230 likes | 242 Views
This presentation explores the basics and legal perspective of digital identity, including current legal challenges and solutions.
E N D
Legal Nature of Digital Identity (Conference 7) Timothy S. ReinigerNovember 13, 2018 Presentation for Advanced Training in Digital Legal Documents at the University of Houston Houston, TX Reiniger LLC
Discussion Topics 1.Basics 2. Legal Perspective 3. Legal Challenges 4. Current Legal Solutions Reiniger LLC
Drivers of Digital Identity • Globalization and connected society • Global mobile phone availability and network coverage • Increased concerns about use of personal data • Growing market of identity service brokers • Increased cybersecurity/identity fraud risks • Increased dependency between public and private sectors Reiniger LLC
Digital Documents: Proof Requirements 1. Identity 2. Integrity 3. Intent All require capability of proof over time Reiniger LLC
Digital Identity: How Experienced in Law • Information Exchange/Sharing • Information Privacy • Information Security Reiniger LLC
Digital Identity: How Conceptualized in Law • Identity in Law • Identifiers • Legal Identity Reiniger LLC
Identity in Law Reiniger LLC
Sources of Laws/Rules • Statutes/Regulations • International Codes • Lex Informatica Reiniger LLC
Digital Identity Categories • Persons • Legal Persons • Non-Person (Digital) Entities Reiniger LLC
Identity Credential Defined "Identity credential" means the data, or the physical object upon which the data may reside, that an identity credential holder may present to verify or authenticate his identity in a digital or online transaction. Reiniger LLC
Sources of Identity Credentials Public Sector (eID) Private Sector Self-Issued/Certified Reiniger LLC
Digital Identity: How Perceived in Law • Context/Relationships • Consent • Control Reiniger LLC
Consent Reiniger LLC
Legal Challenges • Jurisdiction • Assigning Responsibility • Cross-Border Recognition • Third Party Liability • Identity Service Providers Reiniger LLC
SP/IdP SP IdP Users Users Users Third Party Liability Federation and third party bridges don’t solve all trust issues… Federating Entity A contract may not exist between all parties or may not address identity federation issues + + + User Credentials User Credential Accredited Issuer (Outsourced) Accredited Issuer (Insourced) Bridge CA Reiniger LLC
Legal Solutions: The Maritime Law Model Reiniger LLC
European Union Law - eIDAS • eID and Trust Services • Cross-Border Recognition/Interoperability • Liability Allocation Reiniger LLC
Virginia Digital Identity Law Overview SB 814: http://leg1.state.va.us/cgi-bin/legp504.exe?151+ful+SB814S1 Provides Common Legal Framework for Identity System Participants Creates the Commonwealth Identity Management Standards Advisory Council Provides Limitation of Liability for Identity Providers and Identity Trust Framework Operators Creates Additional Relying Party Incentives Reiniger LLC
Virginia Digital Identity Law: Liability Limitation Identity Service Provider Liable for Issuance of Credentials not in Compliance with State Minimum Standards, Existing Contracts, or Trust Framework Rules. Identity Service Provider not Liable for Improper Use of Credential by Holder or Any Other Person. Reiniger LLC
United Nations (UNCITRAL) • Study Effort for Model Law - Principles • Functional Equivalence • Technology Neutrality • Cross-Border Recognition • Party Autonomy • Liability Allocation Reiniger LLC
Digital Identity Trends • Use of mobile phones for citizen authentication • Use of biometrics for authentication • Availability of analytics for real-time and continuous authentication • Internet of things – identification of devices • Citizen/user capability for control of personal data Reiniger LLC
Contact Information Timothy S. Reiniger, Director Reiniger, LLC 40 Belfield Road Cape Elizabeth, Maine 04107 tim@reinigerllc.com 804-997-9213 Reiniger LLC