 year.

19:21 Because none of this is going away.

19:37 I'm going to predict that before the end

19:40 of 2027,

19:40 KERI adoption will reach its tipping

19:42 point.

19:46 [applause]

19:49 All right.

19:53 The journey begins. So, what I wanted to

19:55 do on this first ever conference

19:58 is give a brief history of how we got

20:01 here.

20:02 Sort of like the foundations.

20:05 I think most of you have been there

20:07 through most of the journey.

20:09 But, I know there's some people that

20:10 haven't been, and this talk,

20:13 will be made available online for

20:15 other people. So, I thought this would

20:16 be a good opportunity to sort of

20:19 talk about, where it came

20:21 from.

20:22 I started down this path

20:25 back in 2013, 2014. I wrote a protocol

20:28 called RAET.

20:29 It's reliable asynchronous event

20:31 transport. It is an

20:33 end-to-end, peer-to-peer,

20:35 encrypted, signed, and it was used in

20:39 production at scale, and it was open

20:41 source.

20:42 So, this was years before most of you

20:45 have even heard of Signal. Back when

20:48 Signal wasn't called Signal, it was

20:49 called Whisper.

20:50 But, it was the start of that. So, what

20:52 was the lesson learned?

20:55 Well, I could solve all the problems but

20:56 key management with RAET.

20:58 [laughter]

20:59 So, I said, "Okay, that's not a

21:01 solved problem."

21:03 So, I already knew that

21:07 there was a big problem that had to be

21:08 solved sometime.

21:10 <i>OpenReputation</i>

21:12 I wrote a white paper.

21:15 It started using self-certifying

21:17 identifiers.

21:20 It had the concept of identity ledger

21:23 and identity graph.

21:25 It defined reputation as a modulator for

21:28 trust for online interactions.

21:31 And it

21:34 brought up the idea that we wanted to

21:35 have individual control over the context

21:38 in which we interact online.

21:40 Our internet presence.

21:42 And lesson learned from that is that I

21:44 needed persistent identity. I can't have

21:48 a good reputation without a persistent

21:49 identity, and that's the hard problem of

21:51 identity because nobody had a solution

21:53 for it back then.

21:56 <i>Identity System Essentials</i>, this

21:58 white paper. This is the first draft.

22:01 Introduced cryptonyms, built on the

22:03 SCID model. It provided a formal

22:08 identity model, primary secondary IDs.

22:11 Talked about identifier management

22:13 with HD key chains, three degrees of

22:15 privacy, and it introduced the concept

22:18 of self-sovereignty for identity. And

22:20 the draft paper was

22:23 shared in the community, and lots of

22:24 people amplified and built on the

22:27 concept of SSI, but as far as I know,

22:29 that was the first. And I stole it

22:31 from Phil. Because Phil Windley had

22:34 written some blog posts on

22:36 self-sovereign data, and I said, "Well,

22:38 we don't just want data to be

22:40 self-sovereign. We want our identity to

22:41 be self-sovereign." That was

22:43 back in 2016.

22:47 The lesson I learned, there's a

22:49 hard trade space. If you want to trade

22:51 off security and privacy and

22:53 self-sovereignty and control,

22:55 you're making some pretty hard trades.

23:00 Sovrin Foundation.

23:02 That really changed the environment

23:06 for decentralized identity.

23:08 The idea was there's going to be one

23:11 ledger for digital identity.

23:14 One ledger to rule them all.

23:16 And it had persistent identifiers.

23:19 It had prophylactic [preventive, red.] key rotation,

23:22 not recoverable key rotation. That

23:24 was going to

23:26 come a while later, but it built on

23:28 but it established the foundation of

23:30 managing your key state

23:32 so that you'd have persistent

23:33 identity.

23:35 Hard problem, shared governance.

23:38 That was a hard problem.

23:40 Spent a lot of time trying

23:42 to solve that problem.

23:44 2017, the ledger wars.

23:52 Okay, a lot of you fought in those wars.

23:54 What happened is

23:55 SSI was such a great concept

23:58 that everybody wanted it. Every ledger

24:00 wanted to have their own SSI

24:03 Identity.

24:05 So there was every time somebody would

24:07 have an application

24:10 that they wanted

24:12 decentralized identity for,

24:14 the very next thing was, "Okay, which

24:16 ledger are we going to put it on?"

24:19 All the people for all

24:21 the ledgers would come to the table and

24:23 say, "No, my ledger. No, my ledger."

24:25 And that's what it looked like

24:27 for several years.

24:28 And then

24:30 GDPR came out in 2018 and that made it

24:33 difficult to have identity on a ledger.

24:37 So the whole idea of persistent identity

24:40 using a ledger is a problem for GDPR.

24:44 And so

24:46 the ledger wars, so

24:49 the insight was that blockchain is too

24:52 centralized

24:54 for truly portable identity.

24:58 That was a really hard lesson to learn.

25:00 It took several years of fighting the

25:01 ledger wars to realize that.

25:04 The way of KERI.

25:08 Really the first paper that sort of

25:12 opened the path was this one in 2018.

25:16 The three R's of key management and one

25:18 of those R's

25:19 is Rotation and this is where I

25:22 defined the concept of pre-rotation. So,

25:24 it's in that paper.

25:26 It says, "How are we going to do key

25:27 rotation?

25:28 If we do it the normal way,

25:31 where we use our signing key to rotate

25:34 to a new signing key, if our signing key

25:38 is compromised,

25:39 then we lose control of our identity and

25:41 that's all of blockchain, by the way.

25:44 And that's all of blockchain

25:45 identity. If you lose control of your

25:47 signing key, you lose control of your

25:49 identity. That's

25:51 kind of a problem.

25:53 The other approach is

25:55 have a rotation key that you use to

25:58 rotate your signing key.

26:00 But then what happens if your rotation

26:02 key gets compromised?

26:04 Well, then you have another rotation key

26:05 to rotate the rotation key that rotates

26:07 the signing key. And I had several

26:09 cryptographers says that's best

26:10 practices. Well, what happens when that

26:12 one says two is usually enough. You only

26:14 need two rotation keys. They'll

26:16 never get there.

26:19 Good idea, but

26:20 maybe we could do better.

26:22 Pre-rotation is one-time use only

26:24 rotation keys.

26:26 You rotate your rotation key every time

26:28 you rotate your signing keys.

26:31 Pre-rotation

26:33 and then that also introduced the idea

26:36 of having a log of your key state.

26:41 Didn't call it a KEL event because

26:42 we hadn't coined the term KERI, so it

26:44 couldn't be a KERI event log,

26:45 a KERI Key Event Log, but it was a log.

26:49 Had multisig individual source and

26:52 provenance data.

26:55 The idea is make key management

26:57 fault tolerant. So, I started down that path.

27:01 In 2018, a little bit later,

27:03 paper called. A DID for everything.

27:06 It introduced the idea of <i>Verifiable</i>

27:08 Provenanced Graphs of Cryptographically

27:10 Chained Data.

27:11 That's the core idea that is now in

27:13 the ACDC standard.

27:19 Yeah.

27:21 In 2019, KERI version one white paper.

27:24 So, based on those, I said, "Okay, let's

27:26 see if we can figure out a way to do it

27:27 without a blockchain."

27:29 And the idea is that you have a

27:31 cryptographically verifiable append-only

27:33 event log for each identifier.

27:36 There's no shared governance.

27:39 You get rid of shared governance, you

27:40 get rid of the ledger wars.

27:42 Introduced CESR,

27:45 key rotation, witnesses, deconstructed

27:48 blockchain.

27:50 It solves the hard problem of cross

27:51 trust domain transfer.

27:54 Lesson learned:

27:56 we don't need a blockchain.

27:58 And I spent a couple of years arguing

28:01 with people that said, "No, you have

28:02 to have a blockchain. You can't do it

28:04 with a Key Event Log."

28:06 But now I hardly ever have anybody

28:10 tell me that you need a blockchain for

28:11 identity. Does anybody Is anybody

28:13 arguing that still in the room?

28:16 You don't have to raise your hand.

28:19 [laughter]

28:20 I took that paper on

28:24 the road. I went to IIW several

28:26 conferences, shared with everybody that

28:27 I knew. Tell me what I'm doing wrong.

28:29 Got lots of really good valuable

28:31 feedback. There's a list of

28:36 of acknowledgements in the back of

28:38 the KERI V2 white paper because there

28:40 were some really significant

28:42 meaningful enhancements that came from

28:44 that. One of those is the watcher

28:47 network,

28:48 CESR streaming, hierarchical

28:50 delegation, layered threshold

28:52 structures

28:54 in more detail.

28:56 Basically, it solved all the hard

28:59 problems of key management and so it

29:01 was ready to go and that was 2020.

29:05 And then the same year,

29:09 while we were still refining

29:11 the version 2 white paper came

29:14 across the idea of quantum-secure DIDs.

29:16 I co-wrote a white paper on this.

29:19 Using hashes to protect the

29:22 pre-rotated keys means that we've

29:23 pre-migrated along with the cryptography

29:25 agility. We already

29:28 have a story for post-quantum secure

29:31 and Daniel [Hardman] and I, Daniel did most

29:33 of the work, co-wrote a recent paper

29:35 about the post-quantum

29:38 position for KERI. If you're not

29:39 familiar with that, go read that

29:41 white paper. And then

29:43 you can maybe do a reference for it.

29:45 2020, GLEIF

29:49 Got religion. They said, this

29:52 works. We don't like the ledger wars.

29:54 I think that was your main motivation,

29:55 Karla? Yes. The ledger wars. They

29:58 didn't want to fight those anymore.

30:01 so lasting peace from the ledger wars.

30:05 important insight. It solves

30:07 organizational ID. Organizational

30:09 identity is a new concept. Came from

30:11 that because now you have a

30:12 organizational Root of Trust. It's a

30:14 bootstrap for any organizational ID

30:16 problem.

30:17 And now people in this room are starting

30:19 to get that. I wrote a white paper

30:22 "Universal Identifier Theory" just to

30:24 extend the identity model, unified model

30:27 for identifiers, bootstrap trust, be a

30:30 reputation by reference, multi-valent

30:32 key management, starting to talk about

30:34 how we build infrastructure at scale.

30:37 That went into more detail.

30:40 And then in 2020 we formed a

30:43 task force at Trust over IP to start

30:46 standardizing this stuff and

30:48 ACDC

30:50 became a thing,

30:51 at that point.

30:54 Authentic Chained Data Containers, and

30:56 I think,

30:57 We'll talk a lot about those in the

30:59 next 2 days.

31:03 And then 2022, GLEIF vLEI in production.

31:08 I won't go into

31:10 most of you are familiar with that.

31:12 So, now where we're at?

31:16 There was a story

31:18 missing in KERI. KERI is about

31:23 authentication, proving that you control

31:25 an identifier.

31:27 But, there's more to the story

31:30 and had lots of conversations about how

31:33 do you deal with privacy and

31:36 confidentiality, and

31:38 wrote the white paper, the SPAC white paper

31:42 which is now a task force

31:45 within Trust over IP working group

31:47 at ToIP, and it's like draft version 3

31:50 or something,

31:52 To solve,

31:54 protected communications

31:57 online.

31:59 It uses a three-layer tunnel,

32:05 and the idea is, that if I have

32:07 layered confidential contexts,

32:12 then I can solve

32:15 surveillance and privacy using layered

32:18 confidential contexts. And so,

32:21 that's the basic idea. And what

32:24 I mean by "It's exploitation, stupid,"

32:26 what I'm saying is that the real

32:28 question is, how do we protect people

32:31 from being exploited, not how do we help

32:34 people hide better. Hiding is not a very

32:37 fun place to be. If you've ever tried to

32:39 really hide,

32:41 you don't have a life.

32:43 I know people that live off grid. They

32:44 don't have a life.

32:47 You want to be able to live with a life

32:50 and not be exploited, and that means

32:53 having control over the context of your

32:55 data, not having a context, right?

32:59 That's the main difference.

33:01 Do you have a context that you control,

33:04 that you share data within, or do you

33:06 not have any context?

33:08 Most of the community

33:10 says, "Don't have any context."

33:13 That doesn't work very long

33:15 because

33:16 you live longer than a week, and you can

33:19 maybe have no context for a week or a

33:21 month or 3 months, but you're going

33:24 to run out of places to hide

33:26 after a while.

33:27 So, you need

33:29 a fortress that you can hide in.

33:31 You need multiple fortresses you can

33:32 hide in and have context.

33:35 So, 2023, Utah State Senate work begins.

33:38 Wrote a white paper called <i>Sustainable</i>

33:39 <i>Privacy</i>, talks more at length about the

33:41 regulatory things.

33:43 Fiduciary data loyalty

33:47 is in there.

33:48 The idea is you need a comprehensive

33:51 approach. Technology by itself won't

33:53 solve the problem. You've got to do it ..,

33:54 That meant as a

33:56 technologist, spending a lot of time in

33:59 the room with

34:01 regulators and politicians,

34:05 which were not my favorite

34:07 people, but now they become my favorite

34:08 people. I'm looking for Chris Bramwell,

34:10 but I don't see him.

34:11 He's late today.

34:20 ToIP, we got our own working group,

34:21 which helped speed along the things. We

34:22 had some

34:24 Cardano Foundation made a big investment

34:26 in open-source software.

34:29 Utah State started passing legislation.

34:32 KERI Foundation we established last

34:35 year [Dec 2024, red.]

34:40 No, that was that's wrong. That's

34:42 2024 12 02. So, it's in just the end of

34:45 2024, but it's really last year, to

34:48 try to foster

34:50 KERI throughout the world and get adoption.

34:53 And then we're back; we're now at

34:56 2026.

34:57 And we already did what happened in

34:59 2026. So, that's the history.

35:03 And you know what? I left a whole

35:05 lot of stuff off. There's been a huge

35:07 amount of work by people in this

35:08 community pushing KERI along. But the

35:11 core ideas, where they came from, and

35:13 then

35:14 you know, the milestones that got us to

35:16 where we are, I put on there.

35:19 So, what's the mission of the KERI

35:21 Foundation? Our mission is to foster

35:23 open infrastructure.

35:25 What does that mean?

35:27 It's the I in KERI. I had somebody ask

35:30 me, "Why Is that a typo? You made

35:32 the I in KERI red." I said, "No, I'm

35:34 trying to emphasize that I stands for

35:35 infrastructure."

35:37 KERI doesn't exist without

35:38 infrastructure. It's not a system that

35:40 works without infrastructure. And if you

35:42 don't have infrastructure, people can't

35:44 adopt it. They can't practically use it

35:47 because nobody wants to build their own

35:48 infrastructure.

35:50 So,

35:52 KERI is a decentralized key management

35:55 infrastructure.

35:56 Right? It's It was designed to be web

35:59 scalable

36:00 so that we get an ultra low cost floor.

36:03 Right? That's why blockchain ledgers

36:07 were a problem.

36:10 The idea is .. [tokonomics, red.],

36:12 and I spent time working in the

36:16 blockchain world, I think there was

36:18 somebody here from the Wyoming

36:20 delegation yesterday that used to work

36:21 for Consensus when I worked for him.

36:24 But he had a beard and you know, had a

36:25 different lifestyle. He was all

36:27 clean-shaven and had a suit on and I

36:29 didn't recognize him and he said, "No,

36:30 it's me, really. We worked together." And

36:32 I go, "Oh."

36:33 You know, it took me a minute.

36:36 But, the idea is <i>Tokenomics</i>. You build

36:41 incentives into the governance structure

36:43 so that people work together to build to

36:46 to make your infrastructure alive.

36:48 Another term for that is a

36:50 <i>cooperative model</i>. You can be in

36:52 competition. You can make money.

36:54 Everybody's making money.

36:56 But, they're helping everybody else out

36:59 to build the infrastructure that makes

37:00 it all possible for everybody. And

37:02 that's the idea.

37:04 So, we want to incentivize multiple

37:07 vendors.

37:08 No single vendor lock-in. We don't want

37:10 that. That's bad for KERI.

37:16 If you think about it,

37:19 if you have pre-rotated private keys,

37:24 you can and we have this in the code

37:28 in the Keeper, you can

37:29 reconstruct

37:32 all of your keys if you're using HD

37:34 keychain from any copy of your KEL

37:37 because the HD path is in the KEL. It's

37:40 the sequence number and the offset into

37:42 the into the key list. You don't need

37:44 any other information. You actually

37:46 don't have to worry about losing

37:50 all of your information

37:52 as long as one copy of one legitimate

37:55 valid copy of a KEL exists somewhere in

37:57 the world, you could reconstitute it.

38:00 We don't want wallet vendor lock-in.

38:02 We want multiple wallets. So, we now

38:04 have several wallets that are open-source

38:06 and we're going to demo

38:09 open-source stuff. So, the KERI

38:11 Foundation team, like they've

38:14 only been doing this since January, but

38:16 you can ask them whether

38:18 whether it was hurting their brain to

38:20 try to learn KERI in 3 months.

38:23 Some of them had a head start.

38:26 We've added another wallet. We've

38:29 got a mobile wallet.

38:32 You'll see some talks today of

38:35 people that are building wallets and

38:37 and infrastructure for KERI so that

38:39 we have multiple vendors because

38:42 adoption requires multiple vendors.

38:44 No big adoption wants to have a

38:47 single source of the technology. They

38:49 want to see they want to see multiple

38:51 vendors.

38:54 We have in KERI the concept of

38:57 <i>Non-Cooperative Key Custodianship</i>.

39:00 You can have key custodians that

39:03 are custodians of your signing keys.

39:05 They can have the keys.

39:09 And they can go away. They can hate you.

39:12 They can lose them. And you can still

39:15 reconstitute control over your

39:16 identifier

39:18 because you just have to retain your

39:20 pre-rotated private keys.

39:23 And so the major friction

39:26 of people managing their keys and

39:28 managing their signing infrastructure,

39:30 you can

39:32 rent out.

39:33 But you're not locked in because at any

39:36 moment in time you can pull your

39:38 pre-rotated keys out of

39:40 air gap cold storage, publish your

39:42 rotation,

39:44 signing 'See-ya' to your custodian.

39:47 And I think there have been

39:50 lots of money lost in the blockchain

39:53 world from

39:55 key custodians who have .., what do they

39:57 say? "Not your keys,

39:59 not your coins." Not true in KERI.

40:02 Not your keys, <i>still</i> your identity!

40:04 Not steal, still.

40:08 [laughter]

40:11 Users benefit from witness pools that

40:14 have no common mode failure sources. So

40:17 if your witnesses all come from the same

40:18 vendor, the vendor is a common mode

40:20 failure source. So, you really want to

40:23 tell your customers,

40:25 you know, have witnesses

40:28 supported by multiple vendors.

40:31 The watcher network, every watcher

40:35 that is an honest watcher

40:36 benefits from other watchers sharing

40:40 what they see in <i>duplicity</i>.

40:42 There's a huge incentive for watchers to

40:44 cooperate.

40:46 What we're doing for, what we're

40:49 calling <i>open infrastructure</i>

40:52 is "The Five Ws"

40:54 or <i>One-click KERI</i>. The idea is people

40:56 would come and say, "Okay, I want to use

40:58 KERI. How do I do that?" Well

41:03 Come to some meetings,

41:05 go read these repos, go do this, build a

41:08 bunch of infrastructure, then you can

41:09 use KERI. I'm sure I see

41:12 some people in here that have

41:14 walked that path. That's not a

41:16 really good story for adoption. The

41:18 idea is

41:20 we want to be able to tell somebody

41:22 One click,

41:24 it'll install KERI infrastructure for

41:26 you. You got a wallet, you got

41:27 witnesses, watchers, and now you can

41:29 start to build stuff with it. So, that's

41:31 the goal. So, the five Ws,

41:34 wallet,

41:35 witness,

41:36 watcher,

41:38 web,

41:39 so it's all on the web,

41:41 and wizard. And what wizard is the

41:43 catch-all term. We want <i>user interfaces</i>

41:46 that hide the complexity of key

41:48 management from the users.

41:50 And KERI gives you the ability to do

41:52 that. I mentioned some things that KERI

41:54 has built in that allow you to do that.

41:56 People building user interfaces need to

41:58 understand those so they can build user

42:01 interfaces to take advantage that. The

42:03 other wizard is <i>agents</i>.

42:07 You want interfaces to agentic

42:10 AI, and you want to control those

42:12 interfaces, you want to use KERI to do it.

42:15 So, this is what KERI infrastructure

42:16 looks like.

42:18 We've got a wallet on one side. Whoops,

42:21 go back. [organizing slides]

42:33 We have entity A has a wallet.

42:44 Entity B has a wallet.

42:47 Entity A has their witnesses they

42:48 control. They have watchers they

42:50 control. Entity B has witnesses they

42:53 control, watchers they control. There's

42:55 a shared watcher network. And now entity

42:58 A and entity B

43:00 can communicate

43:02 authentically.

43:05 But, they can't do it without

43:07 the watcher network and the witnesses.

43:12 (Now I can move on.) These are

43:17 early screenshots from

43:19 Mobile wallet that

43:22 that you'll see

43:24 demo-ed today. If you look at

43:26 the sessions, KERI Foundation team is

43:28 doing demos of the KERI stuff.

43:33 HealthKERI had developed

43:36 Locksmith wallet,

43:39 watchers and witnesses

43:42 for their proprietary products. And

43:46 earlier this year, they donated those to

43:48 the KERI Foundation and allowed us to

43:50 debrand them and rebrand them so that

43:53 everybody that wants to build, can build

43:56 on proven production-quality

43:58 infrastructure. And we're hosting those

44:00 repos and we have spun up -

44:04 we'll be providing some

44:06 witness and watcher networks on our own

44:10 servers so that people who want to test

44:12 it out can test it out running in the

44:14 cloud. That's one of the big

44:17 things that we're doing for the

44:20 community and

44:22 and I hope that makes a difference.

44:26 [applause]

44:33 There's two other pieces of

44:34 infrastructure

44:35 that are new;

44:36 that we're building this year:

44:39 Registrar and Observer. And the reason

44:42 these are important is that

44:45 they are how we do this concept what I

44:49 call

44:51 control over context.

44:54 So, I have issuances like SEDI

44:58 issuances.

44:59 They're ACDCs

45:01 and you have a registrar

45:03 and registries for like revocation.

45:06 And you have observers they get bulk

45:09 updates. The key here is the bulk

45:11 update. Bulk update means that the

45:14 observer

45:19 and the issuer can't correlate back to the point of

45:23 validation

45:24 because that's the point of use the

45:26 observer sees it

45:29 but a change in state by the issuer

45:32 can't be correlated forward because of

45:35 the bulk update and the observer's

45:38 not allowed and doesn't need

45:42 to communicate to the issuer because

45:44 they get a an update of all the

45:46 information that they need to do

45:48 verification. The verification

45:50 happens at the observer,

45:54 and observers can't collude

45:59 between each others if you're using

46:02 bulk issued credentials. So, we'll talk

46:03 more detail about that.

46:07 So, this enables bulk issuance. It takes

46:10 advantage of Sparse Merkle trees.

46:13 And so, that's some new

46:14 infrastructure. Another new

46:17 Use case, and these are in the spec,

46:20 these are in the ACDC spec, are things

46:22 called a <i>user presentation registry</i>.

46:25 So, one of the challenges

46:27 in verifiable credential world is that

46:30 if I have a proof

46:32 that a holder has that they're

46:34 the subject or the holder of a

46:36 credential,

46:38 and that proof gets stolen, and they

46:40 steal the user's keys, then that user

46:43 can be impersonated, and they can

46:44 present that credential, and the user

46:45 can't know that's happening or

46:47 doesn't have any way to know it. But, we

46:49 can use the same ...

46:52 (Go back.)

47:00 We can use the same

47:02 registrar mechanism

47:03 so that a user in the ACDC, when they

47:07 get it issued, can

47:09 designate

47:10 that their own registry

47:14 Is going to keep track of

47:17 blinded presentations.

47:19 And that means that a verifier won't be

47:22 able to verify the presentation unless

47:25 the presentation itself is anchored

47:28 in the registry. And this is all

47:30 blinded so that it's not correlatable

47:32 presentation to presentation. But, that

47:34 means that

47:35 issuees or users

47:38 who want to be ultra secure

47:42 can have fault-tolerant detection of

47:44 compromise of their keys with regard to

47:47 their own credentials. And they'll

47:50 know, just like:

47:52 you know that your keys for your KEL

47:55 been compromised because you can watch

47:56 your own witnesses. You can watch your

47:58 own registry to see that somebody else

48:01 is presenting your credentials

48:03 and you didn't do it. And so now

48:06 now you can take

48:08 recovery action.

48:11 So, what is KERI really?

48:13 Well, you've heard the phrase <i>Keys at</i>

48:16 <i>the Edge</i>.

48:21 <i>Security First, Always.</i>

48:24 <i>Minimally Sufficient Means. </i>These are

48:26 mottos, phrases; [another:] <i>Signed Everything</i>.

48:30 Sort of ways to look at the elephant from the

48:33 multiple blind men. [Don't assume one viewpoint captures the entire situation, red.]

48:36 So, all of these are features of

48:38 KERI, but if you only

48:41 thought of it as any one of these,

48:44 it wouldn't be KERI.

48:46 And lots of people have copied parts of

48:48 KERI,

48:50 but they've but not all of KERI. And if

48:52 you don't have all of KERI,

48:54 I guarantee you there are

48:56 vulnerabilities that you'll be

48:57 exposed to.

48:59 Heard a lot about that yesterday.

49:06 So, no more half measures, guys. It's

49:08 It's all KERI or no KERI.

49:10 [laughter]

49:12 KERI is

49:15 truly an identity revolution. There are

49:17 concepts in KERI that don't exist

49:19 anywhere else in the world in identity.

49:22 And I'm going to give you a short I

49:24 love creating acronyms because

49:27 I'm old and if I don't have a mnemonic,

49:30 I won't remember what I thought of

49:31 yesterday. So, this is how I remember

49:33 what I think from day to day.

49:35 Reputable Autonomic Pseudonymity. That

49:38 That encapsulates KERI in the smallest

49:41 set of words. Right? An identifier's

49:45 a pseudonym.

49:46 Is an autonomic pseudonym. What does

49:48 autonomic mean? Well, all of the

49:50 features of true individual control

49:53 over you know autonomic means self

49:55 governing individual control over your

49:57 identifier that's secure that's

49:59 persistent that's perpetual all of those

50:01 things right and reputable

50:04 means it doesn't go away.

50:06 There's something to stick to a

50:08 reputation isn't good unless it sticks

50:10 to something it has to stick to an

50:11 identity right? And then the other

50:15 mnemonic Control over Confidential

50:18 Context in which you use your identity.

50:20 You want to control the context that you

50:22 use the identity and that means that you

50:24 want the context to be confidential. Now

50:27 in the dictionary there are 20

50:29 definitions of the word privacy

50:31 or private.

50:34 About a third of them are synonymous

50:36 with confidential.

50:38 So when I say I'm sharing a secret with

50:40 you and I say it's just private between

50:42 us right?

50:43 That's not private that's confidential

50:45 right?

50:46 Because there's other meanings of the

50:48 word private that don't mean that.

50:50 The core private word means

50:53 intimate means only you know it.

50:57 Right? So a private key is never shared.

51:01 A shared secret isn't private.

51:04 Shared data over the internet is never

51:06 private in that meaning of the word

51:08 private but it could be confidential.

51:10 You could make the information

51:11 confidential.

51:13 So if you're going to interact with

51:14 people you want to interact in

51:16 confidential context and so you want to

51:18 make those contacts you want to have

51:20 control over that confidentiality. That

51:22 means control over what you disclose

51:25 control over what they do with it once

51:26 you disclose it to them.

51:30 So here's the thing RAP-C3

51:33 and if you say it really fast

51:35 it's a rhapsody* and that's KERI. [*an enthusiastic, emotionally expressive outpouring, red.]

51:46 That's it.

51:53 And we have a minute for questions.

51:56 – I think it'd be useful to explain

51:57 the difference between watchers and

51:58 observers.

52:00 So, watchers watch

52:03 the KEL. That's all they watch. They're

52:05 looking for duplicity in your KEL.

52:08 Observers are watching the state of

52:11 issuances that are anchored to the KEL.

52:14 So, KEL?

52:15 Via the TEL. Yeah.

52:17 So, it's a TEL observer. Yeah.

52:19 Yeah.

52:20 – Why do they need to be separated?

52:23 Well,

52:25 they have different purposes.

52:28 So, separation of concerns means you

52:29 design protocols so that everything has

52:32 Yes, it's layered. So, it's a layer,

52:35 right?

52:36 They depend on watchers,

52:39 but they aren't watchers.

52:41 Any more?

52:42 I guess we're out of time.

52:44 No, one more?

52:47 Four more minutes. Okay, I guess we

52:49 we started a little bit late. More

52:51 questions?

52:55 – Please be gentle. I'm Moises.

52:57 Be gentle. I'm a newbie at KERI. So,

53:01 Watchers witnesses. You

53:03 mentioned the term

53:05 KEL or TEL. Key event log.

53:08 No, TEL. But TEL is transaction event

53:11 log.

53:13 – Since there's an exchange of two parties

53:15 of information and keys,

53:17 how do the watchers attach to

53:20 confidential a confidential transaction?

53:23 Well, watchers aren't part of a

53:25 confidential transaction. Your key event

53:27 log is public.

53:29 You're publishing your key state so

53:31 everybody can verify

53:33 any attestation or assertion you make

53:36 relative to an identifier. And to do

53:39 that, you sign the

53:42 You sign things, and you have to verify

53:44 the signatures, so you need to know the

53:47 public key to verify the signature. So,

53:48 the Key Event Log publishes your

53:50 public key and then the witnesses and

53:52 the watchers, the witnesses make the

53:54 public key state highly available and

53:57 also give you a detection mechanism.

54:00 And if you were you at the SEDI

54:02 summit?

54:03 – No. Oh, okay. One of the things that

54:05 happens is that you want to be able

54:06 to detect that your keys have been

54:08 compromised. So, the witnesses are a

54:10 detection mechanism. Because if somebody

54:12 wants to publish something on your KEL,

54:16 they have to get your witnesses to

54:17 witness it, which means you get to see

54:20 it because what the witnesses witness is

54:22 public. And so, you can see that

54:24 somebody's compromised your keys in

54:26 order to publish to the witnesses. And

54:28 then the watchers are watching the

54:30 witnesses to make sure that the

54:31 witnesses don't cheat.

54:33 – Where is it published, if not

54:35 in ledger?

54:37 Well, a KEL is a ledger. It is a

54:41 micro ledger controlled by one

54:44 identifier. So, it's not a shared ledger.

54:46 It's not a shared ledger. It's a

54:48 non-shared ledger. But, technically

54:50 under the hood, it is a

54:52 blockchain. Yeah.

54:54 – But, how is it made public? I guess

54:56 that's my point.

54:58 I probably can't answer that in this

55:00 room. Okay.

55:00 But, if you're here for the conference,

55:02 you got 2 days of people who'll answer

55:04 that for you.

55:05 With that open-source infrastructure

55:07 Okay.

55:08 Yes, that's right.

55:11 Okay, thank you. One more Yes.

55:13 – Maybe you'll answer this later, but

55:16 witnesses are selected by the

55:19 controller,

55:19 and then the watchers are

55:21 selected by the verifiers. What's

55:24 your vision of how a controller actually

55:28 selects a witness?

55:30 Usually they will hire .., They'll either,

55:32 If they're technically savvy, they'll

55:34 spin up their own witness, but most

55:35 people won't do that. They will just

55:37 rent witnesses from witness services,

55:39 just like you would rent

55:41 a cloud host for your website.

55:43 – Okay, do you ever see individuals

55:46 being or employees being controllers, and

55:51 would they have to go hire someone?

55:53 The vLEI, if your work for company

55:55 has a vLEI and you get issued,

55:58 an ECR and OOR credential, you'll have a

56:01 wallet and you'll select

56:03 witnesses that you

56:05 probably your company spins up for their

56:07 employees to use.

56:09 – Okay, and then at the individual level,

56:10 do you ever see grandma having to go

56:12 select a witness?

56:13 One of the things

56:15 in the discussion that we've had

56:16 with the state of Utah is how do you pay

56:18 for disadvantaged populations to have

56:20 infrastructure?

56:22 And so, so there would be that would be

56:24 an entitlement that somebody would

56:26 pay for your infrastructure. But, it's

56:28 going to be the cheapest form of

56:30 infrastructure, which is web

56:31 infrastructure, not really expensive

56:33 blockchain infrastructure.

56:35 – I'm curious to know more

56:37 about the transactional friction

56:40 there or the just the friction

56:42 there.

56:42 a really good conversation to have

56:44 because

56:44 another conversation.

56:45 Yeah.

56:47 – A real quick one on the registrar

56:49 observer network, do you see benefit for

56:52 the registrar putting random

56:55 noise into the stream so that they can't

56:57 tell it's a correlatable event on a

56:59 revocation? Absolutely. The blinded

57:03 state TEL, which is the thing

57:07 that we use, not the current

57:09 version 1 does not have that,

57:12 allows you to do updates because they're

57:14 blinded that don't change the state,

57:17 they're just there to introduce

57:20 to whiten the signal. So, you can as a

57:22 registrar, you can whiten your signal.

57:24 You can you can issue random updates to

57:27 to registries that don't change the

57:30 state. And so, that means that a state

57:32 update doesn't necessarily mean the

57:34 state changed. It just means you did a

57:35 state update and most of them are ... and so

57:38 you could create

57:40 you could roll out 4 million

57:43 registries for birth certificates

57:45 and update them. And then when

57:47 somebody's born, the fact that there's

57:50 an update to a registry doesn't

57:52 correlate to the fact that they were

57:53 born and you then started using that

57:56 registry for their birth

57:58 certificate.

58:00 Thank you very much, Sam.

58:01 Time's out. Running out.

58:05 Do you want to introduce the next

58:06 speaker?

58:07 Yes,

58:08 That's Daniel.

58:11 Do I need to I need to get to move my

58:12 Please a big hand for Sam.

58:15 [applause]