decentralized-identity / decentralized-identity/did-methods

DID method considerations for institutional use of biometrics and decentralization

Open
#12 0 comments 1 reaction 0 assignees View on GitHub
Dominant language
No language data
Stars
21
Forks
20
PR merge metrics
No merged PRs in 30d

Description

The institutional use of biometrics is a growing concern as noted for private [CLEAR and ID.me](https://www.technologyreview.com/2024/11/20/1107002/clear-airport-identity-management-biometrics-facial-recognition/) as well as [public](https://insights.som.yale.edu/insights/what-happens-when-billion-identities-are-digitized) real-world use.

One consideration for which DID methods might benefit from standardization is how DIDs can help to decentralize the process of trusting an individual's signature. What if that signature is on a ballot submission or KYC context? What if the DID is being used in-person or online?

Legacy practice uses federated notaries and their secure logs to deal with this problem. As part of the federation trust chain, there are standards for what individual identity is acceptable. This practice has been extended to allow for on-line notarization in some contexts.

Local (1:1) biometrics are also likely a part of the solution but that probably introduces a secure element along with the DID management software. Will these two separate aspects be "certified" together a la Worldcoin or will the trust be separated between Apple and the state DMV app?

Simply punting the questions above to unspecified "trust frameworks" or real ones like eIDAS or Aadhaar seems like an opportunity lost for our community. Let's say I have a VC signed by DHS or one of their agents (like we have CAs that issue federally acceptable credentials today)? What DID method and mobile hardware assumptions are we making?

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named. Start by reviewing the repository's existing DID method material and the trust assumptions described in this issue, then identify whether the proposal can be scoped to a concrete standardization task. Done means an agreed, implementable direction for handling signatures, biometrics, trust frameworks, and mobile hardware assumptions.

Written by the indexing model from the issue text.

Assessment

Domain
authentication, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
15/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.