1 of 20

Hardware Secured Verifiable Credentials

W3C WebAuthn + Verifiable Credentials + Decentralized Identifiers

1

2 of 20

2

3 of 20

WebAuthn

Registration

  1. Website Request Registration
  2. User Approve Registration
  3. Generate Cryptographic Key
  4. Registration Complete

Note: One cryptographic key per site

3

4 of 20

WebAuthn

Login

  1. User Click Login
  2. Website Request Digital Signature
  3. User Approve Digital Signature
  4. User Provide Digital Signature

4

5 of 20

5

6 of 20

Verifiable Credential Request

Step 1

Step 2

Step 3

Website requests Verifiable Credentials

Individual selects Verifiable Credentials to transmit

Individual transmits Verifiable Credentials

6

7 of 20

Verifiable Credentials Ecosystem

7

Issuer

(Website)

Government, Employer, etc.

Verifier

(Website)

Company, Bank, etc.

Holder

(Digital Wallet /

Personal Data Store)

Citizen, Employee, etc.

Issue Credentials

Send

Presentation

(bundle of credentials)

How do we secure this with hardware-backed cryptography?

8 of 20

WebAuthn + DIDs + Verifiable Credentials

8

9 of 20

DIDs Resolve to DID Documents

9

{� "@context": "https://w3id.org/veres-one/v1",� "id": "did:v1:nym:DwkYwcoyUXHNkpj3whn4DgXB4fcg9gj95vKxYN2apkZD",� "authentication": [{� "type": "Ed25519SignatureAuthentication2018",� "publicKey": [{� "id": "did:v1:test:nym:DwkYwcoyUXHNkpj3whn4DgXB4fcg9gj95vKxYN2apkZD#authn-key-1",� "type": "Ed25519VerificationKey2018",� "controller": "did:v1:nym:DwkYwcoyUXHNkpj3whn4DgXB4fcg9gj95vKxYN2apkZD",� "publicKeyBase58": "DwkYwcoyUXHNkpj3whn4DgXB4fcg9gj95vKxYN2apkZD"� }]� }],� "service": [{� "type": "ExampleMessagingService2018",� "serviceEndpoint": ”https://example.com/services/messages”� }],� … more DID-specific information here …

}

1. Authentication Mechanisms

2. Public Key Material

10 of 20

DEMO

10

11 of 20

Next Steps

11

  1. In Depth Privacy and Security Analysis
  2. WebAuthn support in IFRAME Elements

12 of 20

CCG Roadmap for�Decentralized Identity

JOE ANDRIEU – LEGENDARY REQUIREMENTS

TPAC 2018

13 of 20

Identity

  • How we
    • Recognize,
    • Remember, and
    • Respond to
  • specific people and things

14 of 20

Digital Identity

  • Tool for managing real-world identity

15 of 20

Decentralized Identity

  • Digital identity architecture
  • Administratively independent of any single authority

16 of 20

Current W3C Standards Efforts

  • Verifiable Credentials
    • Anyone can verifiably say� anything about anyone
  • DIDs
    • Anyone can publicly manage � provable identifiers �without administrative interference

17 of 20

VCs + DIDs

  • Move beyond centrally administered IDs
  • Provide for a plurality of authorities
  • Identity emerges from evaluating
    • multiple sources of information,
    • across multiple interactions

18 of 20

Decentralized Identity Stack

  • Services – Interactions of value
  • Understanding – Internal knowledge representation
  • Reasoning – Interpretation & Analysis
  • Consent – Records of authorization
  • Profiles / Presentations / Persona – Representations of individuals
  • Verifiable Credentials – Assertions by knowable authorities
  • Raw Data – Observed facts & transactions
  • DID Documents – Proof of Control & Service References
  • DIDs – Root Identifiers

19 of 20

Potential Future Standards Work

  • DID-Auth (Authn/Authz)
  • OCAP (Authz through Object Capabilities)
  • Credential Requests
  • Consent
  • Storage & Internal Representations
  • Analytics & Algorithms for Evaluation
  • Cryptographic Suites

20 of 20

Thanks

  • Joe Andrieu
  • Co-Chair Credentials Community Group
  • Legendary Requirements
  • joe@legreq.com