Guiding principles

Decentralized identity solutions empower individuals and ensure privacy. IBM® emphasizes these self-sovereign identity principles:

  • Existence: Users must have an independent existence.
  • Control: Users must control their identities.
  • Access: Users must have access to their own data.
  • Transparency: Systems and algorithms must be transparent.
  • Persistence: Identities must be long-lived.
  • Portability: Information and services about identity must be transportable.
  • Interoperability: Identities must be as widely usable as possible.
  • Consent: Users must agree to the use of their identity.
  • Minimization: Disclosure of claims must be minimized.
  • Protection: The rights of users must be protected.

Open decentralized systems enable individuals to fully own and manage their "own identities", leading to the idea of "self-sovereign" identity systems. These systems use a combination of distributed ledger and encryption technology to create immutable identity records that are referred to as Verifiable Credentials (credentials).

These credentials represent reputation-based artifacts stemming from relationships (connections) between peers (people, organizations, things). Each credential contains information (claims) about the peer that is made by the issuer of the credential, such as traits from a driver's license or grades on a college transcript. Each peer can accept and store credentials in their identity container (wallet).

Users can then use these credentials with other relationships to help prove:

  • Who they are?
  • What they have accomplished?
  • What privileges they have been granted?
  • How trusted they are based on thief reputation (trust score)?

Organizations trust credentials based on business policy, regulatory compliance, and attested information claims.