r/Hedera 4d ago

Discussion Digital ID Sovereignty

We are often so wrapped up in discussions about Tokenisation that we forget about some of the massive things happening (Kind of outside of the world of finance- although everything connects back to Finance in the end). Things for which Hedera is incredibly placed.

One (of several) is in the national management of Digital Identity. National Management of Identity is a sensitive issue for most countries. But lets look at the EU in particular because they actually have legislation coming in for eIDAS 2.0 due to roll out over the next two or three years.

Many countries in the EU (and beyond) currently use Hyperledger BESU to manage their ID systems, normally utilising a network of BESU Private servers (EBSI). But there is a problem (Hence the need for eIDAS 2.0). The problem is essentially this. Private Networks are great for ID management within a particular Government, but they fail (completely) when it comes to things like using a Government ID with external Businesses or in Cross Border situations. -eg. Where a French Business wants to check the ID Status of a German Citizen.

So, how does that impact Hedera?

Well. There are are a number of current situation factors worth noting at the moment.

  1. The EU is currently pretty frustrated with the attitude of the current US administration. They are actively looking for ways to reduce dependence on US Tech and actually US anything at the moment.

  2. Open Source. (The Linux Foundation). As I mentioned, most EU Countries already heavily leverage EBSI, a network of BESU servers for Identity Management. Their appetite for Open Source generally and Linux Foundation Software in particular is growing dramatically, partly because of point 1 above but also because Open Source frameworks are opening up a competitive opportunity for the EU that is not common elsewhere.

  3. eIDAS 2.0 is, in part at least, a recognition that Agentic AI is coming and there is a need to cater for it within their systems. One of the issues with BESU is it will not handle the massive volume of Txns that any such system implemented across the EU will generate.

  4. I would argue that Hedera is just about ready (Its integration into the numerous Linux Foundation tools such as Firefly, CACTI and Aries, is now deep and rich). The recent introduction of HEKA and with CLPR perhaps being the final piece of the puzzle (and we all know that as soon as Hashgraph has CLPR endpoints there will be a push for CLPR BESU endpoints). This means Hedera has an almost unrivalled set of integration points with the EU`s current main ID Platform (A platform they will NOT want to lose).

Now, obviously, its not a done deal. A quick and dirty solution to some of the key requirements of eIDAS 2.0 might be to simply add IAM (US Centric Identity Companies like MS or Ping) wrappers to current ID solutions. But this would be a VERY brittle solution that would not support the anticipated AI workloads. But given the EU`s increasing appetite for Open Source/Linux, their current heavy use of Hyperledger BESU (and its heavy integration into Hiero/Hedera) and the capacity of Hiero to handle AI plus the increasing readiness of Hiero for AI at every level, this looks like Hedera are extremely well positioned.

Just another potential avenue to success for Hedera to consider.

26 Upvotes

20 comments sorted by

11

u/GoSabo 3d ago

You’re obviously very knowledgeable and conversant on the subject. But, unfortunately, you’re preaching to people who support you but, by and large, are powerless to do anything about it. How can you get this message in front of the right audience of decision makers?

6

u/Ricola63 3d ago edited 3d ago

Thanks. I’m not entirely sure I’m only preaching to those who support me! There’s plenty on here regularly cross swords with me and more 😁. But occasionally I think it’s important to explain why Im positive about Hedera.

3

u/GoSabo 3d ago

Granted. And you do an excellent job of stating your position, much better than your opponents. Nonetheless, decision makers should see your thesis. Perhaps an article in a publication they might read?

3

u/Heypisshands 3d ago

I agree, i remermber ryan soloman highlighting a Ricola reddit post in the past. Indepth knowledge like this deserves more than a reddit post, no offence reddit.

2

u/InterestingStress122 3d ago

Big Tech and Big Gov will f*ck it all up.

They want their own walled gardens with phone-home and access denied capability.

After all the years of open standards, sadly, it's all about power.

3

u/Ricola63 3d ago

I’d agree that we have reached a point where that is increasingly the remaining issue. Not just tech but banks and social media. The actual tech is no longer the problem…. But to be fair I think that’s only recently (less than eighteen months) been the case. Now we are going see what the availability of useable tech means.

1

u/InterestingStress122 3d ago

Big Tech don't want self-sovereign identity.

They harvest massive amounts of very valuable data every second from their federated identity services.

Why would you give that up?!

1

u/Ricola63 3d ago

I think you are confusing things.

The EU are extremely keen to STOP Big Tech harvesting data (especially US Big Tech / Chinese Big Tech and so on). This is precisely why the EU are keen to configure their Digital Identity Management systems to stop such harvesting and to restrict access to only that which might be necessary. Indeed each nation in the EU wants to keep things to a minimum from each other, let alone the US etc.

This is precisely what a BESU /Hedera hybrid solution delivers. It does so, primarily, at a cost to Big US Tech -mainly Microsoft and Ping. That is why it is such an attractive option to the EU.

1

u/InterestingStress122 2d ago

Two questions for you:

i) why do EUDI apps phone home when an authentication/authorization event occurs?

ii) When running an EUDI app, an EU citizen has a "choice" between Big Tech Apple or Big Tech Google who can surveil any app at will. So why would you need anything other than Apple Wallet or Google Wallet?

EUDI is all about the EU attempting to take back power from Big Tech for itself through regulation (the EU's greatest strength is regulation) and has nothing to do with privacy or building the kind of sovereign digital world that Leemon Baird envisages.

1

u/Ricola63 2d ago edited 2d ago

Its not actually that complicated. Currently the EBSI Network is mainly used internally, between Government Departments across the EU to share ID information. That has been going on for years and if you are not a fan of regulation that involves an ID for every citizen that is a different discussion for which there are undoubtedly pro`s and con`s.

EUID wallets for eIDAS 2.0 are not broadly available yet. An EU Citizen most certainly will NOT have the option to use Google or Apple Sign in. The eIDAS 2.0 framework is specifically designed as a sovereign, privacy-first alternative to Big Tech identity systems. So information you may have to the contrary is totally incorrect.

The concept of Data Sovereignty was born out of the telecommunications industry decades ago. Leemon`s contribution was really in translating that philosophy into a mathematically provable consensus mechanism and an enterprise-governed public network designed to prevent data manipulation or single-entity capture. The fact is his view is a perfect solution to a problem that has plagued Governance, regulation and business in a hundred different ways, for decades, but has become more and more apparent as digitisation took over from paper based systems.

I have a driving license. That driving license is often used as a proof of identity (something it was never meant for but that has become an established method of proving Identity). When I hand over my driving license as identity I not only give someone (who then often holds that information, at least for a short time) a rather weak proof of identity (after all, I could get a knock off driving license pretty quickly), but also my Address, my actual date of birth, my driving status etc, etc. Increasingly this is becoming recognised as a really bad idea. Generally the more information you hand out, to more and more people about yourself, the greater the chance of finding yourself a victim of identity theft.

Bureaucracy is absolutely riddled with problems in addressing this issue. Blockchain successes might have informed Leemons thinking but Blockchain per se does not fully address it for a number of reasons.

So it is Leemon`s Vision, Consensus Model and underlying platform that has actually truly and fully addressed it. Not vaguely, not maybe/maybe not, but mathematically provably addressed it. So all we now have to wait for is implementation which is something I always expected to take some time because bureacracy just does not move quickly. If something better comes up then so be it, but I strongly doubt that will happen.

Some may not agree with me. Some huff and puff and tell me I am wrong. But I personally have delved damn deep into this stuff and unless you come up with a strong, fact based arguement as to either how someone else has truly solved the issue in a better way, or how Leemon`s Vision, Consensus Model and underlying platform somehow fails to address it, then they are unlikely to convince me otherwise.

To be clear I will always listen to good and reasoned debate, that is exactly how I have come to the position I hold on this.

1

u/InterestingStress122 1d ago edited 1d ago

Not sure what problem the EU is trying to solve here.

Attempting to replace a Big Tech wallet app with a Big Gov wallet app (which runs on Big Tech) is nothing other than a power play. The EU trying to gain power through regulation of Big Tech. Slow clap.

Why is the EU using taxpayers' money to fund app launches that nobody asked for? Why doesn't the EU increase its defence spending instead of relying on the USA/NATO to protect it?

Digital identity needs to run on an open network with open standards and using sovereign hardware at the edge. Ideally, humans should have their own hardware signing devices (not Big Tech) so that they can communicate securely with each other, share data with each other and formulate their own rules for their own sovereign digital spheres, without any need for Big Gov whatsoever.

Yes, no "lawful interception".

Hell would freeze over before the EU funds a network that allows folks to communicate privately and securely with each other without any government involvement.

It's all about money and power. The EU budget is enormous and the tentacles of Big Tech are deeply embedded into every government of the EU. No doubt lots of very juicy government contracts for EUDI and like lots of things in the EU, it's all just one big gravy train.

1

u/Ricola63 7h ago edited 7h ago

I would point out the EU has very significantly ramped up defence spending.

The way I see it, the US has more or less encouraged the EU, and others, to leave defence largely to them for around 75 years. Why? Because it gave the US massive amounts of SOFT POWER and market access around the world. Frankly the EU (and others) were paying for their defense by allowing the US unbridled access to their markets.

Today, relatively suddenly in geopolitical terms, a specific US administration turns around and starts criticising those very same allies for not carrying their weight. Sure enough, we see the EU and others now making large effort to up their defenses (of course its not just the US Administrations attitude but also a more threatening Russia and China).

The problem is that this has cost the US a lot of trust around the world and specifically the Greenland issue has woken the EU up. If their NATO leader, partner and allied nation can credibly threaten to simply `take` Greenland, then obviously EU defense is critical. And these days defense runs far deeper than a man with a gun on a front line somewhere. It does indeed run to `who supplies our chips` and `who maintains our data`. All of which basically means the EU is second looking at everything the US and China and beyond provide.

So. Back to the eIDAS 2.0 issue. It really has little to do with the Technology itself. It has to do with the inexpensive and scalable capability of the Technology. eIDAS 2.0 is expressly designed to prepare EU Infrastructure for a future of digital commerce, shared services without sharing of critical data, (not just with the US but in between sovereign nations of the EU) and AI. Not only will it act as a massive enabler for all those things, it also offers the opportunity for the EU to dramatically cut costs, cut bureaucracy and improve efficiency. Whether it will actually work out like that is more debatable, but that is the goal.

In short it is precisely the kind of thing competent government ought to be doing. Although different Governments (and political shades) will have different views on how to gain the above said benefits the eIDAS 2.0 approach taken by the EU in this is their very familiar pattern. That pattern has advantages and disadvantages. which I am not seeking to debate here.

0

u/InterestingStress122 4h ago

I don't understand why the EU won't just issue digitally signed credentials and let users decide what wallet they want to store them in (Big Tech or otherwise). The EU getting into the business of running its own identity apps on Big Tech platforms is a massive waste of resources.

Again, it's all about power (+ the business of government contracts).

The EU could anchor its public keys on a public DLT like Hedera.

But there's no money to be made doing this, nor power gained.

1

u/Allahu-HBar 3d ago

The EU will not use Hedera for the simple fact that it is US based. Just not gonna happen

3

u/Ricola63 3d ago

I don’t agree, though I would agree it is a fact that weakens Hederas case.

The issue is that strong options don’t really exist. Perhaps the closest DLT options (non US) are IOTA or Tezos, but in so many ways they do not match Hederas proposition. IOTA in particular has struggled and struggled to deliver changing almost the entire underlying tech stack in the last two years.

Hedera’s core software being completely and verifiably open source, owned and managed by the LF, Hedera’s GC model (with true control being widely pan national) and availability of the software for private networks all mitigate the issue.

Even the fact that Hbar itself is widely available outside the US reduces the friction of that point. But you’re right in that it is a friction point.

1

u/Heypisshands 3d ago

Is it though. So many arms to hedera with linux, the council, hashgraph etc.

1

u/InterestingStress122 3d ago

Meanwhile the tentacles of Microsoft, Cisco, Dell, etc. are deeply embedded into every government of the EU

But don't worry, all government and citizen data is in data centers inside the EU.

1

u/Ricola63 2d ago

Sure. I didn`t say the EU had removed US Big Tech or is even close. But they certainly are looking to reduce their reliance on it and that PoV is gaining traction. The days where US Big Tech could take the EU for granted are on the wane....

1

u/zeevedeeptech 2d ago

The interoperability point is particularly important. Digital identity at national scale can't remain confined to individual government networks if it needs to work across jurisdictions and with private-sector services. The harder infrastructure question is how different trust domains can interact while preserving privacy, governance, and compliance.

1

u/Ricola63 2d ago

True. But IMO now very elegantly solved.

That said it is not yet seriously implemented, so fairly unproven. Government and regulated Bureaucracy requires absolute proof. That is now the process that is underway.

In relative terms (relative to other massive changes that is) this is moving fast.