Scott Perry

Afternoon Session · 10:07

0:01 There we go. Yay. All right. So my name is Scott Perry. I'm here to talk about open

0:08 standards and open protocols. And so when you're looking at a SEDI project, okay,

0:14 we're just getting started, but there's been effort to deal with decentralized

0:19 identity for the last 20 years, starting with Phil Windley co-chairing the Internet

0:27 Identity Workshop 20 years ago. And then for me, it's been 10 years after I got a

0:32 call from Timothy Ruff saying, I need help around trying to deal with internet trust.

0:39 And I realized as an auditor that was auditing certification authorities, I

0:43 realized that the traditional model wasn't going to work to add internet, to add the

0:49 kind of trust that we're trying to do with the SEDI project. So just a quick little

0:56 bit about me. I'm the auditor in the room. I was auditing for my career. Last 20

1:01 years, I've been auditing cryptography as a profession. Auditing small group folks

1:09 that audit certification authorities. I was the auditor for a certification

1:14 authority based in Utah. It's great to be back here. I was working with DigiSearch

1:20 for quite a long time. And I've also been leading some open source and open

1:26 standards projects. projects that are listed here, but I want to focus on the

1:32 acronym suit that I'm going to talk about because it's important for folks to

1:38 understand there has been a lot of work. There was a question around, is it going

1:43 to work today? I'd say two years ago, things hadn't been completely baked in,

1:48 but I think we're ready. The open source community is absolutely ready for SEDI and

1:53 I'm excited for them to demonstrate their value in all of the work that that they've

1:59 been doing for over 10 years. And so when we start about that, I'm going to give you

2:03 just a summary of some of the organizations that I've been touched with

2:08 that have been developing some unique products that can be leveraged into the

2:14 SEDI project. And it starts with the Linux Foundation. So I don't know if you know,

2:19 but the Linux Foundation is the largest repository of open source code in the

2:24 world. They operate 100% of all the supercomputers and 62.7 of servers run the

2:31 Linux kernel. And so they decided to get involved in decentralized trust. There was

2:39 a number of projects that was driving some of this type of thinking. And so they

2:46 established a subset of their organization last year and they invited and

2:53 consolidated a couple of open source and open standards projects. One that is

3:00 called the Trust over IP and I'd invite all of you to spend time going to the

3:05 Trust over IP. I am the co-chair of the steering committee. We have a couple of

3:09 steering committee members here in the audience and they've been doing enormous

3:14 work to get ready for the SEDI project. We've created a stack, a technology and a

3:21 governance stack. Everyone's talking about governance. Trust over IP is the leading

3:27 organization driving governance standards and methodologies and toolkits. And I hope

3:33 that the organization here, the SEDI projects uses it because it's been

3:37 successful in the C2PA, in GLEIF, in the government of Bhutan and such. It also is

3:44 housing KERI. You've heard some stories about KERI. It's a blueprint of how to

3:48 decentralize identity and make security more autonomous and user controlled. It's

3:54 exactly one of the main principles within the SEDI project. We have a trust spanning

4:01 protocol which acts underneath the internet protocol to the ability to

4:09 authenticate senders and payloads of transactions because we need that level of

4:15 trust in our transaction protocols and also it is leading around trust registries

4:21 which are public repositories of those that have passed certain governance

4:25 frameworks. The Open Wallet Foundation was founded in August 2023. It hosts

4:33 components that can be used to create secure, flexible, and portable wallets.

4:38 Where are we going to keep the SEDI credentials? We need a secure place

4:44 because they have private cryptographic keys. Also, we've talked about the W3C

4:52 started in 1994, produces two key standards that we can leverage within the

4:58 SEDI project. The decentralized identifiers, the DIDS projects, as well as

5:04 defining the components of verifiable credentials which we expect to use. In the

5:11 decentralized identity foundation started in 2017, we have a number of projects that

5:17 are working that can add value. They are the leading place to deal with all of the

5:23 decentralized identity methods that are out in the marketplace and they are

5:28 working to consolidate that. They're creating standards around the

5:32 communication using DIDCOM as well as the presentation exchange of credentials as

5:39 well as hosting an organization called the Creators Assertion Working Group which I

5:45 co-chair which deals with individual and organizational attribution to any digital

5:51 object based on the content credential created by the C2PA. So I would look that

5:58 up as well. Also the OpenID which has been around since 2007 and has modified their

6:04 standards to deal with verifiable credentials with OpenID Connect and OpenID

6:10 verifiable credentials. ISO as we have mentioned here has been instrumental in

6:17 creating foundational security standards both with quality and ISO 27001 for for

6:25 foundational security management systems as well as they have identity management

6:31 standard ISO 24760 and finally also the mobile driver's license the ISO 18018013.

6:43 We talked a little bit about what the role of the federal government would be. Well,

6:48 NIST is providing a lot of value there associated with dealing with post-quantum

6:54 cryptography. They're also dealing with the certification of hardware security

7:01 modules which protect your private key and are the leading standard for digital

7:06 identity guidelines both for proofing of identity, authentication, and federation.

7:14 So what's the case for open standards? How do you use it? Okay. At the end of the

7:18 day, it enhances interoperability and compatibility. accessibility. Okay? It

7:26 prevents the vendor lock-in so that all the tech vendors are using open standards

7:32 and they can use it so you're not locked into an individual technology company and

7:39 can't get out of them. It creates the innovation and collaboration. You're not

7:46 limited to an individual's company, R&D. You're leveraging world R&D. And that's

7:53 what the state of the organizations that I work for, they are creating that research

7:58 and development that we could leverage. It increases flexibility and Joe Jackson to

8:04 mention about future proofing. They're baking in advances of these standards to

8:11 deal with new technologies as they come along and they're free. State loves free,

8:18 right? And the best way to leverage it is steal. this technology and steal these

8:24 standards because it's there for the taking and they work. So I'm going to just

8:30 walk through I'm not going to go into details of some of the products that we've

8:33 created in the open standards world but these are the some of the ones as a

8:38 governance you know professional have leveraged on and you know we've realized

8:44 there was a trust you know triangle with the issuer holder and verifier trust over

8:50 IP added a governance model and we have found that that's the missing, that's the

8:55 secret sauce into making it long-lasting and workable. This, I'm not going to go

9:01 into the detail, but this is the trust over IP trust stack. And you can see that

9:08 there's been a lot of work that's gone into it. And Chris Ramel said to me, if

9:12 you do one thing, let people know how complicated it is. And we've done a lot of

9:17 the baked in work. So governance framework, it's already built. the

9:21 framework's work. You don't have to worry about it. You just have to put in your

9:25 requirements into the governance framework and then you could leverage the time and

9:29 energy to get this to market. So I'm going to quickly go through the reasons why you

9:35 should adopt open standards.

9:41 It's all there and I think we're ready to go and I think you could take advantage of

9:46 a lot of the work that's been done to make this happen. If you want to have an idea

9:51 of a white paper that's free to use on how to use governance and use trust

9:56 registries. I put it out there. It'll be in the videotape so that you could access

10:02 this at your leisure. Thank you very much for your time.