Who do you think you are?
How the convergence of SSI and AI can give people back control over their identity

Fujitsu / April 20, 2022

Many people, and even companies, are worried about who has access to their digital ID or could even have control over it. Recent and highly-publicized data breaches in private sector companies and government organizations make them nervous. And with good reason. According to Risk Based Security's data breach report published in 2021, "The total number of records compromised in 2020 exceeded 37 billion, a 141% increase compared to 2019".

For organizations trying to manage this data, things are not straightforward. The risks of holding data can even be seen as a liability. Even when data and information are encrypted or anonymized, it may still be possible for third parties to identify users unless well-developed cybersecurity processes are part of the integrated data management systems.

With concerns on both sides, although for different reasons, a new approach to identity management is necessary. Self-Sovereign Identity (SSI) is gaining a lot of traction in this context. It means that the data subject controls who has access and how their data is being used.

Conventional ID often relies on judgment

For comparison, think about how a conventional ID works.
Imagine that you are attending a conference abroad, holding a paper certificate issued by a regional hospital in your home country, proving your immunity to a virus during a pandemic. You show the certificate to gain entry. The guard has to verify the validity of that paper certificate by analyzing its physical properties: It must look and feel genuine and valid, and then the guard can choose to accept it or not based on her judgment.
Two prominent issues pop up here. The first is that the system relies on a judgment or a ruling. How can a security desk operative be expected to know what a valid certificate looks like from any hospital in any country? The same issue would also apply to other document types — a driver's license, for example. The second issue is that the process exposes much more information about you than is needed. When we show a conventional ID to prove our age, we also divulge irrelevant details, such as our address or phone number that we would probably prefer not to share with a random individual on security duty. It directly impacts our sense of trust.
Many digital environments are still not much further ahead here, regardless of certain claims. Scanned paper-based IDs still form the basis of most digital onboarding processes.

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...

Loading component...