{"id":313,"date":"2021-02-08T19:08:18","date_gmt":"2021-02-08T18:08:18","guid":{"rendered":"http:\/\/andreasfreitag.org\/podcast\/?p=313"},"modified":"2021-02-09T15:06:41","modified_gmt":"2021-02-09T14:06:41","slug":"am-i-a-self-sovereign-identity-system","status":"publish","type":"post","link":"https:\/\/andreasfreitag.org\/podcast\/2021\/02\/08\/am-i-a-self-sovereign-identity-system\/","title":{"rendered":"Am I a Self-Sovereign Identity system?"},"content":{"rendered":"\n<p>It can be challenging to decide if a Digital Identity system is a <strong>Self-Sovereign Identity<\/strong> (SSI) system or a central Digital Identity system. The question <strong>&#8220;Am I a SSI system?&#8221;<\/strong> can be tricky to answer.  <\/p>\n\n\n\n<p>Providers claiming their solution is SSI based, and of course use Blockchain &#8211;  never let go a buzzword. The claim cannot be proofed, there is no assessment framework and no standard definition for a SSI system.<\/p>\n\n\n\n<p>Even if a solution is based on &#8220;SSI&#8221; open source frameworks like Hyperledger Indy, it is not said that it is a SSI system. A single \u201cshort cut\u201d in the implementation and all self-sovereignty is gone.  SSI principles can be weakened because of technology limitations or process requirements. And sometimes claimed SSI solutions are not even close to SSI or even Identity.<\/p>\n\n\n\n<p>A simple, yes it is SSI, is not enough. There are blurry lines and differences in implementations. The answer, NO it is not a SSI solution, is easier because there are certain KO criteria\u2019s.<\/p>\n\n\n\n<p>So how you can make an assessment? The ques<span style=\"font-size: inherit;\">tion is bothering me for some month.<\/span><\/p>\n\n\n\n<!--more-->\n\n\n\n<h2>27 characteristics of SSI systems<\/h2>\n\n\n\n<p>On the base of the work of Cameron &#8220;Laws of Identity&#8221;, Christopher Allen &#8220;10 principles of SSI&#8221;, Satybaldy &#8220;SSI evaluation framework&#8221; and  Naik and Jenkins &#8220;Governing Principles&#8221; I defined 27 SSI characteristics. Each one has a certain importance to SSI. <\/p>\n\n\n\n<p>The 27 characteristics in the table below are the base for further work. If you have critics, comments or input. Please reach out.<\/p>\n\n\n\n<p>Whats next?<\/p>\n\n\n\n<ul><li>Work on the characteristic, define them and design a basic evaluation matrix<\/li><li>Define a formula for a SSI score<\/li><li>Define KO criterias<\/li><li>Work on a generic SSI architecture<\/li><\/ul>\n\n\n\n<p> I am aware that the mapping includes duplications, blurry lines, and precise mapping was not possible every time and can be discussed. These inaccuracies cannot be avoided and are excepted.<\/p>\n\n\n\n<div class=\"wp-block-columns\">\n<div class=\"wp-block-column\" style=\"flex-basis:100%\">\n<div class=\"wp-container-1 wp-block-group\"><div class=\"wp-block-group__inner-container\">\n<figure class=\"wp-block-table is-style-stripes\"><table><thead><tr><td>#<\/td><td class=\"has-text-align-left\" data-align=\"left\"><strong>&#8220;Laws of Identity&#8221;<\/strong> <\/td><td><strong>&#8220;10 principles of SSI&#8221;<\/strong><\/td><td><strong>&#8220;SSI eval. framew<\/strong>.&#8221;<\/td><td><strong>&#8220;Governing principles&#8221; <\/strong><\/td><td><strong>CHARACTERISTICS<\/strong><\/td><\/tr><\/thead><tbody><tr><td>1<\/td><td class=\"has-text-align-left\" data-align=\"left\">1. User Control and Consent<\/td><td>2. Control<\/td><td>&nbsp;<\/td><td>1. Sovereignty<br>3. Data Access Control<br>4. Data Storage Control<\/td><td><strong>Control<\/strong><\/td><\/tr><tr><td>2<\/td><td class=\"has-text-align-left\" data-align=\"left\">2. Minimal Disclosure for a Constrained Use<\/td><td>9. Minimization<\/td><td>&nbsp;<\/td><td>11. Privacy<\/td><td><strong>Minimal Disclosure<\/strong><\/td><\/tr><tr><td>3<\/td><td class=\"has-text-align-left\" data-align=\"left\">3. Justifiable Parties<\/td><td>1. Existence<br>3. Access<br>4. Transparency<\/td><td>&nbsp;<\/td><td>6. Decentralized<\/td><td><strong>Concerned Parties \u2013 no middleman<\/strong><\/td><\/tr><tr><td>4<\/td><td class=\"has-text-align-left\" data-align=\"left\">4. Directed Identity<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td><strong>Correlation<\/strong><\/td><\/tr><tr><td>5<\/td><td class=\"has-text-align-left\" data-align=\"left\">5. Pluralism of Operators and Technologies<\/td><td>7. Interoperability<\/td><td>&nbsp;<\/td><td>13. Flexibility<br>17. Portability<br>18. Interoperability<\/td><td><strong>Interoperability<\/strong><\/td><\/tr><tr><td>6<\/td><td class=\"has-text-align-left\" data-align=\"left\">6. Human Integration<\/td><td>8. Consent<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td><strong>Consent<\/strong><\/td><\/tr><tr><td>7<\/td><td class=\"has-text-align-left\" data-align=\"left\">7. Consistent Experience Across Contexts<\/td><td>&nbsp;<\/td><td>Usability<\/td><td>&nbsp;<\/td><td><strong>Usability<\/strong><\/td><\/tr><tr><td>8<\/td><td class=\"has-text-align-left\" data-align=\"left\">3. Justifiable Parties<\/td><td>1. Existence<\/td><td>&nbsp;<\/td><td>2. Existence of a User<\/td><td><strong>Existence<\/strong><\/td><\/tr><tr><td>9<\/td><td class=\"has-text-align-left\" data-align=\"left\">3. Justifiable Parties<\/td><td>3. Access<\/td><td>&nbsp;<\/td><td>14. Accessibility<\/td><td><strong>Access<\/strong><\/td><\/tr><tr><td>10<\/td><td class=\"has-text-align-left\" data-align=\"left\">3. Justifiable Parties<\/td><td>4. Transparency<\/td><td>&nbsp;<\/td><td>16. Transparency<\/td><td><strong>Transparency<\/strong><\/td><\/tr><tr><td>11<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>5. Persistence<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td><strong>Persistence<\/strong><\/td><\/tr><tr><td>12<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>6. Portability<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td><strong>Portability<\/strong><\/td><\/tr><tr><td>13<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>10. Protection<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td><strong>Protection<\/strong><\/td><\/tr><tr><td>14<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>5. Longevity<\/td><td><strong>Long living<\/strong><\/td><\/tr><tr><td>15<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>7. Verifiability<\/td><td><strong>Verifiable<\/strong><\/td><\/tr><tr><td>16<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>8. Recovery<\/td><td><strong>Backup \/ Recovery<\/strong><\/td><\/tr><tr><td>17<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>9. Cost Free<\/td><td><strong>Free<\/strong><\/td><\/tr><tr><td>18<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>10. Security<\/td><td><strong>Storage Security<\/strong><\/td><\/tr><tr><td>19<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>10. Security<\/td><td><strong>Communication Security<\/strong><\/td><\/tr><tr><td>20<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>12. Safeguard<\/td><td><strong>Safeguard<\/strong><\/td><\/tr><tr><td>21<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>15. Availability<\/td><td><strong>Availability<\/strong><\/td><\/tr><tr><td>22<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>19. Scalability<\/td><td><strong>Scalability<\/strong><\/td><\/tr><tr><td>23<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>20. Sustainability<\/td><td><strong>Sustainability<\/strong><\/td><\/tr><tr><td>24<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td><strong>Open Source<\/strong><\/td><\/tr><tr><td>25<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td><strong>Traceability<\/strong><\/td><\/tr><tr><td>26<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td><strong>Link-ability<\/strong><\/td><\/tr><tr><td>27<\/td><td class=\"has-text-align-left\" data-align=\"left\">&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td>&nbsp;<\/td><td><strong>Mobility<\/strong><\/td><\/tr><\/tbody><\/table><\/figure>\n<\/div><\/div>\n<\/div>\n<\/div>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>It can be challenging to decide if a Digital Identity system is a Self-Sovereign Identity (SSI) system or a central Digital Identity system. The question &#8220;Am I a SSI system?&#8221; can be tricky to answer. Providers claiming their solution is SSI based, and of course use Blockchain &#8211; never let go a buzzword. The claim &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/andreasfreitag.org\/podcast\/2021\/02\/08\/am-i-a-self-sovereign-identity-system\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Am I a Self-Sovereign Identity system?&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":""},"categories":[3],"tags":[11],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/posts\/313"}],"collection":[{"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/comments?post=313"}],"version-history":[{"count":13,"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/posts\/313\/revisions"}],"predecessor-version":[{"id":328,"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/posts\/313\/revisions\/328"}],"wp:attachment":[{"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/media?parent=313"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/categories?post=313"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/andreasfreitag.org\/podcast\/wp-json\/wp\/v2\/tags?post=313"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}