Interviews

Teresa Wu - Driving Mobile ID Adoption at IDEMIA

Zack Jones

·

·

3 min read

On this episode we spoke with Teresa Wu, Vice President of Smart Credentials and Access at IDEMIA. IDEMIA has been involved with many U.S. states for their mobile IDs, including New York, Arizona, Iowa, Delaware and more. Very few people on earth have more experience than Teresa working with governments to issue digital credentials.

We asked her what would encourage more states to launch mobile IDs and drive end-user adoption. Her response was: more relying party use cases. So, we spent most of our conversation exploring questions like:

  • Should relying parties wait to adopt until standards mature and more people have digital IDs?

  • How can relying parties get started now?

  • How much should the industry channel its energy towards innovation vs. standardization?

  • How will the wallet landscape evolve? Will operating system wallets dominate, or will there be lots of wallets?

We closed out by covering the lessons Teresa has learned through all this experience for public servants. I think this conversation will be relevant to anybody interested in digital IDs, either on the issuance or acceptance side.

You can find Teresa on Linkedin and learn more about IDEMIA on their website.

Subscribe to our newsletter for more announcements related to the future of identity at trinsic.id/podcast

Reach out to Riley (@rileyphughes) and Trinsic (@trinsic_id) on Twitter. We’d love to hear from you.

Full Transcript

Transcript lightly edited for clarity.

Riley Hughes: Welcome to The Future of Identity, a show that highlights the world’s most innovative digital identity ecosystems and the people behind them. I’m Riley Hughes, co-founder of Trinsic, and we are the first identity acceptance network, helping businesses verify their users 10 times faster through close partnerships with dozens of digital identity wallets. Today I spoke with Teresa Wu, Vice President of Smart Credentials and Access at IDEMIA. IDEMIA has been involved with something like a dozen states for their mobile IDs, including New York, Arizona, Iowa, Delaware, and more. Very few people on Earth have more experience than Teresa working with governments to issue digital credentials. So, of course, I asked her what is going to drive more states and drive more adoption within states that already have mDLs, and she said more relying party adoption. So naturally, we spent the majority of our time talking about relying party adoption.

Riley Hughes: Here, when we use the term relying party, we mean businesses that are interested in accepting a mobile driver’s license to verify the identity of their users. So some of the stuff we covered is things like: should relying parties wait to adopt digital credentials until the standards and adoption become more mature? How can relying parties get started today if they want to, and where should the industry channel its innovation energy versus its standardization energy? We also talked about how the wallet landscape will evolve, like whether Apple and Google will simply dominate or whether there will be lots of wallets out there that relying parties will have to figure out how to accept. And we closed out by covering the lessons that Teresa has learned through all this experience for public servants specifically. So I think this conversation will be relevant to anybody interested in digital IDs, either on the issuance or the acceptance side.

Riley Hughes: Now, before we go to my conversation with Teresa, I just want to say the best way to show us that this content is interesting or helpful is to share it with others who would benefit from listening. So thanks in advance. And now to my conversation with Teresa. Welcome to the Future of Identity podcast, where we talk to the people building the world’s most innovative digital identity ecosystems. I’m Riley Hughes, co-founder of Trinsic, and I’m here with Teresa Wu, Vice President of Smart Credentials and Access at IDEMIA. Teresa, welcome to the podcast.

Teresa Wu: Thank you for having me, Riley. It’s good to be here.

Riley Hughes: Yeah, it’s really good to talk to you. We’ve had a couple of conversations with people in the United States working in and around the mobile driver’s license ecosystem, and people tend to really like those types of conversations. And of course, IDEMIA is among the largest players in that world. Excited to talk to you for that reason, as well as just all your experience in the digital identity space and just thoughts on kind of the industry writ large. So yeah, thanks again for joining.

Teresa Wu: Yes, thank you.

Riley Hughes: Let me just start off by maybe pulling that thread of mobile driver’s licenses a bit, simply because I think IDEMIA—I probably should have checked before we recorded—but I don’t know, something like 10 or 12 or more states whose kind of mobile driver’s license apps and technology are built on IDEMIA’s platform. And so I wanted to ask just where are we at right now, as of—we’re recording this in May of 2025, right?—where are we at with mobile driver’s license adoption? Has it gone as quickly or slowly as you had expected? Or, yeah, give us kind of your take on the lay of the land.

Teresa Wu: I think the lay of the land is, I think it has gone faster for a while. It was just one, two states per year going, adopting and launching. And now, I think last year alone, I think we saw different states launching one way or the other, either it’s in their own wallet or it’s in the native wallet. You start seeing definitely more than half the states, it’s actively working in some form, issuing a mobile driver’s license or mobile ID. The reason why the keeping count with IDEMIA is tough, depending on one, because there’s some states that stop, some states start, and some states are having a digital ID, but it’s not for mobile driver’s license purposes. So they are digital ID, but they are not necessarily a mobile driver’s license. But mobile driver’s license is a very niche digital credentials for driving privileges, but their ID, there are other kind of digital ID the state use, like in the case of Tennessee, we use the same platform to issue their PROOF ID. So it’s for the parent to be able to PROOF to the kids, and they have to get themselves verified first.

Teresa Wu: So actually, the platform can be used more than just issuing mobile driver’s license. So that’s why, depending how you ask the question, if you say, ‘mobile driver’s license,’ then I have to get it very strict. When it’s mobile ID or digital ID, then my pie gets bigger.

Riley Hughes: Yeah, for sure. Mobile driver’s license certainly is very niche from the perspective of what is the explicit authorization or intention for the credential in the first place. But from a market interest perspective, and from a sort of mobile driver’s licenses are hot. It’s like the thing that people are really interested in, and I think part of that is because we use our physical driver’s license for so much more than just proving that we can drive. I guess when you think about the landscape, how much sort of emphasis do you think the industry should put on the mobile driver’s license piece versus the broader portfolio of the different types of digital IDs?

Teresa Wu: I think if you talk about U.S., definitely it’s hot because it’s only it that it’s interoperable, widely adopted, and you have, I would say, a collective agency working towards that common goal under several high-level standard, right? It’s all aligned to ISO standard, all aligned to the NIST guideline more or less, or at least there’s the NIST guideline there. And then NIST is trying to build a digital trust around it. There’s an infrastructure effort, and there’s a partnership with TSA on the travel use cases. So definitely I can see why mobile driver’s license in the U.S. is like the major force in this digital ID landscape. You can’t not overlook it because there’s nothing else really that can at least have such a… strong foundation for building up the ecosystem.

Riley Hughes: Yeah, yeah, that makes sense. You mentioned over half the states are actively doing something with mobile driver’s licenses. From my kind of reading of what I can tell, there’s something like a third of the states, I can’t tell what they’re doing or if they’re doing anything or whatever. So there’s like maybe a third that have an mDL, a third that are, like, actively working on it or whatever. And when I say mDL, I should probably say a digital ID. A third that are actively working on it, and then another third that are absent or maybe are working on it in silence or something. But I guess, what is it going to take to get that sort of last third of states that are maybe moving a little bit slower? Or maybe they’re not moving slower. Maybe it’s just timelines kind of fall where they are, and we’ll quickly see those come online. Or I guess, what do you think the next couple years will look like there?

Teresa Wu: So I think in all new technology, you look at the technology adoption curve, right? We learned from school, there’s early adopters, then you have adopters, and you have late adopters. There’s going to always have late adopters, whether it’s legislation challenges or just the technology resources, or they just wait and see to understand the use cases. I think there is no—it’s a different profile, different cycle where they are in the innovation lifecycle. I would say what makes them move, I would say the relying parties. I think when the relying parties, it’s enabling more use cases and make the agency less effort to create use cases or enable use cases, I think that that will have that pivoting effect, like that snowballing effect, to get more agencies to launch, to launch. Because there’s no point in issuing an ID if there’s no use for it.

Riley Hughes: Yes. And on the other hand, there’s no use in accepting IDs unless they’re out there. So this is where the kind of chicken-and-egg problem comes from. And this is where I think governments have such an interesting and compelling role to play because, as a government, you can break that stalemate, right? You can step forward and say, okay, we’re going to do this. And then once the sort of private sector and the broader kind of economy sees what the sort of—like, the government can be like the anchor that then the rest of the ecosystem builds around, potentially, right? So I guess, I don’t know, do you see it the same way? Or have you seen something else help to break that stalemate in the states that you’ve been involved with?

Teresa Wu: So you’re not wrong, because honestly, without TSA doing this pilot with digital ID pilot two to three years ago, starting with Arizona and then the other state, one, two, three. Personally, I work on the reader technology to enable TSA to read mDL. So I can see that government does have that effect, and they did. TSA was that in-person use case that we call the killer use case or the prime use case that may drive that incentivize agency to issue credential because citizen can use it, and it helps with the airport and driving other adoptions. I think ultimately, if we want government, I think government can only help to a certain extent. And in the other part, I see more and more relying party or enterprise try to self-organize to start driving more participation into this effort. Government can only go so far. And I think that the in-person, it has happened because in some of the states, they are seeing some of the smaller businesses use mobile ID, verify mobile ID.

Teresa Wu: But see the dash seven, when the online presentment is really getting out there, which is going to take a little bit, we will see more that another wave of snowball coming. I think it takes— Public-private partnership, the public sector can do so much, and then the private sector need to be able to have this fueling the momentum, like adding fuel to this, by doing pilots, by driving interest, by doing testing, by doing all that. NIST, as another part of the government, have started with the NCCoE mDL acceleration project, and in phase one, we worked with a lot of different parties to come up with a framework on the online KYC use case. So I think the appetite is there, definitely around mobile driver’s license. There’s a lot of, you and I talk about it, is in between, we’re gonna need some transitional use cases, and that’s where the private party, such as yours, can play a role because at some point in this landscape, we don’t have one flavor of mobile ID. We have multiple.

Riley Hughes: Yeah.

Teresa Wu: And you’re gonna need certain relying parties are very early adopters and very adventurous and understand and nimble and can deal with the tech innovation. Some other relying party will see that as a burden and confusion, which is even weigh even more. So I think at some point you’re gonna need that transitional kind of technology enablement, allowing that second wave of relying party to use or consume mDL in the least painful way. I think that’s where the government can help us. This is something in the tech sector we need.

Riley Hughes: Yeah, I totally agree. And okay, so I have three sort of threads I want to pull there because there’s a lot of interesting things there, I think. I think in my question, when I asked or when I brought up governments as maybe a party who can break the stalemate of the chicken and egg stalemate. I was thinking exclusively about basically DMVs and governments issuing credentials. And in your answer, you brought up TSA as the primary driver, which wasn’t on my mind, but essentially a government agency as a— relying party being the driver, which of course, I think it’s a little shimming up like a chimney or between two walls or something. You can’t just scale one wall. You kind of have to get one leg up in the first one, and then the next leg up, and then the next leg up, and then the next leg up. So it’s not all one or the other. I don’t know if that analogy makes sense. Apologies for anybody listening. I’ve just been moving my arms around.

Teresa Wu: I make Riley dance on his own podcast. Just saying.

Riley Hughes: Yes, exactly. But yeah, talking about government relying parties as a compelling kind of driver of adoption, and I think this aligns really well with the podcast episodes that I’ve recorded with people like ID.me and BankID Sweden and other really highly adopted digital ID networks, which have government relying parties that help to drive it. What have you seen with the governments that you work with who accept mDLs, specifically state agencies or maybe other kind of smaller maybe relying parties than the TSA, which really spans the whole country? Have you seen what are the use cases where government relying parties are really able to get value today with the digital credentials that exist?

Teresa Wu: Without—I won’t name any agency, so I can tell what use case I have seen agencies use with mDLs. In the meantime that the online presents being published, we have seen agencies use it as a step-up verification before the person get a disbursement or payment out of their account. There is the use of the step-up verification before you conclude a title transfer. So it’s being used, the identity verification as a way to do step-up, as a step-up mechanism, to say, I want to make sure you who you are. So I’m going to ask for your identity attribute from your mobile driver license. Please share with me so I know who you are, because you, at least you can have it, right, to share with me. I have seen now some agencies considering using that as another way of doing, like, address change, step-up verification, so that we know who is asking by getting the identity attribute from the requester, for example. So those are the use cases we have seen. I have seen interest in using mobile driver license in visitor management, right?

Teresa Wu: If you can get a driver license, verify driver license, you should be able to read the mDL for the visitor or the guest checked in, right? So those are—and some are, the most prominent one that I’ve seen is age verification, like what Iowa did. So Iowa Department of Transportation actually partnered with the Iowa Alcohol Beverages, where they have an app that they publish, so letting the establishment to be able to use to verify age. So the app was used so you can scan the barcode of a normal driver license to verify age, and they integrated the mobile ID verification capability into that alcohol board so that the establishment can use it to verify also mobile driver license of patrons that is visiting the establishment consuming alcohol. So I think age verification definitely is that driver as well to verify age. So those are the main ones. I would say that more and more, I’m hoping the future is that we will see more like onboarding, KYC onboarding.

Teresa Wu: Not just opening a bank account onboarding, like any kind of onboarding that we will say, you can have a license, but we prefer mobile ID. Another jurisdiction has done is that they did not use a mobile driver license, but they have used eIDs. It’s a pilot that we did several years ago. It’s before it ties into your tax filing. So when you file your taxes, along with eID verification, it’s actually got expedited and fast and more secure because it’s the person that filed the tax and not fraudulent filing. So those are the sort of use cases you can see, is that when you can trust that identity, and therefore you can expedite certain transactions. And we see that also in unemployment benefit. There was a customer that have done that. It’s doing IDMV. It’s either we do IDMV verify you with normal documentation, or we tell you, hey, go get a mobile driver license and then come and do an identity verification with your mobile driver license.

Riley Hughes: Yeah, yeah, that’s a great answer. And there’s maybe four or five different use cases that you outlined there. And I was asking specifically about government relying parties, but all the use cases that you outlined are use cases that apply to the private sector as well, just general, whether it’s in finance or healthcare or gig economy or whatever, right? The use cases you’re describing of payouts, onboarding, step-ups, these are things that apply pretty universally.

Teresa Wu: For me, really, I was speakedly absent. Private sector would be rental cars. Isn’t the rental cars really need to verify a driver license when they rent? Or the, like you say, gig, like the gig economy, the Uber, Lyft of the world, at some point, that they’re all online. So once the online enablement is done, I can see that as that it’s a matter of time. It’s a matter of when, it’s not if. They’re gonna have to. This, the use of mobile driver is, it’s coming. It’s just a matter of when, and it’s not a if thing. It’s how to do it and when to do it.

Riley Hughes: I don’t know if you have a view into my little notes here, but you’re perfectly transitioning into my next question, because where I was going to go next is ask about the timing as it relates to relying party adoption specifically. in the context of standards development. So what I’m interested in is that something that I notice tends to happen is that standards, once they’re widely adopted, accelerate adoption dramatically. However, when standards are still in development, like the number of times I’ve heard people say, Oh, we’ll wait for Dash 7 to exist, or, That was published last year, and we’re still wait— you know what I mean? And then now I hear people, instead of talking about Dash 7, they’re talking about the digital credentials API. Okay, we’re going to wait for this to get through the W3C, and we’re going to wait for— It seems to me that as some of these standards are in development, it can tend to cause relying parties to delay and cause adoption to slow while those things are still out there.

Riley Hughes: And then in the meantime, you have states—we did a podcast with the Louisiana mDL folks—and they released online presentation in a non-standard way. It is used a lot, and it’s the highest adoption state. And so, yeah, I’m trying to contend with this kind of question of when should—how should a relying party think about its timing for adoption, given the changing standards landscape? That’s the question.

Teresa Wu: I would say, remember I talk about the innovation life cycle. You get the relying party to identify themselves as early adopters, or just advanced adopters, adopters, late adopters, right? Because then it’s about their willingness to take the risk or willingness to say that what they do, they may need to rework it. A lot of time what I hear relying party want to wait is because they only want to do it once this integration once, they want to do this support once, and don’t want to do it again. At some point— They’re going to come to realization that may not be the optimum outcome. But there’s some early adopters that has been—they don’t wait for the standard. And IDEMIA has been doing eID without standard or without—and standard come along, we participate in it. It takes a long time because it’s a lot of parties have a lot of voices, and you are doing this, like, massive cat herding to converge into the common denominator that can work. The standard, at the end of the day, is the baseline, not the top line.

Teresa Wu: I always tell my client is, yes, standard is the bare minimum to make sure that it’s interoperable. So one reader to one issuer, you can read each other. And that, even though we can write to the spec, we can still have interoperability issue. That’s why we do interop testing and so forth. So it’s not like you write to the spec, the spec is out, naturally, natively, everything just work together seamlessly together. It’s not the case. It won’t be the case. I would say that it’s a lot of what you’re doing here—education. It’s about getting convincing relying party not wait. Try it now. Learn how to do it now. Get your lessons learned. Fail faster so that you learn and innovate, right? And get your lessons learned so that your next system will be—your next iteration is more robust. Like you say, it’s the iteration thing. It’s about when you’re going to start your iteration. It’s going to keep evolving. The digital ID space is not—even with the standard coming out, even with ISO 18013-5, -7, W3C verifiable credentials, all this, the major three standard is being published.

Teresa Wu: It’s not done yet. Even -5, we are looking at renewing it because we learned there’s new technology coming out, right? -5 was based on QR code, NFC, and Bluetooth, and we’re now looking at maybe there’s other transport more efficient. And maybe if NFC is not really scalable across all platforms, maybe we need to look at something else. So standard is never stop changing either. It’s what makes sense. Actually, in the standard in 2021, they have Wi‑Fi aware in it, and Wi‑Fi aware never got adopted, right? I would not— I hear what you’re saying. Some want to wait, but I think it’s because of the innovation profile is different, and the appetite to take the risk is different. And I think that’s why the private sector, the technology provider like IDEMIA or Trinsic, we should looking at what we can do to do that backward compatibility. It’s like how, for people that have invested now, when things change, how we help them evolve and not have them go backward or start over. You build upon it. You don’t have them, Oh, now change. Oh, sorry, you’re gonna tear it down.

Teresa Wu: Just change everything else. Well, that would be very frustrating. I feel like there’s this, like, absorbent layer that needs to—the buffer layer needs to happen between the standard and the relying party, where the buffer will adjust those changes and make the relying party—the adoption—less painful.

Riley Hughes: Yeah. Yeah, I think if you’re a relying party who resonates with that last comment, then I think you should probably reach out to me or Teresa about how to solve that problem. Because I think that’s probably—you’re giving a good—I’m taking notes here on how to improve my sales pitch based on what you’re saying here, Teresa. But yeah, I think you’re right. That’s why we’re doing what we’re doing, right? It’s because it’s, okay, I think this is what the market needs, so let’s try to see if we can help address that. And I think that is, I think, how the market is going to need to play out with respect to standards. The other thing I think about with standards is how, as you mentioned, when you standardize something, everybody’s got to herd the cats, everybody’s got to agree on the standard, and you bake certain things in and make certain assumptions, and then you publish something, and then of course when you learn, you improve the standard.

Riley Hughes: But I don’t know when the first, you know, ISO, the 18013-5, was published versus when it will be updated with these new things that you’re talking about, but the timeline for iterating on a standard is much long.

Teresa Wu: Yes.

Riley Hughes: And if you compare that to a non-standard approach where you could iterate on it every week.

Teresa Wu: Right, because you don’t need to worry about compatibility with some other system, right? You can just keep iterating on it quickly.

Riley Hughes: For technology. to be adopted, you need something that has a product-market fit, right? Something that users want to use and that is, you know, meets the use case. And often it takes iteration to discover what is the thing that is needed here, right? What is the best form factor or the best solution for the problem? And so I view the, like, standardization and innovation are both required for adoption, and yet they are in conflict with one another. Do you see it the same way? Or I guess, how do you think the, again, maybe this is like a similar to a stalemate, right? Like how does the industry break out of this kind of, if you agree that it is a challenge?

Teresa Wu: I think that’s why the industry advocates is important. It’s only, it’s a way where we need to inject energy to not having them in conflict with each other because that’s counterproductive. It’s how to channel one, like align both sides so that it’s become force multiplier. I think there’s nothing wrong with innovating, but if we have a baseline now, and it took a while to create this baseline. Like I said, like IDEMIA started doing mobile ID before there was standard, but we keep doing it. But when the standard agreed, and we were, because we are participating in the standard, so we know it’s coming, we align our innovation effort to that, what standard is coming. I’m not saying we need to have a crystal ball and say, hey, what’s the next version. It’s by people that know what’s coming in the standard because the company invests time and money and participation in those standard discussion working group, working that standard. And so you saw those standards being developed and being created, and a lot of openness to learn and share and get feedback.

Teresa Wu: Now, innovation, I would say that same thing. It’s really about, I would ask people, when they say they want to innovate, great. If it’s innovate around mDL, they need to acknowledge that what exists, what’s being, what was done. You’re on the shoulder of somebody else. You did not do it by yourself, right? So you’re going to build upon what exists and what’s in the baseline if you want to create the momentum. You want to say, Ah, I just want to innovate, and whatever exists, I don’t care. I’m not acknowledging it and start from scratch. You’re probably wasting your time, or recreating the wheel, literally, or you’re just counterproductive. So I think it’s like where you want to play in the innovation, in the, what’s the goal of the innovation? If I would say, like, there was, for a while, there was a debate between ISO and VC, verifiable credentials, and ISO, which one is better, and there’s debate. I actually very uncomfortable with that debate.

Teresa Wu: I was in seven phone calls, and we start to ping one against the other, how these, and then there are papers like that where say, hey, VC is better. There are companies that put papers out there to say, hey, I mean, like, the verifiable credential is much better. It’s blah, blah, blah, blah, blah, privacy-preserving, blah, blah, blah, and ISO doesn’t have any X, Y, and Z. I think that is counterproductive to compare, because they serve two different, I would say, use case or landscape of the digital identity. I think the world is large enough for these two kind of credentials to coexist, and we’re going to need the coexistence and be smart about how the world, digital world, will be more secure, more robust, if the underlying relying parties or the technology can deal with both. It’s a game of and not either. So, I would say that we need to be careful not to, like, pick one against the other, not knowing what can play. Because in the government side, they align on ISO. That ship has sailed. It’s not like you can undo that. It’s not going to be undone.

Teresa Wu: You look at how many government IDs being issued under the ISO format standard. We need to accept that it’s done. But now, there are going to have verifiable credentials, exciting part of the future is in the future where you can have generate verifiable credentials derived or backed by those government credentials. If you feel the energy and the trust in these privately issued credentials, because they have a, call it the trust anchor. The physical ID is the trust anchor of those mobile government documents, right? There’s a chain of trust that’s happening. But when we can derive, create a digital anchor out of that physical trust document, trusted document, out of that IAL3 event, then you can branch off and do many other things from it. So, it becomes a multiplier. I think the way I see it is how it’s critical. I agree with you. It’s critical that we channel our innovation energy by building what’s upon and not against what we have.

Riley Hughes: Yeah.

Teresa Wu: Okay. You’re not convinced, Riley?

Riley Hughes: Well, no, I am. I’m developing a new opinion here on this conversation, or during this conversation, and so I’m going to… Oops. I’m gonna throw out this new opinion, and I want you to interrogate it or tell me what your thoughts are. Okay. So with this standardization versus innovation thing, right, this takes—your answer takes me back to what you were saying earlier about relying parties don’t want to have to rework the thing that they’ve already implemented, right? Of course, if you say, oh, it’s a game of and, not either, then that may make a relying party say, oh no, you mean I have to support not only this one, but now another one, and then maybe another thing after that, and maybe I already did the transport protocol for— dash five that does this one thing, but now there’s going to be a new transport protocol that I need to support that’s going to be a part of the standard. And I think one thing I’ve observed, to your point about interoperability testing, is that supporting a standard does not mean that you’re interoperable with another.

Riley Hughes: It doesn’t mean that the use case is interoperable, because a given use case may use three or five different standards to accomplish the use case, right? From the credential format to the signature scheme to the transport mechanism to the PKI infrastructure to the whatever, right? Like, you’ve got to match five different things up or seven different things up to truly be interoperable at the use case level. And as I’m thinking about this, I’m thinking, man, it’s good to innovate on new things like this because we’ll get, hopefully, the survival of the fittest or whatever. We get the best products. But it’s also harmful because then we’re not standardized, we’re not interoperable anywhere. So here’s the opinion that I’m shaping right now: innovation, maybe like the energy toward innovation on things that build around what’s there. For example, the digital credentials API is an example of an innovation that builds on what’s already there and is compatible with things. Like, that’s a good example, fits that.

Riley Hughes: And then on the standardization side, the thing that I’m really interested in there is, like, standardization at the interoperability profile level, right? So the sort of set of things required to accomplish a use case. Does that make sense? Because I would really like to get to the point where there’s true interoperability at the application level for real-world people, and it just seems each year. Two to four years away, and it keeps being two to four years away every year or something. I don’t know. What are your thoughts on that?

Teresa Wu: I’m more pragmatic, I think, because I probably got deformed or reformed by working for the government program. I’ve always been mostly a B2G kind of person. I’ve been always working for the government, provide, enable them the backend system from way back, even before I do mDL. So I’m very used to the fact that government is all about stability. You look at, think about it, a lot of things the public sector does, it’s public infrastructure. And the public infrastructure need to be stable, need to be robust, need to be resilient and persistent. So I think I’m coming from a school that whatever we build need to last, not just because it’s new and just need to solve this set of problem. It’s really, I guess I’m just prioritize—I’m used to prioritizing. That is the need for stability, because you can’t just switch. Tear down and build up again. It just, you need to continue. It just, your power plant, it makes power. You’re gonna design a power plant, whether it’s coal, gas, energy, water, solar.

Teresa Wu: Once you pick that path, you’re probably gonna stuck on that path for a little bit, even though you innovate outside of it, right? I would say that even ISO, inside ISO is many other standards. It’s the ISO 18013-5. It’s built upon, I think Christopher Go did the little counts, like a dozen, 36 standards. It referenced 36 different standards. So it’s not like it’s a brand new standard. Actually, they use a bunch of existing standards, being used Bluetooth, for example. It’s one of them, right? It’s a standard, and then they use that to build what the protocol looks like. So I don’t have that, I guess I don’t have that kind of worry that, one, maybe I’m having, I accept the fate. Number one, things always change. When you’re in this space, things change all the time. At the same time, how to become that stable, permanent, like that robust layer to get things going. So that’s, I think that’s the balance.

Teresa Wu: It can be uncomfortable to be had, is that my stability comes from the fact that things always change, and we need to always adapt, and we need to make sure that there’s a path for evolution, not revolution. And we have been doing this digital evolution since 2015. So I think that after 10 years of doing digital ID, with the state try different things out, I guess we just know that things always change. Like, standards, it’s bound to change. There will be probably new kind of credentials, and—but I’m not saying the more the merrier, but there’s gonna be, in the world. You want user choices, right? You want choices. So therefore, once you start saying that we want to give people choices and not forcing them to only use this and nothing else, your platform bound to be, need to be flexible, need to have options, and need to be able to evolve.

Riley Hughes: Yeah, that’s interesting. I think you coming from the B2G side and me coming from the startup side, where startups inherently are fast-moving, fast iteration, and also our constraints on things like capital, right? Startups can’t just survive forever, right, without success, right? That’s maybe where my head is coming from. But I do think we align on what you’re describing on that sort of layer that can be stable. I think that the fact of all these standards and then how they relate, and that you need to cover five of the same things in order to be interoperable with the next thing or whatever, is really the insight that led to the product that we have anyway. So I think we see the world in the same way, where that layer needs to exist, and whether a relying party wants to build that layer themselves, that’s great. And if there’s others who they can partner with for that layer, I think that’s probably the way that this gets solved in the near term, in my opinion.

Teresa Wu: Yeah, what I said is it’s for the relying party. When you’re gonna go on this digital journey, who you’re gonna… going to pick as a partner to go on this digital journey with you? It’s important to pick. You can do it yourself, but know what you up yourself to. It’s gonna change. It’s gonna have— that’s going to be a compelling factor, because each market will come have a different notion of what digital ID means. Like, you ask, what is digital ID in the healthcare sector, to the transportation sector, to the government sector, we’re going to tell you two different definitions of what digital ID is, right? So if you’re a relying party and you want to go on this digital journey, it’s the selection of that partner or the path you’re going to go on that journey matters the most, your starting point. You’re going to do it yourself, then you better send people to standard groups to get feedback. Make sure you invest in it, ready to drive the standard yourself as well, right?

Teresa Wu: If not, then you have to have a partner that’s willing to go on this journey and be flexible, know things are changing, and be a robust partner to you. So I think that’s the sort of my thing is if you— it’s not for everyone to go on the digital journey. Infrastructure digital transformation is difficult. Change is difficult. Transformation is difficult. And then you think about digital transformation, it’s more than just technology, by the way. In government, it’s more than just technology. It’s knowledge, it’s process, it’s infrastructure transformation. It’s a lot. It’s a change management. It’s budget and all that. It’s N, N, N, N, N. If you’re gonna go on that journey, I would say some people are waiting. Maybe they’re waiting, or maybe they are looking at what are the things they need to align to make this transformation less painful or more managed, maybe, or they just don’t know where to start. But I think when you start, you need to go wide eyes open. It’s a transformation journey.

Teresa Wu: Therefore, you need a good baseline or partner or technology to do that, and investment and resources to do it.

Riley Hughes: Yeah. Great. One of the things I want to cover today while we’re—I love this thread that we’ve been on, relying parties and relying party adoption. And one of the questions I hear a lot from relying parties is about wallets and just how that landscape will evolve, right? And obviously, IDEMIA powering a lot of wallets across the United States, but also just as Teresa, who participates in all these groups and who’s worked at several identity-related companies and been involved in a whole lot of things and seen standards evolve over time in various ways, I wonder whether you think that the wallet landscape will continue to be fragmented in the United States and that there will be one wallet per state or maybe even more than one wallet per state or something like that into the future, or whether you think things will mostly converge on things like native wallets or other mechanisms of convergence there. Does that make sense?

Teresa Wu: Yes. I’m the party of user choices. So when you talk about accessibility, think about it. This is a product of the masses, right? At the end of the day, we want everybody have a phone in their hand and have a mobile ID in their hand. So it’s about masses. It’s about different people. I’m the party of, I see choices. I think there’s pros and cons. I think having the state having its own wallet give them a path runway. They’re in control of their runway to do many other things, like Louisiana did, right? But by the time you need, they have access to a tool on wallet to serve the citizen, a government pathway to serve the citizen. And then there’s a direct native wallet integration that allows other—it’s very straightforward. It’s onto the end user’s hand, but then it doesn’t give you that other potential. So I think it’s a choice, I would say that is, and then it’s user choices as well. So as long as you and me not never gonna the same flavor of ice cream, same, I think you’re gonna see multiple choices of wallets out there, depending on use cases.

Teresa Wu: You can see that, I can see in the world where the mobile, the state wallet, it become an anchor point, and then the other wallet will say, Hey, I’m gonna check your ID. Can I just do a call and then grab that ID verification so I can reassert you so that I actually, your digital ID in my universe ecosystem is who you say who you are, so I can help you transact somewhere else. So I see that as a node, and then there’s gonna be other nodes. It’s gonna be a universe of wallets. Any commerce app that want to do CIAM properly, they’re gonna want to become a digital wallet anyway. So it’s gonna be a universe of wallets. I’m pretty sure I will win that bet.

Riley Hughes: Yeah. Okay, so let’s play that out for a second, right? Because if there’s a winner-take-all scenario, right, say it’s like just Apple and Google, and they have everything or something, right? Then it’s, okay, that’s pretty clear. We all know what that looks like. But in a world, in a universe of wallets where there are maybe, instead of each state having their own wallet, maybe there’s some open standard that allows the private sector to supply wallets. Maybe I could get my digital credential in my Cash App or something, right? Like a private sector wallet, third-party wallet. And in that scenario, I don’t know, there’s lots of potential wallets in that world. The obvious question then is, how does a relying party know what to trust? And then the sort of general answer to that is accreditations and certifications and registrations and all kinds of governance frameworks and deep industry standards groups and all kinds of other things that we haven’t even gotten to yet as an industry that then come in to address. that problem.

Riley Hughes: I shouldn’t say haven’t gotten to it yet, but it just is obviously very early. If we play this out, is that—do you agree with my assessment there? Do you think that’s where it goes? And how does that world help relying party adoption in the sense that it just feels like that’s going to be yet another thing, yet another accreditation or whatever that wallets have to do, more concepts and frameworks that relying parties need to understand and adopt. Like, how does this play out?

Teresa Wu: So, I’m not really creative, so I’m going to use—do a parallel what NIST 863 was talking about. It’s really depend on your risk. I’m going to channel Ryan Galuzzo in me. Like, it’s all about your risk that you have to deal with. As a business relying party, what is your risk you’re trying to handle? So you have your risk matrix and your threat factors, and you’re figuring what is the level of business risk you’re willing to accept based on what kind of wallet you get, right? So it’s like your sources become—the identity wallet become your sources of information. So you should have a criteria of what kind of wallet you accept the identity from and not. Because, yes, I agree with you, there’s going to be some wallet that’s more secure than the other, and not all wallets are equal. Unfortunately, it’s not—it is now. Nothing is equal, right? So you’re going to have to have some sort of a selection criteria, and based on your business risk you’re willing to accept, which wallet you’re going to trust and which one you don’t.

Teresa Wu: Either you do it yourself, or you say, I will send to this accreditation party if your wallet is not… Certified by a third party, I don’t care if it’s a third party or a certification program, regardless, right? I don’t accept it. That’s a choice. But because what business risk are you dealing with? I think the relying party needs to look at their risk first and what they accept today. Think about it. Some of these relying party, when you create an account, there’s no identity verification. Just say, name, last name, I can be Teresa Panda and I can have an account. Create it. IOU zero. It really depends. I would say that the relying party should look at their business profile and decide. And yes, there’s going to be some, and that’s what TSA did. If you look at what TSA just issued in the rulemaking in order to accept the mDL at the checkpoint, what they have put in as criteria, and they want the state to certify, self-attest, and then get a third-party independent certify what they have done in the issuance process so they can trust the wallet. They didn’t have an accreditations.

Teresa Wu: They just like, these are my criteria. As long as you have a third party, qualified third party help you attest to that, then I’m okay, pretty much. So I think each relying party is going to have to have that journey. What are you willing to accept and then create your thing? Do you need always necessary relying into a third party? No. Does it help? Yes. But it’s always a, I think maybe it’s a human nature thing, is I don’t want to make that decision, so I’m gonna, if you have that, just trust them, then I can trust it. Have someone make that trusting decision for me. It’s a choice.

Riley Hughes: Yeah, and it speaks to, I guess, just again, going back to that, like having a partner that can cover that layer for you and Make sure that if you’re looking to offload that, like, decision-making to another party, then, like, that layer, that acceptance layer, whatever it can be, that’s another argument for that to be present.

Teresa Wu: Yeah, so it’s, for me, it’s like maybe I’m doing too much government contracting, right? But in my head, if you’re a relying party, you look for a tech, look for a partner. You’re gonna have to have criteria. Start writing up your criteria, what you don’t want to deal with, and then put that in, and then have that third party do it for you because it’s a managed service platform and they manage the risk for you, right? But you’re gonna have to say, okay, these are the things I don’t want to see, I don’t want to deal with, this is the risk.

Riley Hughes: Yeah.

Teresa Wu: And then go out there and then pick the right partner for you. I think there’s a lot of discussion going on. Can I have one platform to do everything on? There’s no such thing. But you can pick a partner to understand where you go after so that we can address—it’s an 80/20 thing, in my opinion. There’s never gonna be 100%. Is there a platform that integrates all digital credentials and every single credential under the sun? If someone say that, I would like to see the list because that would be very interesting. I want to know how much time they spend to scour every single country. Anyway.

Riley Hughes: I’ll share with you our list. It’s certainly not all of them, but it’s—

Teresa Wu: Yeah, it’s getting long.

Riley Hughes: Yes, the list is getting long, but it takes time and effort and commitment to get it.

Teresa Wu: Lots. Right?

Riley Hughes: Yes.

Teresa Wu: So I would say to the relying party, you don’t have to reinvent the wheel. You don’t have to redo this effort, but pick the right platform to help you go on that journey. Or you can sit back and look, and then you wait for it to be more mature. And I would say that it’s—I keep saying this—don’t wait. Start baby steps. Just start, so you learn. So at least you start doing, you learn, you’re ahead of your competition. This is a competition game. The platform that understands how to leverage mobile ID. Even with or without a standard, have a better competitive edge than those that just wait and see. Because the online economy is not going down, it’s growing. So it’s how you capture that economy.

Riley Hughes: Yeah, I agree. It’s better to get started with something small than it is to do nothing and wait. Because there’s always a question of when do you stop waiting? Do you stop waiting when its adoption is at a million people, 5 million people, 10 million people? We’ve already crossed those thresholds now, and so that— I think there’s enough there certainly to get started now. I know we’re short on time, but I want to pivot just a little bit from the relying party side to the issuance side. I know that we have people who listen to this podcast who work in governments, and I guess if there’s a listener who works at a DMV or who works for an agency that could be an issuer of some type of a credential, I guess what have you learned from working with so many similar agencies issuing credentials? What are your top three takeaways for where you’ve seen deployments go well and be successful?

Teresa Wu: One thing I learned quickly when I was being the program sponsor is that you should not assume everybody understands what the mDL is, because mDL is such a technology—like, people think that it’s just digital rendering of this thing on someone’s phone. But in order to enable it, there’s a lot of technology involved, security technology involved. So it’s very important that first thing we do as a technology project, assuming not everybody is technologists, right? There’s some better than the others. So you have to understand the team on the DMV side and on the vendor side, who does what, and do a level set. So we actually do quite a bit of level setting, technology level setting, to explain what things are, and then you start looking at specialized—right?—what one team knows how to do the integration, one team knows the security, and so that that discussion is a little bit more conducive and productive.

Teresa Wu: So really about knowing the audience that this is a very high technology program, therefore we need to be careful not to make it into too much of a— Jargon to the point where it’s not inclusive for other team members to be able to follow, because we have come from all different backgrounds, especially in the DMV world. Not everybody has come from a technology world, so that’s important to work with the people. Number two, I think it’s always, for me, I love my technology team, is that when anything’s that understanding the standards and having as direct, as short path as possible directly to analyzing what’s the customer impact. The customer don’t care what the standard change, to be honest. They care about what does it mean to them? What does it impact them? So you have to make that translation. The faster you make that translation, or the more proactive you are in making that translation, helping them plan ahead better. So standard change is one thing. We have to translate and we have to look forward. So that proactive posture, it’s important because they have to plan.

Teresa Wu: It’s a machine, right? The government, it’s a big machine. It has to work, and we have to understand that. We can tell them, yeah, this is changing. You need to make this change. They’re gonna say, yeah, but I rely on five other teams to do it, so I’m gonna have to coordinate. It doesn’t change overnight. So all those need time, and all those gear, all those cogs in the wheel, this machine need to really, like, click and work with each other. And understand that, it’s very important. And the third piece, I learned, at least in working with my programs, transparency, right? No program will go flawlessly. No program. So it’s about when things are not as expected, it’s some disappointment in things, be it you fail and you learn and you recover, you own it and you learn it and you be transparent how to fix it, and you learn over time, and they go on a journey with you. Because if you come in and tell your customer that it’s gonna be perfect, it’s gonna be like, it doesn’t work. It definitely, I go in, it’s gonna have hiccups.

Teresa Wu: So let’s— Leave and babies liaison with those hiccups together. So it’s team, it’s a collaboration, and it’s about transparency and get and learn from those, whether it’s errors, mistake, delay, you learn from it and get better over time. That’s the whole point of, I think that’s why I think I like the IDEMIA platform, because it’s a platform. So once you learn one program, the other program benefit from it because it’s cross-across, it’s not those standalone integration. It’s one platform. I know, from you, what you mean. So it’s a platform, it’s SaaS, and one improvement we go in, it helps other program do better. And I really like that with what I see in the mDL program. So the third one is even a small win, it have a multiplier effect across all our customers. So I would say that that would be my third thing.

Riley Hughes: Thank you. And yeah, there’s obviously a lot of experience and wisdom behind those. So I appreciate you sharing that here, and I’m sure that’ll be really useful for a lot of the listeners. We always close out the podcast with a final question, which is: tell me what the future of identity looks like to you, and why you get up in the morning trying to build it. Like, what motivates you to spend your time working on this problem?

Teresa Wu: I think in the world, the future of identity is gonna be a world of identity. Identity is really a difficult topic. We have been trying to solve this online identity online forever, right? Since the web, interweb, or the web has been invented. I think securing the identity layer will help us build the trust where in the future, where we can be less victim of— Fraud, deepfake. I think we are all victims one way or the other. I would say you are lying if you know no one that was victim of any kind of identity fraud.

Riley Hughes: Yeah, phishing attack, Gen AI attack, and all that.

Teresa Wu: And it’s gonna get worse. Those threats is getting worse. So you ask me how I wake up in the morning. For me, I’m building that infrastructure so that we can be more resilient against these threat actors. I want us to be able, my kids, my family, to be able to transact online and be resilient and be robust against these attacks. I don’t— I actually want this attack to go away. I want them to be obsolete. Can we work to that future where we don’t have to be a victim of phishing attack or cyber attack anymore?

Riley Hughes: Yeah.

Teresa Wu: Can we work on— that will be the future where the digital crimes will not be a threat on the vulnerable.

Riley Hughes: Yeah. It truly is society’s most vulnerable who are targeted by those types of things, right?

Teresa Wu: So our job here, what we’re doing, I think it builds that shield, that layer, to help those vulnerable population, even us, to be able to transact safely online, protect those identity, protect people’s assets, financial records, or our PII in the future, where we don’t have to like, oh, another hack again, another steal and things on the dark web and all so forth. How can we do it so that the future of identity, the identity is not something that is secure where we don’t have to be fear that someone’s gonna take it and misappropriate and misuse it and victimize you. That would be my, I think, my calling, my aspiration. I think having a trust and then creating an ecosystem of usable, practical reusable identity is great. Awesome. I think that’s a lot of use case there. But for me, it’s ultimately how we can protect us from all this cyber attack. And I haven’t talked about digital identity, and I actually worry about post-quantum.

Teresa Wu: But if we don’t have this secure digital layer and this infrastructure and all this cybersecurity hygiene and practices, or zero trust practices, where identity is one of the pillar, we do that strong, how are we going to migrate and how are we going to deal with the world of post-quantum, where the trust element is even more challenging to do in the world post-quantum? But that’s later. But that’s how I see one thing or the other, why what we’re doing here have big things to play, and have a bigger thing at play.

Riley Hughes: Yeah, thanks a lot. And we spent a lot of time talking about digital credentials and mobile driver’s licenses. Obviously, your role at IDEMIA is bigger than that, right? In your title at the beginning, I mentioned smart credentials and access. And I think when you take both those, we didn’t talk as much about the access side and talk about how these things converge, but I’m sure maybe another time we could. But really, that seems like the combination of those things really can lead to that safety and trust that you’re talking about online. Yeah, I can see why that is your motivator. And I appreciate you joining and sharing that energy with the rest of the world.

Teresa Wu: So thank you for having me.

Riley Hughes: Yeah, thanks a lot, Teresa. And yeah, we’ll talk to you soon. Thanks so much for listening. If you enjoyed this content, please share it with others who will benefit from it. I’ve been getting some great feedback on the podcast recently, and since we don’t do a lot of self-promotion or ads or whatever, sharing the word really is the best way to signal to us that the content is valuable and that we should keep doing it. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out to me directly on LinkedIn or X at Riley P. Hughes, and visit Trinsic if you’re interested in building the future of identity. You can also visit trinsic.id/podcast to subscribe to new shows and subscribe to the Future of Identity newsletter, where we’ll share the essential reusable identity news we rely on straight to your inbox.

Zack Jones

Director of Product Partnerships @ Trinsic

Zack Jones leads the product partnerships at Trinsic that together form the connections that make up the world’s largest identity acceptance network. Zack is a published author, expert on digital IDs, and passionate about entrepreneurship.

Newsletter

Subscribe to weekly insights and updates in the digital ID ecosystem.

sphere background icon