Who Uses Decentralized Identity Solutions?
There are several use cases for implementing decentralized identity systems.
Employers: Decentralized identity solutions can aid employers in new hire digital identity authentication and help them more quickly onboard new employees into existing company infrastructures. Decentralized identifiers stored within an employee’s digital wallet can include phone numbers, mailing addresses, and other contact information. Additionally, employees can share their credentials with their new employers, like vaccination records for on-site work and professional certifications.
Customers: Having autonomy over one’s digital identity can empower customers to have a firmer understanding of which businesses can access their personal data. For example, patients can offboard from and integrate into healthcare systems with decentralized identity solutions while revoking and granting access to their healthcare records from one provider to the next. Leveraging a decentralized identity solution can help customers secure their digital identities and the parties accessing their sensitive data.
IoT devices: The Internet of Things (IoT) refers to devices embedded with sensors, scanners, actuators, and the like, which are connected to computing systems. These connected devices allow the internet to observe and influence the real world, such as vehicles that can alert friends, family, and emergency services if they have crashed. Decentralized identity solutions can verify devices’ identities while enabling device owners to create access rules for the data the devices record and the processes they implement. Additionally, decentralizing IoT device identity management can make siloed IoT devices interoperable between manufacturers’ proprietary processes. In this way, decentralized identity solutions can prevent malicious actors from accessing IoT devices, stealing their data, and influencing the world around them. This can include digital personal assistants, offices, and labs with locks controlled by smartphones.
Challenges with Decentralized Identity Solutions
There are several decentralized identity platforms to choose from, but there is a lack of standardization across them, which causes several of the following challenges:
Interoperability: Key differences between blockchains create interoperability challenges between decentralized identity systems. This can limit organizations to using a single blockchain for decentralized identity management. New employees with pre-existing digital wallets on other blockchains must adopt the blockchain of choice for their new employer. Additionally, this may cause customers to choose to work with enterprises that accept ledgers from the blockchain their credentials are already stored on.
Security and privacy concerns: Lack of standardization also poses potential security and privacy concerns with blockchain technology. There is no standard protocol for public and private key management related to DLT. Just like conventional PKI, if a malicious actor steals a digital wallet’s private key, they can decrypt and access its contents. Other credentials used for wallet access and asset disbursement, including biometric factors, have no standard method of storage, which concerns privacy watchdogs intent on keeping blockchain user PII private.
User adoption: Scalability can be an issue for users accustomed to centralized identity management. Decentralized identity management systems are more challenging to operate than traditional centralized management systems. Lacking features like usernames and passwords creates complex user experiences for would-be adopters. This has prevented user adoption and affected the concept’s scalability. Decentralized identity management systems also tend to have slower processing speeds than established centralized identity management systems, which also deters enterprises and customers from embracing the concept.
How to Buy Decentralized Identity Solutions
Requirements Gathering (RFI/RFP) for Decentralized Identity Solutions
When selecting a decentralized identity solution, buyers should consider the following factors to best meet their needs:
Scalability: Buyers must prioritize how scalable the decentralized identity solution is. The number of digital identities they want to transfer to the decentralized identity solution from their pre-existing centralized identity management system, in addition to the number of new identities buyers want to create, will ultimately be limited to how easy it is to scale the solution.
Ease for end-users: Many decentralized identity solutions are complex and require end-users to have a savvy understanding of blockchain and distributed ledger technologies to fully grasp how to own their digital identities. Buyers should pay close attention to how easy it will be for end-users to interact with each decentralized identity solution’s interface.
Compare Decentralized Identity Solutions
Create a long list
While some decentralized identity solutions are for general use, some products may be tailored for narrower purposes. Buyers should create a long list tailored to their needs. Does the buyer need to implement a decentralized identity solution for students or employees? Does the buyer need a solution for a variety of use-cases?
Create a short list
To further narrow the pool of potential products, buyers should read product user reviews from g2.com. Reviews speak to the user experience, the complexity of implementation, costs, and overall functionality of the decentralized identity solution. Beyond reading reviews, buyers are also empowered to leverage the G2 Grid® to see how competing decentralized identity solutions compare to each other.
Conduct demos
By selecting the “Get a quote” button, buyers can often directly contact vendors on g2.com to request a product demo. During each demo, buyers should ask the same questions to fairly evaluate each product against the others the buyer is considering. Buyers should ask decentralized identity vendors about the solution’s processing speeds, user interface, ease of user adoption across an enterprise, how keys are managed, and the typical length of time it takes to move from a centralized identity management system to their specific decentralized identity solution. Buyers should also ask vendors about end-user training, as many are still unfamiliar with blockchain and distributed ledger technology.
Selection of Decentralized Identity Solutions
Choose a selection team
When buyers consider different products, several key stakeholders should be included in the decision-making process. It is important to include the day-to-day administrator of the organization’s current, centralized identity management system so they can ask vendors about phasing out the old system and phasing in the vendor’s product. Software engineers and at least one IT department representative should also be included to learn how to successfully integrate blockchain technology into their enterprise’s pre-existing infrastructure.
Negotiation
It may be possible for buyers to secure a deal with decentralized identity solution vendors. Buyers should ask if better rates are possible based on the number of identities the organization plans to decentralize and the types of identities they plan on decentralizing, including students, customers, and employees. The duration of the agreement between the buyer and the vendor may also be a factor to consider, with longer contracts sometimes allowing buyers to secure better rates.
Final decision
The final decision will come down to the decentralized identity solution’s use cases, scalability, ease of adoption, and end-user confidence in interacting with the blockchain. As identity management is a crucial aspect of business operations affecting administrators and end-users, consensus across the organization may be beneficial. Informing end-users of the advantages of having sovereignty over their digital identities and providing training is imperative to ensuring end-user adoption.
Ultimately, the final decision makers will likely be: the enterprise’s arbiter of identity management, the person responsible for the enterprise’s security, a leader within the software engineering team, and the chief executive or operations officer.