Interviews

Rohan Pinto - 1Kosmos's Journey from Blockchain to Passwordless Authentication

Zack Jones

·

·

3 min read

In this episode of The Future of Identity Podcast, I’m joined by Rohan Pinto, Co-founder and CTO of 1Kosmos, a company at the forefront of decentralized identity and passwordless authentication solutions. We explore the evolution of identity management and the journey from blockchain-based beginnings to building secure, user-controlled identity systems that go beyond traditional centralized approaches.
We dive into several key topics, including:

  • Rohan’s background in identity and access management, and his transition into building cryptographic solutions that emphasize user control over their identities.

  • The role of blockchain as an enabler in identity verification and why it’s not the complete solution to today’s identity challenges.

  • 1Kosmos’s unique approach to authentication, including their pivot from blockchain to passwordless access using biometric verification.

  • The challenges and potential of user-controlled identity and verifiable credentials, and why widespread adoption has been slower than expected.

  • Rohan’s perspective on the future of identity, including how decentralized identifiers and biometrics will reshape how we access systems and interact with digital services.

Rohan shares insights from his new book and offers a deep dive into the complexities and opportunities of building a more secure, user-centric identity ecosystem. This episode is a must-listen for anyone interested in the future of identity, security, and the evolving digital landscape.
You can learn more about 1Kosmos at 1kosmos.com.
Subscribe to our weekly newsletter for more announcements related to the future of identity at trinsic.id/podcast

Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.

Full Transcript

Transcript lightly edited for clarity.

Riley Hughes: Welcome to the Future of Identity podcast, where we talk to the people building the ID tech products of tomorrow. I’m Riley Hughes, co-founder of Trinsic, and I’m here with Rohan Pinto, co-founder and CTO of 1Kosmos. Rohan, welcome to the show.

Rohan Pinto: Thank you. Thank you so much. Thank you for having me, Riley. It’s a pleasure talking to you.

Riley Hughes: Yeah, I was fortunate to listen to a couple of podcasts and vlogs that you’ve done in the past in preparation for this, and I think this will be a really interesting conversation. I originally reached out because I saw that you published a book, and it looked very comprehensive. I went on Amazon and looked at the table of contents and kind of read through the summaries of the sections, and it looked extremely comprehensive. And I know as a family man and a startup founder, I’m very interested to know how you had all the time to write such a thorough book. But hopefully here in the conversation, we can dive into some of the concepts that you talk about there.

Rohan Pinto: Absolutely. And you know what? Let me get one thing out of the way. Every time I listen to an author on a podcast or giving an interview, every third line is, Oh, I’ve covered that in my book. You can read about it in my book. So I’m going to stay away from that and probably start off your podcast by saying, Buy my book, you know, so I don’t have to repeat myself over and over again on that one note. But no, it took me a very long time to write that book. It took me almost a year and a half, obviously, because it’s like you have your day job, you got your full-time job. There are so many other responsibilities that you have as a dad, as a parent, you know, your own life and, you know, all the other things that you do. So it took me around a year and a half to wrap up the entirety of the contents of that particular book. So it was not a short undertaking.

Riley Hughes: Yeah, yeah, sounds like it. Everybody, listeners can just go ahead and assume that anything you say on this podcast, you can probably read more about the same topic in your book, and if it’s interesting, you should dive in.

Rohan Pinto: Yeah, exactly. Great. And if you don’t find it in the book, you can always shoot us an email, and I can probably use that as a topic for my next book.

Riley Hughes: Perfect, perfect. Yeah, wonderful. I wanted to start off just by asking about, you know, a little bit about 1Kosmos. As you know, on this podcast, we try to dive into the product side of reusable ID products. And so I’m curious, you know, as a lot of companies in this decentralized identity space, including my own company, Trinsic, started during the sort of blockchain hype, and then ultimately the blockchain element less and less over time, even to the point where some of them, you know, some moved away from it entirely. As I look at, you know, 1Kosmos, I see, you know, there’s still elements of that strewn throughout the, you know, on the website and the materials. So I’m curious, you know, there’s plenty of non-blockchain IAM solutions and identity verification solutions and even reusable ID companies. So curious, you know, what are you seeing in the market that causes you to lean into that decentralized angle, and how is that working for you?

Rohan Pinto: Okay, I’m going to try and give it my best shot, right? Because there are a whole bunch of questions in that one little statement that you made. To start off with, I come from the identity and access management background, so I’m not a crypto guy or a blockchain guy who suddenly decided to jump into the identity management space. It’s actually been the other way around. I was part of a company called Forte that then became Netscape, that then became Sun Microsystems, and I was part of the Sun engineering team that built one of the first single sign-on products that’s out there. And I was also part of the directory services team, because way back in 1999 and 2000, a directory that a company had hosted was considered to be the identity management infrastructure for that company. So every time somebody said identity management, they were assuming that the credentials were stored in some kind of directory or Active Directory or an Oracle database of sorts. And then came the whole era of single sign-on, where you want to sign on once and never have to sign in again.

Rohan Pinto: And came out technologies like SAML and OIDC and OpenID Connect, and there were a whole bunch of other small protocols that did play a role in the single sign-on space. So I’ve been in the identity management space for a very long time, but my core skills are actually cryptography, cryptography and PKI. And way back when Bitcoin became a big thing and when Bitcoin started booming and everybody started talking about blockchain and cryptocurrency, it drew my interest because I loved the technology that powered cryptocurrencies like Bitcoin or Ethereum or whatever you want to call it. So the technology that powered it was all based on the decentralized blockchain. And being a cryptography expert and being in the identity management space, I saw that there was a way in which you could actually change the paradigm of how identity is way managed and used in the future. So that’s when I came out with this product called BlockID, where you put the control back in the hands of the user.

Rohan Pinto: So you let the user control all facets of his or her own identity so that they can control where their identity is used, what it is used for, regardless of whether it’s used for data warehousing or whether it’s used for authentication and access management, or whether it triggers off some rules engine that’s based on authorization workflows that might be established within an organization. So when we started off, we actually started off as a blockchain-based company and we said, hey, you know what? Here’s a decentralized identity that puts control back in the hands of the user. And we ran into the cat and mouse problem, or the horse before the cart problem, or the cart before the horse problem, saying, while the technology is fantastic and you can have every user own and control their identity, the big question that came up is what do they do with it? Where can they use it? What’s the point in me having my identity on my device and me saying I can control it if nobody is willing to accept that identity or if there’s no place that I can use this identity going forward?

Rohan Pinto: So even though we started off as a blockchain-based company, we pivoted off of the— The blockchain is not a solution to today’s problem in the identity management space. It’s an enabler. We strongly believe that the blockchain is an enabler out here. So what we have done is we have built a solution on top of the blockchain. where in the initial days, yes, blockchain took center stage because our focus was in actually building the infrastructure that enabled users to control their data. But once that was built, we said, what can the user do with this? So we pivoted off of just being a blockchain-based identity management infrastructure to actually leveraging technologies and protocols like FIDO, like ECDSA, do identity verification, and actually have the ability to bind the true identity of a person to a decentralized identity and then use that decentralized identifier to access systems and things without the user having to remember a user ID and password or an OTP code.

Rohan Pinto: So we wanted to do away with the traditional methods of authentication, which is user ID password, which is the primary one. Second one is the OTP, and the third is a FIDO key. And the problem that I saw with the FIDO key is that it’s fantastic. I love the protocol, I love the technology, but it’s based on contact, which means that anybody with a FIDO2 key, if I have possession of your key, I can access all the applications that you have access to by simply touching the key. So we came up with a product called OneKey, and OneKey is basically a fingerprint-based FIDO key that is not bound to a user. And what I mean by that is, if you have—I don’t want to use the term YubiKey, but it’s the most commonly used FIDO token that’s out there, so I know that YubiKey is the name of the organization, or Yubico. So let’s say you have a YubiKey with you. Now—

Riley Hughes: It’s bound to one identity, so you can have your ID on your YubiKey, and you can use that ID to access n number of applications for you as a user.

Rohan Pinto: Sure. The second problem that we saw with a normal or a standardized FIDO key is that it’s based on contact, which means that you can touch it with your fingertip, you can touch it with a pencil, you can touch it with a pen, and it is still considered authentication. Yes, it does factor in presence, but it doesn’t factor in who is present. So that’s when we came out with OneKey, and OneKey is literally a FIDO2 key that’s got a capacitive sensor on it that actually recognizes fingerprints. So what we have done is we have a decentralized identifier, we do identity verification, and we bind the identity credentials to the decentralized identifier. Then we bind a FIDO token to the same decentralized identifier, and then we bind it to the fingerprint of that particular person on that particular device, which means that when you log into any system using OneKey, which is basically a FIDO2 key with a fingerprint sensor on it, you have the assurance that the person logging into the system is actually Rohan Pinto and not somebody else who has got possession of Rohan Pinto’s key.

Rohan Pinto: The pivot that we did from blockchain was that we still use the blockchain, but blockchain has not become the center or the forefront of our product stack. Our forefront is passwordless. Our forefront is identity verification. Our forefront is single sign-on into applications and things, because I don’t think there’s any vendor out there that does single sign-on into web applications by leveraging SAML and OIDC, but at the same time also giving you passwordless access into your Windows laptop, into your Mac laptops, and to your Linux workstations. So giving passwordless into systems. And into web applications using that same identifier is what makes our solution quite unique and different compared to other decentralized identity solutions that exist out there, or centralized identity solutions that exist out there. Because if the centralized solutions take care of SAML, single sign-on, privileged access management, we do that too. We do passwordless too, and we do identity verification too.

Rohan Pinto: So the whole premise is based on the fact that when the person authenticates, you have a very high level of assurance that the person authenticating into the system is actually the person who that credential was initially issued to, every single time. And we do continuous authentication as well. So we are more a passwordless player than a blockchain player right now.

Riley Hughes: Yeah, okay, that’s really helpful. And you gave a really good overview of the 1Kosmos platform there, which is where I was going to go next. But before we go further into the product side, I just want to double-click on one thing that you said in that answer, which I think is really insightful. You said that blockchain is not a solution to today’s problem, but an enabler. And I wonder if what you mean, and you can tell me if this is right, but it’s just that, you know, while blockchain may not be a requirement in order to do identity verification, or to do single sign-on, or to issue FIDO tokens, or whatever, however, it is, in your view, an enabler of a future world which we all hope will emerge, right? You’re looking at for the future world, and blockchain plays a role in that as opposed to in the sort of today’s problems that people are facing. Is that a proper framing?

Rohan Pinto: It is. It is good. It is a proper framing. But so here’s the thing, right? So let’s take a step back to a few years in the past. All credentials were stored in databases. They were stored in Active Directory. They were stored in directory services. That doesn’t necessarily mean that your database becomes your identity management solution. It’s just a credential store, and you had your identity management solution sitting on top of it, regardless whether your front end was based on ForgeRock’s OpenAM or IBM Tivoli or Azure or Ping Identity or Okta or— whatsoever. They all leverage a data store of sorts, and the data store could have been Oracle, it could be MySQL, it could be NoSQL, it could be LDAP, it could be Active Directory. With a decentralized store, here’s the difference. One is that the credential is not owned by the organization that actually issued the credential, because there are facets of my credential.

Rohan Pinto: For example, my first name, my last name, my social insurance number, my health card number, my educational documents, my degrees, my passport, my driver’s license are all facets of an identity that belong to me that I own. The organization that I join doesn’t own that. What the organization owns is the user ID and password that was created for me to access their systems. So typically, when you create a profile within an organization, they create a profile with your first name, with your last name, with your date of birth, with your education qualifications, with your driver’s license number. And I am reluctant to say this, but organizations do have what I would call God mentality. And what I mean by that is they believe that they own all the credentials and tokens that they issue to their consumers and their employees within their organization. And it’s hard to get an organization mindset off of that God mentality where they think that they own all the credentials on the system and tell them that, no, you don’t own it anymore. It’s your employees who own their own credentials.

Rohan Pinto: It’s your consumers, it’s your users who own their own credentials. So that’s a huge paradigm shift in the thought process of how identities used to be managed to how identities should be managed in the future. And in order to do that, having an identity on a centralized database is not a no-no. But still is problematic because no matter how secure your organization is, there still is somebody within that organization, maybe as low down as the database administrator, who has the ability to go and change my last name from Pinto to Riley, or, sorry, to Hughes, or change my date of birth. So somebody does have the ability to manually go into any centralized database and change any aspect of a person’s identity data, be it your date of birth or your educational documents or your driver’s license expiration date or your age or your last name. Whereas when you look at blockchain as a storage mechanism, again, I’m not referring to the public blockchain because no data should be stored on any public blockchain, period.

Rohan Pinto: I don’t think we should be going into that argument because even back in the day when data was stored in directory services, nobody takes a directory and puts it onto the public internet and says, That’s where my identities are stored. The same thing goes with blockchains as well. Just because there are public blockchains like Bitcoin and Ethereum, that doesn’t necessarily mean that that’s a blockchain that you need to use. Our infrastructure, we deploy private permission ledgers for each and every customers of ours. And we follow what we call as a multi-cloud single-tenant model, which means that it’s a cloud-based service and every tenant or every customer of ours has their own dedicated infrastructure of both their API gateway, their services, as well as their own blockchain. So if there ever comes a time where a customer says, We want to move away from 1Kosmos and we want to go to Trinsic and we want 1Kosmos to delete all customer data from our environment, we can simply shut down that entire infrastructure, thus losing access to all the data associated with that organization.

Rohan Pinto: We also have to remember things in terms of GDPR or the right to be forgotten, because there could be a user within an organization who wants to exercise his right to be forgotten. So we have architected a platform such that the user also has the ability to destroy his or her own public data, regardless of whether that data is stored on the blockchain or not. And I can talk about it for the next two hours of how we actually do it from a technology stack. But if you speak about it from a 10,000-feet overview level, yes, the user does have the ability to delete his or her own data that resides on a blockchain because it’s an encrypted blob of data that’s encrypted using the user’s own private-public key pair, that only the user has got the ability to decrypt and present it to any requesting source or requesting party. So yes, the blockchain is the enabler, and the solution that you build on top of the blockchain that drives use cases or organizational needs is what makes the solution work rather than the blockchain itself being a solution.

Rohan Pinto: And that’s what I meant by blockchain being an enabler to solutions that you can build on top of it rather than blockchain being a solution in itself.

Riley Hughes: Yeah, that’s helpful and really interesting. It makes me wonder, one thing that I’ve seen a lot of companies in the identity facing is that identity touches everything, right? It’s every interaction. And so there’s this temptation for people to want to solve everything. And you mentioned a bunch of different credentials from name to passport to education credentials to whatever, and it’s tempting to want to be a general purpose, do-everything platform. On the other hand, a lot of conventional wisdom for startups is to get really, really good at one thing and be the best in the world at your little niche and be really good at that. And it seems like you’ve taken an interesting approach here where you’re not really on either one of those spectrums from what I can tell, and you can correct me if I’m wrong, but it seems like 1Kosmos has, you know, instead of of maybe just leaning in on whatever your first initial product offering was, you have expanded, right?

Riley Hughes: You have expanded through, but you’ve almost expanded, like, vertically as opposed to horizontally, where you cover, you know, everything from the decentralized ID to the ID verification to the authentication to the, you know, whatever, like the— whole stack like that, almost offering more services to a given customer as opposed to trying to offer one single service to a larger number of customers, if that makes sense. So I wonder what went into that decision and how has that, you know, played out for you. Would you recommend that to other people too?

Rohan Pinto: Absolutely. I would absolutely recommend it to other people because when we talk in terms of identity, right, it’s not about just having a credential. It’s also about using the credential, which means that even though I have a decentralized identifier with me, if I need to have the ability to use this decentralized identifier to access any web application or system without the need for a user ID and password by simply leveraging biometrics, which is a much more secure form of encrypting and storing your credential data, or verifying that it’s a true person using technologies like live ID. I’m not talking about face ID or touch ID. Live ID is basically the ability of the system to look at the person in real time. And identify that it is actually Rohan Pinto who’s trying to authenticate into the platform rather than somebody else. So when you’re looking at how that identity can be used and what can it be used for, you will automatically find yourself to be in a space that you’re not just focusing on enabling a user to have a decentralized identifier.

Rohan Pinto: You want to enable that user to use that identity to access systems and things, which means that you would now take a step into the authentication space. When you take a step into the authentication space, it’s not about simple authentication. You also want to verify that the identity authenticating is the true identity of the person at runtime, rather than saying, user ID Riley, password one two three, logged in, great. But was it actually Riley logging in, or was it somebody else that he had given his credentials to? So you have that huge disparity between how traditional credentials are used and how passwordless systems work.

Riley Hughes: So could I jump in here real quick? I mean, if I were to take the other side of this, I would say if you look at Okta, you know, worth tens of billions of dollars, does billion-plus in revenue. They don’t have an identity verification solution built in, right? Or if you look at the identity verification space, if you look at Onfido or Jumio or Mitek, they generally don’t have full-fledged single sign-on products.

Rohan Pinto: Absolutely.

Riley Hughes: Right?

Rohan Pinto: Absolutely. The way the world generally works today is these things are separate.

Riley Hughes: But what you’re saying is it’s important to keep them embedded. Is this a contrarian take of yours that you think will differentiate 1Kosmos, or do you think that over time the whole space will, like every player will have to offer everything, or how do you see this playing out?

Rohan Pinto: I wouldn’t say every player would have to offer everything. You pick and choose what you want to play with. The way we see it is that the primary need in the industry today is secure authentication. 99.99% of the breaches that you see everywhere is based on compromised credentials. So the first space that we wanted to address, a target, was the authentication space and ensuring that you’ve got a very strong form of authentication. And instead of building a siloed unique product, we built a strong authentication mechanism on top of a decentralized identity. Now, once you’ve addressed authentication, the second thing you want to make sure is not just authentication, but you want to make sure that the person authenticating is actually the person who the credential was issued to. So we moved into the identity verification space. Now, even though it might sound like a term that’s new to a lot of organizations, it’s something that everybody has been doing from day one. You join a company, the first thing that they do is they do a background check on you.

Rohan Pinto: They check your educational documents. They check your work history before they give you a job offer. So regardless of the kind of identity verification processes that organization A follows versus organization B follows, there’s identity verification done everywhere right from the get-go. But once identity verification is done, you give them a siloed token to authenticate into systems. There is no connection between the user who has been verified, to whom the credential was issued to, and that credential being actually used to authenticate into systems.

Rohan Pinto: So we thought it’s really important for us to bring those two things together into one unified solution where You not only have a decentralized identifier, you have a verified identity tied to it, and you have live biometrics tied to it, which means that you can now leverage it for passwordless access into systems and things without compromising security, providing you traceability, providing you—instead of you having 25 different systems to go and analyze what happened in your risk management engine, what happened in your database, what happened in your LDAP server, what happened on your SSO platform, what do the log analysis engine says, what’s stored in Elasticsearch, before you can trace a particular breach to a particular individual who accessed 25 different systems at the same point in time. Whereas with a platform like this, you know that it is Rohan who verified himself. You know that it is Rohan who verified his documents. You know that the documents were attested by sources of truth like Amva and ICAO and other third-party sources of truth.

Rohan Pinto: You know that a FIDO key has been bound to that verified identity, and Rohan used his real-time biometrics to use that very same identity to access systems and things. So I wouldn’t say that authentication needs to be separate, authorization has to be separate, identity verification has to be separate. They all play a role between each other. So we said instead of coming out with three or four different products that really don’t talk to each other, come out with one solution that offers the best of breed. So if you have a customer who says, We don’t care about identity verification. We have our own identity verification processes in place, but we want to somehow bind that distributed identifier or that decentralized identity to the corporate identity that was issued to the user, and then use that identity to log into systems, you can do that as well. So we give our customers a choice of using passwordless for systems, passwordless for web applications, users for identity verification, or users for just building a decentralized identifier.

Rohan Pinto: You have the entire platform stack and you can pick and choose which service model you want to deploy the stack on.

Riley Hughes: Great, that makes a lot of sense. That’s also a proven model, right, where there are a lot of really successful platform companies that have built really good solutions where they have the whole thing, but you don’t necessarily need to buy the entire thing in order to make it functional, which is, I think, an interesting way to architect it. I wonder, when I think about, you know, as you describe this, I wonder, do you describe yourself as a self-sovereign identity or decentralized identity solution? Because as far as I can tell from your description—and granted, I think this is a necessity at this stage of the market, but I’ll just ask the question anyway to push on this a little bit—you know, 1Kosmos as the identity verification company is the issuer. You’re creating the DID. As far as I can tell, you’re the wallet provider, right? And the only place people can really use those credentials from 1Kosmos is with 1Kosmos customers, right?

Riley Hughes: So, you know, a lot of people think of a self-sovereign identity as something where a user gets, you know, credentials from multiple sources and they can use it anywhere through some common standard. How do you see where you’re at today versus maybe where you want to go?

Rohan Pinto: Okay. So I would like to take a step back because the question itself was, I wouldn’t say wrong, but the way it was phrased, if I jump into answering that question, the assumption is that the question was right and that’s what I’m answering. So here’s where you’re wrong. We are not the provider and wallet and verifier. Our platform for identity verification is based on the fact that our consumers, or our customers, need to have the ability to issue a credential. They need to provide their users the ability to hold a credential. They need to have the ability to present that credential. And there’s some service that needs to consume that credential. So when we built our identity, our verifiable credentials model into our engine, we have the ability to consume any decentralized VC as long as it complies with the W3C standards. I’m not sure about other organizations, but right now we are the only ones that can consume a Microsoft Entra verifiable credential in our mobile app, apart from Microsoft Authenticator. Because if you look at how Microsoft Entra is built, it’s based on Azure.

Rohan Pinto: You’ve got to log into Azure to issue a credential. The credential is consumed and stored in Microsoft Authenticator, and you use Microsoft Authenticator to present that credential back to a service that’s hosted on Azure itself. Our model is slightly different. We can consume a credential issued by Entra. We can hold it in our wallet, and we can present that credential to any W3C-consuming party or a verification service. It’s not about OneKosmos issuing a credential, holding the credential, and verifying it on our platform. We have got consumers issuing credentials from Entra and presenting it on a OneKosmos platform. We have consumers issuing a credential on the OneKosmos platform and presenting it to Entra. And the reason I use Entra as an example right now is because I don’t see anybody else playing in the verifiable credential space that actually has a production-grade product out there. Sorry, I also want to mention Avenim. Sorry, I had a brain freeze there for a moment. So we have the ability to consume any credential, present any credential to anybody.

Rohan Pinto: However, the problem that we saw is that for anybody to issue a credential, They need to have a lot of infrastructure and technology deployed at their end to be able to issue a verifiable credential. A lot of our consumers, a lot of our customers said that we’ve got tons of credentials. We’ve got access to, let’s say, employment records. We’ve got access to educational documents, but we don’t have a system that actually converts that to a verifiable credential. So what we built was an API-driven approach where a customer can literally call our APIs, pass on a full-fledged document that adheres to a certain schema structure. We convert that document to a verifiable credential and pass it back on to the organization that requested it. The organization that requested it now has the ability to push that verifiable credential onto their users, be it an employee or a consumer. And when they push that credential onto their users, the user needs to have some way of storing that credential.

Rohan Pinto: You could either store it in a BlockID app, you could store it in a Microsoft Authenticator app, or you could store it in any third-party app that has the ability to store a W3C issued credential in it, and you can present it to anybody. So no, we are not an organization that issues, holds, and verifies a credential. We provide our customers the ability to convert any credential to a verifiable credential. We provide our customers the ability to push that credential to a wallet. The wallet could be a BlockID wallet, and I’m not sure if you’ve noticed that our solution is also sold as a white… white-label solution. So a lot of our customers take our SDK and they white-label their own app. For example, Verizon has got Verizon ID. Verizon ID is nothing but BlockID under the hood. We power-built the entire Verizon ID platform. Same thing with other customers. I’m not sure how many names I can use out here, but customers like to call their app or their platform their ID. For example, every customer we go to, they all have their own mobile app for employee productivity.

Rohan Pinto: They have their own mobile app where their employees can access their payroll, from access to their work resources, et cetera. They didn’t want to have another app where the user had to prove his identity and hold his identity. So our SDK can be baked into any existing app that the organization might have. So a lot of products that you probably use today, Riley, do have BlockID under the hood. So if you’re using a banking app, for example, I’m just going to use the term banking app without using the name of any bank. If you have a banking app and you have verified your identity in the banking app, it’s actually OneKosmos BlockID powering that entire aspect of storing and holding that credential within your banking app. It’s us actually doing it.

Riley Hughes: Yeah, and that makes sense. So this leads me to some other questions here, which—

Rohan Pinto: Absolutely.

Riley Hughes: If OneKosmos, and a lot of the questions I’m asking, as you can tell, have some assumptions baked in, so I appreciate that you’re clarifying a lot of these assumptions. And so the same thing is going to happen here. Please correct me where I get this wrong. But if OneKosmos— is paid to verify, Riley, right? You get paid to do identity verification. Now I get a reusable credential, and I choose to store it in a different wallet, and then I just present that to some third party that you have no idea of. Does that not undermine the business model? And how do you think about that? And how do you address the kind of economic question there?

Rohan Pinto: Yeah. No, it doesn’t undermine our business model. In fact, the question you ask goes back to one of the sales pitches I had done around five years ago, where I went to an organization and said, Hey, look at the advantages of having a decentralized identifier and a verified identity in your wallet, where now if somebody already has a verifiable credential with them or a verified identity with them, to onboard that user onto your platform, all the user has to do is present your credential and you can verify and onboard that user. And the first question they asked me was, Wow, that means that our onboarding process for new customers is going to be a piece of cake, because whoever has a verified credential or a verified identity issued by anybody else in the world, another bank, for example, we could onboard them by just snapping our fingers. But that also means that all the investment that we have made in verifying individuals at our bank can now take the credential and go to another bank. Yes, that is possible.

Rohan Pinto: The thought process here is very similar to the number portability act that they have with cell phone numbers. Once you get a cell phone number, back in the day, if I switch my carrier from Verizon to, let’s say, AT&T, I lose my Verizon number and I get an AT&T number. Now that has changed over a period of time because now I can port my number. I can take my number with me from carrier one to carrier two to carrier three. So the ideology there is very similar to the number portability act that they have for cell phone numbers, where I carry my identity with me. Yes, you enabled me to verify my credential, but I have my credential and I can use that somewhere else altogether. It does not undermine the business model at all because the business model is not in making our customers pay a dollar every time a user uses that identity. It’s a one-time credential that we give to a user. For example. Imagine if the DMV charged you a dollar every time you showed your driver’s license at the LCBO when you wanted to buy beer. No, they don’t.

Rohan Pinto: You go, you show your identity to prove that you’re over 18, and you get to buy alcohol. You do not pay for showing your identity every single time. It’s the flexibility that you get by having a verifiable credential with you that you can now seamlessly use all the services within that organization that provisioned your identity for you, but you can carry that identity with you from organization A to organization B without having to go through the pain of verifying your identity all over again. Now, you can add aspects of identity data on top of your existing verifiable credential. For example, you change a job, you have a new employer, you got new education documents, you can always augment it with more, but it’s your identity. You own it. You have the ability to present it to whoever you want to present it to, as long as the requester has the ability to consume something like that. So no, it does not undermine the business model at all.

Rohan Pinto: In fact, it makes it much easier for market adoption and for consumers to actually say, hey, great, I can now leave company A and go to company B, and I can still log in using the same decentralized identity that I have on my app or my mobile phone.

Riley Hughes: Yeah, yeah, and I think that that argument makes sense. I appreciate the principled stand there around, like when customers say, oh, if a user gets a reusable ID, then that means they could leave my company and go to my competitor really easily. And the answer is, but then you can also get new customers from the competitor easily. And there’s, you know, unfortunately you can’t stop technological progress from making people’s lives easier, so you might as well embrace it and be the leader in the space and be the product that everyone wants to come to as opposed to the one people want to leave. And so I totally, totally hear you there.

Rohan Pinto: And that’s very, that’s very important to remember, not just in the identity management space, but in life in general. You don’t win anything by making it harder for somebody to leave your walled garden and go somewhere else. The easier you make it for the user to go from point A to point B to point C, the users will start adopting your product. The minute you start building a walled garden where you try to contain all your users only within your organization, if a user is not happy and he has to go, he will go, regardless of how easy or hard you made it for him or her.

Riley Hughes: Well, as soon as you start putting up the walls, people start looking for the escape route. Whereas if there’s no walls, there’s no urgency, there’s no reason to look for an escape because you’re like, I can just escape anytime I want.

Rohan Pinto: And interestingly enough, every time this topic came up when I would speak to customers is that the focus was more on, Oh my God, that means our users can go away, and we are going to make it easier for them to go and open an account with another bank, instead of focusing on the fact that the users coming in to open an account at your bank, you can onboard them within the next five to ten seconds.

Riley Hughes: Now let me zoom in on that for just a moment to try to make this a little more concrete. Suppose that I’m onboarding it and you didn’t use any bank names and I don’t know any of your bank customers, so I’ll just say Wells Fargo, right? I’m trying to onboard with Wells Fargo. Pretend, imagine that they are a customer of yours or a customer of Entra or some other verifiable credential-based thing, right? Now also suppose that I have a Verizon ID.

Rohan Pinto: On my phone.

Riley Hughes: Yeah. When I go to the bank and they say, Oh, I need to verify your identity, how does the bank know that I have a Verizen ID? How do I remember that I have a Verizen ID? How do I know that my Verizen ID will meet the bank’s verification requirement, right? How do you connect the dots between wherever this thing lives? I mean, it’s one thing if it’s in a dedicated standalone app, right? And if I, as a consumer, think, Oh, I have my decentralized ID wallet, and there’s one wallet to rule them all, and I can, you know, use that, that’s one thing. But that’s really challenging from an adoption perspective. Clearly, the white-label approach is much easier from an adoption perspective so that people don’t have to download a second app. But then you run into this problem of where are my credentials, and how do I know where they are, and how do I find them when I need them?

Rohan Pinto: One thing that’s really important out here is education. We need to educate our consumers, our users, that let’s say you join organization A and you have a Verizen ID on your phone, and tomorrow you want to leave organization A and go to organization B. If they are not educated enough to know that they could have used that same ID to go and onboard themselves at the second customer, they can use their Verizen ID app itself to do it. So education is quite critical out here to make sure that the consumers also know how many places they can use that same identity. For example, I’m pretty certain that if you open your phone right now, you’ve got Google Authenticator on it. You probably have Microsoft Authenticator on it as well, and almost every organization out there—

Riley Hughes: Plus like three other authenticator apps, by the way.

Rohan Pinto: Yeah, I’ve got a whole bunch myself. In fact, I’ve got like four groups of just authenticator apps.

Riley Hughes: Yeah, yeah, authenticator apps and SSI wallets. I’ve got like 80 of them.

Rohan Pinto: Yeah, right. And the reason I said Google Authenticator and Microsoft Authenticator is because I want to zone in on OTP codes. Every application out there relies on TOTP or HOTP for securing, or for second-factor authentication, or for MFA into their organization. And you can store that OTP code in Google Authenticator. You can store it in Microsoft Authenticator. You can store it in an authenticator app that the company itself might have. You can store it in FreeOTP, which is another app that you can download off the App Store. Now, as a consumer, Oh, you know what? This is a great example. My son called me up two days ago and said, Dad, I’m trying to log into this thing and it’s asking me for the OTP code. And I’m typing in the OTP code from the BlockID app and it’s not working. Mind you, my son’s only 19. And I said, No, son, it literally tells you out there on your Google Authenticator app, so use that OTP code and not this one.

Rohan Pinto: So even for something as simple as using an OTP code, there needs to be some form of education to ensure that the user knows that the OTP code is stored in Authenticator or Google Authenticator or Microsoft Authenticator or somewhere else, and also telling the user that, oh, you don’t have to store it in three different places. You can just store it in Google Authenticator and use that same OTP code everywhere else. The same education, the same concept goes to a reusable identity as well. And we also have the concept of data portability, which means that if I’ve got a Verizon ID app on my phone and if I’ve got the BlockID app on my phone, if I’ve verified my identity using the BlockID app, in two clicks I can transfer my entire identity data from BlockID over to Verizon ID, which is very different from moving an OTP code from Google Authenticator to Microsoft Authenticator, which is not possible. You still have to enter your secret keying phase on the second app. So we have enabled data portability, which means that the user can carry his identity with him wherever he goes.

Rohan Pinto: And this thought came across when we initially started building the platform, where if the user goes to one bank, has verified his identity, which let’s say Wells Fargo, right? So he’s got the Wells Fargo app, he’s got his identity on it, and then he wants to leave Wells Fargo and open an account at Bank of America. But of course, when you open an account at Bank of America, you can’t be using your Wells Fargo app to check your Bank of America account. You just want to use your identity aspect. So when you go and enroll yourself on Bank of America, you can use your Wells Fargo app to present your identity. And the next thing you know is that your entire identity data can be ported from one app to another app, thus making his identity reusable across multiple apps as well.

Riley Hughes: So let me add, let me get a little—this all makes sense conceptually. Do you, if I were to get a little more concrete, though, do you have customers doing this? Or I should say users who are able to do this between your customers? And if so, do you track metrics or the impact, right? You mentioned, oh, you could onboard in five seconds. Is it actually five seconds? And if so, how much better is that in terms of the uplift or conversion for the relying party having accepted a user in five seconds relative to what they were doing before, which maybe took, you know, days sometimes?

Rohan Pinto: Yeah, sometimes it’s days. Sometimes days. Yes, we do track metrics. Yes, we do have users who go—so let me talk about our platform a little bit to put some context. Ours is a SaaS service. I did speak about multi-cloud single tenancy model, which means that for every customer of ours, we deploy a dedicated infrastructure for them. They have their own blockchain infrastructure. They have their own Ethereum nodes. They have their own IPFS cluster. They have their own API gateway. They have their own stack deployed. We also have the concept of communities within a tenant or a customer. For example, our customer is Verizon ID. So every time you go to verizonid.verizon.com, that’s the tenant infrastructure that we host for Verizon. But Verizon has got 50 other customers that they serve to. So their 50 customers are all communities under the Verizon tenant. We have seen people move from one community to another community within a customer or within a tenant.

Rohan Pinto: But for all practical reasons, we have not seen, even though we have the feature, we have not seen a user move from one customer to another.

Riley Hughes: Got it. That’s really helpful. I appreciate you expanding on that, because that is what I would expect given the state of where the market is at. But not a lot of people come out and say it that clearly, so I appreciate the insight there, and that makes sense.

Rohan Pinto: Think about communities as various departments within an organization, right? You’ve got marketing, you’ve got engineering, you’ve got sales, and you’ve got an employee today who’s part of marketing. Tomorrow moves to sales. Day after tomorrow, I don’t know, get some education qualifications, upgraded, moves to engineering. So he basically moves from one department to another department within the same organization, which is the same behavior where the user moves from one community to another community within a tenant infrastructure. We see a lot of that, but moving from one customer completely over to the other, we have not seen any so far. When it comes up to metrics on authentication, our metrics are actually very high because authentication is crucial to anything and everything today. It is crucial that you need to authenticate almost instantaneously. So our authentication rates, we do probably around 10 million authentication threshold with a two-second authentication time for each authentication request. And onboarding time also is not just five seconds.

Rohan Pinto: I’ve seen it happen anywhere between two seconds to 15 seconds. It all depends on what the organization has enabled for that particular user to go and verify himself. For example, in India, they want users to verify and validate themselves using their Aadhaar card. In North America, it’s a social security number or the social insurance number. Now, scanning a driver’s license is very different from scanning a social insurance number, because if you look at a social security card, there’s nothing but a number on it. Absolutely no other verification criteria of sorts. But we have actually tapped into… The verifying authority to validate the authenticity of the social insurance number capture the user’s biometrics and verify the combination of the two against a live system before enrolling that identity. So the facets of identity that a user can actually enroll varies from organization to organization, varies from geographic region to geographic region. India wants Aadhaar card, Canada wants SIN number, U.S. wants social insurance number. Somebody else wants a driver’s license.

Rohan Pinto: Somebody else wants a passport. Somebody else wants a combination of those three. Somebody else wants a completely different identity document or an educational document that needs to be used. So because our platform is based on the entire verifiable, we can convert any document, any ID document to a verifiable credential. We consume almost any credential out there to create your verifiable credential. But authentication is something else altogether. Authentication does leverage, does tie into the identity verification process for continuous verification, but it runs off of its own stream because you can’t have identity verification play a role at the time of authentication, but actually verify that identity at runtime during authentication, which makes the entire process super fast, both on the verification side as well as the authentication side.

Riley Hughes: Yeah. Well, I want to transition to this sort of last section here about your book. I just wonder if you could speak a little more to it. I know we covered that at the beginning, but I had just a few more questions on it. I looked over the table of contents, like I mentioned, and there were quite a few things I thought I could ask you about in our call here, or in our interview here. But the one thing that I thought I wanted to touch on is there’s a section on self-sovereign identity, and there’s a section about the adoption challenges of self-sovereign identity. So I wonder if you could give us maybe a sneak peek into what you wrote there, or if you could expound on why you think the self-sovereign identity space, which you and I were both in in, I don’t know, probably 2016, 2017 era, right, where the vision today is virtually the same as the vision was then.

Riley Hughes: The technology today is a little bit better, a little more advanced, but fundamentally there’s very many commonalities between the verifiable credentials and blockchains and whatever that were around back then that are around today. Why do you think Give. given so much interest and excitement and vision for the future that so many people have around self-sovereign identity, why does it not have more adoption?

Rohan Pinto: Okay, so we don’t play in the self-sovereign identity space. There’s a big difference between self-sovereign identity and what decentralized identifiers do. Self-sovereign identity is where you assert your own identity and verify yourself based on, of course, a decentralized identifier. But we play in the decentralized identifier space. We do not let the user go and state and claim who they are. We actually let the user enroll his identity using an identity document already issued by a trusted verification source or a source of authority that can be verified. For example, your driver’s license is issued to you by the DMV. You can use your driver’s license to enroll your verifiable credential and bind it to your decentralized identifier, but that does not make it a self-sovereign identity. In my world, the way I look at—

Riley Hughes: And when you say self-sovereign, are you referring to that as like a self-asserted identity, basically?

Rohan Pinto: Self-asserted, correct, yeah.

Riley Hughes: Maybe let me zoom out from the terminology here and just conceptually, right, user-controlled identity with a, or identity wallets with credentials in them, regardless of which technology or which whatever, like that concept of decentralized, you know, user-controlled identity, why is that not more widely adopted than it is today?

Rohan Pinto: Because it’s rocket science. Think about it this way. The iPhone is so, the iOS, it’s so simple to use that my mom, my grandma, my not-so-tech-savvy relatives find it very easy to use an Apple iPhone as compared to an Android device or a OnePlus device or another device. Why? Because it’s ease of use. So what we have tried to do on the 1Kosmos platform is, while we maintain the security and the complexity of the technology stack, we try to make it as simple and user-friendly as possible for the end user, where all the end user has to do is download the app, take, scan their driver’s license and phone, and everything else happens behind the scenes. Which is why we see a lot of adoption. We have on— I cannot use certain names, and I’m sure you understand why.

Riley Hughes: Of course, yeah, that’s fine.

Rohan Pinto: But things like Verizon ID, I can talk about it because it’s public information that’s out there. But when you make it very easy for the user, and the user doesn’t really have to care about the complexity of the technology and what you’re doing behind it, that’s the way you gain adoption. The one problem that I saw, that I experienced when I started 1Kosmos way back in 2015, 2016, is that everybody I spoke to said, Oh my God, Rohan, this is absolutely brilliant. This is going to solve— this is the next thing best after sliced bread. This is fantastic. Everybody’s going to love it. And I said, Okay, great. We’ve got 8 billion people on this planet. Who’s going to use it? None. Nobody is going to use this fantastic decentralized identity product that I have, that I’m saying, Hey, consumer, look at the amount of power you have in your hands when you control your own identity. The first thing the user is going to do is, What do I do with it? Where can I use it? So we changed the model and we went the top-down approach. So we said, Hey, you know what?

Rohan Pinto: We’re going to go to organizations and show organizations how they can benefit from decentralized identity and passwordless access and verifiable credentials, and show them that how they can bring down their onboarding time from weeks or days to a few seconds, and show them a huge ROI in terms of their authentication platform or their access management platform or their rules-based platform or their privileged access management platform, and drive adoption top down, which means that the minute an organization signed up and said, We love this technology. We’re going to use it for passwordless access to all our workstations within our organization. We’re going to use it for passwordless access to all our MacBooks and all our web applications. And all we’re going to do is tell all our employees and all our consumers to download our app, and we’re going to bake your SDK into an app. Adoption became a piece of cake. So adoption is very critical and crucial to the success or failure of anything that we put out there.

Rohan Pinto: So if users are not going to adopt it because they don’t know where to use it at, it’s not going to fly. But if there are services out there that say that you can use your verifiable credential to access our single sign-on platform, thereby giving you passwordless access to all the assets within our organization, employees are going to say, Oh my God, this is awesome. I go to my work, I scan a QR code, and I’m done. And now I have access to literally every… Infrastructure component that I need to have access to, whether it is SSH into a Linux workstation, whether it is logging on to your Windows workstation or your MacBook, or whether it is using a single sign-on product. And I would also like to bring up one more point. When we started this discussion earlier, you brought up Okta. And you did mention that Okta is a big giant. And one of Okta’s principles when they started off was, You don’t fight the bear, you ride the bear. I’m not sure if you’ve heard that term before.

Rohan Pinto: So when you try to come up with any product, regardless of how great it is, you have to remember that you’re going into the market where there’s already established presence of IBM, Microsoft, Ping, Okta, Oracle. And these are big guys that have had their presence in the single sign-on space at organizations worldwide. Sorry, I have to mention ForgeRock out there as well. So you’ve got these organizations that play a pivotal role in managing single sign-on solutions for these organizations. Now imagine going into an organization and saying, We’ve got something better. You need to replace your entire Microsoft stack with ours. They’re going to show me the door. Nobody’s going to throw away their entire investment that they have made in their centralized, or whatever you want to call it, in their access and identity management system over the last 10 years for something, for a shiny new object that has come along. So that’s where you got to ride the bear rather than fight the bear.

Rohan Pinto: Saying instead of going to organizations and saying, Replace your entire single sign-on system with this beautiful new self-sovereign identity platform that we have, we say, Here’s a self-sovereign identity platform that we have. Here’s the benefit that it brings to the table. And you can leverage it without changing your existing infrastructure because we’ve got a plugin into Azure, we’ve got a plugin into Okta, we’ve got a plugin into Ping. So if you’ve got Ping Federate, all you do is enable a plugin, and now you can have passwordless access into your entire Ping infrastructure by just clicking a button. So from a user experience perspective, the user said, Oh wow, I don’t have to remember a 16 alphanumeric password string that I have to change every 60, 90, or, you know, 120 days. I don’t need to have a secondary token to enter an OTP code or pull up another app to get an OTP code, or have to rely on a method like SMS to receive an OTP code or an email or a magic link. I can literally use This phone scan a QR code, it looks at my face and I’m in.

Rohan Pinto: That’s as simple as it can get from a user’s standpoint. But from an organizational standpoint, you have turned on biometrics, you have decentralized identifiers, and you’ve got verified identities tied to it, and you’re using FIDO tokens to actually access your system and things, without replacing anything that the organization already has by augmenting it with an additional technology. And of course, if they want to move away over a period of time, we would love it, because that’s additional license cost for us, right? So getting user adoption has always been a challenge, and instead of us going to consumers and trying to drive adoption from the bottom all the way to the top, our approach is go to organizations and drive adoption the other way around.

Riley Hughes: The one last thing that I want to ask you, Rohan, and I appreciate again this conversation. This has been a wonderful one. I always ask guests at the end of each episode, What does the future of identity look like to you? And I wonder if there’s any connection there to your book. If you were able to illustrate anything in that book that outlines how you see the future of identity playing out, or if you had any insights.

Rohan Pinto: And like I said at the beginning of this interview, every time I listen to a podcast where you have an author who has written a book, every second statement is, You can read about it in my book, or, I’ve addressed this in my book, and I’m going to try and stay away from that. So I just want to get it, Just buy my book and read it. Great, let’s put that aside. Now, the future of identity is—identity is the crust of everything. I don’t think people realize how important identity is for a user. I remember when we started our company way back in 2016, 2015 is when we were still in the baking stage, where I was really not out there saying that we have built something, but I was still working on it. There was one tagline that I used to use: Identity is your right and not a privilege. And a lot of people assume that when an identity credential is granted to you, it’s a privilege that you have it. And I say, no, it’s not a privilege. It’s your right to own your identity.

Rohan Pinto: Now, of course, it brings about a whole bunch of challenges on how you’re going to take that identity with you from company A to company B to company C and use it without any interruptions. That’s a separate topic altogether. But the advancements that I see in the identity management space, I think we are right at the beginning of this huge boom that’s going to change the way everything is going to work in the future. Let me give you a small example. I can, in fact, connect my Ring doorbell to my Yale door lock. And even though I’ve got a passcode customized on my Yale door lock, one for me, one for my daughter, one for my son, the minute I approach my door, it recognizes my face and it lets me in without me having the need to punch in a code at all. You’ll see a lot of IoT devices today talk to each other. I can have a little Amazon Sticky on my washing machine that’s going to remind me when I need to change my detergent in my washing machine. I can today control my refrigerator temperature, my freezer temperature from my mobile device. I can control my lights.

Rohan Pinto: I can control my television set. I can control my laptop. I can control almost everything digitally today. But I’ve got an app for Ring. I’ve got an app for Alexa. I’ve got an app for my refrigerator. I’ve got an app for everything else. And every app has its own credentials. And every other user, it’s the same credential everywhere. So if it’s compromised in one place, it’s compromised everywhere else. I’m sure you would have noticed that too. You log into Google Chrome now and Google’s password manager tells you, Oh, your password was found to be compromised in 200 other places. We advise you to change your password now. So… Right now, we have siloed identity systems all over the place. At some point, it’s going to be unified into one singular identity. I’m not going to use the term singularity because it means something else altogether. But you need to have one identity to control everything and anything, regardless of whether the product that you purchased or the system that you’re trying to access was procured from vendor A or vendor B.

Rohan Pinto: It shouldn’t matter to me whether my doorbell is from Ring or whether it’s from Google Nest or whether it’s from Blink or whichever the third-party vendor is. If I could use a singular identity to control that doorbell of mine, my door lock, my refrigerator, my TV, everything around me, that’s the power of what identity can do. So down the line, I do see a world where it’s a singular identity. I’m not talking about a One Kosmos identity. I’m talking about a decentralized identifier being used with biometrics to access systems and things, regardless of whether it’s Trinsic ID or One Kosmos ID or Civic ID or Okta ID or a Ping ID, regardless of which one it is, or Entra for that matter. Biometrics would take center stage. It would play a huge pivotal role in how secure authentication is managed in the future.

Rohan Pinto: Verifiable credentials still has got a long, long way to go because of the 25 universities that I’ve spoken to, probably one or two of them have the ability to issue a verifiable credential, and that is because they are Azure customers, and they can literally log on to Azure and issue a verifiable credential. But the industry itself has got a long way to go before they can actually have stable infrastructure on their side to issue credentials as well as consume credentials, because you’ve got to play on both sides of the fence. It’s not enough if you can issue it; you also need to be able to consume it.

Riley Hughes: Yep.

Rohan Pinto: And this is going to take place, so I would say over the next five to 10 years, where you would have everything come together as one, regardless of whether it’s in one app or two apps.

Riley Hughes: Yeah, awesome. Well, great. Thanks a lot, Rohan. This has been a wonderful conversation, and I hope that it was as interesting to you as it was for me. Last thing, do you have anything to plug, or if people want to get in touch, where can they find you?

Rohan Pinto: Oh, finding me is very simple. I tell people, not to brag, but I tell people, just Google Rohan Pinto and you’re going to find me. There used to be a time where I was afraid of saying Google Rohan Pinto because you don’t know what information is out there on the internet, right? But finding me is very simple. You can literally go to 1kosmos.com and go to the contact page and contact me from there. I author on Forbes quite often, so you can also read my posts on Forbes and contact me through that. My personal website is rohanpinto.com, so obviously you can just email me, rohan@rohanpinto.com. But the simplest way to get in touch with me is just Google me. You’re going to find either my address, or my phone number, or my email address, somewhere or the other.

Riley Hughes: Great. So much privacy for a person who is focused on privacy, right?

Rohan Pinto: Yeah, exactly.

Riley Hughes: Yeah, nice. Awesome. Great. Thanks a lot, and thank you for listening. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out on Twitter at Trinsic underscore ID, or to me at Riley P. Hughes, and visit Trinsic if you’re interested in building the ID tech products of the future. Subscribe to get new episodes as they drop.

Zack Jones

Director of Product Partnerships @ Trinsic

Zack Jones leads the product partnerships at Trinsic that together form the connections that make up the world’s largest identity acceptance network. Zack is a published author, expert on digital IDs, and passionate about entrepreneurship.

Newsletter

Subscribe to weekly insights and updates in the digital ID ecosystem.

sphere background icon