New approach to ID verification aims to safeguard privacy

By Nicola Brittain

29 Oct 2009

Comments: 8

A Computing logo
Collage depicting security measures
The Global Trust Council's scheme would reduce the need for biometric security

Government and industry are being encouraged to take part in a new electronic identity scheme that could put control of online privacy back into the hands of individual web users.

International policy body the Global Trust Council (GTC) hopes to put a universal legal framework in place that will see online identity verified using “relationships”, sidestepping the need for database-held information, and upholding the individual’s right to privacy and to retain details of their identity.

How would it work?
Service providers looking to establish an online identity would ask the user for access to organisations with which they have a relationship ­ such as a bank or government department.

Once the organisation had responded, a witness would oversee dealings between the user and service provider.

“The organisation would only need to give a yes or no answer,” said Andre Laperriere, director general of the GTC Secretariat. “For example, the state might say that the person either is or isn’t a British citizen.”

As soon as the individual is asked to verify more relationships, it becomes increasingly difficult for them to be faked.

Benefits of the scheme
Adoption of the scheme would bring two important benefits, according to GTC. First, the individual will retain their identity, meaning that they do not have to give personal information to the state.

“To get into some countries such as the US you must surrender vital information about yourself such as the map of your eye, or your fingerprints. The minute the US government has that fingerprint, it is not yours any longer,” said Laperriere.

Second, the scheme would halt the creation of mountains of personal information and help prevent personal data going awry ­ – such as when insurance firm Zurich lost personal information relating to 50,000 UK customers that had been stored on a backup tape.

“A high-level legal framework of this sort is the missing piece and it would allow smoother business transactions and easier dealings with the state,” said Ant Allan, research vice president at analyst Gartner.

“There are already technical models in place such as Microsoft’s Geneva or Open ID - as used by Google - but they do not yet sit within a legal framework so there is no basis of trust that would enable online financial interactions.”

GTC wants government and commerce to be involved in the scheme, and several countries including Sweden and Switzerland will launch pilots next month, with two undisclosed UK-based financial companies also carrying out internal trials.

The council will also hold a place at the Commonwealth heads of state meeting on 27-29 November.

Laperriere said there were major financial benefits to the scheme. “The relationships-based system will see reductions in trading time, eliminate the need for databases held online, and mean that there were more potential business partners for commerce ­ – thereby cutting costs and increasing opportunities for banks and other businesses,” he said.

The GTC is looking to bring 20 member states on board by this time next year. It also plans to have established more than 200 sector-based policy initiatives in the same time frame, including areas such as e-banking, e-voting and e-commerce.

But there is still work to be done, said Allen. “Commercial institutions will need to be convinced that there are commercial benefits; without a business incentive to take up this scheme, it will not get beyond the theoretical stages,” he said.

Reader comments

Technology Frameworks Are as Vital as Legal Frameworks

Philosophically, the Global Trust Council has outlined a vital series of core goals and principles. Putting the individual back at the center of the equation is critical, and the debate between the individual and the state is at the heart of the ongoing healthcare debate in the United States. My colleague at CLOUD, Inc, Paul Wilkinson, and I wrote on this topic in a recent law review article, "Set the Default Open." Written within American jurisprudence, it still has global implications and looks at both legal frameworks and technology. It can be found here: http://www.trolp.org/main_pgs/issues/v14n1/Thompson&Wilkinson.pdf

However, the GTC will not achieve its lofty goals if it is dependent on Microsoft's Geneva or OpenID. It is not that these frameworks are not good and solid work, but they are a solution to the wrong problem. Both of these approaches assume that the foundation of the Internet and the Web as they exist today are static. CLOUD, Inc. believes the Internet is broken. While HTML sparked an Internet boom, it made people look at the Internet as a way to connect Web pages, not people.

Securing user data scattered among large numbers of Web silos is complex and consumes huge amounts of every users? most valuable resource: time. The solution isn?t another identity standard or method for data portability. It?s a paradigm shift. CLOUD?s technology standard is that shift. It transcends mere identity to empower Internet users to control precisely how their information is used. Think of it as a privacy and authenticity standard that can work in more ways than HTML for the simple reason that it marks up facts about people, not text. The standard would permit anyone ? user or service provider ? to develop tools that are simultaneously more sophisticated and easier to use.

This new fabric is the vital piece in the puzzle to make noble goals, like the GTCs, possible. The evolution of identity rights, its history and its future is addressed well by Peter Vander Auwera of SWIFT here: http://petervan.wordpress.com/2010/03/14/identity-rights-system-3-0/.

With the right legal frameworks AND the right technology frameworks, the vision embraced by the GTC can truly put power back in the hands of individuals.

Posted by: @ANewCLOUD  23 Mar 2010

Ask me first.

Does this really mean that my bank, hospital, and administration would ask me when they want to access my files? That would be great!

Posted by: Aymen  13 Nov 2009

Finally

No more big brother. Finally an initiative that takes the individual in consideration!

Posted by: Tom  09 Nov 2009

Great News

This is more that great! We really need this to secure ID and make digital business on the global market!

Posted by: Nalp Nillin  29 Oct 2009

The Swedes

It seems that we see around the corner, a new safer Internet. Swedes solves the problem and gives the solution that the globe so long waiting for. The need is huge.

Posted by: AndrewE  29 Oct 2009

Trust

Its about time! It's time for a change and reestablish the trust within all digital interactions or transactions. The financial institutions really need it to secure existing payment solutions, out of today's chaos.

Posted by: Werner Haag  29 Oct 2009

Can't Wait

This would ensure that the hated UK ID Card and sinister National Identity Register can be forgotten about, and the IPS go back to its traditional job of issuing passports. I can't wait.

Posted by: Simon Evans  29 Oct 2009

New e-me

Finally, I will be in charge of my own e-Me (digital identity)! Wherever I go, my e-Me be a companion, regardless of borders.

Posted by: Stefan  29 Oct 2009

Have your say on this article

All fields required. Your email address will not be displayed on the site.

By submitting a comment you agree to abide by our Terms & Conditions

  • Digg
  • Tweet

Newsletters

Sign up for our FREE newsletters

Technology Patent Wars

Large companies such as Microsoft, Facebook and Google have been hoovering up technology patents recently. Is this stifling innovation?

88 %

5 %

7 %