The highly specialized world of digital identity is opening itself to a wider audience.
Announced Tuesday, the Trust over IP (ToIP) Foundation is backed by governments, nonprofits and private-sector firms. Key players include Mastercard, IBM and the Canadian Province of British Columbia.Â
A vast ecosystem of public bodies and private companies, large and small, are working on establishing decentralized digital trust, using an array of technologies. The ToIP Foundation, which will live within the Linux Foundation, is a move to rein together core issues that matter to all of them, as well as creating appropriate technologies.Â
Read more: COVID-19 âImmunity Passportâ Unites 60 Firms on Self-Sovereign ID Project
Drummond Reed, chief trust officer at digital identity startup Evernym, said the ToIP Foundation is about defining something as fundamental as the transport layers of the internet itself. But in this case, the technology stack is specifically for establishing trust between people and organizations rather than just between machines, as is the case with internet protocol (IP).
âToIP is able to address problems of establishing and maintaining trust between any two parties of any kind anywhere on the internet,â said Reed.
John Jordan, executive director of British Columbiaâs digital transformation arm, coined the term âTrust over IPâ â a play on the âVoice over IPâ technology that powers modern-day telecommunications.
Jordan, who has been working closely with the Hyperledger blockchain arm of the Linux Foundation, says the story of ToIP âisnât really a technology story.â
âThis is a story about how we help organizations, governments and people make good decisions about using technology to establish and build trustworthy relationships over the internet,â he said in an interview.
Founding Steering members include Accenture, BrightHive, Cloudocracy, Continuum Loop, CULedger, Dhiway, esatus, Evernym, Finicity, Futurewei Technologies, IBM Security, IdRamp, Lumedic, Mastercard, MITRE, the Province of British Columbia and SICPA. Contributing members include DIDx, GLEIF, The Human Colossus Foundation, iRespond, kiva.org, Marist College, Northern Block, R3, Secours.io, TNO and University of Arkansas. Â
For Jordan, the two core governance concerns of ToIP will be ensuring a privacy-enhancing and peer-to-peer architecture.Â
âNot client-server,â he said. âP2P is a respectful equal footing for both sides of the equation. As soon as we have an intermediary, our ability to evaluate the overall trust of that relationship is confounded. We also want to see that those interactions can be done in a way that is private.âÂ
Read more: Vinay Guptaâs Big Idea: An Identity Layer for Your Things
While governments like British Columbia can offer a natural cornerstone of trust to issue so-called âverifiable credentials,â the ToIP Foundation includes many trust-issuing starting points across finance, healthcare and education, said Reed.
âThere has been a lot of interest regarding COVID-19-related situations, both health and back to work,â he said. âThere are also several universities involved, looking at digital credentials in education which is just a huge area; itâs a whole industry.â
Mastercard has been deeply involved in work on digital identity, approaching it with a wide lens, not just on financial services, but also looking toward the delivery of digital health, education and government services.
Mastercardâs approach to digital identity is predicated upon a user-centric, distributed model, said Charles Walton, Mastercardâs senior vice president of digital identity. âPersonal information sits with its rightful owner, you. It boils down to: I own my identity and I control my identity data,â he said.
This cannot be accomplished in isolation, Walton added; Mastercardâ s participation within the Trust over IP Foundation builds atop the groundwork currently in place to ensure industry standards.
Mastercard envisions a âcollaborative digital ecosystem,â where âtrust providersâ can be organizations such as a bank, mobile network operator, university, or postal service that has a preexisting, trusted relationship with the user.Â
âTrust providers connect users to the ID service, enabling them to sign up, use, and manage their digital identity,â said Walton. âFor financial institutions, by providing digital identity access with ID, they can extend and build an even deeper relationship in new ways. Also, if ID is embedded into a bankâs mobile application, they become a part of each interaction the user has with their digital identity. Across all areas of life â financial, travel, health, education â the bankâs brand can be a part of it, delivering even greater value and recognition.â
Read more: Money Reimagined: A World Where Privacy and Saving Lives Can Coexist
The need for standards was echoed by fellow ToIP member IBM.
âThere is no ârecipe bookâ for the exchange of trusted data across multiple vendor solutions,â said Dan Gisolfi, CTO of the decentralized identity arm of IBM Security. âThe new Trust over IP Foundation marks an evolutionary step which goes beyond standards, specs and code, with the goal of creating a community-driven playbook for establishing âecosystems of trust.ââ