Wayne Chang

Morning Session · 22:34

0:04 Thanks so much, Joe. Really grateful for the opportunity to be here and talk more

0:07 about the different approaches, especially in the context of how do we start with

0:12 individual rights, think about the policy before we rush to the technology, right?

0:17 Because there's an implicit social contract, right? That is the use of these

0:22 digital identity systems. And it is much better for that to be an explicit one

0:26 rather than one that is the most convenient or imposed or anything else.

0:29 else, right? So I think we're all here for the same thing. And being able to move

0:33 towards that, I have a pretty nerdy quote actually that I want to start with from a

0:38 fantasy novel by Brandon Sanderson. Then be wise about it. There are two kinds of

0:43 important people, Shallan. Some, when the boulder of time rolls towards them, plant

0:48 themselves before it and throughout their hands. All their lives they've been told

0:51 how great they are. They assume the world itself will bend to their whims as a

0:55 caregiver once did when fetching a fresh cup of milk. Those people end up squished.

1:00 Others step to the side as the boulder passes, but are quick to say, see what I

1:05 did? I made it roll there. Don't make me do it again. These are the ones who get

1:10 everyone else squished. Is there not a third type of person? There is, but they

1:15 are rare. These know they can't stop the boulder. They walk beside it, study it,

1:21 and bide their time. Then they nudge it ever so slightly to bend its path. These

1:27 are the ones who actually changed the world, and they terrify me for people

1:31 never see as far as they think they do. And I think the wisdom in that is it takes

1:36 a diversity of thought approaches and use cases and opinions to actually consider

1:41 all the different facets of this. It's an enormously complex and ambitious

1:45 undertaking to build digital identity in a way that minimizes the harms, but we're

1:50 able to derive most of the benefits. So I'm really happy that we're in a room with

1:56 a ton of diverse thinkers from people who are experts on individual rights, what

2:01 constituents care about, what people actually feel, the technology itself,

2:05 including the cryptography, security and privacy aspects of it, adoption, change

2:10 management and user experience. So I think that we're very excited to show how these

2:16 concepts from SEDI where you start with the policy and the rights and then the

2:22 technology is figured out after that. That's really what we want to showcase and

2:26 how it can help our existing investments we can derive value from those. And

2:32 especially as we saw with the adoption, MDL is in I think 17 states at this point.

2:40 A lot of investment, a lot of great security people have been thinking about

2:43 that model. The TSA spent over $250 million on machines that can accept the

2:48 MDL. So is that all to waste if it doesn't comply? Or what are we thinking about

2:54 here? What about everything else? And fortunately, you might even be able to

2:59 shed some more light on this. Yeah. Thanks, Soren. And thanks for taking all

3:02 our five minutes. But it's been actually an honor to work with Utah. Excellent

3:12 team, excellent people. It has been a fantastic experience and we're really

3:17 happy, of course, with all the work that they perform and we had the honor to

3:21 support them to have a successful MDL issued and being used and utilized in many

3:28 not enough use cases and relying parties including TSA and credit unions and law

3:35 enforcement. But we're happy to be also part of this group that Chris put together

3:41 to assist the best we can with our experience and knowledge and technology to

3:47 make whatever next steps Utah chooses to take successful. So it's amazing. So what

3:57 are we seeing over there? That's a verifier. A verifier is something a

4:03 relying party would have. A relying party being anything, anyone that accepts and

4:09 consumes a digital identity and MDL. And that can be a government agency that asks

4:17 for your ID. It can be law enforcement. It can be anyone in the private sector. It

4:21 could be a bank, could be AIDS restricted alcohol sales, tobacco, and so on.

4:27 Whenever they ask for that ID card of your driver's license, you can present the MDL

4:34 or at least that is the purpose and you can use verifiers as simple as an app or

4:41 in a fixed point with a scanner or eventually online. All that technology

4:47 exists and hopefully it's going to be part of the ecosystem we all operate in. Can

4:52 you talk about what's going to happen between this SEDI wallet and And what kind

4:57 of, you know, how is the data transmitted? What happens between this application

5:03 running on your phone and an application that holds a credential on my phone? Well,

5:08 yeah, originally the ISO standard, which is what the Utah MDL is complying to,

5:14 along with our close to 20 other jurisdictions that issue an MDL that

5:18 complies to the ISO 18013-5, which is the in-person standard. it had a phone home,

5:29 it had a connection to the system on record that is no longer the case. And

5:34 similarly, any verification we would conduct with a SEDI, it will only consume

5:40 whatever you have on the phone and you present. – And it goes, this could work in

5:45 the mountains, right? If there's no internet or anything. – Correct. It will

5:49 be done offline because again, it will cryptographically analyze whatever you

5:56 have provisioned in your phone as your digital identity. I always really like

6:01 this part where it goes over Bluetooth and NFC proximity technologies that involve no

6:07 servers, right? It's just peer-to-peer over device. That's actually the best

6:11 privacy profile you could hope for, right? So there are parts that have had

6:15 extraordinary investments that are really valuable from a privacy and usability

6:19 perspective. And what we see in that wallet is not an MDL. There's no driving

6:24 privileges there. It is a credential that is solely focused on identification,

6:29 right? And that the reason that it is a SEDI credential is that it conforms to the

6:37 code in SEDI, right? Is the idea. So if we start looking over here, I told you it

6:43 would be a nerdy presentation, right? We looked in the Utah code, right? And there

6:48 is SEDI enshrined in it as statutes. And when you click in, you're able to see the

6:54 different definitions, and requirement from Senate Bill 260 that was signed into

6:58 law by Governor Cox earlier this spring. And thank you to representative and

7:03 senator for the work and the whole coalition. So it's really about controls.

7:09 It's really about these are the things we're expecting this credential to do and

7:13 operate, right? That's what it represents. So data formats, everything else, those

7:19 are things to figure out, but making it policy-based and starting it from there is

7:25 the most important part because that is the social contract, right? To express the

7:29 will of a people and have those as the agreed upon controls if someone is to

7:33 participate in the system. So we just want to demonstrate that this model, right, can

7:39 also work with the corpus of investment for existing systems that have been

7:43 significant and growing in adoption. So we have looked into the mobile driver's

7:48 license technical specification. Sure. We have looked at the sub component called a

7:53 mobile document or an MDOT. And that is just a data format. That doesn't describe

7:58 how to use it or anything else. And there are other pieces that we can build up to

8:02 that we can agree with and are aligned to the SEDI framework. So that is the idea

8:07 and what you're going to see with this demonstration. – And similar, of course,

8:11 any digital identity, the benefits are you're not using your card, you don't

8:15 share your card, you don't show any information, it's not copied, you don't

8:19 flash past so-called whatever it is on the phone. and it respects the privacy of the

8:26 user and you only share what you choose. So if you want just your age to enter a

8:34 bar or alcohol sales, that's that is all you share, not the entire ID. Unless of

8:40 course you're at a bank or you're applying for a loan or law enforcement is asking

8:44 for the entire ID, that is when you share if you choose the entire information.

8:51 That's right. And the MDOC data format here point supports selective disclosure

8:54 as part of that base. We like that. We're like, okay, that sounds pretty good. Let's

8:58 take that part. Right. So we're going to demonstrate and there's no contact. You

9:02 can do it's a QR barcode scanning. It is via Bluetooth through a good range or a

9:11 tap NFC just like as everyone is familiar with the Apple pay and so on. Yep. So

9:17 let's say that we're in a use case where let's call it law enforcement. Let's say

9:22 there is warranted ability to request information, right? So there's going to be

9:27 a lot of it being requested. – So you can see there it says all info. So I'm asking

9:31 for all of the information from the user. – But this can be tailored to different

9:37 profiles depending on the context. And that's the really important policy work we

9:40 need help with to figure out. So I'm going to share the identity by creating a QR

9:50 code. You can either tap or create a QR code to share it. What it does is it

9:54 brokers a secure connection over Bluetooth. So it adds encryption on top of

9:58 Bluetooth because Bluetooth itself has challenges. That's how the MDL protocol

10:02 worked. That part of the MDOC and standard seemed to be pretty promising. And we were

10:08 able to show a QR code. So we're bringing up the scanner. No contact.

10:17 And actually it's going to consume. I get to decide what I share or not over here on

10:26 this screen. Those are the fields requested. As the user, I get to make the

10:29 determination. That's another feature of the protocol that was supported. And when

10:33 I press approve, it's transmitted over basically the Bluetooth connection peer-to

10:40 -peer. So this would work in the mountains without any kind of external connectivity,

10:44 right? And again, this is being used at a ton of airports already, right? So we're

10:49 just able to make sure that that part of the technology can also work for SEDI

10:52 credentials. – So you can see that I'm seeing the information that he shared. I

11:00 can bring up the picture, do one last visual check if I wish. And it has the

11:07 document information. So I know it's from Utah, the document number and that's about

11:12 it. Yeah. – As simple as that. Plus, of course, I have the verification on the age

11:18 verification. – Yeah. Well, let's say I'm I'm at a bar right at night and I want to

11:23 show I'm over 21 but kind of don't want you to know my full name and where I live,

11:27 my address, right? How do we do that? – So, I will just the one that is asking for

11:34 the information can can ask only for the age. So, unlike of what you choose, I can

11:42 only ask for the age and whatever you share, I will only get the age. And of

11:48 course, as you saw, once my hey, I leave that verified information I had is gone.

11:56 It's not saved. It's not tracked. None of that. And you cannot get a screenshot.

12:01 Yeah. So the policy consideration here is that there are many different attributes

12:05 that you could add to this thing and ask for, right? So those are the really

12:09 important decisions to be made. Can we add veteran status, disability rating? Can we

12:14 add how many dependents you have? These are all really relevant for programs like

12:18 Wix and others that that require expedient access, but we also want to eliminate the

12:23 fraud, right? So, and because it's the user consenting to display the

12:27 information, you don't really have to go with one of these very complex interagency

12:32 data sharing agreements if we faithfully present an opportunity consent for people,

12:38 right? So, if it's tough to do across agencies and coordinate, just give it to

12:41 the person and let them decide, right? All right. So, I know your age. You're looking

12:47 too young to me. Thank you. Thank you.

12:58 Oh, is this the right one that you've requested? Did you configure it to just

13:02 select the age only? – Just the age only. – Well, see, now I have the opportunity to

13:06 deny all this stuff. – If you agree, I want to deny all this new age. Try again?

13:14 – Yeah. Yeah.

13:20 Yeah.

13:23 Because there is an option also to request I need find info or to project that one.

13:30 Right. Because that was on. Oh for age. Okay. Yeah. Okay. So now I can let him in.

13:37 So you turn on the safety.

13:42 Let's see. Age over 18. Got a different set of things requested. But you know

13:47 what? I'm really just going to get rid of all these things except my portrait and

13:51 age. And that's all you're going to get. And the Verify will have to deal with it.

13:58 So I think there is a setting where I've definitely seen that work with this app

14:01 though. – You want to try again? – Sure. – Let's give it an answer. Right.

14:12 And you say okay. So those are the only data fields that ever left the wallet,

14:21 right? During that specific interaction. So yeah. See us after will definitely show

14:27 that you can do an age demonstration. I think that I have a version of the GT

14:32 mobile app where I can just ask for the age of mine. But But you'll see other

14:36 profiles where we can get it. So great. We have two more things to show you really

14:43 quickly. And one of them has to do… – What's the floor? – Okay, great. – And

14:49 those I'm on setter by the way. – Yeah. – Okay. – Welcome. Thank you. All right. So

14:55 the other two use cases.

15:02 One is banking and it's very important for people to get access to financial

15:06 services. Many of the same methods are more or less used for benefits

15:12 distribution when you're trying to figure out eligibility and identity verification

15:15 for some of those things, right? So this is a generally useful flow. In fact, NIST

15:28 has this National Cybersecurity Center of Excellence, right? And we're trying to

15:33 figure out how are we going to do banking KYC? privacy with the mobile driver's

15:36 license. I see some folks in here who are actually formal participants in this

15:40 program. So that's great because a lot of federal agencies and other states are

15:44 going to look to the output of this program and how that's going to work.

15:56 There are a lot of banks, a lot of tech companies, a lot of other actors, and

16:00 basically we're trying to figure out how do we preserve privacy but also allow for

16:04 these kinds of use cases.

16:11 They're even talking about shapes that it's going to work. But right now it's

16:14 just called the MDL program. There's no reason why it needs to be. It could just

16:17 be digital identities, right? But that's kind of the only thing that popped up,

16:20 right? So to have a credential that has steady controls over it would be very

16:25 interesting, I think. But back to our banking example, and this is where a lot

16:31 of tech companies have invested a ton of effort. They're best UX people. their best

16:35 security folks. How do we make this really good? And the interface is mostly for the

16:42 MDL, but those technologists have agreed that, hey, other things might be

16:47 acceptable here. Passports, EIDs in Europe are not driver's licenses, right? So MDL

16:53 isn't so strongly applicable in some areas. So how do we allow a diversity of

16:58 different credential types to be accepted? And there have been great strides in the

17:03 user experience towards this. So we're going to basically open a fictitious bank

17:07 account.

17:11 And I'm also going to make sure that I can show you what happens in the wallet

17:17 alongside that if I can figure out how to make this small again. There we go. So

17:26 we're at Arch's bank. We're going to open an account. We're going to begin our

17:31 banking application. and type in our email. I'll just imagine that I get a

17:41 confirmation code. You've probably done this before. Go to your email, you find

17:43 the code, you put it in. Multi-factor. So right now it's a phone number, but you

17:48 know future approaches like pass keys and digital credentials will hopefully leave

17:52 the need for this. So put a phone number in there. Same deal. Again, many banking

17:58 systems just work like this today. And a social security number is required by

18:04 FinCEN's customer identification program. So that's a Bank Secrecy Act requirement.

18:08 So, you know, you'll just see it as a requirement for banks. But at this stage,

18:12 it's part of identity verification, right? And what a lot of institutions do today is

18:18 they say, hey, upload a picture of your driver's license or upload a picture of

18:23 utility bill. And none of those security features are actually valid when you just

18:28 take a picture of it, right? Like that's the new world of security needs to be

18:32 built on things that AI is bad at. That's showing up in person. That's breaking

18:36 cryptography, especially post-quantum cryptography. That's making very complex

18:41 computational predictions about physics and how light refracts on things or how

18:46 you know something can change geometrically. And that's what a lot of

18:51 the liveness algorithms are about. But it all starts with having a really strongly

18:56 certified credential. And when you want to verify with it, then it uses the operating

19:03 system level controls to say, hey, do you want to share your data? It's built on the

19:08 same technologies as passkeys, actually, if you look under the hood. We want to

19:12 share it. QR code comes up. We see on the wallet. I'll scan it. You won't be able to

19:17 see everything. I think there's some privacy protections with the screen share,

19:20 but you'll be able to see the important parts. So it tells me only connect to

19:25 devices you trust. And when I connect what happens, you'll see a lower popover. This

19:32 is kind of like the Apple Pay experience or the Google Pay experience. It's part of

19:37 the operating system and you get to pick which wallet it comes out of, right?

19:40 You've been requested a credential from somewhere. We're going to agree. And

19:44 again, we have that opportunity to consent what gets sent, right? If we send it, then

19:50 what happens is instantaneously a cryptographic payload is sent along with

19:54 the data fields and that can be verified by a server. So it goes to from the phone

19:59 to the laptop, goes from the laptop to the server, and then it gets verified way

20:05 easier and more secure than uploading all those different documents. You submit and

20:11 you're good to go. So getting easy access to financial services benefits a slew of

20:17 other things requires really good UX, but we can't compromise on individual rights.

20:22 We can't compromise on security as we get there, right? So let's take those existing

20:26 investments that companies put their best UX and security people on and apply it to

20:30 a framework that is individual rights driven, right? So that's the proposal for

20:35 ensuring backwards compatibility to a lot of these systems. A lot of the time you

20:38 think legacy old experience, but these are actually some really great experiences

20:42 happening, right? And the last thing I'll show is interoperability with a completely

20:47 different system. This is the same technology harness. Thank you for the

20:53 Veridian team for providing their issuance portal for this part of the demo. So

20:56 different company, not Spruce ID. It's not like one company built all this stuff.

21:00 These are interoperable protocols. And there's something called the Global Legal

21:05 Entity Identifier Foundation that is able to do identification for organizations to

21:10 a high degree of proofing so that we can know who we're doing business with if a

21:14 company wants to get a benefit or something else, right? So basically, I

21:19 want to have another credential on my phone where I can have that employee badge

21:25 or proof that I'm part of an organization Let's say I'm going to ask someone else

21:28 for a credential or I want to open a business banking account. These are useful

21:32 to understand what entity I'm associated with. What if you're part of LEO and you

21:36 want to show that you're a real cop and you're not trying to just coerce someone

21:40 to do something, right? So you can issue a credential for this. There's some numbers

21:46 as part of it. I'll put my name. We'll just say employee and we'll issue the

21:51 credential. And this is a totally different technology stack built on KERI

21:55 and ACDCs, which protocol and format invented right here in Utah. You get to

22:00 accept it and a new credential shows up as an official organization role. And then

22:06 when we want to go request it, we can request a presentation from that wallet.

22:12 The wallets have been linked prior. It's a demo. Request a presentation. We will see

22:21 the request happening and approving it. We'll see the request is updated, right?

22:27 And these are different data formats entirely, but following the same control

22:31 principles, right? So that's the end of my demo. Thank you.