Video summary
Who are you…And how to prove your identity digitally? | Rene Mayrhofer | TEDxLinz
Main summary
Key takeaways
Scientific concepts, discoveries, and nature phenomena presented
Digital identity as an infrastructure for society
Digital identity is framed as encompassing both:
- Already-digitized personal data, such as:
- Messages and calls
- Photos/videos
- Social networks
- Traditionally physical documents kept in wallets, such as:
- Cash/credit cards
- Social security cards
- Driver’s licenses
- Passports
The concept also extends to how identity is authenticated in real-world interactions, including:
- Doors
- Transport
- Hospitals
- Hotels
- Border crossings
Biometric authentication
The talk highlights biometrics as a way to replace or reduce reliance on passwords/PINs, using:
- Faces
- Voices
- Fingerprints
- Iris patterns
It also describes selective disclosure: an interaction should reveal only the attributes needed, for example:
- A vending machine might only need confirmation of “over 16”
- A bank account opening may require full proof of identity
Privacy-preserving identity attributes
A core emphasis is minimizing data exposure during verification by providing proof of specific attributes without disclosing full personal details such as:
- Name
- Address
- Date of birth
- Nationality
Centralized vs decentralized identity architectures (security and governance)
Centralized model
In the centralized model, a global centralized database of biometric templates would allow verifiers (e.g., border guards, hotels, transport services) to authenticate users without performing their own checks.
Risks claimed include:
- Security fragility: a successful attack could enable mass identity takeover
- Power concentration: whoever controls the database could enable surveillance/censorship and even service denial (described as “virtual death”)
Decentralized model
The decentralized approach replaces a centralized biometric database with decentralized digital identities:
- Each person is associated with a personal agent (software acting on the person’s behalf).
- Biometrics are stored/used by the personal agent, not in a single global database.
Cryptography, secure hardware, and distributed protocols
Decentralization is described as requiring:
- Cryptographic protocols with bidirectional network communication
- Secure hardware, such as smart cards/chip-based devices
- Independent validation/certification of implementations
Network communication pattern in the decentralized system
A three-party interaction is described:
- The verifier asks to authenticate certain identity aspects.
- Biometric sensors provide live measurements to the personal agent.
- The personal agent uses those measurements to authenticate the requested attributes and sends the result to the verifier.
Outcome: verifiers receive only the relevant identity aspects for that specific interaction.
Computing/control of the personal agent
Personal agents can run:
- On a user’s own smartphone/home devices, or
- Via a chosen cloud service provider
Users can turn the agent on/off, aiming to reduce tracking and limit availability when desired.
Methodology / system outline (decentralized digital identity)
Set up
- Deploy decentralized biometric sensors in the environment (run by verifiers, users, or independent third parties).
- Create a personal agent per individual (an active software “digital shadow”).
Authentication workflow
- A verifier initiates an authentication request for specific attributes.
- Appropriate biometric sensor(s) capture live measurements.
- Measurements are forwarded only to the individual’s personal agent.
- The personal agent verifies the requested attributes using stored biometric templates.
- The verifier receives only the outcome/attested attributes needed for that interaction.
Implementation requirements
- Use cryptographic protocols with bidirectional communication
- Employ secure hardware (e.g., smart card chips)
- Require independent certification of secure components
User control
- The owner chooses where the personal agent runs (device or preferred cloud).
- The owner can temporarily/permanently disable it to reduce tracking and control access.
Researchers or sources featured
- Rene Mayrhofer (speaker; described as working in computer security and leading a research group)
- Minority Report (2002 movie; cited as a science-fiction reference for seamless borderless identity-based movement)
- Mentions of organizations (not presented as specific researchers):