Tuesday, 11 July 2017

Just in case

From early adoption to maturity

Around 15 years ago, my mother asked what I wanted for Christmas.  My answer was a new wallet (please) and my requirement was that it had to have plenty of slots for cards.  This was in the boom years for store loyalty cards and credit card companies bribing you with gifts and incentives for singing up and using their cards.  At a guess, I’d say that my wallet contained over 20 different cards at any one time.  Fast forward to today and my wallet has 3 cards and a driving licence in it; and far less cash than I used to carry around.  Yet I have more store cards than you can imagine - a full sweep of supermarkets, varying qualities of chicken and burgers, purveyors of camping equipment (used once every ten years on average), sports centres, airport lounge passes, airlines, et al – though now they’re virtual, in my digital wallet.

As a relatively early adopter of technology, I don’t want a wallet for Christmas.  In fact, I don’t want a wallet at all.  My payment method of choice is my watch (smartphone payments are so 2016!).  So why do I still carry my wallet with me?  Well, mainly, the answer is “just in case”.  For those annoying times when shops either don’t accept new money at all or insist that under a certain amount I have to pay with metal or polymer like they did back in the day.  It seems that no matter how I explain that the percentage charge for credit card transactions is less than they’ll spend on cash handling some shops still haven’t moved with the times.  Whilst I have been known to make my evening meal choice based on payment method rather than cuisine, I haven’t quite reached the point of boycotting all providers who don’t allow me to flash my watch at them.



Yet it isn’t just the merchants who cause me to carry my wallet with me “just in case”.  You see my watch likes to behave like a child who has been dragged away from the chocolate at the counter and sometimes has a tantrum – either not working at all or asking me to try again later; of course I don’t mind coming back to re-do my shopping at a time my watch finds more convenient.  Sometimes I can flip back to 2016 and use my smartphone to pay, other times I have to fish my wallet out, put my card in to the slot and try and remember the random number; occasionally it’s good to reminisce about how my parents paid for things when they were my age.

Of course, it isn’t just payments and retail.  The other thing in my wallet is my driving licence.  Now admittedly, it’s been a few years since anyone has asked me whether I’m old enough to buy alcohol without laughing; though I have been asked to prove my identity when taking out credit agreements when having my driving licence has been really handy.  Though of course driving licences aren’t identity documents, they show my entitlement to drive.

Which brings me on to another just in case moment – the UK National Identity card.  Whilst it never got as far as full rollout, the pilot programme issued real cards to real people, and allowed them to do real things – such as use their card instead of their passport to travel within the EU.  I remember standing in Birmingham Airport, with a passport hidden in my back pocket, with the good folk at boarder control crowded round a PC screen whilst I showed them the government website and explained how it all worked.  Whilst I was prepared to hold my nerve for a while, faced with being right and not on the plane or pulling out the just in case passport and being on the plane, I would have gone for the latter option.

As you can imagine, when the Driver and Vehicle Licensing Agency (DVLA) announced that they will roll out a version of your licence on your smartphone and the UAE started allowing passengers at Dubai to use their smart-wallet passport to cross its border, I was rather excited that my wallet was moving one step further towards being consigned to history – much like my DVD collection.

The pace of innovation will always be constrained by uptake, adoption, prevalence, ubiquity and reliability.  For early adopters, the need to have a back-up – just in case – will always remain; the challenge for innovators is to reduce the time taken to move into the mainstream.  Having spent 15 years winding down on my wallet dependence I am well aware just how long things will take.  I really hope that in another 15 years I won’t have to carry my driving licence with me – or better still than what’s on my smart-wallet will be my driving licence rather than just a version of it.  And that my passport doesn’t have to come on holiday with me in my back pocket just in case.

As we move towards reliable, trusted, digital identities – our entitlements, such as payments, driving licences and passports, should be asserted digitally regardless as to whether we are using them in an online or physical channel.  The cost savings, fraud reduction and improved customer experience will be immense.


And my biggest wish, is that my DVD collection doesn’t fall through the creaking roof from the loft where I’ve stored them in preference for streaming. And why I have stored them? Well you know, just in case.     


Read my other posts
Let's get physical - how to get fit for the digital era by leveraging the offline world
I have control - Can we truly own our identity
Tipping the balance - Getting the right balance between security and user experience
You don't know what you're doing - Poor security practices are putting users at risk 
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA



Connect with Bryn on Linked In: Bryn Robinson-Morgan

Monday, 17 April 2017

I have control

Can we truly own our identity?

Digital identity is a complex subject; as with most digital transformations, taking a process that exists in an analogue world and digitising it for use online doesn’t create a great solution.  A number of models for digital identity exist, and are often spoken about in terms such as centralised, federated, distributed, user-centric, self-sovereign.  There are countless papers by the great and the good of the identity world that talk about the merits and flaws of the varying models.  There’s a school of thought that centralised is bad and self-sovereign is the panacea for digital identity – though often these ideas focus too much on the model and less about the use.  And the arguments are often mired in digitisation of analogue.

Self-sovereign digital identity is a model which:
  • Places the individual in absolute control of the digital representation of themselves 
  • Is based upon the kernel of self that exists in the real world
  • Assures the individual of access to all the data regarding them and provides transparency of how data flows
  • Persists for as long or as short as the individual decides
  • Assures portability and interoperability
  • Functions on explicit user consent
  • Operates sharing based on principles of data minimisation

These are all traits which it is hard to argue shouldn’t be the foundation of any digital identity model – never one to shy away from an argument, here goes:

Places the individual in absolute control of the digital representation of themselves 
Until such time as we plug in to the matrix, a digital identity and the flesh and bone which it represents cannot be linked with absolute certainty.   When the link between the two is, or is reasonably believed to be broken, control of the digital identity must be revoked (either permanently or temporarily).  This introduces a higher power of control over the individual’s identity.

Is based upon the kernel of self that exists in the real world
Identity in the real world is also complicated.  In the real world, our identities are often assigned by central authorities such as governments; or they’re guaranteed by 3rd parties such as our parents; or they’re accepted based upon assigned attributes such as name, address and date of birth; or they’re based upon our DNA.  And more often than not, they’re a combination of all of these.  If our digital identity is based upon our real-world identity it cannot be self-sovereign.

Assures the individual of access to all the data regarding them and provides transparency of how data flows
We should always strive towards openness and honesty.  Yet there are circumstances where we need to keep data hidden and circumstances where its beneficial for the user to do so.  As an example, the organisation who will rely on digital identity are often required to check for fraud and criminality against our identity.  This isn’t information that we should give to the user, yet it is often closely tied to their identity.  So commercially and practically it needs to flow with the identity assertion.  When we give information to an individual, we also have a duty of care not just when that data isn’t correct, yet also when that information risks disenfranchising the individual.  Credit scores used to be information passed from Agency to Supplier about the individual without their involvement.  This changed, and in the last 20 years, they have gone from information that we know, to information that we can actually manage.  Yet for many people, a poor credit score creates exclusion – which leads to disenfranchisement.  If digital identity is to be inclusive, the data that we give back to the individual needs to have the duty of care built in.  We should work towards openness, we shouldn’t dive straight into it without understanding the consequences.

Persists for as long or as short as the individual decides
For some nations, having a government issued identity card is mandatory, for others it is optional or simply doesn’t exist.  Rather than eulogising on which is right, digital identity needs to recognise all models do and will exist, and look to provide a digital identity model which supports mandatory and optional membership of government registers.  Similarly, fraud systems need to persist identity elements to protect from bad actors.  We can offer choice in how long our digital identity as a “thing” persists, on the data that makes it up we can’t.

Assures portability and interoperability
Data portability is a convenience factor that shouldn’t be wilfully restricted.  Identity portability is where the value and complexity lies.  In order to drive the market, the work done in proofing the identity and attribute claims can’t simply be ported from one party to another.  To do so risks separation of effort and reward, which disincentives the commercial efforts required to develop and maintain a functioning marketplace.

Interoperability can only be assured with mutual trust.  Mutual recognition is reliant on the creation and adoption of interoperable standards.  Interoperability of systems should only be required once interoperability of standards is achieved.  We shouldn’t expect that everything interoperates with everything else unless everything is equal.

Functions on explicit user consent
The notion that an individual can explicitly permission what data is shared by whom and with whom is reliant on goodwill that doesn’t exist.  If we are given the choice to share only positive information and withhold anything negative, this is going to be a common choice.  This will restrict the ability for the receiving organisation to rely on the data.  Hobson’s choice (take what’s on offer or nothing at all) isn’t explicit consent for data sharing either.  We should be far more honest with how we define consent, so that a user understands when we need broad consent to search for good and bad information about their identity and when we’re seeking explicit consent to only share attribute X from organisation Y with organisation Z.

Operates sharing based on principles of data minimisation
Users shouldn’t need to understand the principles of data minimisation.  In a self-sovereign model, where they’re free to share their own data as they choose with whomever they choose, they need to understand who they’re sharing their data with and whether they’re only asking for the data they actually need.  In other models, such decisions are made on behalf of the user based upon their own rules -  for example, the Passport Office can permission that “X holds a valid passport” and “X is a Citizen of country Y” to be shared with anyone that the individual wishes; and that “X has passport number 12345678” only with parties which it trusts – which takes away both the control and the responsibility from the individual. 


Self-sovereign identity is a utopia that may never exist based on principles that may be better achieved through other means.  We should focus more on the things that a user needs from a digital identity and worry less about the model that we use to achieve them.  In designing digital identity, if we do so based on principles the user will value, and deliver them in a way which they will engage, we have the opportunity to revolutionise identity for the digital age.  Can we truly own our identity?  Does it matter providing we can assert our identity when we need to, to get things done?


Read my other posts
Let's get physical - how to get fit for the digital era by leveraging the offline world
Just in Case - From early adoption to maturity
Tipping the balance - Getting the right balance between security and user experience
You don't know what you're doing - Poor security practices are putting users at risk 
I didn't say you could touch me - Biometric authentication and identity
You don't need to tell me - Impacts of the EU General Data Protection Regulations
Coming together on being alone - The need for a clear government digital strategy
I'm not the person I used to be - Authentication for real world identities
Distributed Identity has no clothes - Will distributed ledger technology solve identity
Bring Your Own Downfall - Why we should embrace federated identity
Unblocking Digital Identity - Identity on the Blockchain as the next big thing
Tick to Agree - Doing the right thing with customer's data
The Kids Are All Right - Convenient authentication: the minimum standard for the younger generation
The ridiculous mouse - Why identity assurance must be a rewarding experience for users
Big Brother's Protection - How Big Brother can protect our privacy
I don't know who I am anymore - How to prove your identity online
Three Little Words - What it means for your business to be agile
Defining the Business Analyst - Better job descriptions for Business Analysis
Unexpected Customer Behaviour -  The role of self-service in your customer service strategy
Rip it up and start again - The successful Business Transformation
Too Big To Fail - Keeping the heart of your business alive
The upstarts at the startups - How startups are changing big business 
One Small Step - The practice of greatness
In pursuit of mediocrity - Why performance management systems drive mediocrity

About me

Bryn Robinson-Morgan is an independent Business Consultant with interests in Identity Assurance, Agile Organisational Design and Customer Centric Architecture.  Bryn near 20 years experience working with some of the United Kingdom's leading brands and largest organisations.

Follow Bryn on Twitter: @No1_BA



Connect with Bryn on Linked In: Bryn Robinson-Morgan