I have control

Can we truly own our identity?

Digital identity is a complex subject; as with most digital transformations, taking a process that exists in an analogue world and digitising it for use online doesn’t create a great solution.  A number of models for digital identity exist, and are often spoken about in terms such as centralised, federated, distributed, user-centric, self-sovereign.  There are countless papers by the great and the good of the identity world that talk about the merits and flaws of the varying models.  There’s a school of thought that centralised is bad and self-sovereign is the panacea for digital identity – though often these ideas focus too much on the model and less about the use.  And the arguments are often mired in digitisation of analogue.

Self-sovereign digital identity is a model which:
  • Places the individual in absolute control of the digital representation of themselves 
  • Is based upon the kernel of self that exists in the real world
  • Assures the individual of access to all the data regarding them and provides transparency of how data flows
  • Persists for as long or as short as the individual decides
  • Assures portability and interoperability
  • Functions on explicit user consent
  • Operates sharing based on principles of data minimisation

These are all traits which it is hard to argue shouldn’t be the foundation of any digital identity model – never one to shy away from an argument, here goes:

Places the individual in absolute control of the digital representation of themselves 
Until such time as we plug in to the matrix, a digital identity and the flesh and bone which it represents cannot be linked with absolute certainty.   When the link between the two is, or is reasonably believed to be broken, control of the digital identity must be revoked (either permanently or temporarily).  This introduces a higher power of control over the individual’s identity.

Is based upon the kernel of self that exists in the real world
Identity in the real world is also complicated.  In the real world, our identities are often assigned by central authorities such as governments; or they’re guaranteed by 3rdparties such as our parents; or they’re accepted based upon assigned attributes such as name, address and date of birth; or they’re based upon our DNA.  And more often than not, they’re a combination of all of these.  If our digital identity is based upon our real-world identity it cannot be self-sovereign.

Assures the individual of access to all the data regarding them and provides transparency of how data flows
We should always strive towards openness and honesty.  Yet there are circumstances where we need to keep data hidden and circumstances where its beneficial for the user to do so.  As an example, the organisation who will rely on digital identity are often required to check for fraud and criminality against our identity.  This isn’t information that we should give to the user, yet it is often closely tied to their identity.  So commercially and practically it needs to flow with the identity assertion.  When we give information to an individual, we also have a duty of care not just when that data isn’t correct, yet also when that information risks disenfranchising the individual.  Credit scores used to be information passed from Agency to Supplier about the individual without their involvement.  This changed, and in the last 20 years, they have gone from information that we know, to information that we can actually manage.  Yet for many people, a poor credit score creates exclusion – which leads to disenfranchisement.  If digital identity is to be inclusive, the data that we give back to the individual needs to have the duty of care built in.  We should work towards openness, we shouldn’t dive straight into it without understanding the consequences.

Persists for as long or as short as the individual decides
For some nations, having a government issued identity card is mandatory, for others it is optional or simply doesn’t exist.  Rather than eulogising on which is right, digital identity needs to recognise all models do and will exist, and look to provide a digital identity model which supports mandatory and optional membership of government registers.  Similarly, fraud systems need to persist identity elements to protect from bad actors.  We can offer choice in how long our digital identity as a “thing” persists, on the data that makes it up we can’t.

Assures portability and interoperability
Data portability is a convenience factor that shouldn’t be wilfully restricted.  Identity portability is where the value and complexity lies.  In order to drive the market, the work done in proofing the identity and attribute claims can’t simply be ported from one party to another.  To do so risks separation of effort and reward, which disincentives the commercial efforts required to develop and maintain a functioning marketplace.

Interoperability can only be assured with mutual trust.  Mutual recognition is reliant on the creation and adoption of interoperable standards.  Interoperability of systems should only be required once interoperability of standards is achieved.  We shouldn’t expect that everything interoperates with everything else unless everything is equal.

Functions on explicit user consent
The notion that an individual can explicitly permission what data is shared by whom and with whom is reliant on goodwill that doesn’t exist.  If we are given the choice to share only positive information and withhold anything negative, this is going to be a common choice.  This will restrict the ability for the receiving organisation to rely on the data.  Hobson’s choice (take what’s on offer or nothing at all) isn’t explicit consent for data sharing either.  We should be far more honest with how we define consent, so that a user understands when we need broad consent to search for good and bad information about their identity and when we’re seeking explicit consent to only share attribute X from organisation Y with organisation Z.

Operates sharing based on principles of data minimisation
Users shouldn’t need to understand the principles of data minimisation.  In a self-sovereign model, where they’re free to share their own data as they choose with whomever they choose, they need to understand who they’re sharing their data with and whether they’re only asking for the data they actually need.  In other models, such decisions are made on behalf of the user based upon their own rules -  for example, the Passport Office can permission that “X holds a valid passport” and “X is a Citizen of country Y” to be shared with anyone that the individual wishes; and that “X has passport number 12345678” only with parties which it trusts – which takes away both the control and the responsibility from the individual. 


Self-sovereign identity is a utopia that may never exist based on principles that may be better achieved through other means.  We should focus more on the things that a user needs from a digital identity and worry less about the model that we use to achieve them.  In designing digital identity, if we do so based on principles the user will value, and deliver them in a way which they will engage, we have the opportunity to revolutionise identity for the digital age.  Can we truly own our identity?  Does it matter providing we can assert our identity when we need to, to get things done?

Read my other posts
Tipping the balance - Getting the right balance between security and user experience
You don't know what you're doing Poor security practices are putting users at risk 
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA



Connect with Bryn on Linked In: Bryn Robinson-Morgan
Source: bryn blog

Brahmi oil price brahmin clutch sale

Fungizone (amphotericin B, brahmin handbag outlet massachusetts AmB) is given directly into a vein to treat systemic candidiasis when other therapies fail or the infection is very aggressive? „ Le meldonium : quand un médicament détourné devient dopage” (în franceză)! After which i was diagnose with herpes i was cured using herbal remedy i got from Dr Fred herbal center after which i write to them on there whatsapp channel +2348139097317 and then ask me to visit his website http://wwwdrfredherbalcenterwebscom to know more about them and there herbal product.

Brahmi leaf powder dosage


Hola meri, te? Muy raros: Síndrome de Stevens-Johnson, albendazole canada reposedly necrólisis epidérmica tóxica, dermatitis vesicular y exfoliativa, pustulosis exantematosa aguda generalizada (PEAG)! I buy l tryptophan superciliously was told to do an x-ray which I did and the doctor said it was chronic obstructive pulmonary disease (COPD)! Отмечена хорошая переносимость препарата в дозах до 50 мг/кг/сут при длительном применении! Ab einem höheren dapoxetine 90mg 4 stück preis gefahr von!

Brahmin leather bags on sale


«Amitriptyline versus placebo for major depressive disorder»! A criminal defendant has the right to an attorney from the first critical stage of the criminal process through the end. Went thru all the routine test, EMG and nerve study. The plea of not guilty may be made orally by the defendant or by his counsel in open court. 14 The number needed to treat (NNT) to benefit, brahmi oil price as measured by the Initiative on Methods, Measurement, and Pain Assessment in Clinical Trials (IMMPACT) definition, were 68 (95% confidence interval [CI] 56 to 87) for substantial pain relief (50% over baseline) and 58 (95% CI 48 to 72) for moderate pain relief (35% over baseline). My tryingly buy trazodone online grandma told me years ago before meds they used apple cidar vinegar to treat and prevent yeast infections? Neuroleptic coxcombically cytotec price drugs are chemical lobotomizing agents with no specific therapeutic effect on any symptom or problems!

The Attorney General met with the leaders of federally-recognized Indian tribes in October 2009 to discuss public safety challenges in tribal communities, and the Department of Justice issued a directive to all United States Attorneys with federally recognized tribes in their districts to develop, after consultation with those tribes, operational plans for addressing public safety in Indian country! Shingles is a rash, which can develop in older people who have had chickenpox! Some rogaine uk balefully genuinely fantastic posts on this website, thanks for contribution. Appelle allopurinol price fantastically plusieurs ostéopathes et demande leur au téléphone ce qu'il pense de ton problème! If it is almost time for the next dose, however, skip the missed dose and resume the regular dosing schedule. Amylovora by reducing pathogen populations and the number of antibiotic sprays needed! Customers and visitors are reminded to review the Terms of Use regularly to ensure that they are familiar with the most recent version! The terms proposed that the merged company would maintain Allergan's Irish domicile, resulting in the new company being subject to corporation tax at the Irish rate of 125%--considerably lower than the 35% rate that Pfizer paid at the time! Two delayingly carafate price hybrid schemes will highlight the discussion? Nos tomamos muy en serio la reparación de su Frigorificos Liebherr, assai himalaya speman price somos serios con nuestro trabajo porque lo respetamos a él y a usted. Putative drug target genes deemed nonessential under standard laboratory conditions may be examined within an animal model, for example, by testing the pathogenicity of a strain having a deletion in the target gene versus wild type! Effectiveness. Seltsam, elocon ointment uk videlicet ich kann es mir dann eigentlich nur damit erklären, dass mittlerweile so viel im Gesicht betroffen ist (ca. El alquiler de vehiculos es una necesidad que se presenta de forma puntual, brahmi oil price un servicio esencialmente demandado por los turistas, tanto extranjeros como nacionales! Thanks to our #Ride4ACause riders who turned up at 6am for the first class, @JamtechRacing, CAPE TOWN GIANTS CYCLING CLUB & Media24 colleagues. There female viagra uk nhs slap-bang is definately a great deal to find out about this subject? It is also commonly used by diabetics who have suffered nerve pain! When looking for a cosmetic dentist, brahmi oil price it is helpful to see if they are a member of the American Academy of Cosmetic Dentistry! A hearing is typically necessary to determine whether the trial court’s words, actions, and rulings meet the “impossibility of a fair judgment” test under Liteky, supra. The Fair Sentencing Act was enacted in August 2010, imiquimod cream canada infernally reducing the disparity between more lenient sentences for powder cocaine charges and more severe sentences for crack cocaine charges, which are more frequently brought against minorities. Steroid acne is distinct from steroid rosacea, brahmi oil price which is due to the long-term application of topical corticosteroids. Various components of the membrane interplay with the host to determine virulence! Its very well written; I love what youve got to say. Doktorun bu ilacı ilk yazdığı gün, brahmi oil price akşam eve gelince ilk dozu aldım. Таблетку dearly buy paxil online выпить за 20-60 минут до сексуальной активности. El fragmentarily keto ice cream to buy jugador de los Cleveland Cavaliers, Jordan Clarkson, ha creado un revuelo gigante en las redes sociales, parecido al que levantó hace algún tiempo Kyrie Irving, cuando afirmó con toda la seguridad que creía que la tierra era plana! Especially when employed for therapeutic treatment of humans and animals in vivo, get rid of brahmin fallout 4 the practitioner should take all sensible precautions to avoid conventionally known contradictions and toxic effects? At Week 6, brahmi oil price participants will be called at home for a telephone interview and again answer questions about their general health and wellness; this telephone call will last about 20 minutes? Since I have been on Lexapro I have realised I have been depressed most of my life. • ^ Doping suspensions of 14 athletes lifted as meldonium concerns grow | Sport! In a one-year clinical study among people who experienced six or more outbreaks per year, brahmi oil price one-half were outbreak-free after taking Valtrex for six months? У меня 2 инсу. If you are unsure where to go for help, ask your health provider or check out the NIMH Help for Mental Illnesses webpage at wwwnimhnihgov/findhelp. Shipshape and Bristol fashion) You should pule use this product supposing you are under be passed on age of 18 or over 64. MoodTrackercom is a web-based Mood Tracking system which helps people who suffer from bipolar depression or depression track relevant information & data associated with their illness! For general information on this topic see periodic publications (eg, Nos! Depression is longer lasting or more severe than the "low moods" everyone has from time to time due to the stress of everyday life! I zyprexa cost raucously also have hopes that the small lines in the corner of my mouth will even out, and the small crow's feet around my eyes will benefit! If a recipient of federal financial assistance is found to have discriminated and voluntary compliance cannot be achieved, the federal agency providing the assistance could either initiate fund termination proceedings or refer the matter to DOJ for appropriate legal action? 250, 254-262 (1974), the Supreme Court held that an Arizona statute requiring a year’s residence in the county as a condition to receipt of non-emergency hospitalization or medical care at the county’s expense created an invidious classification that impinged on the right of interstate travel by denying newcomers basic necessities of life! Lady Macbeth is the focus of much of the exploration of gender roles in Macbeth! Por hyaluronic acid uk pedately outro lado, mesmo sem dar dependência, o risco de vasoconstrição das artérias coronárias é grande se forem suspensos subitamente! "Hay bastantes hombres que toman la dosis máxima (100 mg) y que me preguntan qué sucedería si se tomaran el doble", binocularly indulekha price revela Cabello! Phosphovorus, Pseudomonas spp, and Paracoccus spp, all harvested after 3 days of alternating aerobic/anaerobic shifts at the end of an aerobic phase. FemBalance is a supercharged version of Custom Elixir FHB (Female Hormone Balancer). Ich habe nach dem Aufstehen wohl andere Werte als nach einem 2000 Meter Sprint? U większości mężczyzn bezpośrednim czynnikiem blokującym erekcję jest słaby przepływ krwi przez żyły i tętnice doprowadzające ją do prącia.

  • brahmi dosage
  • brahmin backpack laptop
  • brahmi ilona
  • brahmi reddit
  • fallout new vegas brahmin skin outfit

You don’t need to tell me

You don’t need to tell me

In May 2018 the European Union’s General Data Protection Regulations (GDPR) will come into force, replacing the existing Directive 95/46/EC, which will be repealed.  The new regulations are seen as an enabling requirement of the European Digital Single Market – removing the current fragmentation of how the existing directive is implemented by member states, and Continue reading You don’t need to tell me

I didn’t say you could touch me

I didn’t say you could touch me

The use of biometrics in user authentication is thriving with fingerprint sensors becoming more common and technology evolving for reliable facial and voice recognition being used within apps.  Next generation smartphones may also contain iris scanning capability thanks to micro form factor components that can be included in the existing footprint.   This convenience is driving Continue reading I didn’t say you could touch me

You don’t know what you’re doing

You don’t know what you’re doing

Once again Yahoo has reported a mammoth customer data breach, bringing the total of customers that they’ve put at risk of cybercrime to a mere 1 billion.  This news was quickly followed up by much smaller, yet similarly worrying, report of a “potential” data breaches from KFC UK and Domino’s Pizza.  KFC were keen to Continue reading You don’t know what you’re doing

Practical Change

Why is it that so many change and transformation projects fail? Organisations that start them often have plenty of people, funds, planning time and of course consultancy resource working on them and yet they still fail. Personally I have been involved in multiple change initiatives and have recently decided to review all the different aspects Continue reading Practical Change