Great move by the Commonwealth. Moving from a data mindset to a claim/proofing one using attestation moves us to Zero Knowledge Proofs #ZKP. ISO 18013 and 23220 allows these attestation and claims to be shared in a secure way both online and off-line. This has security benefits but also starts changing our mindsets on eligibility. Where we move from seeking data to accepting claims. #Digital #Technology #identity 👏👏👏
data ➡️ attestation Address ➡️ is a NSW resident Payroll slip ➡️ is employed Passport no ➡️ is an Australian citizen Date of birth ➡️ is above 18 Bank statement ➡️ has Australian bank account Driver Licence no ➡️ is authorised to drive You can see from above - how sending copies of our drivers licence, passport, bank statement etc would enable bad actors to quickly build a detailed profile about us 🟰 a significant cyber risk 😞 🔹 A bouncer doesn’t need our full date of birth - unless an astrology read is also on offer 🧐 they just need to make sure you are above 18 years 🔹same rationale applies with so many other instances when we are asked to provide a copy of our licence, passport etc With digital ID and verifiable credentials - we can move into a far more secure world. In essence - this is what the Trust Exchange (TEx) that Min Bill Shorten recently announced is aimed to do … replacing sensitive data - with an attestation ✅ Will provide a further update soon on some of the pilots underway at Services Australia
While this does not apply to all cases, I love how well thought out it is and am glad to see people finally understand the power of attestation (not even mention how much this optimizes the data structure itself).
Opec Kemp for discussion with Belinda tomorrow
A highly respected consultant specialising in eHealth and digital health transformation
1moAssertion models are not new, but in the digital identity and authorisation management space they can be a valuable addition so long as the assertion statements can be universally understood and the validation / evidence behind the assertion is trustworthy AND maintained. Take the drivers license example … having a drivers license doesn’t necessarily authorise you to drive if there are conditions, it’s for a particular class of vehicle, it’s suspended etc. etc.