Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

5/15/2019
04:30 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

Microsoft Builds on Decentralized Identity Vision

The company elaborates on its plan to balance data control between businesses and consumers by giving more autonomy to individuals.

Microsoft wants to give people more control over their digital identities. In doing so, it aims to shift the power between consumers and the businesses currently holding most of their data.

Organizations have the bulk of control over users' information, and people are becoming more aware. More than 75% think companies need to protect their information — a 16% increase from last year — and 68% strongly agree it's their responsibility to protect their information. More are taking action by changing passwords and enabling multifactor authentication (MFA) after learning of a breach.

Still, more can be done, and Microsoft this week shared updates on its plan to reshape the future of identity. In February 2018, it outlined this vision and explained its investment in using blockchain and distributed ledger technologies to create decentralized digital identities. Rather than having people give broad consent to apps and services and spread their identities across providers, Microsoft wants them to have an "encrypted digital hub" for storing identity data.

"Our goal is to create a decentralized identity ecosystem where millions of organizations, billions of people, and countless devices can securely interact over an interoperable system built on standards and open source components," writes Daniel Buchner, program manager in Microsoft's Identity Division, in an update published Monday.

In a separate blog post posted today, Joy Chik, corporate vice president for Microsoft Identity, explained the role of businesses in helping to achieve this goal. She argues in a world where people have greater control over information, businesses must be more intentional about the type of information they collect, where it's from, where it's stored, and how much it collects.

"They accept information from individuals that an independent authority has verified, like citizenship verified by a government agency or education level verified by a university," she writes. With these verifiable credentials, people can prove who they are without the business holding all of their sensitive data. This puts less liability on organizations and gives people control. Further, businesses can choose to store data with people rather than keeping it themselves.

"The individual, in essence, becomes a data controller," she adds. "This changes the relationship — and the balance of power — within organizations."

As part of a decentralized identity (DID) system, public keys and identifiers can be linked to distributed ledger tech (Bitcoin, Ethereum, and others) that complies with standards set by the community via the Decentralized Identity Foundation (DIF) and W3C Credentials Community Group. But while these ledgers are useful for the foundation of decentralized identifiers, they should not be used to store personal identity data, Microsoft says. This demands different storage. Its solution is Identity Hubs, unveiled in early March, which are decentralized, off-chain personal data stores that give people control over identity info, official documents, app data, and more.

Since early 2018, Microsoft has been building on its vision with contributions to emerging industry standards and development of open source components, explains Alex Simons, vice president of program management for Microsoft's Identity Division, in Monday's blog post. This week Microsoft announced an early preview of Identity Overlay Network (ION). The is a DID network based on Sidetree, a blockchain-agnostic protocol for building DID networks; it was built in partnership with Microsoft and other DIF members, including Transmute and Consensys.

ION is a public and permission-less open network that anyone can use to create DIDs and manage their public key infrastructure (PKI) state. The code for its reference node is still under development, Microsoft says, and there are still aspects to be implemented before it's ready to be tested on the Bitcoin mainnet. In the coming months, it'll be working with open source contributors and players in the identity community to publicly launch ION on Bitcoin's mainnet.

Related Content:

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Firms Improve Threat Detection but Face Increasingly Disruptive Attacks
Robert Lemos, Contributing Writer,  2/20/2020
Ransomware Damage Hit $11.5B in 2019
Dark Reading Staff 2/20/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19668
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-17963. Reason: This candidate is a reservation duplicate of CVE-2018-17963. Notes: All CVE users should reference CVE-2018-17963 instead of this candidate. All references and descriptions in this candidate have been removed to preve...
CVE-2019-12882
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
CVE-2017-6363
PUBLISHED: 2020-02-27
** DISPUTED ** In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be 'obsolete, and should only be used for...
CVE-2017-6371
PUBLISHED: 2020-02-27
Synchronet BBS 3.16c for Windows allows remote attackers to cause a denial of service (service crash) via a long string in the HTTP Referer header.
CVE-2017-5861
PUBLISHED: 2020-02-27
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-1000020. Reason: This candidate is a reservation duplicate of CVE-2017-1000020. Notes: All CVE users should reference CVE-2017-1000020 instead of this candidate. All references and descriptions in this candidate have been removed to...