decentralized-identity / decentralized-identity/did-methods
DID method considerations for institutional use of biometrics and decentralization
- Dominant language
- No language data
- Stars
- 21
- Forks
- 20
- PR merge metrics
- No merged PRs in 30d
Description
The institutional use of biometrics is a growing concern as noted for private [CLEAR and ID.me](https://www.technologyreview.com/2024/11/20/1107002/clear-airport-identity-management-biometrics-facial-recognition/) as well as [public](https://insights.som.yale.edu/insights/what-happens-when-billion-identities-are-digitized) real-world use.
One consideration for which DID methods might benefit from standardization is how DIDs can help to decentralize the process of trusting an individual's signature. What if that signature is on a ballot submission or KYC context? What if the DID is being used in-person or online?
Legacy practice uses federated notaries and their secure logs to deal with this problem. As part of the federation trust chain, there are standards for what individual identity is acceptable. This practice has been extended to allow for on-line notarization in some contexts.
Local (1:1) biometrics are also likely a part of the solution but that probably introduces a secure element along with the DID management software. Will these two separate aspects be "certified" together a la Worldcoin or will the trust be separated between Apple and the state DMV app?
Simply punting the questions above to unspecified "trust frameworks" or real ones like eIDAS or Aadhaar seems like an opportunity lost for our community. Let's say I have a VC signed by DHS or one of their agents (like we have CAs that issue federally acceptable credentials today)? What DID method and mobile hardware assumptions are we making?
Contributor guide
Research direction
No files, tests, or entry points are named. Start by reviewing the repository's existing DID method material and the trust assumptions described in this issue, then identify whether the proposal can be scoped to a concrete standardization task. Done means an agreed, implementable direction for handling signatures, biometrics, trust frameworks, and mobile hardware assumptions.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100