0:00 That must have been a really long day.
0:07 It was
0:11 today. I was obviously here all day. Actually, it looked like I missed some
0:17 meetings today. I assure you, I work really hard. I really do. All right. This
0:24 is actually, I think, going to be the most exciting part of the day. This is the
0:28 final discussion. I am going to ask and we didn't plan on some chairs. Could we get a
0:34 couple chairs just for some of this? We're actually going to discuss how are we going
0:39 to move forward. We have enough brain power in this room. We have enough
0:45 policymaking authority. We have the ability to create legislation. We had
0:50 Senator Kullimore here earlier, our Senate majority leader. I've already heard
0:54 there's going to be discussions happening with some other state Senate majority
0:57 leaders. We have counterparts parts and states. We have companies we work with. So
1:02 now the discussion for this last hour before we leave is how do we move forward?
1:06 You never want to have a summit like this without some outcome and some
1:10 deliverables. We have a lot of momentum built and in order to keep this going, you
1:15 don't stop. That's what usually slows government down is then you go back and
1:18 you review. So the question is how do we keep the momentum going? I think three
1:24 will be good. So we're going to ask Representative Cutler to come up and then
1:28 is Alan Fuller? in here? Alan, if you'll come up. So this is we're going to have
1:34 we'll just have one mic for us to share, but then the rest of the mics we'll have
1:38 some interns around and we want to discuss what are we doing next? What are our next
1:46 action items from our side? But then how do we engage with states to go ahead and
1:51 get this consortium going? And then I see the clock here says 14 minutes, but I
1:57 think we're just at the end, right? So we haven't four timers, right? Okay. So let's
2:08 actually check.
2:18 I think it'd be beneficial if we explain some of what our next steps are actually
2:24 going to be. Alan, do you want to take the first? Let me just get started by saying
2:30 that Senate Bill 260 gave the Department of Government Operations of which Chris
2:36 and I and Marvin Dodge was here are a part are all part of and it tasks us with
2:43 coming back to the legislature with a specific proposal and the input we receive
2:49 here and the input we receive through a request for information that we put out
2:52 many of you responded to that RFI. Thank you for that. We over the next couple of
2:56 months are going to be putting together a proposal to go back to the legislature for
3:01 our SEDI program going forward. And you know, we live in the real world. We have
3:08 to, if we're going to create a system that's going to have provide identity for
3:12 millions of people in the state, it has to be something that works really well as
3:17 performant and secure as private. And so all of the principles that we've talked
3:21 about today need to eventually come together in a real life system that
3:25 actually works. Maybe we can turn over to you and represent Cutler. Sure. One of the
3:32 thoughts that I have is in order to, we can, I mentioned this before, we can pass
3:39 the policy, but we need our industry partners and we need a large enough
3:44 coalition that we have a critical mass. So what you can do to help is encourage our
3:50 industry partners that you, by telling them, look, I'm interested in in this or
3:57 let's work together to get something done.
4:02 Communicating that you're interested in being part of a critical mass to move this
4:05 forward, even if we don't necessarily agree on all the finer points, I think is
4:10 really important. I thought the gentleman from the blockchain co-inventor that was
4:20 real wisdom that working together, even if it's not perfect, we can make a tremendous
4:26 impact. So, but we can't do this without our industry partners pushing very, very
4:32 hard and getting products that we can put in an alpha phase or a beta phase and
4:39 start testing and finding the flaws and finding the successes.
4:46 Two practical things that I think we can expand. Here in Utah for the last couple
4:52 months, we've actually held a private sector stakeholder group every Friday we
4:57 meet, whether we're exhausted or not, to engage with the private sector. I do think
5:02 we should expand that to invite all private sector in other states. If you are
5:07 ready to participate and you want to engage, you want to help be part of
5:11 building the solution, we can expand that and get that set up so you can come and
5:14 coordinate. And this doesn't have to just be a Utah stakeholder group. This is part
5:19 of the SEDI consortium. How do we make sure everybody's engaged and
5:22 participating? We want a diverse set of ideas, you know, so long as you love
5:28 constitutional rights. And but I think, you know, we all have a role to play here.
5:36 And for the private market, there's always going to be money to play. You can bring
5:40 real value-added services. We don't want government to be doing beyond the bare
5:45 minimum of providing a foundation to protect individuals. So this is amazing
5:50 for you. This is going to be really disruptive in a good way to move that
5:54 money from incumbent players to others that can help create a more competitive
5:58 marketplace. So that's one thing we'll do right away. We'll open that up. I'll start
6:03 on the communication for that and get invites out set next week. I think we had
6:07 the National Chamber of Commerce Foundation here today as well. So I'm
6:11 assuming you might be able to help us with that as well. How do we get this out to
6:14 all the businesses that are part of that? The other thing is now that we're through
6:19 the summit, we need to go back and start defining some of those baseline
6:22 requirements. What are the requirements we're going to compare technology to and
6:28 everybody should play a part in that. Obviously the RFI is closed. We have a was
6:33 it a thousand or thirteen hundred pages to read. We have twelve hundred pages to read
6:37 and I know we don't have all the info we need. So we're going to need everyone to
6:41 participate to say what additional requirements are we missing? And then
6:45 comes the hard work of the technology needs to prove itself. How do you meet the
6:49 requirements? And then also I think to what you said earlier the hierarchy of
6:54 values. That's going to be the hardest part. I know a lot of people in this room
6:59 are concerned that we are going to compromise on the wrong things in the name
7:03 of interoperability and efficiency. So as we define the requirements, we're going to
7:09 have to create this hierarchy of values, which I have seen nowhere. I think that
7:13 slide was the first time I've seen that presented in that way to have technology
7:18 value at the highest level of that constitutional rights. So that's going to
7:22 be a hard part in the requirements building list. but that's the type of
7:25 stuff that's going to build trust with the public when they see what we are
7:28 prioritizing. And I think it's going to be great. I think it's actually going to be
7:31 great for government. Trust is at an all -time low. So this is a really good way to
7:35 be very transparent to an extreme and let them know that we really want to protect
7:40 them. One of the things I think that we should talk a lot about is something that
7:46 Ryan brought up earlier in his presentation about the kind of practical
7:50 side of rolling something like this out. and gaining adoption. We need to find a
7:58 launch customer that not maybe customer is not the right word, but a launch tenant
8:04 that can help us that will pick this up and run with it maybe in Utah like a Zions
8:10 Bank or something like that that will help launch the whole process and also create
8:17 the system in such a way that it incentivizes use rather than
8:22 disincentivizing use. in order to get adoption. One of the big problems that we
8:27 have with our current MDL program in Utah is that by charging the verifiers for the
8:34 verification software, it's a disincentive for them to verify. And that makes it so
8:39 you got an MDL that people can walk around with on their phone, but there's not very
8:44 many places it can be used. So then you have not very much adoption. And we want
8:49 to set this up systematically so that it will have adoption and incentives to use
8:55 from the beginning.
8:59 – Kristen Allen, if people have ideas for use cases, where do they go? And I think
9:05 I'm thinking back to our experience with verifiable digital credentials. We didn't
9:11 start with the most critical key. We started with something easy that no one
9:16 was it wasn't controversial. Though I think maybe there's some lessons learned
9:22 here that How do we start this and get some use cases where we can learn from
9:27 before scaling it? And what are your thoughts on that process? Well, I was
9:33 thinking they should call the legislator. All the
9:44 RFI responses are protected, but I think I can semi-quote what was in them. One of
9:49 the best ones that I read was it was actually from an entity that's not looking
9:53 to compete. They were just giving advice of how they could best serve their
9:56 customers with this. And they said, and this is actually a saying, I was in
10:00 health, uh, human services for seven years before this role. Um, they said in that
10:05 RFI response, help us meet the clients where they are, meet people where the use
10:09 cases are. Um, and so they said, you know, TSA probably was not the best example.
10:15 That's not something that, you know, everybody is going to need, but there's
10:19 lots of people who have their kids going to school every year. They need to, uh, to
10:23 enroll and need to have a birth certificate or immunization records. There
10:26 are use cases where we don't have to try to replicate what's already being done
10:30 with MDL and is working and they're getting traction on that side. What are
10:34 other use cases that we can tackle to tackle other more complex issues that are
10:41 a different subset of individuals, but it's meeting people where they are and
10:45 they're going to use it. And government's great. I love the saying, government can
10:49 actually do almost whatever it wants because it's the only entity that can have
10:52 a legal monopoly. So the only thing stopping us from getting the credentials
10:56 out to where they're needed in a secure way and getting these use cases is I think
11:01 that's the legislature. Speaking of the legislature. You need money. Yeah, if we
11:07 need money, we know who to talk to. You know, this is not just about us talking.
11:12 We really want to this is audience participation. I really wanted to maybe
11:16 start by asking the audience some questions, especially can I start with the
11:20 legislators in the room? What do you feel like you've seen today or what questions
11:27 do you have coming out of the conversations today? Would anybody like to
11:31 please?
11:36 And introduce yourself too.
11:44 Okay. Knowledge is power and you know getting more of us in the room or you know
11:51 legislative trainings, et cetera, because it's hard to vote for something if you're
11:55 insecure or ignorant of an issue. You're less apt to vote for something or even
12:01 make any kind of progress if you are unsure of what you're voting for, which is
12:06 a good thing. You don't want your legislators voting on things that they
12:09 don't know about. So I think increase, I see a handful of us here today. Maybe it's
12:14 because my colleagues just know all the things, but I've certainly learned a lot
12:18 today. Appreciate especially those presenters who really broke it down into
12:23 simplistic terms for me. And, you know, I'm a lot more comfortable. I was never
12:28 against, not completely against it, but I definitely feel more comfortable after the
12:34 things I've learned today. So I would just say, especially with our lawmakers, we
12:39 need them. We need us in a room so that everyone can understand and then make the
12:44 decision based on that. And I think that, you know, the more people learn, the more
12:47 comfortable they'll be with the direction that we're heading. Thank you.
12:56 Anyone else? Questions out there? Yeah, let's open up to everyone. Other thoughts
13:03 and…
13:06 Thank
13:12 you.
13:15 Were you the one that works with the anatomy labs? Who is that? Anonymy Labs?
13:22 No, he's over there. Steve McCown. So, I use MySudo. That's, yep. Excellent. I was
13:29 curious. So, you're asking how we can implement this technology into that. I
13:33 mean, is this something that's being implemented into MySudo? We do a wide
13:39 variety of credentials. We implement and support a wide variety of credentials. And
13:46 so, SEDI is definitely on our roadmap. out. What? Okay. Well, that's awesome. And
13:54 I just think that this is excellent technology. My limited understanding so
13:59 far, but I think from some of the policies that we've seen get passed, the app store
14:04 identification, forgetting SB, whichever one that was, and just a variety of bills
14:10 that Utah has passed has been, you know, for the children. It's kind of like the
14:14 the messaging push behind it, but it's devastating to internet privacy and
14:18 anonymity. like we've talked about some of these here, in my opinion. And I think
14:22 that SEDI is one of the technologies that can bridge that gap and that can really
14:26 help us. And my understanding right now, it seems like this is some vital
14:29 technology. So I just, I'm championing, you know, everyone here working on this.
14:33 It's great. So. Thank you. Question over here. So maybe not so much a question.
14:39 It's just, you know, you talked about what use cases and things that you can do to
14:43 make it move forward. So Eric Jorgensen, I'm the motor vehicle director out of
14:48 Arizona. Jonah, fantastic conversation and discussion this week. Thank you very much
14:52 for today for putting it on. I think a couple of things that I would just want to
14:58 say that I think would be key was one is, you know, we already have a great head
15:06 start on this with MDL, right? So somebody early on said, hey, let's not worry about
15:11 the technology aspect of it. This is really about the underpinning policies.
15:15 And I will tell you, I've been involved with MDL for the past. 10 years almost.
15:21 Over 10 years now. And I haven't heard a single thing today that like butts heads
15:29 with that technology. And the good news is when we talk about adoption, 60% of the US
15:34 population is covered by a state that issues a MDL today. So we already have it.
15:39 And in Arizona, by the way, we have over 1 .2 million MDLs issued. We have a
15:47 population of 5.6 million driver's licenses out there. Biggest use case is
15:56 not TSA. It's the motor vehicle division. It's state services. We use it now. We
16:03 used it in a pre part seven ISO compliant way to do it, but we had it out there. We
16:09 consume our own MDL and that became one of the biggest use cases. Massive driver for
16:17 adoption for us. So something to think about and something that is in your
16:21 control as you look at it is why not use it yourselves? That's a place where you
16:27 can control both sides of the equation and make sure not only is the provisioning
16:31 done in a privacy-preserving and secure way, but the consumption too and set kind
16:36 of that example for everybody else on how to consume it too. So just a thought.
16:39 That's terrific. And also let's acknowledge Chris Keras. Chris, if you
16:42 could raise your hand. He's the director of our our driver's license division here
16:47 in the state of Utah has done a terrific job leading our MDL program. We're
16:51 grateful for him. I think Jimmy Higgs is here as well somewhere. I don't see him at
16:54 the moment who will be the next driver's license division lead after Chris retires.
17:02 We are I believe that my expectation and hope and this was mentioned to me today
17:12 too from someone else that likely the states who are already doing MDL will be
17:17 the first adopters of moving to more broad study because they kind of get it and have
17:21 already invested in creating a credential like that. Let's see. I think I saw a hand
17:26 up here. I think it was was it Sarah or Okay,
17:32 we'll go here and then back. Oh, yeah, Amelia, please. Yeah. I know that I've
17:37 obviously been working on this with you guys for years. Introduce yourself,
17:41 Amelia. My name is Amelia Powers Gardner. I'm a county commissioner in Utah County.
17:45 And I've been working on decentralized ID and self-sovereign identity since 2019 pre
17:52 -COVID. And, you know, as I look for as a county commissioner in the fastest growing
17:57 county in the state, we're 43.6% of the state's growth. As I'm starting to look at
18:02 capital projects and building brick and mortar to the tune of tens of millions of
18:08 dollars because of for a growing population, the sooner we can get these
18:13 services instituted in a way that we can start utilizing them to deliver services
18:19 to our citizens in a secure, private way, that prevents me from having to spend
18:24 millions of dollars. And so my question comes in, like, I know we've got the
18:28 groundwork, but I mean, you know me, I'm like, I want to run first. I want to run
18:34 first and then I want to walk and then I want to crawl on. We do need backwards
18:36 compatibility, but when are we going to have the ability for an organization like
18:40 mine that has already done some of this work? when are you going to give us the
18:44 ability to start adopting this on a broad scale? When do I start getting the schema
18:51 and the requirements so that I can start implementing this for my citizens so that
18:55 I can deliver services to my citizens without having to spend tens of millions
18:58 of dollars building brick and mortar buildings? Was that chastising us, Amelia?
19:06 I'm joking. Yeah. Yeah. Yeah. So there's a lot actually going on in Utah for those
19:15 that are from other states and just, you know, we work with Amelia all the time. So
19:18 we've had this discussion. For every state, you actually have a unique
19:23 opportunity right now. Every state nationwide is pretty much non-compliant
19:28 with their records management and data governance laws. And Amelia is shaking her
19:33 head, but this is the opportunity. So when I say that, what I mean is you all have
19:36 antiquated laws from the 70s and 80s that require certain things like disposal of
19:41 data according to retention schedules. Most systems have not been created to
19:46 dispose of data. Most states haven't established the purpose and use of data.
19:51 Most states haven't been giving privacy notices. And that sounds really bad, but
19:56 the great thing about it means there needs to be a modernization anyway over the next
20:01 decade. And so you're in the unique spot of because you know there's non-compliance
20:06 and I'll actually I'll share out after if one of my team can take a note, we had
20:11 interns over the summer actually research all 50 states' laws to determine where
20:16 they are legislation-wise. So you can see where is your state with privacy, with
20:21 records management, with data governance. You'll know you're non-compliant, but now
20:24 that you know what's coming with digital identity, you know you need data
20:27 governance. And now what Amelia mentioned is the schemas, this concept of what are
20:32 the rules? What's the schema? What's the formats of the data that needs to be
20:36 collected? When Amelia is asking what's the schema, it's hey, when somebody
20:39 applies for a building permit. What is the exact data the county should be
20:43 collecting? What needs to be on the forum so they can automatically ingest it,
20:47 automate that process with AI or machine learning, and then move toward the
20:51 efficiency that government can get. So what I'm saying is now is actually the
20:55 perfect time to learn where you are. And it takes about a decade to transform. Utah
21:00 is about three years in on this journey. And that's why we've been modernizing our
21:03 laws. We've been getting comprehensive privacy law. Amelia, but the schemas will
21:07 come sooner. We actually have on our team we're doing modernization of then the data
21:11 governance structures, the rules around the data, how long can you keep it? What's
21:14 the legal basis? What's the purpose and purposes and uses? We're starting to
21:19 define what are the immutable records, which records are immutable public
21:22 permanent records, which makes sense to go on a blockchain. These are the things you
21:27 need in a schema to then implement technology correctly. If you jump right to
21:31 the technology without having these things, you end up having to backtrack. So
21:34 I don't know if that's the answer, but it's coming soon. And the schemas I think
21:38 will be very soon. We have some almost ready. Maybe Sarah? I just want to echo
21:46 thanks again for having this event. It has been really, really powerful learning a
21:51 ton and getting to make sort of leaps and bounds forward. So thank you. I think
21:57 there's an opportunity to create a more sort of like formal digital space where
22:03 those things that you were just talking about, Chris, if you could post them,
22:07 playbooks, I think this opportunity of how can we learn from you also share what we
22:13 are doing in Colorado and other states so that we can learn together. I was
22:17 reflecting on the statement about MDL and opportunities around MDL. We recently
22:25 discovered that the standard MDL contract with the big tech wallet companies, Apple,
22:31 Google, Samsung, in our case, have a clause in them that says they are sole and
22:36 exclusive provisioner and revoker of MDL. And like, that's something I want to share
22:41 with you all about like one particular thing, because it does conflict with the
22:45 SEDI idea. And so how do we join forces together and say like, hey, Apple, Google,
22:50 let's not have that as the standard clause. Yeah. All of us are sort of
22:57 against that idea. So I think that there is an ask maybe and how can we contribute?
23:03 It's not just an ask of you. Can we host it? Can we do something so that we can do
23:08 that knowledge sharing and really accelerate our co-growth? We will be
23:13 emailing out after the summit. One, obviously we had the white paper of what
23:17 is SEDI. We have some resources that we've created of model legislation, model
23:23 resolutions, model executive orders. For us to do a formal consortium, there should
23:28 be something you want your elected officials, governor or legislature to
23:30 authorize. We've had this discussion with our governor and let him know we wanted to
23:36 do a consortium, which is why we've invited you all today. If one more state
23:39 for, I mean, we've had a couple reach out and say, actually, we're very interested.
23:42 If you can get the formal approval, we'll start seDI.gov. And it's not seDI.Utah
23:48 .gov, seDI.gov. You need at least two states with formal approval. And that's
23:52 where we start building that multi-state formal consortium and we can start then
23:57 advocating for ourselves and for our citizens and put these resources there and
24:02 we can build it together.
24:11 Yeah, that works. Okay. So first of all, thank you. This is actually turned out
24:16 very well as an event and I think there's been a lot of really great interest. I
24:23 always talk about this as an idea when we talk about off-Broadway use cases as
24:27 representative Kohler mentioned, but I think the idea of vital records is
24:33 something that is not so much any having anything really implemented yet. And I
24:40 always like to say death records because everyone needs one one day. Death and
24:46 taxes are the two things that they say are inevitable. And there's a guardianship
24:50 mechanism and a burial permit mechanism and a plot of land. Kind of have
24:56 everything at once. I do have him the treasurer of a cemetery, so I would love
25:02 some funds. We're actually going to have George McKeown make a comment about how
25:07 are we engaging vital records. The amazing thing actually about government is once we
25:11 start saying we want to do something, it opens doors with all these organizations.
25:16 I wasn't anticipating getting on stage. So one of the things we've done is we've
25:19 reached out to Napsus and I just gave a discussion to their security and privacy
25:24 group last week. We are actually talking about the schema that they have for a
25:29 national standard for a certified birth certificate and their digital schema. So
25:33 we have committed that if they want us to come out to their December event, we will
25:37 bring a SEDI compatible version of that. So they're close on their standard. We
25:42 just need to wrap it in the appropriate cryptography to make sure that meets the
25:45 SEDI threshold. And I think we'll be there. The real goal will be is in June of
25:49 next year when they have their annual event that will really move that forward
25:52 with them and kind of codify all that.
25:57 One of the this session as we go in to make recommendations for the SEDI program
26:03 and we also we need to recommend what would the next legislation look like part
26:07 of that does need to be prioritization of credentials and that's been a very common
26:10 ask. How do we get these other value-added credentials not just mobile driver's
26:14 license or a driving credential but it was birth certificate, your immunization
26:18 records, your death certificate and And so I would anticipate that would be part of
26:24 the discussion we have this session is not only do we need to get it out there, but
26:27 then we need to work with the group. So we had I think we had part of the group group
26:30 here from health and human services today where vital records is, but I think that
26:35 is a low hanging fruit use case to get out there. We'd actually love to know what are
26:39 you going to use that data for if people have it? What's the private sector able to
26:43 provide value for if you have those records though? And Scott, I think you had
26:47 a question, right? I have three things. One, excellent day, really outstanding.
26:54 Two, incrementalism is important, but there's a cart and a horse kind of aspect
27:01 to this. And so, how do you get to trust? And I think that's one thing that we
27:08 really need to ask ourselves in terms of who is trusted to each of us. And if
27:14 that's our teacher, our professor, our doctor, our lawyer, our banker, I mean
27:20 where that comes in, I think really it might help you define use cases and how to
27:27 go after those early and first. And third, if you want an example of one state that
27:33 I, if you went to Hawaii anytime during the pandemic, Hawaii did a really
27:39 excellent job of making sure that they could reopen their economy, which is
27:45 tourism, by making sure that they had the smart health card for people to come in
27:51 and show proof. You had to prove you were vaccinated in order to visit at that time.
27:57 And they did a really a great job of it. People were motivated, of course, to fill
28:01 this out and an ID for it. But it's just one example that you might want to loop in
28:08 Hawaii on.
28:13 All right. So listening to all the constituents here, the challenge I think
28:19 that we have here is a scope problem. There's lots of things that can be done,
28:24 but the way to get something done is iterative. And it needs to start with the
28:30 core of what you're looking for. So you've done two things. You've said, we're going
28:35 to have a state endorsed identity. Okay. And you have a law. So you have two things
28:43 to build upon. I think you start there. What is the state going to do whether you
28:48 have paper to present to the state to endorse, but it has to be focused on the
28:55 first and foremost thing, which is how do we issue a state-endorsed digital identity
29:00 and start there? And then use cases will come once you have that established. If
29:06 you don't have that established, what's the SEDI project? So that needs to be the
29:11 absolute core, and it needs to start with a risk assessment because there's a
29:15 million risks we talk about today. but there are only certain risks that can be
29:19 mitigated by a project like this. And that will drive the scope of how you can
29:25 mitigate the risk to the degree that the state can accept. And you take the law and
29:31 all the requirements that you have in the law and put it in the governance framework
29:35 and the set of requirements. And at least you are have you have momentum. You need
29:39 to start with momentum and leadership and others will come and use cases will come.
29:46 But it has to be right down the road for what you've done. Don't lose focus on
29:53 that. You have law to drive a state -endorsed digital identity. Make that
30:00 happen. You have the means to do it and you have the expertise in the room here to
30:05 start for sure.
30:10 So Matthew Helston here from Brigham Young University and I think transcripts and
30:15 educational data is a very complex use case and been working on this since 2016
30:20 with SSI space and we've made a long way so it's really amazing but I wanted to
30:27 emphasize something that I think about with decentralized identity I think is
30:32 important is that just because we have a credential and a set credential doesn't
30:37 mean we have a ubiquitous identifier. So we don't want to have a unique identifier
30:43 that correlates us wherever we go. We have the possibility of using that identifier
30:49 where we want to, but we can create an ephemeral identifier with our credential
30:54 and make a connection with another entity to present our information. That's really
31:00 important that when we think of our use cases, we're not thinking of I can be
31:04 correlated wherever in that a great user experience and that may be true, but I may
31:09 not want that as an individual and the technology needs to support the privacy
31:14 policy of me being able to choose to create an identifier to present my
31:19 interface and my information through. So I want to emphasize that. Another thing I
31:25 wanted to emphasize is credentials need to be intentional. They don't have to be
31:30 where everything is stored in one credential, right? I can have a very micro
31:35 credential for a specific intended purpose and the technology stack allows me to take
31:42 multiple credentials and draw selective disclosure information from each of them
31:48 and aggregate it into a presentation for the verifier. So that means as an issuer
31:54 of a credential I don't have to solve all my use cases where I think my credential
31:59 is going to be used. I just have to focus on my data and give that to the
32:04 individual. individual and let the verifier define their own data contract
32:09 that really empowers them from a data model perspective of verifier defines
32:15 their contract and we can fulfill it from a number of credentials. We can give an
32:22 example of that with our the first credential and this is what representative
32:25 Cutler is referring to is our off-highway vehicle training certificate which we put
32:29 out a verifiable digital credential for this training certificate to drive your
32:33 four-wheeler on the roads. Yeah, thank you. And we have, but it doesn't say who
32:40 you are. So you still, it doesn't provide your identity. You have to have both an
32:45 identity and this credential to say, you know, who you are and that you've taken
32:49 the course. Let's see, where are we with our microphones? Maybe here. Yeah, go
32:52 ahead. Yeah. Phil Long from the US Chamber of Commerce Foundation and T3 Innovation
32:58 Network. I just want to bring us back to the actually the first presentation that
33:02 was given this morning by Ryan First. first who are Ryan. Yeah. That reminded us
33:09 that we really need to look at the examples of failures of the things that
33:14 we're looking at as potential priorities to try to learn from them because we tend
33:20 to dismiss that was done by them. It was done at a different time perhaps a year
33:24 ago. It may not be relevant, but there are things and lessons in there that will be
33:29 extremely valuable if you look for them. So that's one thing. And the second to
33:34 reinforce several of the comments here, which is to pick the two or three to start
33:39 with that are win-wins for all of the stakeholders involved because everybody's
33:44 going to have resistance to it at some point in this early stage. So where you
33:49 can come up with one where there's beneficial time savings for a government
33:53 office to get something done, that time savings benefits the individual who's
33:57 making a request and the benefit of the credential actually has direct value to
34:02 that person for what they're trying to do. Those combinations are absolutely critical
34:07 and I applaud you for doing all of this. Thank you. Do we still have Jeremy Grant
34:11 here? I'm going to steal a line that he said, we can't build identity or what did
34:18 he call it? It says we can't build identity or we're a bunch of identity
34:22 weenies building identity for other identity weenies. And so we can't be
34:28 identity nerds trying to build this really small use case of like, Yeah, it'd be
34:34 great to use a verifiable credential to… I don't know, Timothy, what's a really weird
34:37 use case? You can probably think of one off your head. What? Okay. You got a use
34:45 case? Oh, yeah. What about the beekeepers license? Okay. Beekeepers license. That's
34:51 a pretty small use case. And does government go and actually check beekeeper
34:56 licenses? So, but we have to build identity for people that it's going to
35:01 have value and we have to meet them where they are. How are they going to get value?
35:06 How is government going to get some value? And I think that's also where I said we
35:09 have the ability because we are a monopoly to solve the catch-22 of well let's create
35:14 that instance where both can get value and we're already spending money on it. So
35:19 it's let's move those resources to actually realize the savings that can come
35:22 from that. All right. So who has ideas of how we can work together with other
35:27 government entities?
35:37 Hello, hello. My name is Mariano, Mariano Green. I'm from Mexico City. I'm very glad
35:41 to be here with you guys. Even though that I'm born Mexican-American, I'm more
35:45 Mexican than American. I live most of my life there in Mexico. So I have learned a
35:50 lot with you guys how we can implement. We have been working with clear companies,
35:55 try to like develop the Mexican an environment there. But we came to the
36:01 conclusion that it has to be a grassroots movement. It has to be with the
36:05 communities. The community has to endorse their own, not only the identity, like
36:12 yes, identity has to be more broad, but it's something that this movement has to
36:20 be more locally. I have been talking with some of these persons here and a lot of
36:27 those persons came to the same conclusion, you know? And that's the way that I think
36:31 personally the human being has to like has to move towards to that because if not
36:38 that will happen with centralization and control power. We all know that. So this
36:44 idea of stay indoors, I will say it more like community indoors. That's my grain of
36:50 salt. I like that community indoors. One of the I had the opportunity I think it
36:56 was as representative Chevrier still here. She invited me to speak at one of her
37:01 events for Stand for Health Freedom a couple weeks ago. And we had a really
37:04 interesting discussion of you mentioned community of how to decentralize the
37:08 proofing process out into the community. A lot of cities and towns and school
37:13 districts or even our post offices are in the community. Do you need to go
37:16 essentially to a DMV to do proofing or can we have lots of entities doing it? Move it
37:21 out to the community so there's more trust because these are their neighbors that
37:23 work out there. If you can standardize the identity verification and proofing
37:27 process, there's some real low-hanging fruit and we can eliminate some of those
37:32 inefficiencies or barriers for people that can't get it currently. And if you could
37:37 just go to your local city recorder or your local treasurer or your local postal
37:41 office, why don't you have all the options? And that's, I think, a great way
37:45 to get that grassroots going of those communities that want it. We know Utah
37:49 County and some small cities have been saying we want it. If we could build it,
37:53 bring it out to them. Pat Brooks with the state of Missouri judiciary.
38:01 I'm not sure how many people here are familiar with the standard called NEEM.
38:06 Anyone familiar with NEEM? NEEM is the national information exchange model and
38:14 that started as what was the predecessor of that was called GJXDM and that was a
38:20 global justice data exchange change model. And what you're talking about doing here
38:27 is following the same path that that program followed. You have a grassroots
38:33 follow along with the gentleman just before that people had a need to do
38:40 something and the standards were established and not so much in legislation
38:46 but in adoption from a technology perspective to say this is how we can get
38:51 the work done. Going back to the comments of publishing schemas, publishing
38:54 standards that people can adopt. And the organization that started that was a multi
39:02 -state organization and it was in the justice domain. And what happened to it
39:07 was it saw a need to exchange information in multiple domains. And identity is one
39:15 of those domains. And so I would encourage you to make sure that if we're
39:20 establishing a standard for multiple states to follow that we look at if there
39:27 is RA something at the national level that could be more readily adopted than maybe
39:32 building something from total to scratch. You have governance that you have to
39:36 issue. You have to have vitality issues. You have technology standards. But I think
39:45 this is a wonderful idea and I think that it can be well served to see how others
39:53 have done something similar and going forward.
40:02 Michael Proper, I have seen this dilemma that we've been building and sitting upon
40:10 for years, well over a decade actually, and the solutions right in front of us.
40:19 But will we really see it? And what I mean by that is we know that we've all got to
40:25 come together and adopt a system and we know that there's a political side of it
40:30 and there's a technology side of it. But what if they really existed? Would you
40:37 really adopt them? Would you really use them? Even if it had the beekeeper
40:41 scenario built into it and 86 other certificates, permits, licenses that
40:50 already exist and already use these standards. standards. Would you really use
40:55 it? Would the state of Utah really use it? Would the state of Arizona really use it?
41:02 Would Mexico really use it? Mexico doesn't know. It's a community thing. It's the
41:10 person that would actually be the ultimate decision maker if they're going to use it.
41:15 That's why MDL has such… I think Arizona has a ton of adoption. 17% adoption. If we
41:23 could do that with a decentralized system where the individual actually will throw.
41:28 If we could do the same 20% of MDL energy into a decentralized system and people
41:35 knew about it, the awareness and adoption would go through the roof because it's
41:39 around the individual first. If we want to be true and honest around what's going on,
41:45 Cindy who has a son that's dead is one very small proof. It's not just a person's
41:51 life and their breath that's gone. It's their time on earth that sucked from them,
41:56 from these corporations. Whether they're slumming around pornography or they're
42:03 slumming around video games that are taking the youth. Or we're allowing AI to
42:10 be able to replicate and take not just from the next generation, the
42:16 grandparents, our parents, our children. This is our responsibility. In Hawaii,
42:23 it's our kuleana. It's our time. And I look at what Chris and Phil and Sam and
42:31 Tim, these people have dedicated decades of their life. I too, 19 years, $28
42:41 million of my own hard-earned money into this technology for the state, for the
42:49 countries, other countries, for no price. Would you really adopt it? Would you
42:57 really look at it? Because if you do it here and you can do 10% of what we're
43:03 talking about, other states will get on board with it. If you give it back to the
43:07 individuals and truly let them own their own identity, their own data, their own
43:12 payments, their own assets, and pass it to the next generation, instead of the state
43:17 sucking out hundreds of millions of dollars of unclaimed assets because people
43:20 don't even know where they are. The technology is here today. It's not just in
43:28 some proprietary phone that's really open. It's not about a phone. Even though
43:33 Cindy's parents, Cindy's son, that's how they that's how he took his life. That's
43:39 how they stole him. As a parent of six kids, I want to be able to say, I did
43:45 everything that I could. So that my son that went to this university And when I
43:52 sat on the board of this university, when her son killed himself, was responsible
43:58 enough to say, you know what? Enough is enough. We got to stop the games. We got
44:03 to come together with the policy. We got to come together with the technology. And
44:09 we have to actually act. Charlie Kirk was killed 500 feet from here, 150 feet from
44:15 here. The action behind his choice network was all what it's about acting. It's about
44:21 doing. The technology's here. People have seen it. People can live it. They can
44:28 adopt it. You can download it. Utah life. Go to your app store, download it, log in.
44:34 It's simple. This isn't hypothetical. These are real systems that really
44:39 function better than Bitcoin, better than Ethereum, better than the banking system,
44:45 better than the current identity management systems. And I'm sorry, I want
44:50 to slow down and I want to just let the process take its process. And Chris, I
44:55 emphatically support everything that you're doing. But we don't have time. We
45:02 don't have another 10 years for another decade worth of kids to not only stick
45:07 bullets in their heads, but to stick bits in their heads that takes them away from
45:12 the life that they've been given. It steals their time. It steals their souls.
45:16 It steals their hearts. I'm sorry that this means so much to me. But I can see
45:26 the solution.
45:34 Thank you, Michael. And our timeline is that 10 years is data governance. Our time
45:40 on lists is as fast as we can. Senator Collin Moore said this on KUTV last week
45:47 and he said, we have to get it right. You know, we don't want to cause more harm,
45:50 but the time is as fast as we can get out there. So parents and individuals have the
45:55 tool. So that's our timeline and that's our commitment is we're trying to get it
45:58 out as fast as we can. Obviously, we have to follow the law, but we understand the
46:04 importance and that it's needed now. This is not something that we want regular
46:09 bureaucracy to just sit on. And I think that's why we're all here. This is not
46:14 normal bureaucracy. This is not a normal meeting. This is something different is
46:19 happening and this is going to get done right.
46:30 I'm not going to try to follow that, but my question is for those in the private
46:36 sector partners who are helping us, what can we do to help move this faster?
46:41 Understanding that we have to do it right, but how can we move faster? Tim, should we
46:49 go here?
46:58 I've been working in the space for over a decade now. It's like trying to push a
47:05 really heavy rock uphill really hard. A lot of failure. A lot of things we tried
47:10 in different ways that didn't work and then very optimistic about SEDI and what's
47:15 happening in the state level? I think the answer, I've always been a small
47:20 government guy. And the reality is that now that government is getting into the
47:28 digital identity space, it's several decades behind private industry and
47:33 private industry has turned the digital identity space into this just incredible
47:38 surveillance mechanism. But now government's getting into the digital
47:42 identity space. And government at the end you said has the monopoly on whatever it
47:50 decides to do. Government will dictate how much privacy or freedom or autonomy we
47:59 have or don't have in the digital realm is my prediction after all I've seen. So to
48:06 answer your question about how to finally solve this, I think Utah has to be
48:12 successful in getting other states and create momentum. I know that Utah has
48:18 deprioritized interoperability, which is really interesting when you look at Utah's
48:23 hierarchy of values for a lot of identity initiatives specifically, but technology
48:30 in general, the highest priority is interoperability. And so what gets
48:34 sacrificed is security and privacy. Specifically with the MDL standard, there
48:41 was a country that said we need to have phone home and they didn't call it that.
48:45 We need to have server retrieval and it was baked into the standard because a
48:48 country demanded it. Different culture. It's not our culture. Someone else's
48:52 culture demanded it. It got baked in. A bunch of us squawked about this a couple
48:57 few months ago and they have now separated it thankfully. But the point is that was
49:02 made earlier.
49:06 We as Utah need to do what's best for Utahns if even if it means that we're not
49:11 interoperable with the rest of the world. We have to deprioritize interoperability
49:15 and do what's best for the privacy and security of our citizens. And so what I
49:20 think is the answer to your question is to get Utah to be more than just Utah that's
49:24 doing this, to get some representatives from other states who are here to actually
49:29 move forward and join. It reminds me of the end of the movie, A Bug's Life, where
49:34 the grasshoppers were were bullying the ants through the whole movie. And finally,
49:39 at the very end, the ants realize they're more powerful if they lock arms. I, I,
49:44 this digital identity community thing is so big and I see grasshoppers everywhere
49:49 who are the bullies in digital identity and I think the only way we do it is
49:54 Utah's an ant and we need to lock lock arms with other ants and scare the
49:59 grasshoppers out of this space.
50:08 My name is Jeremy Furster from Cardano Foundation in Veridian and I'm going to
50:13 say that I'm in the technologist camp or stakeholder group. And normally when
50:18 speaking to policymakers, there is a view from technologists that you're way off the
50:25 mark with what you're presenting as policy. However, that is not the case at
50:30 all when coming to SEDI. And I think the engagement that you receive and the
50:38 interest that you're receiving, the reason why it's so high is because fundamentally
50:43 the policy makes sense for the constituents. We've been able to
50:49 demonstrate with our demo that today SEDI is not just policy. It can be codified. It
50:56 can be implemented. And I would ask, do you see a path where you can eat your own
51:03 dog food? Because when you look to implement SEDI, you need that first user.
51:09 A very easy low-hanging fruit could be having a SEDI wallet to have a
51:15 passwordless login to a government website. And if you do something like
51:21 this, it's very low risk to actually get things started and have something put into
51:26 production that is end-to-end.
51:31 Well, I'm going to make a quick comment because I actually got some text. I get
51:34 texts every weekend, just you guys know from citizens that are like, I hate this.
51:38 What are you doing? And they actually sent a text and you may have been about to go
51:42 here where they're going to say, Hey, They were like, what is this Utah ID I now need
51:46 to use to log into a system? It's a just a single sign-on portal, which any it's any
51:50 single sign-on system is going to have tracking. It's a centralized. Yeah, it's a
51:54 username password type system. So there's low hanging fruit. And I think there's
51:58 discussions already happening. So we know constituents have identified the system.
52:02 They actually have said they want SEDI on. We have the man here in charge of it. So
52:08 we have a couple of initiatives that we're working on. And we have first of all, we
52:12 have our we have in a beta form our next version citizen portal which we branded
52:20 MyUtah and you'll probably see Governor Cox making an announcement about this
52:24 early next year. But the goal and we don't have this quite here yet. I'm looking at
52:29 but we'll be getting there where we hope to be able to have people authenticate
52:33 with a SEDI credential for that. And we don't quite have the SEDI credential yet
52:40 to do that, but we want it. And so that'll be one of our first and best use cases to
52:46 get that going. And we also want to look at state systems. So we have our 22,000
52:50 state employees and we have identity and access management that we log them into
52:54 our state system and we like to have a SEDI credential so that they can log in as
52:59 employees and we would like to move away from passwords even with our multifactor.
53:05 We don't love them. We'd like to move to a more secure SEDI type credential for login
53:10 and use in identity and access management systems across the state. hopefully
53:14 that'll be one place we can start to get rolling.
53:22 I'm Mark Allen. I'm with Citizen Portal, my brother today, Ancestry.com and we're
53:27 trying to work towards government transparency and accountability. And
53:31 Chris, you're spot on when you say that most of the state of Utah is not
53:35 compliant. I think our stats show about 15 % of public meetings are being recorded
53:41 gavel to gavel. I think some of the low -hanging fruit that I'd suggest for
53:46 authentication and certification would be within your own home of state government.
53:54 I have been branded a vexatious litigant as of last night, but the judge of Charlie
53:59 Kirk case because I asked for a court record. Let that sink in. I asked for a
54:06 WebEx video hearing.
54:11 I can't get anybody in the state of Utah to give me a certified record. When I'm
54:16 doing grammar, they say, oh, it's a duplicate request. I want state certified,
54:23 authenticated, genuine record that I can take to the bank and say, I'm innocent.
54:31 But when I ask for that, I get branded a vexatious litigant. So my admission
54:36 admonition as a state and county delegate is also with what we're doing is clean up
54:41 your own house first, not at your level, but at the clerk level where they won't
54:46 give me a certified record where the keyboard is the weapon of today. And I'm
54:51 the first victim probably in the state of Utah of lawfare. And, but if I had
54:57 everything that you've been talking about today, SETA, ability to authenticate,
55:02 ability to track back into the record to see who was the ghost that hit the
55:07 keyboard word to backdate a record by two years. I wouldn't be as smart as I am now,
55:15 but I've learned a lot in the last 10 years and I'd say Utah, let's get it right
55:19 first. Let's start in the judiciary where the problems are. And then my personal
55:25 identifying information, I can control and protect it, but mine's been scattered to
55:30 databases around the world. And I don't know how to undamage what that's been
55:36 done. We also have a problem with all three branches of government in Utah.
55:42 They're not watchdogging each other. There's not enough healthy friction. I'd
55:46 like to see a little more healthy friction between stuff. So, and this is not
55:49 specific SETI related. It really is civil rights, my personal protections. And I
55:58 don't need to go deeper down that because I really appreciate what you're trying to
56:01 do. If we would have had implemented what you did, what you're talking about 10
56:05 years ago, my life would be totally different. But I've seen how China
56:10 weaponizes and surveils. I've been surveilled in Utah, Provo, Utah. So court
56:18 certified records, definitions are really important. What's a certified record? What
56:23 does a certified record look like to you if I go down to the court and try and get
56:29 a digital copy or something that someone will go, oh, this is, we made a mistake.
56:36 How do we undo the mistake. So that's a personal use case scenario, but I think
56:42 our courts they don't on a standard basis do a transcript. You can't get a certified
56:48 record unless I pay for it. $2,500 for me to get a certified record. So I would
56:54 start within the court judiciary and start certifying records and start doing court
56:59 transcripts if it were me. That's low hanging fruit that would benefit most of
57:04 Utah. Thank you, Mark. We are All right. We're going to have one more question.
57:10 We're at time, but Jeremy Baker is a Utah privacy commissioner. If you don't know,
57:14 governance structure in Utah, we have a whole commission dedicated to privacy. So
57:18 take that back to your state if you don't have one. Go ahead, Jeremy. So I'm
57:22 actually going to take this from a different perspective, and this is from my
57:25 private sector experience with being someone that integrates security and
57:30 identity into software applications. And it's related to how do we get the private
57:36 sector to adopt this. A lot of private sector companies like even Roblox or
57:41 others, they end up using identity providers like AWS Cognito, Okta, Azure,
57:48 B2C. All of those they've added in different integrations for identities. So
57:54 you have like your social media logins that are allowed in there as well as like
57:58 the current adoption of passkeys, which has been really slow to roll out across
58:03 the entire private sector even though they're significantly better idea than
58:08 passwords and usernames. But to get SEDI adopted across all of them, I think the
58:16 framework like what we've talked about today having an open framework where those
58:20 major identity providers could bring that integration in as an authentication
58:25 service under the umbrella to have it as an option to add directly into
58:31 applications that are currently working with their products. I think that that
58:36 would be a significant push for adoption. – Thank you, Jeremy. Okay, we're going to
58:42 close up first by raising hands who wants to help get SEDI going forward. Okay. And
58:49 if it's not up, okay, everyone got it up. And that was the worst thing to do because
58:53 I am shameless. One of my tricks in government is I have no problem asking for
58:57 your time. So you will all be getting calls in your states to move this forward
59:02 and we'll be shameless together to take this national. We are so thankful that
59:07 everyone came today. I know this is a long day and this was a lot of information, but
59:12 you now are ready to actually have the in -depth discussions. So we will go back.
59:16 We'll do some of the grunt work to get organized. We'll set up and we'll make our
59:20 materials available. We'll reach out to the states to get at least one more
59:24 formally involved so we can get seDI.gov .going going at seDI.Utah.gov doesn't have
59:29 the same, you know, ring to it. We want seDI.gov. But we'll get rolling on that
59:34 and And we're going to meet back here again in less than six months for the next
59:38 SEDI summit. And from what we're already hearing, it's probably going to be twice
59:41 as big. And by that point, with the pace we're going, not only will we have more
59:46 legislation, but hopefully we have a lot more to share so other states can take it,
59:50 steal from our tax dollars and take it to your state so you don't have to pay for
59:53 it. And let's get SEDI rolling. So thank you everyone. Max Max Max Max Max Max Max
59:57 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:57 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:57 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:57 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:57 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:57 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:58 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:58 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:58 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:58 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max
59:58 Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Max Thank you.