







archived 8 Jul 2012 20:39:42 UTC
The Path to Self-Sovereign Identity
Today I head out to a month-long series of events associated with identity: I’m starting with the 22st (!) Internet Identity Workshop next week; then I’...

SPIFFE | Secure Production Identity Framework for Everyone
10 Years of SPIFFE! Express your interest in Community Day 2026 →
Identity is the Platform
This is the talk I gave at Mindtrek in Tampere, Finland. Slides are available here: http://factoryjoe.com/blog/2009/10/01/identity-is-the-platform/
IAM Confused: Decoding 8 Real World Cloud Identity Breaches - Maya Levine, Sysdig
Solving AT Protocol's Centralized Identity - blog.boscolo.co
I spent the weekend building a proof of concept for a truly decentralized DID method using Farcaster's battle-tested identity system. Here's why AT Protocol needs this third DID option.
SyRA: Sybil-Resilient Anonymous Signatures with Applications to Decentralized Identity
We study Sybil-Resilient Anonymous (SyRA) signatures, a cryptographic primitive that enables credentialed users to generate, on demand, unlinkable pseudonyms tied to any given context, and issue signatures on behalf of these pseudonyms. Concretely, SyRA allows a distributed issuer to turn any legacy identity or personhood identifier, possibly of low entropy, into a unique associated cryptographic key of high pseudoentropy, for use in generating signatures for any given context. Sybil-resilient anonymous signatures achieve three main objectives: 1) Sybil resilience: every user is entitled to at most one digital identity, 2) anonymity: no information about the user’s real identity is leaked, and 3) non-interactive context switching: users can create on their own at most one credential for any given context in a manner that is unlinkable across contexts. We conceptualize the SyRA primitive as an ideal functionality in the Universal Composition (UC) setting and put forth SASSI, an efficient, pairing-based construction that realizes it by utilizing two levels of verifiable random functions (VRFs), a design which may be of independent interest. The first level consists of threshold VRF issuance of a user’s unique secret key tied to their real-world identifier. The second level allows a user to create signatures for each context, under a unique pseudonym per context. Compared to prior cryptographic tools capable of realizing SyRA, SASSI has the unique feature that issuers are stateless and hence do not need to retain any information about past user interactions, a relevant property for a decentralized implementation. We overview various applications of SASSI in multiparty systems, such as cryptocurrency account management and airdrops, e-voting (e.g., for decentralized governance), and privacy-preserving regulatory compliance (e.g., AML/CFT checks). In the context of creating addresses for digital assets, SyRA signatures enable users to embed their legacy identity into their address in a manner that protects their privacy for each application with which they interact. We demonstrate the practicality of SASSI by providing an implementation and performance evaluation of our construction.

Keri.one | The First Truly Decentralized Identity System
Key Event Receipt Infrastructure (KERI) is the first truly fully decentralized identity system.
Building the world's trusted identity platform • Yoti
Our comprehensive suite of customer verification tools make it easy for businesses to be compliant and safe for people to prove who they are.

Sirraya One | Enterprise Decentralized Identity Platform
NIST-certified quantum-resistant identity with zero-knowledge proofs. Government & military-grade verifiable credentials.

tassis/atfield-core
Framework-agnostic AT Protocol utilities for identity resolution and public record reads.
2026 List of Identity and Related Conferences and Standards Development Events
Agenda and minutes of meetings of the Federated Identity Community Group - fedidcg/meetings
Evolution of AI Agent Registry Solutions: Centralized, Enterprise, and Distributed Approaches
Autonomous AI agents now operate across cloud, enterprise, and decentralized domains, creating demand for registry infrastructures that enable trustworthy discovery, capability negotiation, and identity assurance. We analyze five prominent approaches: (1) MCP Registry (centralized publication of mcp.json descriptors), (2) A2A Agent Cards (decentralized self-describing JSON capability manifests), (3) AGNTCY Agent Directory Service (IPFS Kademlia DHT content routing extended for semantic taxonomy-based content discovery, OCI artifact storage, and Sigstore-backed integrity), (4) Microsoft Entra Agent ID (enterprise SaaS directory with policy and zero-trust integration), and (5) NANDA Index AgentFacts (cryptographically verifiable, privacy-preserving fact model with credentialed assertions). Using four evaluation dimensions: security, authentication, scalability, and maintainability, we surface architectural trade-offs between centralized control, enterprise governance, and distributed resilience. We conclude with design recommendations for an emerging Internet of AI Agents requiring verifiable identity, adaptive discovery flows, and interoperable capability semantics.

IIW – Internet Identity Workshop
The Internet Identity Workshop — where the identity community meets to discuss and advance digital identity.

ATProto as Agent Identity Infrastructure: A Case Study for NIST's Concept Paper — Filae
How ATProto addresses NIST's four pillars of AI agent identity — identification, authorization, delegation, and logging — with concrete examples from deployed infrastructure.

W3C Invites Implementations of Decentralized Identifiers (DIDs) v1.1 w3.org/news/2026/w3c-invites-impleme…
W3C Invites Implementations of Decentralized Identifiers (DIDs) v1.1
www.w3.org