The Landscape of SEDI - George McEwan

KERICONF26 Day 1 · 38:35

0:00 George McEwan | The Landscape of SEDI | KERI Conference 2026

0:02 So everyone, I'm George McEwan. I'm the

0:04 privacy architect for the state of Utah.

0:06 So there's a lot of synchronicity that

0:08 happens when you go to these various

0:10 events. And amazingly enough, I'm going

0:12 to talk a little bit about healthcare in

0:14 the rural healthcare setting and why

0:15 we look at it the way we do. One of

0:18 the things I'm going to make very clear

0:19 is that the state is going to declare

0:20 some boundaries in what it does in the

0:23 KERI infrastructure and what the

0:24 expectations are for the community

0:27 because one of the things we learned as

0:29 I was the IT director during the COVID

0:32 era at the department of health, there

0:34 was definitely some resistance to where

0:36 government had offered the technologies

0:39 or applications or worked with platform

0:42 providers to provide things like

0:44 exposure notification and the backlash

0:47 was very intense. That's

0:50 probably the best word I can use. And so

0:52 we realize that where government can

0:54 help and we can set regulations and we

0:56 can set frameworks in play, there's

0:58 definitely a spot where the government

0:59 has an edge and we say this is private

1:01 sector and for the individual to handle.

1:04 So, what I'm going to do is I'm going to

1:05 run you through a little bit of a

1:06 presentation that we do with we'll

1:09 call them non-nerds, normal people.

1:12 Because we can talk in shorthand in the

1:13 SEDI community and in the KERI

1:15 community and cyber security. We have

1:17 words they don't understand. So, what

1:19 we did is we put together kind of a

1:20 generic presentation that we add slides

1:23 to depending on who we're talking to.

1:25 So, realistically, we hit them on these

1:28 points. Digital identity is here. It's

1:30 coming. It's going to be something. Now,

1:33 one of the, I would say, the beauties of

1:34 the SEDI program is Chris Bramwell

1:37 said, "Well, we could take this and

1:39 put this against what are the

1:41 constitutional rights that someone has."

1:43 And by doing so, you get past all of the

1:46 vendor needs to make money. You get you

1:48 get right down to the root of the

1:50 problem, which is there needs to be

1:51 accountability and that your rights need

1:54 to be preserved and that privacy is not

1:56 impossible when you are talking about

1:59 digitally issued credentials. And of

2:01 course then we get into the stakes.

2:04 If the government doesn't choose or

2:07 regulate, the market does it itself. And

2:09 the goals of a open market are a

2:13 little bit different than what a

2:14 government needs to be providing the

2:16 services that a citizen would want. And

2:18 of course, we know that besides

2:20 governments, there's also organizations

2:22 that put together specifications that

2:24 may or may not be rooted in the same

2:26 value system that we're trying to

2:27 maintain. So we're very adamant that we

2:30 want to make sure that whatever we do in

2:33 the SEDI environment, it's reflective of

2:35 the values, goals, and rights that are

2:37 held here in America. Now, it is not

2:40 hard for this statement to be believed

2:43 by all of you, right? Whoever has the

2:46 data has the control. And the model

2:49 right now, everything to the left or

2:51 sorry, my right everything over there

2:54 is how we work today. Your identity is

2:57 owned by other individuals. It's granted

3:00 back to you with limited rights. And

3:02 then if you've ever looked through all

3:04 those long user licenses, in effect,

3:08 you've given up all control for the

3:10 services that you have. And

3:12 this isn't limited to just, hey, I got

3:14 myself an email address for free. Your

3:17 financial institutions do this, your

3:19 hospitals and your HMOs, your care

3:22 organizations, they're holding a lot of

3:24 the data that belongs to you. And

3:26 because it's set up that way, you are

3:29 basically powerless to do anything about

3:31 it. And in a lot of cases, you'll find

3:33 that incorrect data may be used in

3:36 profiling you to create an improper

3:39 picture of who you are.

3:42 So really what we want to accomplish

3:44 inside the SEDI framework is the idea

3:46 that you are the individual who controls

3:49 that information because

3:52 wherever the information sits, it is fair

3:54 to say without contradiction that

3:57 impacts the financial outcomes. It

4:00 impacts your opportunities. There are a

4:02 lot of things that get impacted because

4:04 you don't control what should

4:06 rightfully be yours. And this is not to

4:09 say that everyone did it for a nefarious

4:11 purpose. I mean, profit-seeking motive.

4:13 We're a capitalist society. Yeah, that's

4:15 understood. But the problem is we built

4:17 everything to be so exploitative of you

4:20 that we forgot that you are the

4:22 individual who ultimately gets hurt if

4:24 something goes wrong. In the state of

4:26 Utah, inside government,

4:28 there's a very good way that we look at

4:29 data. When we make a data error in

4:32 government, it's a negative outcome for

4:34 a real person. Classic example, oh the

4:38 Medicaid eligibility system, which is a

4:40 real time system, goes down for a couple

4:42 hours. Now, if you're standard IT,

4:44 you're like, big deal. Things happen.

4:45 We'll get it back up. No big deal. But

4:47 then when the Medicaid director marches

4:49 in with their flesh hook and rips a

4:52 pound off of you and says, "Right now,

4:54 somewhere in Utah, there is a single

4:56 mother who took two buses two hours out

4:59 of their day to go to the pharmacy to

5:02 get medication for pain management." and

5:04 the pharmacy directors at that

5:07 facility said, "We can give you one pill

5:09 because we can't confirm your

5:10 eligibility. You'll need to come back."

5:13 That's the sort of situation we deal

5:14 with when we talk about our data errors.

5:16 And of course, we try very hard in

5:18 government to be good stewards of that

5:20 data. But realistically, if the

5:23 individual has a lot more control, who's

5:25 a better advocate than you? You are

5:27 definitely going to be your best

5:28 advocate.

5:30 Now, when we get into the concepts of

5:32 state endorsed digital identity, we

5:34 really try to keep this as simple as

5:36 possible. And this is probably

5:39 way too high. And everyone's like,

5:40 "Yeah, I get this slide immediately."

5:41 But what we try and explain to them is

5:43 those core concepts that we put into the

5:45 bill of rights that identity is yours.

5:49 It's not issued by the state, but the

5:51 state has a role to endorse it for

5:52 certain legal purposes. And of course,

5:54 we get into the concept of what is a

5:57 digital identity? How does it get

5:59 created a little bit and then we go into

6:01 the whole idea of how it becomes your

6:02 state endorsed digital identity through

6:04 this process of vetting. Now there are

6:07 some potentially debatable questions on

6:10 here. We don't get into the politics

6:12 of this, but we do know that there are

6:14 some markers that need to uniquely

6:17 identify you to be part of that digital

6:19 identity. And this isn't to say that

6:21 these are forever attributes. For

6:23 example, your address, your biometric of

6:27 your face, those are going to change.

6:28 And we have existing laws that handle

6:30 that. For example, if you are

6:32 getting a driver's license at 16, that's

6:35 not valid for more than 5 years because

6:37 we know you're going to change by the

6:38 time you get to college. And of course,

6:40 with the residents here in Utah who have

6:43 driver's licenses who are over 18, it's

6:46 a 10-year window. So there are

6:47 opportunities for those things to be

6:49 changed as part of the credential or to ..,

6:52 for lack of a better term, lose the

6:53 endorsement.

6:55 Now when we talk about healthcare data

6:58 there are a ton of different places

6:59 where this applies. Now we had

7:02 healthKERI talking about the provider

7:03 payer relationship. That's just one of a

7:06 myriad of relationships that exist

7:09 between you and your healthcare

7:11 interactions. Whether that's the

7:12 ownership of your individual data, your

7:15 desire to participate in some sort of

7:17 demographic mapping. Today, we

7:19 don't do that. Today we have systems

7:21 that basically, at government control,

7:24 take your data and aggregate it for

7:26 research purposes.

7:29 And for some people, that's not

7:31 shocking. But when you go to a

7:33 state and you say, "Hey, do you have an

7:34 All-Payer Claims Database?" If the

7:37 person's in the no, that means that

7:39 every encounter you have that's part of

7:41 your insurance program in that state

7:44 with your physician and the notes

7:46 associated with all your ICD-10 codes,

7:48 everything that happened during that

7:50 medical encounter is now in a government

7:52 database for the purposes of looking at

7:56 healthcare outcomes. Did patient A and

7:59 patient B who received different

8:00 medications, which one had the better

8:02 outcome? So there's a lot of good

8:04 intentions in terms of why these data

8:06 sets exist. But I will also tell you the

8:09 most dangerous thing in government is a

8:11 well-meaning bureaucrat. It's not that

8:13 they're trying to do something

8:14 nefarious, but sometimes they try and

8:15 get hold of data and put it together to

8:18 create a picture. Well, where you don't

8:20 have any interface to this and you don't

8:22 have any control over that data, there's

8:24 the possibility that that inference,

8:26 that conclusion may help you, it may

8:28 harm you. So this is part of the reason

8:30 we want to start looking at how we

8:32 switch this model around so that you

8:34 have more executive control and how your

8:37 digital twin story gets told.

8:40 Now when we talk to them about the state

8:43 endorsed digital identity, we also like

8:45 to help people understand this

8:46 concept of perpetual identity. And this

8:49 is where we differ with the mobile

8:51 driver's license community and they're

8:53 saying you can use it for everything.

8:54 I'm like, you can use it for everything

8:56 that you don't mind having burned down

8:58 if you move to a new state. That's

8:59 totally fine. But in our particular

9:02 instance, we want to be able to say that

9:04 there are certain documents that you may

9:06 associate with your SEDI and they

9:09 could be your medical records, you know,

9:11 your digital driver's license. Any of

9:13 these items that you have associated

9:15 with your SEDI can be created and you

9:18 may have information that you are going

9:20 to selfassociate like, hey, here's my

9:22 claims history. Here's some of my MRI

9:25 scans, things that you have in your

9:27 possession that you want to get into

9:28 your digital records but currently

9:31 don't have. And this is where these

9:32 functionalities like Blue Button are

9:34 fantastic is you have the ability to say

9:37 this is categorically my MRI. I'm going

9:39 to send it to you electronically. You

9:41 can pull it directly into my

9:43 record set. That's the level of control

9:45 that we want to have. Not: go to doctor

9:48 office A, pay $50 for a doc fee to have

9:51 them really, it still cracks me up, fax

9:54 information to doctor B, and then

9:57 hopefully they didn't lose anything in

9:58 translation and the whole packet's

10:00 complete, which you generally find out

10:02 on your next medical appointment that

10:04 it's not somebody dropped pages 8

10:06 through 12, and now you got to go

10:07 through this whole cycle again. So, we

10:09 have these inefficiencies that are in

10:10 the system the way we run it today. And

10:12 we're telling people, no, if once you're

10:14 in control of this, you can start to

10:16 aggregate your data as necessary. And of

10:19 course, we talk about the concept of

10:20 perpetual ownership. If I move from Utah

10:23 to Texas, there are certain privileges

10:25 that go away. I don't keep a Utah

10:28 driver's endorsement anymore. I have to

10:30 go get a Texas one. But everything else

10:32 that I had associated with my SEDI is

10:35 still valid. And in fact, because I have

10:38 a SEDI that's authorized by Utah or

10:40 endorsed by Utah, Texas can say, "We

10:44 know that's Utah. So, we're going to

10:45 accept these baseline facts that you've

10:47 asserted. We can bring you right into

10:49 the system and we can move on." And hey,

10:51 guess what? You can go get your Texas

10:54 driver's license endorsement without all

10:56 the reproofs that we have to do along

10:58 the way.

11:00 So when we looked at SEDI as a

11:03 functional item, we wanted to build into

11:05 the framework some very important

11:07 principles. And of course you can see

11:09 them up here. We break them into some

11:10 general categories. Now this is where I

11:12 want you as KERI experts to start

11:15 ticking off in your mind which one of

11:17 these items are solved by KERI, which

11:20 one of these ones are actually enhanced

11:22 by KERI, and also when we get to the

11:24 end, I'm going to give you a little

11:26 here's what we're not going to do at the

11:27 state level. Okay? So privacy and

11:29 autonomy this is pretty straightforward.

11:32 We want you to have interactions with

11:34 your digital identity that the

11:36 government does not monitor has no

11:38 capability to and also third parties.

11:41 We do not want crosscontext correlation.

11:44 We want you to have individual

11:45 relationships and as such there are

11:48 technologies that will do that. Funny I

11:50 think there's one in the room here

11:51 that might do that. We do want you to

11:53 have this capability of selective

11:54 disclosure. I was telling Mike a

11:57 story where I went to my grandkid,

12:00 picked them up for a fun day out and we

12:03 went to a trampoline place and the first

12:05 thing they did was get grandpa to sign a

12:07 liability waiver. And as I was looking

12:10 at it, the first thing I thought is, you

12:12 do not need my birthday. You just need

12:15 to know that I'm old enough to enter

12:16 into a release of liability. And I kind

12:18 of sparked because not only would that

12:21 be a problem, I don't actually have

12:23 permission for my daughter to release

12:25 liability for her children. So there's

12:26 some other things that could get cleaned

12:28 up in that situation, but this is part

12:30 of the community education. This is the

12:32 open sourcing of privacy we hope to have

12:35 happen is I'm not going to have every

12:37 single interaction where I'm going to be

12:38 able to ask why, but we do want to get

12:40 people and just across the world saying,

12:43 "Do you really need that for this

12:45 transaction?" And that's part of where I

12:47 say in keeping with what Chris has

12:50 said, a 10-year journey. Now, if you

12:52 think back in cyber security, how long

12:55 did it get people to understand the

12:57 Nigerian prince scam before we could go

12:59 on to that's a fishing email and then

13:02 that became part of the lexicon that

13:04 people use? It took a long time. I

13:07 call it about a 15-year window just

13:09 going back over my history and saying,

13:11 "Yeah, it's about when we got people to

13:12 understand it." And still we fall for

13:14 these things. But this is the same

13:16 journey we're going to be on with

13:18 selective disclosure. We have to get

13:20 people understanding "No, no, no, you're

13:21 in the driver's seat. You don't have to

13:24 give up this information to be able to

13:26 receive services." Now, there's a major

13:28 medical provider that I'm not going to

13:30 mention them by name, but when you go in

13:32 to receive services, they give you this

13:34 great set of disclosures. And one of

13:36 them is basically a blanket that says

13:39 you're seating all your rights for all

13:41 your data that we may use in research

13:43 purposes including biological samples.

13:45 We don't have to notify you. And by the

13:47 way, if you don't agree to this, we're

13:49 not treating you. That is scary that

13:51 they have that capability. But as we get

13:54 a community that's becoming more savvy

13:56 about these things, not just small

13:57 groups like us, but the larger

13:59 community, we can affect change and make

14:01 those policies flat out illegal. Okay?

14:04 And of course, one of the things that I

14:06 do want to mention is personas in the

14:09 term that we're using it in is basically

14:11 helping people understand. You don't

14:13 have to stand there at the counter and

14:14 pick element A, element B, element.

14:17 There are certain transactions you're

14:19 going to have that are going to be

14:20 standard. If you go to

14:23 a bar or you might have a pub crawling a

14:25 persona that says, "Here's my name,

14:27 here's my face, and here's when I want

14:30 you to cut me off and call the Uber for

14:32 me." That's going to be something that

14:34 we would expect the wallets to start

14:36 supporting is how do I map these things

14:39 very quickly so I can get to through

14:41 the interaction as frictionally

14:43 frictionless as possible.

14:46 So we get the next one going. Okay, I

14:48 talked a little bit very fast about

14:50 delegation and guardianship the other

14:53 day. Probably faster than I should have,

14:55 but we'll talk about it some more.

14:59 Delegation and guardianship is one of

15:02 the most critical relationships that we

15:04 see both from a government and a

15:06 societal capability. From a government

15:09 standpoint, there are multiple programs

15:12 that operate based on the relationship

15:14 that a parent has to a child a

15:17 caregiver to a foster child. You can you

15:20 can go down the litany of them and

15:21 you'll find there's a lot. In the story

15:23 I told yesterday about getting a durable

15:26 medical power of attorney for my

15:28 father while he was basically passed out

15:30 on the bed. He doesn't really remember

15:32 that. And there are situations where he

15:35 may want to rescind that. How does he do

15:38 that? All we've got is a scroll on a

15:40 piece of paper that I can guarantee you

15:42 is not his signature, but it will hold

15:44 up in court because a notary came, took

15:46 400 bucks in hash from me and said,

15:47 "Yep, he had a positive

15:50 acknowledgement of what happened." So,

15:52 when we have these situations of where

15:54 we have vulnerable individuals who need

15:56 assistance or you have an aging adult

15:59 who quite frankly need you to help them

16:01 with their finances and other

16:03 items, it's really cumbersome today.

16:07 And I've had to do this for one relative

16:09 where we had to bring the court order

16:10 down to the bank and then they went

16:12 through this whole trust and

16:14 verification process. They called

16:16 the courts. They wanted the make

16:18 sure that the all the numbers matched

16:21 up on the case and everything. It was

16:23 ridiculous. And it and fortunately, they

16:26 only had one bank. I was thinking, what

16:28 if they had like an investment portfolio

16:30 completely separate and that investment

16:32 company isn't even in my state? I

16:35 got chills on how long that would take

16:37 me to help them out. And with the

16:40 technologies that KERI is providing,

16:42 there's the ability to really do that

16:44 quickly through these the these designed

16:46 and delegated guardian relationships.

16:48 And as I mentioned in that little

16:50 vignette yesterday that all my brothers

16:52 and sisters were sitting around the

16:54 table arguing,

16:56 I realized there's six adults here that

16:59 could come to some consensus on what is

17:02 best for the situation. And it would be

17:04 in the interest of my father or my

17:06 mother to have us have that sort of

17:08 capability. So multi- signature to be

17:10 able to authorize these activities.

17:13 Totally important. Now we talked a

17:15 little bit about agentic AI. It's

17:18 coming. I'm playing with a lot of

17:19 them. They're still in my little

17:21 sandbox, but some of them are getting

17:22 more useful. And one of the things that

17:25 I would find extremely useful is I was

17:28 playing around with Open Claw and I

17:30 decided I wanted to

17:31 implement Gemini's or Google CLI

17:34 and it's like well I usually ask Grock

17:37 how to do that but I thought I would ask

17:39 Gemini directly and it came up with this

17:41 big fat don't do that is a

17:43 violation of our policies and terms and

17:45 conditions and we will shut you down no

17:47 ifs ands or buts, you know, "Bad you!"

17:51 And I realized as I thought through what

17:54 would have been the implications of

17:55 losing my I call it my burner account,

17:59 but I have not dozens, I have hundreds

18:02 of logins that are tied to that.

18:04 Hundreds of logins. So if that company

18:07 decided to take it away from me, I would

18:09 break my digital life in more ways than

18:11 one. So

18:14 here's your product placement idea. If

18:15 anyone wants to add this, I would love

18:18 that once my SEDI goes live that I have

18:21 the capability to go and break all those

18:23 relationships automatically and

18:24 reassociate them with an identity that I

18:27 physically control. That's where I want

18:29 to end up because at the end of the day,

18:32 if we leave all those accounts and logins

18:35 out there, we're seeding our power to

18:37 control our own destiny. And of course,

18:39 we've talked about the permission and

18:41 consent the demo for KERI blocks.

18:44 some of you might have seen at IIW [#41] was

18:47 fantastic. For those who didn't, and

18:48 I'll just give you the two-minute

18:49 overview, the goals are the same.

18:52 Parents do not want their children in

18:54 environments where there are predators.

18:56 And we know that there are online

18:57 communities that despite their best

19:00 efforts, wink the profit

19:02 motive is still there. So, they're not

19:04 investing in the technologies that will

19:06 protect children. And in this particular

19:08 example, we had a parent credential,

19:11 a SEDI-based credential that did a

19:14 derivative credential for their child

19:17 and said, "This is my child. This they

19:19 are 13 and they can be on this system

19:22 from 5 to 7 PM, two nights a week,

19:25 and they can only talk to other children

19:27 who have a validated SEDI credential."

19:30 And it's fun to watch the chat window

19:31 and all the people disappear who are not

19:34 able to talk to your child. Now, some

19:36 people think that's overly

19:37 restrictive. You're going to have your

19:38 genius child get around it anyway. That

19:41 is where we do have that interface

19:43 between technology and law. Especially

19:46 in Utah, we've talked a lot about the

19:47 harms to children through social media

19:49 and other ways. I don't think it's

19:52 going to be too much of a stretch once

19:53 the technology is ubiquitous to have

19:56 the law catch up to help parents

19:59 manage their children's online

20:01 environments. Okay. Security and

20:03 recovery. One of the things that when I

20:06 read Sam's paper for the very first

20:08 time, I was like, "Okay, why is it that

20:11 we've been doing PKI this way for like

20:13 25 years at this point and nobody

20:16 figured out this really obvious thing,

20:18 which is if you can't tell what the key

20:19 state is and where you're going next,

20:21 you're back to that whole trust model

20:23 and all the things we did to make CA's

20:25 work and the intermediate certificate

20:27 and by the way, get rid of this one."

20:28 And I was like, Sam, it was genius how

20:31 simple it was when you looked at it, but

20:33 it was one of those things

20:35 that, until somebody came up with that

20:37 answer, we were going to still suffer

20:38 from the same problem. So where KERI

20:40 has done a lot of things to help us out

20:42 and of course like Sam and I have talked

20:44 about this over the last three years

20:45 about detection of compromise, the KERI

20:48 specification continues to get

20:52 updated to meet the real world

20:54 demands that we have. And one of those

20:56 is this whole idea of the mutual

20:58 authentication. We've just talked about

21:00 that with the phones. We've talked about

21:02 that with healthcare providers. And I

21:05 will predict something that is going to

21:07 be in the future. So we have health

21:08 information networks all across the

21:10 United States. And they make a lot of

21:12 money brokering the transaction or

21:14 uplifting it from one EDI format to

21:16 another. What a world it would be is if

21:18 I'm the provider and I can reach out

21:21 directly to a discovered payer

21:22 interface. we have this mutual

21:24 authentication and I can just move that

21:28 significantly changes the overhead that

21:31 a provider office has to have. I mean I

21:33 I know that my dentist for example he

21:36 has

21:38 about nine administrative personnel.

21:40 He's one dentist with two hygienists but

21:42 he does a lot of work in social

21:44 services programs and he has to have

21:46 that level of people to continue to keep

21:48 up with the paperwork. And of course

21:50 that's kind of reflected in his pricing.

21:52 So every couple years he goes off plan

21:54 and I have to pay more to use his

21:56 services. But if we could get those

21:58 administrative burdens lowered, think of

22:00 where we could go.

22:03 No credential works unless there's

22:05 comprehensive utility. One of the

22:07 long-standing jokes about the mobile

22:09 driver's license is that it works at the

22:12 TSA. Well, it doesn't. Their terminals

22:15 are down. They're like, "Well, hey, do

22:17 you have your physical license?" And

22:18 I've heard this one myself because that

22:20 interaction will go a lot faster than

22:22 trying to play around with the terminal.

22:23 So it doesn't have a lot of usability

22:26 and the models were wrong.

22:30 One of those models was is we tried to

22:32 monetize in the wrong way or at least

22:33 vendors did. In our case the

22:36 our we're an alcohol control state. So

22:39 you have to go to a state liquor store.

22:41 But when you are the director of the

22:43 state liquor store and a vendor comes to

22:44 you and says, "Hey, by the way, I need

22:45 you to pay X number of dollars per month

22:48 per store to be able to accept this

22:50 digital credential." And they're like,

22:51 "Wait a minute. Isn't that issued by

22:53 public safety?

22:55 Why do I pay money to public

22:58 safety or to a vendor to accept a

23:00 credential that the state issued?" And

23:02 of course, their answer was so logical.

23:04 Well, I can look at the I can look at

23:06 the state ID or I can look at the

23:08 driver's license for free. So adoption

23:11 is a problem. There are a numbers of

23:13 areas where we hope to see functionality

23:16 come along like I talked about replacing

23:18 username and passwords or taking over

23:20 accounts. We want to make sure that this

23:22 area which is where the ACDC comes in

23:24 great is offline verification. I can't

23:27 have my environment completely breaking

23:29 because I don't have online access at

23:31 all times. Now, Joe Jackson during our

23:34 our study panel, he talked about our

23:37 offhighway vehicle OV certificate

23:40 that we did. And when Joe and I talked

23:42 about it, I said, "Joe, this is fine for

23:44 X.509 technology. Completely fine. It's a

23:47 lifetime endorsement. It's never

23:49 revocable and you have to supply a

23:52 primary credential with it. So, just

23:54 because you show the QR code and it has

23:56 your information embedded in it, you

23:58 have to show a driver's license." So we

24:00 said, let's go down the road with this

24:02 one because we want to make sure that

24:05 there's an appetite for these

24:06 credentials and that it would be

24:08 extremely low risk. So Joe told you a

24:10 little bit about and things we've

24:12 learned along the way there. But I'll

24:15 tell you what, the funniest thing that

24:16 happened is once we release those, the

24:19 boating community, everyone who's owns a

24:21 boat, I've heard this story like 40

24:22 times now. They're like, I own a boat

24:25 and you guys have this OHV thing that I

24:27 could have on my phone. Why do I have to

24:29 have a printed PDF? And they always say

24:31 paper on my boat. We're in the water.

24:34 Why do I have to have paper? So, we kind

24:36 of smile and say things are coming. The

24:38 the appetite is there for these

24:40 credentials. We have no loss of ideas

24:43 and use cases of where we want them to

24:45 go. Key to the whole success is the open

24:49 standards, no vendor lockin.

24:52 We have been very clear to the community

24:55 that security by obscurity is never

24:58 going to be a solution we're ever going

24:59 to be interested. Somebody brings me a

25:01 closed source package and says it's

25:02 magic, I don't believe them. I want to

25:05 see under the hood and in some cases I

25:08 lack the time these days, but if I can

25:10 get down into the code and look at A

25:12 plus B does equal C, I get a lot more

25:15 comfortable. And I try to point out to

25:17 non-technical people, the reason Apache

25:20 is such a successful project and how has

25:23 the high level of security it does is

25:26 there's lots of people looking at it and

25:28 that's where we need to be in identity

25:30 systems and identity credentials because

25:33 I can tell you across this room and I

25:35 know some of you by face, some of you by

25:36 name, there is a lot of expertise that

25:39 can get into a room and say A and B are

25:42 not equaling C and here's why. And as a

25:44 state, I don't want to have to broker

25:47 broker that and be able to say, "Yeah,

25:49 we made that decision on our own. We

25:51 want the community to support us because

25:53 ultimately the beauty of this is, it's

25:56 your data." And by golly, you're going

25:58 to care about your data. So, I'm going

26:00 to get some really good feedback as we

26:02 go along in this program, which we have.

26:04 And we enjoy the fact that you can do

26:06 that. And as Chris has said, if a

26:08 standard requires you to pay to be able

26:10 to understand your interface between you

26:12 and your government or how your identity

26:14 works, that's a non-starter for us. We

26:16 just we just won't go there.

26:18 Now, this part about any app becoming a

26:20 wallet, what we mean by that is we do

26:23 have some digital credentials in the

26:24 state already. For example, if you

26:26 download the Department of Natural

26:28 Resources app, you can get a QR code for

26:30 your fishing license and your hunting

26:32 license. That's great. But that's only

26:34 inside their little tiny ecosystem. We

26:36 want to be able to broaden that out. But

26:37 that doesn't mean they have to throw

26:38 away their app because they've

26:40 invested some good money in it. They

26:41 also have some poaching features.

26:44 So you can take a picture of a carcass

26:45 and a GPS and it will send it to you DNR

26:48 enforcement officers. So we don't want

26:50 to say "No you got to go

26:51 through the wallet only," but there

26:54 are going to be instances where we will

26:56 see extension of SEDI credentials

26:58 inside existing applications in the

27:00 state. The other thing that we are

27:02 very aware of is the first mover

27:05 advantage for a lot of people is not

27:07 going to be going through the platforms.

27:09 They're going to be doing their own

27:10 trusted apps. To me, there are many

27:13 Roots of Trust that can come into your

27:15 relationships. For example, I may trust

27:17 my bank and you say, "Hey, we're going

27:20 to help you out with your Wells Fargo

27:22 wallet and we know about these

27:24 pre-key rotations and we provide a

27:26 service where you can escrow those keys

27:28 with us and using your multisig

27:30 capability. Us plus you plus whatever

27:33 you know key material you have, we can

27:36 unlock your next key for you." That's

27:38 fine and that's perfect. And I want to

27:40 harp on this just a little bit. The

27:42 state's credential is the SEDI. We are

27:45 not the wallet. We're not your key

27:47 escrow. We're not your key recovery. I

27:49 kind of smile and my wife says

27:51 this a lot. She's a children's

27:52 librarian. She works in a public

27:54 library. She has a little counter. It's

27:57 almost her personal drinking game where

27:59 she says, and I quote, "I'm sorry, I do

28:02 not know your Gmail password. I can't

28:04 help you with that. Do you have somebody

28:06 you can call to help you with that?" And

28:08 she has people who argue with her. No,

28:10 no, I used this computer yesterday. You

28:12 should know my password. And so from the

28:15 state, I suspect we're going to get

28:17 something like that where people are

28:18 going to be like, well, you issued it.

28:20 You should know how to recover my keys.

28:22 Nope. That's part of this whole

28:24 idea of, hey, I'm turning it over to

28:26 you. Now, with the wallets, one of the

28:28 things I do also want to say is that the

28:30 state definitely is going to be looking

28:32 for third parties who will go and audit

28:34 wallets and provide some we'll call

28:37 them seals of approval. What I

28:39 anticipate happening is when you go to

28:41 the state to get your

28:42 endorsement for your study is we're

28:45 expecting a cryptographic hash and a

28:46 signature of the application you're

28:48 using. And I can say "Yeah, that's

28:51 one of the ones we recognize as meeting

28:53 the standards of the state. We will go

28:54 ahead and finish up this issuance

28:57 process and give it to you."

28:59 Steve McCown's going to

29:00 take the source code directly and he's

29:02 going to compile his own wallet and make

29:04 sure it meets his requirements. So when

29:06 Steve comes to the state and says "Here's

29:09 my wallet!" and in the presentation he

29:11 provides us a hash and a signature we

29:13 don't know we'll say "Okay, Steve, we're

29:16 happy to issue to this to you but we

29:18 also want you to affirmatively consent

29:20 that the state doesn't know anything

29:22 about the security of what you're doing."

29:24 Yes, you want it. Here you go. Because

29:27 we do want that freedom of choice and

29:28 the ability for people to operate, but

29:30 we also want to have that

29:32 guardianship that the state has, which

29:34 is the public interest to say, we know

29:36 you're not all techies and if you bring

29:38 us something that you got your .ru wallet

29:41 and it seems like it was the right idea.

29:43 We want to make you aware of what that

29:44 potential security risk would be. So,

29:46 that's something I expect to see coming

29:48 in the ecosystem.

29:50 Now we at the end of our slide deck

29:53 always go back to what is the

29:56 key points we want and we want you to be

29:59 in charge. We want you to determine who

30:02 you share data with, when you share it

30:04 with them, and why that matters in the

30:07 healthcare environment is we know that

30:10 data can be weaponized against you in

30:12 the health space. And if you

30:15 have no visibility to that and AI models

30:18 are starting to be used and I'll say

30:21 quite frankly in inappropriate ways to

30:22 come to like billing and costing

30:25 decisions, you have to be made aware of

30:27 that. So you have to have control over

30:29 that.

30:32 Interoperability. You've heard this if

30:33 you've been here the last two days.

30:35 What's the interoperability? Well, we

30:38 are going to have to be interoperable.

30:40 We can't expect that every state is

30:42 going to say, you know, we believe

30:44 exactly how Utah believes and we think

30:46 their technology choices are great and

30:49 we are going to go that way.

30:52 I don't know if you noticed during the

30:53 panel with Joe and our representative

30:56 from California, Joe had said we have to

30:59 agree that we're solving the same

31:00 problem. If we're not, then

31:02 interoperability isn't a question. And I

31:05 completely agree with where Joe was at

31:06 on that. We definitely want to make sure

31:08 that we're solving the same issue and

31:10 that we're moving forward in something

31:12 that is rational for all of us. So

31:14 digital reciprocity between states is

31:16 something we're going to have to deal

31:17 with. We definitely want to make sure

31:19 that, hey, if you've ditched all your

31:21 your plastic, you jumped on a plane and

31:23 you're suddenly in Oregon and you get

31:25 pulled over in your rental car, your

31:27 digital driver's license has to be

31:29 something that can be considered valid

31:31 in all jurisdictions. And that's

31:34 quite frankly a format war that it's not

31:36 my problem right now that I'm trying to

31:38 solve. I'm trying to solve the core

31:40 identity issues for Utah residents. Now,

31:42 Of course, we have the

31:45 Olympics coming up 2034.

31:48 There's probably going to be digital

31:49 credentials that come to us from other

31:51 jurisdictions even outside the United

31:53 States. Well, we are building this

31:56 system around the concept of American

31:58 values. And what it is no tracking,

31:59 no surveillance, no, you know, no

32:01 monitoring. So, in those cases, we may

32:03 say, "Yeah, that's a valid credential

32:05 from where you came from." We might

32:06 issue a temporary one while you're here

32:08 for the Olympics to allow you to

32:10 interface and do the things that you

32:11 need to do, but we're certainly not

32:13 going to phone home to a foreign server

32:15 and participate in state surveillance on

32:17 behalf of a of a foreign government. We

32:19 just won't do that. So, when it comes to

32:21 the healthcare interoperability issues,

32:24 we want to make sure that the blast

32:26 radius is always 1. And this is the

32:28 thing that .., I hate to say it, but we're

32:30 finally getting to the point where data

32:32 breaches, people are understanding that

32:34 your data continues to get lost because

32:36 they're in central systems; these huge

32:38 honeypots. If we do this right, people

32:41 are still going to get social

32:42 engineered. But if the blast radius is

32:44 1, that's a much better situation for

32:46 us to be able to handle than having a

32:47 blast radius of, "Oh, 100 million records

32:49 were lost. Would you like some free

32:50 credit monitoring and hope things work

32:53 out for you?" And when we look at the

32:56 overall cyber security risk, there's

32:59 definitely going to be some things that

33:00 we are going to look at from the from

33:01 the wallet provider community, key

33:03 escrow and how that's done is going to

33:05 be super important to us because it's

33:07 not your identity if somebody else has

33:09 full access to your keys and can perform

33:11 rotations without your permission. You

33:13 know, I got asked the other day, well,

33:14 what happens if I'm

33:17 at the border and the law enforcement

33:20 agency requires my phone from me and

33:24 they copy my whole phone and then

33:26 they wander away and now I know they've

33:28 got my current keys. Well, Sam, you can

33:31 put this on a t-shirt if you want, but I

33:32 just said when in doubt, rotate out. You

33:34 don't have to stay with that key pair.

33:36 When you get your phone back, move on to

33:38 your next set. So, I'm going to give you

33:40 a situation that happens in rural

33:42 healthcare because we talked all about

33:43 these things in kind of this really

33:45 large buckets, but when I was down

33:48 talking to rural healthcare, we had to

33:49 have some specific examples of how rural

33:52 healthcare is hurt by not having a good

33:54 identity system that can provide instant

33:57 validation and of assertions of

33:58 credentials. So, if you look up there,

34:01 50,000 to 100,000 is the and this is

34:04 across the nation, not just Utah. this

34:06 peer-reviewed studies that they can

34:08 bring in a doctor or say a critical care

34:10 nurse and getting to the point of having

34:12 the original documentation validated.

34:14 They're basically sweeping floors or

34:16 doing something else or working in a

34:18 non-risk position while those

34:20 credentials get validated. 50 to 100,000

34:23 per provider they bring into the system.

34:25 And the tragedy is when you look at

34:27 these small healthcare systems in these

34:28 rural settings, you may get hospital

34:30 privileges for this rural hospital 50

34:33 miles down the road where you might want

34:35 to work on a weekend or provide

34:37 services. You're not accredited. So you

34:39 have to go through this whole

34:40 credentiing process again. So it's

34:42 really hard for people who have made the

34:44 commitment as a healthcare provider to

34:46 be in a rural community to be able to

34:48 service more than one. It becomes a

34:51 nightmare and a paper castle. So, we're

34:53 looking at SEDI and the subsequent

34:56 credentials that get

34:59 endorsed by the medical

35:01 organizations and others. We want them

35:03 to be able to show up with an ACDC in

35:05 the middle of the night and say, "Here

35:06 you go. Here's my whole chain of

35:07 credentials." And all those boxes get

35:09 ticked and that person goes to work

35:11 doing the job that they want to do in

35:13 that rural community. And of course, one

35:15 of the things that we don't want to

35:18 Underplay is the fact that these

35:20 rural healthcare systems compliance is

35:23 a huge issue. You blow up one thing and

35:25 you suddenly get all your payments

35:26 stopped. In a lot of cases, that can

35:29 be detrimental to the organization. I

35:31 know for a fact that in the state of

35:32 Utah skilled nursing facilities for

35:36 long-term hospice care patients, their

35:39 hash flow is about 2 and a half to 3

35:40 weeks. So, if you get an interruption in

35:42 payments, you're calling relatives and

35:44 saying, "You need to find somewhere else

35:46 because I can't afford to keep my

35:47 facility open." So, it's a real risk.

35:50 All right, let's talk about us. I

35:53 don't know if I'm going to try and get

35:54 this as good as phonehome, but I want to

35:56 kill the clipboard. I am so sick and

36:00 tired of going to an organization that

36:02 has my medical records, and every time I

36:04 come in, they want all this demographic

36:07 data they already have.

36:10 It drives me insane and I hope it drives

36:12 you insane, too, because it's like,

36:13 look, you know who I am. Think if I

36:16 attest to things haven't changed since

36:18 the last time I saw you, but I'm here

36:19 for a sniffle or a broken arm, I don't

36:21 need miles of paperwork to tell you the

36:23 things that I you already know about me.

36:25 And I will say I've been rendered

36:27 functionally illiterate by computers. My

36:29 handwriting is awful. So half the time

36:31 when I'm in these places, they're like,

36:33 "Is that an E or is that an A?" I'm

36:35 like, " I don't know. I'm in

36:37 pain. I'm in a doctor's office. I'm not

36:38 really interested in a critique about my

36:40 my handwriting. And so what we really

36:43 want to do with this kill the clipboard

36:45 is reduce these inaccuracies that come

36:47 in. And for the love of everything, why

36:49 do you have to get a copy a physical

36:51 copy of my medical card when I provided

36:54 it to you a month ago? And part of this

36:56 is not the it's not the fault of the

36:58 front-end worker. They have a set of

37:00 procedures that are trying to do risk

37:02 reduction. And so this is the way that

37:04 we operate our systems. And from my

37:07 perspective, if I could just go in and

37:09 do a tap and say, "Yeah, let me just

37:12 punch the items on the iPad of where I

37:14 hurt and how bad, that's a much better

37:16 experience for me as an individual." And

37:18 I also know that the data errors aren't

37:20 going to be because you couldn't read my

37:21 spelling or you transposed a number on

37:24 my medical card. It all came across in a

37:26 trustable transaction or series of chain

37:28 credentials that we can now move forward

37:30 on the situation. So that's the utopia I

37:33 look for. Now as I said at the SEDI

37:36 summit we look at this in government in

37:39 in a lot of different ways but if you

37:41 take any process whether it's government

37:43 or whether it's business look at the pie

37:46 chart of how much of that transaction is

37:48 trust verification risk management and

37:51 all the other things you actually do

37:52 before you get to service delivery. It's

37:55 inordinate the amount of time we spend

37:57 in making these things work because

37:59 we're we're resetting the trust model

38:01 every single time. In government, where

38:04 this hurts us so much is that we

38:06 actually have to staff people who are

38:08 part of that front office to injust

38:11 this paperwork, make some value

38:13 judgments, move things forward, and it's

38:15 not something that is sustainable. So

38:17 Utah has experienced record growth over

38:20 the last decade. We're just growing,

38:21 growing. Well, we don't want to grow

38:24 government at the same

38:26 rate. I can't keep hiring people to

38:29 ingest this physical paperwork. I have

38:31 to remain in the digital realm, but I

38:32 have to be accurate.

38:36 So, we are facing this dilemma

38:39 everywhere in the United States. As

38:41 populations grow, as you know, civil

38:44 servants retire, next generation may not

38:46 be looking for that sort of work because

38:48 generally it doesn't pay really well. In

38:50 fact, it doesn't ever pay really well.

38:51 But you those are the individuals we

38:54 want to be able to have a good

38:55 experience with us. But we're not just

38:57 going to keep adding and adding and

38:58 adding. So we have to get the digital

39:00 systems working to our best effect.

39:05 So when we look at overall the situation

39:08 that SEDI can solve, it's not a situation

39:11 of where it solves only one problem. It

39:13 solves a number of problems. So when

39:15 you're thinking about your specific

39:18 marketplace that you work in and how

39:20 KERI is going to make things a lot

39:22 better, We see it as an underpinning

39:24 that breaks a lot of the

39:26 traditional models and lets us move on.

39:28 I look forward to a world, you know,

39:30 endpoints where I can identify and

39:32 move things around without an

39:34 intermediary. I know Chris and I have

39:36 talked about this a lot is that when

39:38 this is live and you have these items

39:41 available to you in a functional format

39:43 with utility, we're going to have a lot

39:45 of people who are going, "What's my

39:47 purpose in life now?" Because I've had

39:49 my job as an intermediary for a long

39:51 time. But I'll tell you what, there's

39:53 always going to be something new for

39:54 people to do. I love history and one

39:57 of the things I find funny is when the

39:58 automobiles were first allowed in

40:00 London, it was a requirement that you

40:03 had a signalman walk in front of your

40:05 vehicle with a bell and he'd ring the

40:06 bell to make sure as you put it away

40:09 that the horses were not startled and

40:11 they even extended that into the evening

40:12 where he would carry a lantern. We don't

40:15 have signalmen in front of cars today.

40:17 They do something else. And as we

40:20 move forward with our new user

40:23 centric, you know, sovereign

40:25 environment, I think we're going to see

40:26 some significant changes in

40:28 marketplaces. But it's not just going to

40:30 be driven by the state. We can set

40:31 governance. We can set law. But as a

40:34 larger community, we need to ask those

40:36 questions why we do the things the way

40:37 we do. And if we are not afraid of those

40:40 questions, not only in business, but in

40:42 government, we're going to see these

40:43 massive improvements along the way.

40:45 Okay, we have like three minutes. It's

40:47 always hard to be the one who's like

40:48 backed up against lunch because the

40:50 questions drop off. So, if you don't ask

40:52 your question now, that's okay. Find me

40:54 at lunch or over the next day

40:56 or so. Do we have any questions I can

40:58 answer in the next couple of seconds,

41:01 minutes, whatever.

41:09 Can we get a copy of that?

41:11 Absolutely.

41:14 That was a simple one. Give me a harder

41:17 one.

41:18 - My question is about on

41:21 the delegation slide. You mentioned

41:23 several populations where it's super

41:25 relevant and one of them is like

41:27 unhoused population and migrants and

41:30 what how does delegation look in that

41:33 case? Who's the delegator?

41:37 So in that specific case I'll tell

41:39 you what we find with homeless

41:41 population specifically in the

41:42 healthcare environment. So when we have

41:44 an encounter with somebody who's

41:46 homeless, the best we can do is put them

41:48 on something like emergency Medicaid,

41:49 which is super expensive for the state,

41:51 and we can provide those critical

41:52 services that keep them from

41:54 dying, but that's not long-term

41:57 maintenance. It's not

41:58 prophylactic medications or anything of

42:00 that nature. Those don't come until we

42:02 have identified that individual. And

42:04 given that we might have to query them

42:06 like where were you born approximately

42:08 when were you born all these items that

42:09 we case work it's assigned to them. It

42:12 is generally 6 to 8 weeks before we have

42:15 documentation in hand that we can now

42:17 say we have identified you and we can

42:20 now move you off of the emergency

42:21 Medicaid and put you on to a different

42:23 service. The tragedy is once they

42:26 hand them that packet of information

42:27 within 30 days the majority of them have

42:30 lost their documentation. And it's like

42:32 well of course they're unhoused. they're

42:34 not going to walk around with

42:35 a manilla folder under their arm. So,

42:38 how do you solve that problem? Well,

42:39 there's a couple ways you can do it. One

42:41 of the .., I was at a conference and I

42:43 was just being flip and I said, "Well,

42:45 why don't we do a system called Nomad?"

42:47 And they were like, "What do you mean by

42:49 that?" I said, " National Online

42:52 Assisted Documentation, or

42:54 management of assist of documentation."

42:56 So we are looking at opportunities in it

42:58 that could do something like that which

43:00 is basically there are some things

43:01 you're always going to have with you and

43:03 those are going to be some of your

43:03 biometrics and if you are willing to

43:05 work with the state to get you

43:07 identified and put you into a national

43:10 data store that's encrypted to your

43:12 biometrics then we have means for how we

43:14 can get those people on the system.

43:16 There are care relationships that exist

43:18 inside the state like Foster Care or we

43:20 have Battered Women who are put in like

43:23 safe harbor shelters. So there are some

43:26 there are some relationships that we

43:28 need to clarify in not only in law but

43:31 how that works digitally because there

43:32 are certain rights that get communicated

43:34 to each group. So as we move along there

43:36 will be both a policy side and a

43:38 software technology side to work on it.

43:40 But the interesting thing is we do

43:43 think that the easiest relationship for

43:45 us to solve right off the bat is the

43:47 parent child relationship. That's pretty

43:49 easy to prove. But when we get into some

43:51 of these more complicated

43:52 situations, so say for example, a

43:55 Medicaid household is defined by the

43:57 number of people living under the same

43:58 roof and what happens if you have an

44:01 acrimonious divorce. Party A has a lot

44:04 of KYC data to try and infiltrate what

44:07 party B is doing. So the state's going

44:08 to have to be very careful as we roll

44:10 these out to make sure that when we do

44:11 endorse something like a parent child

44:13 relationship that we do have a glass

44:15 break where we can go and turn that off

44:17 so that we keep everyone safe.

44:20 Okay, I think you is we're at lunch.

44:22 So, thank you again. I look forward to

44:23 talking to you individually. Reach me

44:25 out to me at any time. I'm always

44:27 willing to talk about both the tech and

44:29 the policy. Thank you very much.

44:32 Thanks.