Skip to main content

Digital Identity in UbID

Digital identity is often confused with an account. An account is a relationship with one service. A digital identity is broader: it connects a person or organization with identifiers, credentials, devices, keys, and trusted relationships that may be useful across many services.

UbID models identity as a continuously governed set of verifiable relationships rather than a single universal profile.

Account identity versus portable identity

Account-centered modelUbID trust model
One organization creates and controls the account.Different institutions can issue different governed credentials.
Identity attributes remain inside the service database.Credentials can remain under holder control and be presented elsewhere.
The person repeats proofing for many providers.Existing trusted evidence can be reused when policy permits.
The service decides what information is visible.The holder can authorize proportionate presentation.
Recovery is usually controlled by the account provider.Recovery is treated as a governed continuity protocol.

UbID does not eliminate accounts. Institutions may still need local accounts, sessions, and entitlements. It adds a portable trust layer that can improve how identity evidence is established and reused.

Identity proofing, authentication, and credentials

These concepts solve different problems:

  • Identity proofing evaluates evidence about who a person is or whether a claim is trustworthy.
  • Authentication confirms control of an approved authenticator or session.
  • A credential carries signed claims from an issuer.
  • Verification evaluates whether presented evidence satisfies a policy.
  • Authorization determines what the authenticated or verified party may do.

A strong authentication event does not automatically prove every identity claim. A valid credential does not automatically authorize every action. UbID keeps these layers distinct so institutions can apply the right assurance at the right point.

Holder control with institutional responsibility

Self-managed identity does not mean that every claim is self-declared or that institutions surrender authority. Governments, universities, employers, banks, professional bodies, and other organizations remain responsible for the claims they issue.

Holder control means the person can protect, organize, and present those credentials. The holder controls use; the issuer remains responsible for truth and lifecycle; the verifier remains responsible for policy.

Scoped identifiers and reduced correlation

A universal identifier reused everywhere can make activities easy to correlate. UbID favors scoped identifiers and purpose-bound evidence where appropriate. This helps participants establish trust without automatically creating one global record of a person's activity.

The exact identifier strategy depends on the credential, relationship, regulation, and interoperability profile. The architectural objective is to avoid unnecessary correlation while preserving verifiability.

Devices, keys, and continuity

A digital identity must survive real-life events. Phones are replaced, devices are lost, authenticators fail, and people need to move between devices.

For that reason, UbID treats device registration, key protection, recovery, revocation, and rotation as part of identity security. Identity continuity should be possible without creating a universal administrator capable of taking over every account.

A managed lifecycle

Digital identity is not established once and then forgotten. Evidence changes. Credentials expire. Roles end. Devices are replaced. Policies evolve. UbID therefore manages identity as a lifecycle in which trust can be established, used, reviewed, updated, suspended, recovered, and retired with clear responsibility at every stage.