An architectural analysis of user-centric identity management
Implementing regulations
Architecture & Reference Framework (ARF)
EUDI as advertised (Q&A, recitals …)
Citizens will be in full control over which data they share with which parties.*
* Fineprint:
Participation in the EU Digital Identity space dependent on economical and political incentives,
putting it at risk for commercial and criminal exploitation.
(ISOC, CEPIS, CA/B, EFF)
OpenID’s “new trust model”
A paradigm shift towards user-centricity, increasing portability, privacy, and control
The standard we have:
A ‘local cache’ to manage consent for the access to (signed) personal info by approved parties.
The standard we need:
A ‘remote key’ to manage delegated control for any interaction with any (authentic) service by any party.
Sharing decision-making power with another person
Thanks!
Q&A at the end
Research funded by SolidLab Vlaanderen & SecuWeb