ブログの前編ではConsumer Identity World、後編ではInternet Identity Workshopについてレポートします。
トレンドに関する学びは大きく以下3点でした: - Self-Sovereign Identityの実現方法はブロックチェーンに限らない - ブロックチェーン基盤のIdentificationの規格整備やユースケース確立にはまだ時間がかかりそうだ - 従来型のIdentification業界が着々とセキュリティを強化しながら前進している ブロックチェーンと従来型の双方が、目的に応じた技術を選定するという「Appropriate Technology」という考え方に言及することが多かったのが印象的でした。
私たちのThe Invisiblesプロジェクトでは、最初から”We are technology agnostic” -バズワードに関係なく目的に合致したテクノロジーを使っていくよ - という風にパートナーと合意してあったので、今回の視察を得て、Self-Sovereign Open ID Connectなどブロックチェーンに限らない従来型のIdentity技術の検討も進めていくことになりました。
Consumer Identity World
KuppingerColeというヨーロッパを代表する情報セキュリティ専門のアナリスト企業主催のConsumer Identity World USA 2019で基調講演及びパネルディスカッションをやらせていただきました。
私たちがThe Invisiblesプロジェクトで作りたいものは、「市民権とは関係なく、組織や国境を越えて受け入れられる分散型アイデンティティ」で、そのためには一つの組織に頼らなく手もいいようにデータの信頼性を保証する仕組みとそれを支える技術が必要です。
コンセプトを固めつつも、実際に動き出しており、 ① 仕組みに関しては、ISO(国際標準化機構)と難民向けにデジタルアイデンティティを発行するプロセスを標準化する国際規格をドラフトするワーキンググループを立ち上げ中 ② 技術に関しては、ブロックチェーンを活用したアイデンティティウォレットを医師向けにバングラデシュで発行し、実証しています。
その一方で、ZARAやH&Mなどの大企業、労働組合、被害者の家族、サプライチェーンのほかの中小企業などが集まってドラフトしたISO 45001という労働環境の基準を定めた国際規格によって大企業は工場がその規格に準拠しているかを確認できるようになったため、状況がよくなりつつあります。
__③私がしているのは夢物語ではなく、過去にNansen Passportという事例があります
④ 現在実際に作成している一組織に頼らない分散型アイデンティティプロセスモデル
”Next Steps and Trends in Consumer Identity Management”というパネルディスカッションに参加させていただきました。その中でのハイライトを取り上げます。(思ったり思い出せず、、追記する可能性大です)
What are the emerging trends in consumer identity?
Me: One thing I feel is strengthening momentum towards individuals owning their own data. One example is MyData movement, whose mission is exactly "Empower individuals by improving their right to self-determination regarding their personal data." Right now, MyData 2019 conference is happening in Helsinki, and I, myself help run MyData Japan chapter.
True that individuals owning their data means more responsibility on individuals themselves. You cannot blame insurance company for breach of your data if you were supposed to keep track and take care of that data yourself. Which is why we are seeing the emergence of initiatives like information banks in Japan
を目指すMyDataのムーブメントです。CIWとヘルシンキで同時期開催されていた、MyData 2019カンファレンスは今までにない盛り上がりをみせ、来年はMyData Asia2020をMyData Japan chapterと企画しております。
What is the future of decentralized identity?
Me: Sovrin Foundation has been one of the first runners in the space. And it is impressive to see big corporations like IBM, Cisco, T-Mobile joining their network.
These big corporations are still at the stage where they are internally checking if this technology can be used, so I do not think mass adoption wil be anytime soon, but examples like this still make me feel optimistic.
私:Sovrin Foundationはこの分野で最初のランナーの1人でした。また、IBM、Cisco、T-Mobileなどの大企業がネットワークに参加しているのも印象的です。
What do you think of "Self-Sovereign Identity"?
Justin (Audience): it is a misnomer. It is a myth. Christian (KuppingerCole):Who regulates the space? Government?
Me: Let me come back to this because this touches upon my favorite topic of international standards. Identity goes beyond national borders, and there is no way governments can govern it.
My other concern is the fact that the Internet space is governed by algorithms written by coders who do not have much knowledge in legal, sociological nor ethical matters.
We really need various stakeholders - governments, tech companies, NGOs, UN agancies - coming together to draft standards that work for parties involved individuals, while respecting rights of the individuals.
What I would add now: I am currently reading a book Tools and Weapons: The Promise and The Peril of the Digital Age written by a Microsoft President Brad Smith, where he details the struggle of a tech giant dealing with legal, ethical and social issues. The book opened my eyes that Microsoft was doing more than I thought, but also confirmed that we still have a long way to go before we would be talking openly about these matters.
Let's talk about consent
Me: There is this emerging notion of layered consent: 1/ consent towards access to my data and 2/ consent towards usage of that data.
For example, I might be ok for my credit history and social footprint to be used to grant me a loan, but I might not be ok for the same data to be used to influence my voting decision. Nor I might not be ok for an insurance company to access the same data.
The discussion has just started and I am curious to see if we can accommodate both aspects in one 'consent' or these two should be more clearly separated.
Me: Another important aspect of consent is the fact that giving consent to our own data affects our family and friends.
By getting access to my DNA, these companies get access to my family's DNA. By allowing a wifi service to access my social network including a list of my followers, they get access to the profiles of my followers.
Until these DNA companies get privacy right, I am not giving them my DNA, but the scary thing is that they would be able to get it if someone in my family shares their DNA data...
Me: Estonia has an interesting example of consent being related to transparency.
There, individuals can see all the logs of how their data is being used. My friend saw that police has accessed his data, so he contacted the police to find out why they did that, since he did not remembering violating any law. The police got back to him saying that his car was parked next to a car into which a thief broke in, so they were confirming the owners of surrounding cars. Well, sounds legit, so my frience dropped the case.
