Alan Fuller

Afternoon Session · 6:01

0:00 Thank you, Chris. And it's a pleasure to be here today. I'm so grateful. I had

0:03 really great conversations here. And I'm so glad that you're all able to come. Let

0:09 me just quickly make one big point. And I want to talk about digital identity as

0:15 critical infrastructure. So as Phil Windley talked about earlier, the purpose

0:20 of a digital identity is to create a trusted relationship online. And we used

0:26 to talk about with trust credentials that was going to be like with identity and

0:32 access management systems, that you needed something you know and something you have.

0:38 But that is becoming not sufficient. And what we need is something you can prove.

0:43 And something you can prove is a credential with cryptographic codes that

0:47 can verify both the holder and the issuer of the credential. And I just want to

0:53 point out that this is actually new territory for states to be leaning in to

0:59 this area where we are adding a state endorsement to a relationship where it

1:04 hasn't really existed before. Yes, the state has issued driver's licenses and

1:10 other credentials, lots of them, but the online age changes the nature of these

1:15 things. Okay, so in the digital age where so much of our lives have moved online

1:22 from social media, social banking, commerce, application for government

1:28 services, where so much of our relationships have moved online, this

1:33 identity, digital identity becomes absolutely critical infrastructure.

1:37 There's so many public sector areas that rely on this and we've seen in our country

1:42 since COVID hundreds of billions of dollars in fraud and a lot of that fraud

1:48 is tied directly to not having good identity verification. So, you know, for

1:54 at the state level, public social services systems like food stamps or unemployment

2:00 insurance or housing assistance or Medicaid or child health insurance. Many

2:06 of these rely on being able to identify someone successfully. We have a lot of

2:13 discussion in our state about voter registration and signature gathering and

2:18 petitions for citizen initiatives. Can we do those digitally without having a true

2:25 digital identity? In the last legislative session, one of our leading senators asked

2:29 me, what will it take to be able to do online elections and will this help us do

2:34 it? And I told them, I know for darn sure you can't do an online election without a

2:41 digital credential that is reliable and trustworthy for identity. Professional

2:46 licenses and education credential and also our corrections and public safety

2:51 interactions. Across the private sector, we have a plethora of use cases as well

2:58 that that rely on secure online infrastructure, whether it's verifying

3:02 proof of age online or in person, whether it's accessing our health records and

3:08 benefits and also our financial transactions. We have the know your

3:12 customer requirements in that area and then we have many different online

3:17 commercial and travel related needs. But we have a big problem. And so as part of

3:24 my organization, we have the state cyber security center. And what we see is we're

3:29 constantly under attack. Our state systems in Utah have about a billion and a half

3:34 scans per day of our system. And we have numerous efforts by malicious actors

3:43 trying to create fraud, trying to create ransomware attacks. And so what we see is

3:50 our infrastructure, especially our digital infrastructure of all kinds, will be under

3:57 attack. And the point of attack, the attack vector most often used, is

4:03 identity. And so because digital identity is critical infrastructure, incomplete and

4:11 half measures with regard to the security of these systems are not acceptable. We

4:18 have to have reciprocity between states, but that also means that all states need

4:23 to have strong security around their digital identity systems. We have to build

4:28 SEDI with the highest level of security that is available. And we know that

4:33 nothing is perfect. So we need an ability if compromise occurs, or I should say when

4:41 compromise occurs, we must have a way to recover. So when we think about SEDI and

4:46 we think about keys, cryptographic keys that are the backing that credential. What

4:52 I'm talking about for the technical person and the technical people in the room is we

4:56 need a way to rotate those keys. One of the concerns I have about the current MDL

5:02 technology is that we don't have a great ability to recover if those are

5:07 compromised, you know, short of canceling and reissuing credentials. So the ability

5:12 to revoke is important. The ability to recover if it's compromised is essential.

5:21 Thank you so much. Glad you're here.

5:34 We could do this quickly like a pit stop, right?

5:43 All righty.

5:47 They said wait 30 seconds. something