(This is a Japanese machine translation. The original English is available here.)

Ladies and gentlemen,

Let me take you on the OpenID community’s journey through the evolution of digital identity. This story continues to this day. I have been involved in this community from the beginning, so I believe I can give you a fairly reliable account. There are also several lessons we can draw from this story.

It all began with OpenID 1.0. It was a simple yet innovative solution that enabled blog owners to prove their identity online. At its core was a self-asserted identity system in which trust was built through history and interactions within the blogging community.

The transition to OpenID 2.0 sparked a major expansion. What began as a blog-centric solution attracted diverse communities engaged in similar initiatives. The introduction of OpenID Providers brought major platforms such as Yahoo into the ecosystem. This movement gained international momentum, and in Japan, the establishment of the OpenID Foundation Japan was featured by major television stations and magazines.

As the community grew rapidly, we also encountered challenges. Because of its initially informal nature, even intellectual property rights were not properly managed. I spent 4 years resolving this situation.

Although OpenID 2.0 was successful, it had limitations. It faced problems of cryptographic vulnerability and complexity, which hindered adoption. Traditional solutions such as XML Digital Signatures had similar problems. We therefore developed entirely new signature formats, JWS and JWT, which became the foundation of OpenID Connect.

The impact was significant. Google led the implementation, many companies followed, and eventually Apple joined the movement as well. The smartphone revolution spread OpenID Connect throughout the connected world, permeating both private-sector applications and government services.

But is that the end? No, it is not.

We face 3 critical challenges.

  1. Only half of the world’s population has access to smartphones.
  2. Many governments still lack the infrastructure to provide citizens with legal digital IDs.
  3. Traditional identity providers can verify only a limited subset of information about us, placing a heavy burden on issuers that must provide scalable systems operating 24 hours a day, 365 days a year.

Japan’s advanced digital identity infrastructure is certainly impressive, but it is exceptional from a global perspective. We need a more versatile solution to which issuers can connect only when needed.

The path forward requires a stronger, more collaborative community. Fortunately, Japan has a community that transcends organizational boundaries. In the 8th month of this year, FIDO, W3C, and the OpenID Foundation Japan jointly held an event attended by more than 200 people, exceeding the venue’s capacity.

SIDI Hub Tokyo is a new step in this initiative. It brings together a broader community. I would like to thank the Digital Agency for bringing us together and providing such a wonderful facility. I look forward to meaningful discussions.

Thank you.

Slides: https://gamma.app/docs/The-Evolution-of-Digital-Identity-OpenIDs-Journey-sb1lbqdx3ozjhg1


Related posts