Timothy Ruff

Afternoon Session · 18:00

0:03 I would like to recognize two individuals if they are here. Scott Stornetta, are you

0:10 here? Been walking around. Is he in the room? Samuel Smith. He took off. I was

0:22 hoping to, I want to acknowledge two people whom I think are fathers of modern

0:30 digital trust. And I'll just say that Scott Stornetta was cited by Satoshi

0:37 Nakamoto's Bitcoin paper. He's the original conceiver of blockchain, which is

0:44 a really important innovation in digital trust. We wouldn't have cryptocurrency

0:48 without that innovation. And literally the creator of blockchain quoted Scott

0:52 Stornetta, who's been here today. He's out in the hall or somewhere. And then Sam had

0:56 to leave. Sam is the creator of the KERI protocol key event receipt infrastructure

1:00 that has inspired the SEDI identity model including the very exciting thing I get to

1:07 talk about which is guardianship and delegation. A really big breakthrough in

1:12 digital trust to solve a very thorny problem. Now I'm going to break from how I

1:16 usually present things and I am going to I'm

1:22 going to really almost read the slides which I hate to do that but I know this is

1:28 being videoed And I know these presentations are going to be asked for.

1:31 And I want anyone who gets this presentation at a later time to be able to

1:34 understand every single point. And so you're going to see me, you know,

1:39 basically reading some of this, but we're going to go quickly. Really important

1:43 concept. First of all, a couple of definitions. Guardianship gives someone

1:48 legal authority and responsibility to make decisions for another, like a child or a

1:54 disabled person. So real key concepts underlying there legal authority and

2:01 responsibility. Two different really important concepts that make up

2:06 guardianship. Delegation, I want to wait for my example to come up. There's a

2:14 little bit of a lag here. Temporarily transfers specific duties or powers but

2:19 not full legal responsibility. Key concepts are temporarily and specific

2:25 duties or powers and not full legal responsibility. That's the difference

2:31 between guardianship and delegation. So let's give an example. If a parent

2:35 delegates school pickup to a neighbor, the parent still holds the ultimate

2:40 responsibility for the child's welfare. Okay, that's just a task that has been

2:46 delegated, but not ultimate responsibility or legal authority. Guardianship legally

2:51 transfers that responsibility. The guardian and not the parent is now the one

2:56 accountable for decisions and care. So those are the two conceptual differences.

3:02 Now I'm going to share with you 10 tools that we use in combination to make

3:08 guardianship and delegation work as well as all of the rest of the SEDI protocol. I

3:14 chose Lego here instead of a toolbox. The difference is when you put Legos together,

3:21 you might make a pirate ship. You might make a pirate, you might make spaceship,

3:26 you might make a dinosaur. You put them together in different combinations to do

3:29 the thing you're trying to do. A toolbox, you get out of the toolbox and you do

3:33 something to use the tools and then you're done. So with SEDI, it's very much the

3:38 Legos, even though they are tools. The first tool is verifiable containers. Now,

3:44 for those of you familiar with verifiable credentials, we're talking about the same

3:47 concept, but a verifiable credential is misnamed. It is a container that holds

3:53 data and makes it portable. It might or might not be a credential. It can have

3:56 anything inside the container. It's the container that's verifiable technically.

4:00 So it makes data portable and verifiable. The next tool is secure attribution to

4:05 verify who digitally signed a thing. So if you get a container that has some data in

4:09 it, who put that container together? Who did it? And being able to secure part is

4:18 really important. Verify who did it. The third tool, non-reputability. You can't

4:25 later say that you didn't. once it's been signed, it is non-reputable. You can't

4:32 later say someone else did that. So when you have encryption with TLS or HTTPS, you

4:39 see the encryption that happens on the internet. There is repudiability. You

4:43 don't know who is on the other side of it. It's not bound to a human person or an

4:48 individual. It's just there's a weak form of authentication that goes with

4:54 encryption, but it's not like a digital signature that you can actually bind to an

4:59 individual and say who did the thing. Chain signatures which give you verifiable

5:04 provenance so you can actually see a chain of authority rather than just a single

5:09 level. So if someone signs something like a manager, well, who was their boss?

5:15 Where'd they get their authority from? Who was their boss? Who did they work for? And

5:19 is that really the company? How do we know that was really the company? And on you

5:23 can see a full chain and it's unlimited. A full chain of provenance on there is

5:27 another really important tool. And then weighted multisig critical for business

5:31 and on a whole lot of other cases we're going to talk about here in a moment. But

5:35 weighted multisig means that you can have one of two signatures. You can have one of

5:41 one, just one person signs it and they have the full weight. You could have one

5:45 of two, two of three, five of seven, 11 of 92, whatever you make up. Okay. So it's

5:50 weighted because you can have one signature have more weight than another.

5:55 and in a situation with divorced parents and things like that and where the court

6:00 might be intervening, really important in guardianship to have weighted multisig.

6:05 We'll talk a little bit about that. Consent. The ability to use your identity

6:11 to make a non-reputable agreement and say, I agree to a thing. Delegation of

6:18 authority, which we're going to talk about in a little greater detail. Revocability

6:21 of that delegation. And critically, a really important breakthrough with SEDI,

6:28 privacy respecting delegation. I was just talking to a representative from another

6:32 state who said that the reason that they were adopting a very popular technology

6:38 for identity is because their technical people thought that there was no way to

6:42 get around a phone home for revocation. That is not true. There is a way to get

6:49 around a phone home and have privacy respecting revocation. Really important

6:54 breakthrough in digital trust in one of the tools in SEDI. Graduated disclosure

6:58 which can be selective contractual. Basically you can disclose as little as

7:04 you want to disclose when you're doing something and there's actually a way to

7:08 only disclose that thing once terms for disclosure have been agreed to and

7:12 consented to and that can happen behind the scenes with agentic AI and these

7:17 agreements can be made and you actually don't disclose a thing until the terms

7:19 have been agreed and it's mutual. It's like a real-time NDA. done digitally.

7:26 Really exciting capability and detection and recovery from compromise. As a matter

7:31 of fact, SEDI brings a four-step concept I'm very excited about from a security

7:36 standpoint. SEDI expects compromise, then it can detect compromise, then it can

7:43 contain compromise and recover. These are mind-bendingly awesome in digital trust.

7:51 Expect, detect, contain, recover. Secure attribution, really important in Utah law,

7:59 an electronic signature can be as legally valid as handwritten with some

8:02 assumptions. There's got to be an intent to sign. There's got to be attribution,

8:08 which is where SEDI comes in and really helps consent to electronic transaction,

8:12 which interestingly, there's going to be a dilemma, a legal one. Can you use digital

8:17 means to agree to use digital means?

8:22 That's going to be a fun one. And then no legal exclusion. Sometimes there's a legal

8:27 exclusion that says you cannot use digital. You must have paper. SEDI can use

8:32 its own tools to prove each of these. Doesn't mean that we legally want it to.

8:37 There's going to be some policy debates, but it does mean that SEDI can use the

8:41 tools to do these things. So guardianship, examples of guardianship, parent of a

8:45 child, the natural guardian, guardian of a disabled adult, guardian for an orphan,

8:49 orphan, which is court appointed or temporary guardianship like when parents

8:54 are traveling. Guardianship is the missing piece of government digital identity. You

8:59 don't see it anywhere. You don't see it talked about. I think it is the cherry on

9:05 the Sunday when you're doing a digital identity system if you're government. If

9:09 you're not government, you don't care as much. But when you are government, you

9:12 absolutely are the dog wagged by the tail of dependent populations. So these are the

9:18 children children, infants, elderly, disabled, homeless, right? There's

9:23 advocates for all of those and they're loud and they're powerful and they should

9:27 be. And so to be able to have guardianship and digital guardianship that actually

9:33 brings those dependent populations into the digital realm, really important stuff.

9:39 And if there's one takeaway from any representatives of other states that are

9:42 looking at SEDI, there's some privacy and autonomy reasons for looking at SEDI.

9:48 There's some security reasons for looking at SEDI. But I think the number one reason

9:52 why a state would look at SEDI is because of digital guardianship. Because it

9:58 includes everybody. All the different dependent populations you want to include.

10:01 No government system has figured this out. Few of them are even talking about it.

10:07 Only 25% of US 16 year olds get a driver's license. Only 50% of 20 year olds have

10:14 driver's licenses. But yet 100% of 15teen -year-olds need identity.

10:23 SETI solves a big technical challenge, decentralized digital guardianship that's

10:27 peer-to-peer with no phone home and no dependence on any vendor network or

10:31 blockchain. That's a really important thing. You know what's easy to do

10:36 technically? To prove a guardian relationship, if you phone home to a

10:40 server and the server says, oh yeah, that's the parent of the child, we're

10:43 good. And you're phoning home to the server. That's easy technically to do. You

10:48 know it's extremely hard that requires the breakthroughs enabled by Sam Smith, who I

10:53 mentioned earlier, is to be able to verify that guardian relationship in a

10:58 decentralized manner where you're not phoning home. Offline, using Bluetooth

11:04 peer-to-peer, major breakthrough in digital trust. Now, you know, I gave these

11:10 guys some kudos at the beginning. SEDI can mimic any form of guardianship. A guardian

11:15 can prove that the guardian award can prove who their guardian is and verifiers

11:20 can follow guardian requirements for award authorization. So what I mean by that is

11:26 Johnny requests to spend 35 bucks on Fortnite and his mother is prompted for

11:31 approval. It's a simple example of how a verifier can follow guardian requirements

11:38 for award authorization. Guardianship however gets very tricky. A single

11:45 guardian is very simple. It's one-to-one. A single parent actually is the simplest

11:49 use case. A single parent just they're the only one who makes the decision, right? It

11:55 gets trickier when there's two parents. When they're married, it's still trickier

11:58 than a single single because you can say the parents either one of them can say

12:03 Johnny can do it. You can say both of them have to approve before Johnny can do it.

12:09 You can say up to a certain dollar amount either parent can do it, but if it exceeds

12:14 another dollar amount, then both parents need to be able to do it. and that's what

12:19 I call graduated. So you can have conditions in there and things like that

12:23 for that approval. It gets even trickier with divorced parents where you have a two

12:29 -to-one relationship with Johnny, potentially a three-to-one relationship if

12:32 the court is involved, which they might be for some things that Johnny might want to

12:37 do. And there's waiting. So you can give more weight to the court. You can give

12:42 more weight to one parent. You can give weight to a grandparent. You can do

12:46 whatever you want. It's called weighted M of N multi-sig and so you can divide that

12:51 authority however you choose. And adults show children of a disabled parent. So

12:58 I've got a mother who's 89 and she's starting to forget some things and she's

13:02 got a lot of living adult children. And there's some of these adult children who

13:07 should probably not have a say in what happens with mom. It's an opinion, but at

13:12 some point that might have to be adjudicated. And someone might have to

13:16 say, well, when push comes to sub, the kids are not agreeing. How is that

13:20 adjudicated? And however that is, if the conclusion is that a certain subset of

13:26 children have authority and maybe one has more than the others, that can be modeled

13:31 with MFN weighted multisig, which is part of KERI, part of SEDI. How about homeless

13:36 people unable to carry credentials? Well, what are you doing there to bring that

13:42 homeless person in the digital realm if they're unable to carry credentials? How

13:46 does work in real life. We try to mimic what happens in real life and that is

13:49 there's a government agency that actually holds some credentials or has the ability

13:54 to do something on behalf of that homeless person. Very tricky situations. And I'm

14:01 going a little bit slower than I want so I'm going to go a lot faster. Delegation.

14:04 A parent signs a permission slip that authorizes another adult child to pick up

14:08 their child or a manager delegates a task or an individual delegates to an AI agent.

14:15 We talk about AI and agentic AI. That is a form of delegation. Delegation is

14:21 absolutely everywhere. A legislature can delegate to committees and agencies who

14:25 then delegate to departments and outside companies who delegate multiple levels of

14:29 employees who provide a service to a citizen. So delegation is absolutely

14:35 everywhere. All organizations, private or public or are hierarchies of delegation.

14:41 SEDI enables an individual to directly delegate authority to another without

14:45 involving anyone else. else. The individual, the authority can go directly

14:49 to the delegate and give them that authority. With SEDI anyone anywhere can

14:55 verify the claimed authority without phoning home. We talked about that earlier

14:58 decentralization. SEDI can mimic any form of delegation. A delegator can prove what

15:04 and to whom they've delegated. A delegate can prove what's delegated and from whom.

15:09 And by the way, the word delegate a little bit awkward because in some cases a noun,

15:13 in some cases a verb. Okay, so I'm I'm using the form delegate here in number

15:18 two. A delegate noun can prove what's delegated verb and from home. Delegation

15:24 can expire or be revoked. A delegate can delegate again with proof of authority to

15:30 do so. Delegations are non-reputable which means they can't be denied later.

15:36 Delegations can form hierarchies or chains. They're auditable, traceable. They

15:40 cannot be forged. They're resilient to key rotation. And rules and restrictions can

15:44 be made verifiable, machine readable, and enforceable. Sounds like a dream list. It

15:49 is. Now you know why we're excited. Agentic future, by the way, I have to

15:53 laugh at this picture of grandma being helped by a robot. And no, that wasn't

15:57 made by AI. And no, I didn't take that photo. But Microsoft CEO said this and I'm

16:05 paraphrasing because this quote is too long, but the the paraphrase of the

16:09 Microsoft CEO, AI agents will replace all software as a service, SaaS. class. CEO of

16:17 Microsoft. And the reason he says that is because of frankly what I think is

16:25 illustrated by grandma. It's a user experience. Most agentic tasks are simple

16:30 and don't require delegation, but some important ones do. And they require some

16:35 delegation, some authority on behalf of the agent. And I think one of the greatest

16:40 use cases, I keep it in the wrong button and gets rid of them. I think one of the

16:44 greatest use cases for agentic AI is user experience for elderly people. I know my

16:51 mom could talk to an agent and ask her to do something. She struggles to open her

16:55 phone and start an app to play Scrabble with her daughter in Pennsylvania. But I

17:00 know she could talk to an agent and say, please open the Scrabble game or please do

17:05 something. I think the future of AI for elderly people is really, really bright.

17:10 And I want that agent's authority to do something on behalf of my mom, carefully

17:16 constrained.

17:21 SEDI is ideal for delegating to agentic AI. So in conclusion, SEDI brings

17:26 guardianship and delegation into verifiable digital form, harmonizing law

17:31 and technology. SEDI includes everyone through digital guardianship. Parents,

17:36 caregivers, and courts can securely represent those who cannot self-manage

17:40 their identity. Through SEDI, delegation individuals can safely empower others or

17:46 AI agents with limited revocable authority. SETI actualizes both human and

17:52 legal rights and principles and is designed for the coming agentic AI era.

17:56 Thank you.