Video summary

Who are you…And how to prove your identity digitally? | Rene Mayrhofer | TEDxLinz

Main summary

Key takeaways

Science and Nature

Scientific concepts, discoveries, and nature phenomena presented

Digital identity as an infrastructure for society

Digital identity is framed as encompassing both:

  • Already-digitized personal data, such as:
    • Messages and calls
    • Photos/videos
    • Social networks
  • Traditionally physical documents kept in wallets, such as:
    • Cash/credit cards
    • Social security cards
    • Driver’s licenses
    • Passports

The concept also extends to how identity is authenticated in real-world interactions, including:

  • Doors
  • Transport
  • Hospitals
  • Hotels
  • Border crossings

Biometric authentication

The talk highlights biometrics as a way to replace or reduce reliance on passwords/PINs, using:

  • Faces
  • Voices
  • Fingerprints
  • Iris patterns

It also describes selective disclosure: an interaction should reveal only the attributes needed, for example:

  • A vending machine might only need confirmation of “over 16”
  • A bank account opening may require full proof of identity

Privacy-preserving identity attributes

A core emphasis is minimizing data exposure during verification by providing proof of specific attributes without disclosing full personal details such as:

  • Name
  • Address
  • Date of birth
  • Nationality

Centralized vs decentralized identity architectures (security and governance)

Centralized model

In the centralized model, a global centralized database of biometric templates would allow verifiers (e.g., border guards, hotels, transport services) to authenticate users without performing their own checks.

Risks claimed include:

  • Security fragility: a successful attack could enable mass identity takeover
  • Power concentration: whoever controls the database could enable surveillance/censorship and even service denial (described as “virtual death”)

Decentralized model

The decentralized approach replaces a centralized biometric database with decentralized digital identities:

  • Each person is associated with a personal agent (software acting on the person’s behalf).
  • Biometrics are stored/used by the personal agent, not in a single global database.

Cryptography, secure hardware, and distributed protocols

Decentralization is described as requiring:

  • Cryptographic protocols with bidirectional network communication
  • Secure hardware, such as smart cards/chip-based devices
  • Independent validation/certification of implementations

Network communication pattern in the decentralized system

A three-party interaction is described:

  • The verifier asks to authenticate certain identity aspects.
  • Biometric sensors provide live measurements to the personal agent.
  • The personal agent uses those measurements to authenticate the requested attributes and sends the result to the verifier.

Outcome: verifiers receive only the relevant identity aspects for that specific interaction.

Computing/control of the personal agent

Personal agents can run:

  • On a user’s own smartphone/home devices, or
  • Via a chosen cloud service provider

Users can turn the agent on/off, aiming to reduce tracking and limit availability when desired.


Methodology / system outline (decentralized digital identity)

Set up

  • Deploy decentralized biometric sensors in the environment (run by verifiers, users, or independent third parties).
  • Create a personal agent per individual (an active software “digital shadow”).

Authentication workflow

  1. A verifier initiates an authentication request for specific attributes.
  2. Appropriate biometric sensor(s) capture live measurements.
  3. Measurements are forwarded only to the individual’s personal agent.
  4. The personal agent verifies the requested attributes using stored biometric templates.
  5. The verifier receives only the outcome/attested attributes needed for that interaction.

Implementation requirements

  • Use cryptographic protocols with bidirectional communication
  • Employ secure hardware (e.g., smart card chips)
  • Require independent certification of secure components

User control

  • The owner chooses where the personal agent runs (device or preferred cloud).
  • The owner can temporarily/permanently disable it to reduce tracking and control access.

Researchers or sources featured

  • Rene Mayrhofer (speaker; described as working in computer security and leading a research group)
  • Minority Report (2002 movie; cited as a science-fiction reference for seamless borderless identity-based movement)
  • Mentions of organizations (not presented as specific researchers):
    • Facebook
    • Google

Original video