Interviews
Thomas Mayfield – Building Interoperable Web3 Identity with the Veridian Platform

Kelly Javanmardi
·
·
6 min read

In this episode of The Future of Identity Podcast, I’m joined by Thomas Mayfield, Head of Decentralized Trust & Identity Solutions at the Cardano Foundation. Thomas leads the development of the Veridian Wallet, an open-source digital identity platform built on the KERI (Key Event Receipt Infrastructure) protocol and funded by the Foundation.
Our conversation explores the rapidly evolving Web3 digital identity ecosystem—and how Veridian aims to bridge Web2 and Web3 with universal interoperable identifiers that cut through today’s fragmented identity landscape. We also dig into the growing urgency to rebuild digital trust as data breaches, ransomware, and AI-powered threats escalate.
In this episode we explore:
Why interoperability—across Web2, Web3, and beyond—is essential to breaking down identity “walled gardens.”
How the KERI protocol enables quantum-proof, tamper-evident, and recoverable identifiers for individuals, organizations, and AI agents.
Real-world adoption: how the United Nations is using Veridian for organizational identity and passwordless authentication.
The potential for verifiable IoT and AI agent identities to transform trust in machine-to-machine and human-to-machine interactions.
How developers can leverage Veridian’s open-source infrastructure, sandbox environments, and tooling to build secure, compliant identity solutions faster.
The role of regulation in driving adoption—and why future-proofing identity systems now could save billions in breach-related costs.
This episode is essential listening for anyone working on decentralized identity—whether you’re building infrastructure, integrating identity into products, or shaping policy. Thomas offers a rare, in-depth look at how to design for both future-proof security and real-world interoperability.
Enjoy the episode, and don’t forget to share it with others who are passionate about the future of identity!
Learn more about the Cardano Foundation here.
How to get in touch
Most people listen to the Future of Identity on Apple or Spotify or Youtube. You can find all ways to listen at trinsic.id/podcast.
We write a weekly newsletter to highlight the biggest news and developments from the reusable ID industry. To sign up and join over one thousand readers from the identity industry, you can input your email directly into the form below.
As always, you can reach out to our host, Riley Hughes, on X (@rileyphughes) or LinkedIn. We love hearing from listeners! See you again in two weeks.
Full Transcript
Transcript lightly edited for clarity.
Riley Hughes: Welcome to The Future of Identity, a show that highlights the world’s most innovative digital identity ecosystems and the people behind them. I’m Riley Hughes, co-founder of Trinsic, and we are the first identity acceptance network, helping businesses verify their users 10x faster through close partnerships with dozens of digital identity wallets. Today, I spoke with Thomas Mayfield, the head of decentralized trust and identity solutions at the Cardano Foundation, where he leads the development of the Veridian Wallet, an open-source digital identity platform funded by the foundation. We delved into the Web3 digital identity ecosystem and the world of KERI, which is a set of technologies that can power decentralized identity applications and is what is powering the Veridian platform. We talked about some of the use cases that enterprises are using the Veridian platform for and what the future of identity looks like when companies build their platforms with security and privacy at the core. And now to my conversation with Thomas.
Riley Hughes: Welcome to The Future of Identity podcast, where we talk to the people building the world’s most innovative digital identity ecosystems. I’m Riley Hughes, co-founder of Trinsic, and I’m here with Thomas Mayfield, the head of decentralized trust and identity solutions at the Cardano Foundation. Thomas, welcome to the podcast.
Thomas Mayfield: Hi, Riley. Pleasure to be here with you and the team.
Riley Hughes: I’m excited to talk because when we first started this podcast, we had a lot of people from the Web3 world, people working on decentralized identity, on the podcast to talk about those projects. As of late, we’ve had a lot of people from the traditional identity space or the government-driven, you know, mobile driver’s license identity. And so I thought this was a really good opportunity to check back in on what’s new in the world of decentralized identity with the recent launch of your—well, can maybe speak to the recent launch. I thought this would be a good opportunity to do so. So my first question is just what is new in the Web3 or decentralized identity world?
Thomas Mayfield: That’s a great question. Realistically, just to try and keep a finger on what’s happening in Web3 space is difficult enough. Then when you add the complexity of decentralized identity and the ever-growing sort of protocols and DID methods, I mean, that becomes even more complex. What I can speak about is what we’re doing at the Cardano Foundation and how we’re putting a different spin on decentralized identity with the use of our blockchain and the systems we’re building. You mentioned the launch, so that’s the Veridian platform you’re referring to. And what we’ve done with Veridian is it’s extremely different than what other Web3 implementations consist of. This is an interoperable solution that bridges the gap between both Web2 and Web3. The way we communicate this is it’s an optional, light-touch, decentralized ledger technology implementation. We can probably delve deeper into what exactly that means.
Thomas Mayfield: We definitely understood there’s a significance being able to interoperate across those traditional Web2 spaces, where the majority of industry and business is, and bridge that across to the more innovative Web3 space and maybe bring some of that trust and verifiability that’s been well established into Web3.
Riley Hughes: I think most listeners to the podcast are relatively familiar with the concept of an identity wallet and the identity space generally. So maybe you could double-click on the Veridian platform launch, how it differs from other digital IDs or identity wallets people might be familiar with. Should people think about this as for the Cardano ecosystem, right, the decentralized identity project needed there so that it can kind of, you know, bring that ecosystem, you know, in line with kind of how other ecosystems operate or have projects related to this? Or is the vision here something bigger than that? Or, yeah, I guess. Yeah, let’s you.
Thomas Mayfield: That’s a fair point. So I come from a background of traditional computer security and digital forensics. What I kind of brought to the organization, extensive experience in Web2 and a solid understanding of blockchain. But the PhD work I’m also doing is around decentralized identity and industrial IoT and verifiable ID. So what I established within the organization is a bigger picture. There’s a larger problem to solve here. We live in an era where digital trust is eroding. This is before we consider elements of AI and quantum security. I have some stats here, so I’m going to pull from a piece of paper. We live in a world where 30,000 websites are compromised every single day. We have data breaches that exposed 1.9 billion users within the U.S. alone last year, and this number is growing every single year. We’re talking approximately $5 million on average per breach in USD. So this overarching goal for what we built with the Veridian platform was, can we actually tackle and solve some of these challenges?
Thomas Mayfield: Can we identify where the gaps are, where the solutions are not meeting the road, so to speak? That was our overall vision. When we speak about Veridian platform, we want to establish that it’s not just an identity wallet. It’s not just cloud infrastructure. It is a whole consortium of infrastructure, components, services, and the wallet itself plays a significant role. But one last stat I need to pull from here for you. IBM release a report every year, and last year what was most interesting is they have this very scary fact that it takes, on average, 258 days for an organization to identify a breach and correct it. We see ever-growing ransomware attacks and data breaches, so we wanted to find a solution to tackle and solve these problems. And that’s what the Veridian platform and all of the infrastructure in and of itself brings to the table. Not only a wallet for organizations or individuals, or a backend wallet that can be run on a machine, but a whole series of infrastructure and services that can try to put a dent in these challenges.
Thomas Mayfield: With the appropriate infrastructure in place, you should have real-time monitoring and awareness that something suspicious or unusual has taken place, perhaps give you the opportunity. to recover and prevent these things from happening. We look at ransomware attacks alone, which are an ever-growing problem. Ask the issue here is these attackers get in your system and run wild in there for potentially almost a year, based on what IBM’s report is saying. If we can reduce that time that it takes to detect these attacks, or even eliminate the possibility of these compromises by leveraging things like multi-sig identifiers, then that would be a win. So kind of essentially what our motivation here while creating these future-proof systems that can try and solve this larger problem that exists across Web2.
Riley Hughes: When I, my first day on the job in the identity space in 2017, I walked into Evernym’s office, and Evernym had a big poster on the wall after you walked in that said something like, Data breaches: a thing of the past. Maybe let’s go a layer deeper, right? So I guess what I’m saying is the broader identity space is all trying to solve this problem and maybe coming at it from different angles or focusing on different elements of it. From your point of view, which aspect is Veridian aimed to solve? What are you focused on first?
Thomas Mayfield: The main objective we’re focused on is creating interoperable identifiers. We want to remove these walled gardens, these silos. Decentralization is a topic we are familiar with from the blockchain space, but our overarching goal is to really target this universal interoperable identifier whereby you can have interop and verifiability outside of your ecosystem. We all have fairly secure systems internally, but as soon as we expose to the open internet or we start interacting with other ecosystems, that’s where the breakdown sort of takes place. So unless you have an identity protocol that is interoperable outside your organization or domain, you’re some siloed up in the world, and that’s sort of our main focus here.
Riley Hughes: I see. One of the challenges that I totally resonate with your vision, I’ve talked about it like, you know, universal. I’ve drawn analogies in the past to something like Visa, right? Like I can take my Visa card and I can use it anywhere, online, in person, domestic, abroad, whatever. Ideally, identity should work that way. I should have an identity or an identifier that is privacy-preserving, that I can take wherever and it works anywhere because of interoperability. I think one of the challenges that we’ve seen develop in the identity space is interoperability. You need standards for interoperability to exist, right? You need both parties to speak the same language in order for them to work together. And we’ve had a sort of Tower of Babel scenario in the identity space over the last handful of years, where there’s a lot of standards. The mobile driver’s license wallets are not interoperable with the verifiable credentials wallets, which are not interoperable with the sort of blockchain-based SBT-type wallets, which are not interoperable with whatever.
Riley Hughes: What is your vision for interoperability and potentially overcoming that challenge, or do you see it differently? Do you think that we’re missing something here?
Thomas Mayfield: This is the big challenge. We have technology decisions that have been taken without full consideration for the consequence. We envision a solution that can provide a universal interoperable layer and allow you to still keep using internally whatever you’ve established. We argue that there are security trade-offs to not using a more robust protocol. But also, we looked at what industry was doing as well. So one of the unique elements of the Veridian platform, it’s the first identity platform and mobile wallet built on top of the KERI protocol. Kevent receipt infrastructure protocol. We started our research into this three years ago. I came from a PhD background, already studying to research these specific protocols and how they can be applied mostly to IoT and not individuals. We went down the typical path that many people do when it comes to decentralized identity. We started developing the DID method based on the W3C specifications. We also explored and experimented with the DID methods that were available in our ecosystem.
Thomas Mayfield: And we came to this ultimate understanding that these solutions are fantastic and they’re innovative. They’re not interoperable outside of our ecosystem. I mean, my DID method on the Cardano blockchain can’t be interpreted by a DID method in Ethereum and can’t be interpreted by an ISP or an IDP in the Web2 space. So we wanted to identify how can we have an interoperable identity solution, one that is perhaps already going to be established in industry. And when we went down this rabbit hole of understanding KERI and all the different protocols associated with decentralized identity, what really caught our eye was KERI was already being leveraged in industry within the financial sector. If this is being used in such a highly regulated industry, there must be something behind this protocol. And that’s really where our voyage into the KERI ecosystem and understanding the verifiable credentials associated with that, the authentic chained data containers. Your audience is probably already wondering how many acronyms exist. The terminology alone, you can get lost in this space.
Thomas Mayfield: So we went through this whole journey ourselves. But when we speak about this interoperable identity layer, the Global Legal Entity Identifier Foundation, which is overseen by the Regulatory Oversight Commission, was started as a result of the financial collapse in 2008. Their main goal was to create transparency within the financial derivatives markets. In order to do this, they had to create a globally interoperable identity layer or identifier. They mandated that the KERI protocol is the only technology that can be utilized to do this. This validated our thoughts around the KERI protocol, proved to us this was being used in industry, and we thought, right, how do we bring this into blockchain? If established in Web2, it’s decentralized public key infrastructure and management. It operates in traditional high availability cloud infrastructure services like AWS or run on prem. But how do we merge this into the blockchain space? We went down this path working with legal firm in the European Union. I mean, a lot of this was around sort of understanding data privacy.
Thomas Mayfield: the regulations around the protocols. And this is how we ultimately landed on where we are today, leveraging the KERI protocol and Veridian, creating once again this universal interoperable identity layer. So you can span this across what you already have built. You don’t need to stop your production systems, but rather you just need to implement these additional components. I don’t know if that directly addresses your question, but what we foresee is the reality is you can’t expect everybody to stop using what they have. If they want to enhance their interoperability, we give them this opportunity to apply the Veridian platform, more specific components to their existing systems to help bridge and create this secure interoperable. Or you can build your system from the ground up using Veridian and have a purely KERI-based ACDC infrastructure if you have the opportunity to do so.
Riley Hughes: I see. So I guess just a couple follow-ups there. It sounds like you built this platform based on the variant of decentralized identity that suited your case the best and that you found to be most suitable based on your research, right? And then also have an interoperability layer that has plugins to other types of systems. How does that universal interop piece work?
Thomas Mayfield: Oh yeah, great question. And also, just to step back, we knew that if we were going to build something from the ground up, it needed to be future-proof. So the fact that the KERI protocol is quantum-proof, that it’s network-agnostic, so even if we have an implementation in blockchain, it can be applied across networks throughout the future, and this ability to recover from key compromise. These were like three key factors that made us sort of lean in even more to the KERI protocol. I can share sort of our own journey. How did we apply this interoperability or apply this additional identifier to our own organization identity foundation. We are using a centralized email systems, and typically what many corporations and organizations are using. What we’ve done is we’ve been able to bind the existing identifier, whether it applies to the emails that our employees are using, to the identifier that we’ve then established at this layer. So in some of our systems, you log in using email, using a password.
Thomas Mayfield: But when it comes to more trusted processes, there is a sort of pivot in the logic of the systems that then ask you to present a verifiable credential or to sign a data payload based on the identifier that’s supposed to be bound to the existing identity. That’s one way we’ve done it for us, buying this verifiable layer, interoperability layer to an existing identity solution. There are other elements. We’ve done work with other organizations. We’ve established that, you know, what makes sense is you just kind of reestablish sort of a shadow system or a parallel system and slowly start iterating across to this more secure use case. The most important thing is understanding business needs of the client or the customer. You know, if they have the ability to pause, then that’s fantastic. If not, then we have to find ways to integrate incrementally. But establishing that binding is really the key there.
Riley Hughes: I see. And then in terms of the Veridian platform, should I think about it as like, well, I guess let me ask it this way. If I’m a developer who is interested in implementing KERI as the technology underpinning my application, it sounds like I could use Veridian as an infrastructure layer to help me do that more easily. Is that a fair characterization?
Thomas Mayfield: Yeah, absolutely. So the Veridian platform is an open source platform. It gives you not only just the infrastructure that you need and the user-side wallets, but it also gives you the browser extensions to integrate the mobile wallet into your web-based sessions, so you can do things like pass this authentication. But you’re exactly right, Riley. The Veridian platform is this building block that developers can leverage if they want to build a solution from the ground up that uses a future-proof identity protocol, in this case, the KERI protocol.
Riley Hughes: Yeah. Great. To your point there on the sort of depends on the business needs, and, you know, I think a good segue into what ends up being the crux of a lot of decentralized identity projects, which is like, okay, show me the adoption, right? Because from what I’ve observed, this chicken-and-egg problem, or the sort of, there’s a handful of challenges that decentralized identity projects tend to face when they go to market. And I know that the Cardano Foundation and Veridian has some sort of institutional or enterprise adoption that is noteworthy. So I wanted to double-click on that and what others, perhaps people interested in building in the same ecosystem or building on top of the Veridian platform, could learn to help them with their deployments as well. I wonder if you could speak to who’s using this platform today and what are the use cases that it’s most optimized for that you’re targeting.
Thomas Mayfield: Cool. Outside of our use of it within the Cardano Foundation, all of our employees have Verifiable Identity. We leverage the Verifiable Credential Management System that we have to provide credentials access passes for and identity overseas for our employees. But outside of the CF, most notably, and currently actually, where right now we’re working with, we’re ongoing work with the United Nations and specifically the UNDP, United Nations Development Program, and specifically an organization within there known as Tadamon. This NGO works with civil service organizations. They are in a unique position to some extent, but they also suffer from problems many organizations have. They deal with individuals and organizations globally dispersed with various technology needs and skill sets, different languages, different business practices, and ultimately what this resulted in is fragmented databases with multiple identifiers that reference one person. So depending on which region and which platform you’re registering with, that database then set up a unique ID for these users.
Thomas Mayfield: What you had here is in some organizations, the person that registered the CSO and then left and took the password and email with it, now they can’t. access the system and have to create a whole new fire. No longer can you continue the reputation you’ve been building. They ended up with multiple identifiers for multiple users and no way to have true interoperability across all of these other subsidiaries with identities. We created an organizational identity solution for them, whereby these CSOs could onboard from day one with a verifiable identity through a white-labeled version of the Veridian wallet, leveraging the same infrastructure that the Veridian wallet you can download from the app stores today bridges. And then they could create verifiable credentials for their CSOs to present, eliminating the need for usernames and passwords, doing this passwordless authentication approach. Irrefutable cryptographic primitives that no longer require you to write down the password on a sticky note and stick it under your computer in case you forget it, which we’ve all seen happen.
Thomas Mayfield: And I must admit, some years in the past, I’ve done this myself. We brought that solution into place, but this was just the initial building block. And that is sort of maybe the most important thing here when it comes to adoption and understanding these protocols, is if you build out a fundamentally secure identity layer, then everything you build on top of that benefits from that identity. If you start with a weak foundation, maybe by leveraging identity protocol that’s a bit easier to use or less complex from a cryptographic perspective, you find out that when you get to a point where there is a breach in your system or an unknown impact, say something like quantum perhaps, and you have to stop and rebuild. And the energy, the effort, and financial costs associated with doing that rebuild. Far outweigh what it would have taken if you had taken the initial investment in the beginning. So when it comes to adoption, we have this NGO leveraging the Veridium platform for organizational identity and specifically passwordless authentication.
Thomas Mayfield: But we’re also looking at sort of the non-human element. So the advent of agentic AI, artificial intelligence—
Riley Hughes: Can I interrupt you a little bit there?
Thomas Mayfield: Yeah,
Riley Hughes: that’s really interesting. And I think organizational identity certainly is something that the KERI ecosystem has focused on. Obviously, you mentioned GLEIF earlier, and so that makes a lot of sense. You mentioned toward the beginning of the conversation about your background, focusing on things like IoT and non-human identities. How do you see that space evolving? Is Veridium applicable there? And what’s your take on that?
Thomas Mayfield: That’s exactly right. The vision behind Veridium is an identity protocol platform solution that can be applied to individuals, organizations, and non-humans. So when we speak about IoT or we speak about machine identity or non-human identity in general, Veridium can be applied to all of these use cases or business cases. In the realm of agentic AI, it is possible to run the equivalent of visual interface, you know, this user interface that is running on a mobile phone. That can be run in the backend. It doesn’t have a user interface component to it. You can establish identifiers that are irrefutable for machines, for identities of agentic AI. But not just the agents themselves. And what we are seeing now, based on the research and the findings, is the actual data sets that are used to create these machine learning models, they need to be verifiable as well. You need to be able to verify what is being provided by an agentic AI system, all the way down to the raw data that trained it and where it came from.
Thomas Mayfield: I mean, a lot of people are leveraging this technology for the simplistic means, but all of the public data has already been used to train these AI models. And what is being used now are actually the prompts that users are putting into systems as an alternative data set to train these models on. But even what we put into a system should be identifiable, and from my perspective as a user, I should be able to revoke or limit the ability for that data set to be used to train other AI models. So everything from the agent itself to the data set that’s created for the machine learning algorithms and models that apply to these agents, they all need to be considered.
Thomas Mayfield: And then outside of AI, when you think of industrial IoT, this ubiquitous technology, I mean, we all have IoT devices we’re talking on right now, but from an industrial perspective, whether it’s on the shop floor of a manufacturing plant or some of these use cases we’ve looked at with sort of carbon emissions and environmental contexts, where you’ve got devices and sensors in the field taking in readings that ultimately result in maybe credits being attributed to an organization because of the footprint AI reducing, should it be verifiable? I mean, half the problem, and we spoke about at the beginning, is this sort of the internet being broke, collapsing digital trust. We need to implement a world where everything on the internet is irrefutable, and that applies to IoT significantly. So in the future, and leveraging something like the Veridian platform, you can create verifiable IoT, verifiable Web3, verifiable Web2, verifiable everything, so to speak.
Riley Hughes: Yeah, like it’s an interesting word. I don’t know if I’ve heard people talk about this using the term irrefutable that much, but I think it’s an interesting one, right? Like, how would the internet be different if everything you saw were irrefutable? I mean, it certainly has its challenges in accomplishing it because it’s hard to get to 100% certainty in anything, but it is an interesting thought experiment to get there. And, you know, you mentioned the AI point is really interesting, right? From the models to the agents to the prompts to the sort of how all that fits together. I remember in 2018, one of the—or, well, maybe it was 2019—one of the early customers we had at Trinsic was using… The verifiable credential platform to manage the software supply chain, right? It was sort of like, and specifically it was data sets being used inside of a larger big data BI type of a thing. That was the first use case where I was like, whoa, this technology is not, you know, for people’s first name, last name, date of birth. Like this stuff can apply in all kinds of interesting scenarios.
Riley Hughes: And so I’m interested in, especially with things like AI, have you seen any? anything there that gives us a glimpse into what the future will look like? I mean, I think conceptually it makes sense that an agent should have an identity, or that humans should be able to delegate their authority, which is attached to an identity, to an agent or something. But, you know, since there’s nothing that’s ubiquitously adopted yet, I think the jury’s still out on exactly what that looks like. What have you seen? Have you seen anything that can give us a glimpse, or are people building things like that on top of the Veridian platform?
Thomas Mayfield: Yeah, I can speak about an organization we’re speaking with that’s actually Asian market. What they have today is agentic AI systems with identifiers. They’re using decentralized identity for these agents, and what is the ability for these agents to take instructions from the controller. One common example they leverage is the ability to book a flight and book a hotel using these agents. The challenges they have at the moment are actually not necessarily creating the verifiable identity for these agents, because this has been proven already in the past. It’s actually this transition between an AI agent being able to execute a financial payment. It’s a lot easier to do it in the crypto space, and that’s what these agents currently do, execute settlements on blockchains. The next step is to aggregate that into traditional finance, so this AI can be verifiable to the standards acceptable by the financial regulatory bodies, which is another fantastic use case for the vLEI, and the organizational identity already recognized at that financial level.
Thomas Mayfield: But if we take a step back about the irrefutable… The biggest challenge we have with the internet today is that it was never designed for security. What we have is what’s ubiquitously referred to as bolt-on security solutions. We’re adding to the problem by trying to solve it bit by bit as we identify it. What we’ve been able to do with the Veridian platform and leveraging one of these components called the secure tunnel is we’re able to create web-based interactions that no longer rely on traditional HTTP headers and certificates, a purely KERI-based communication strategy between the mobile device and the web browser. And we actually demonstrated this two years ago at the Internet Identity Workshop in Mountain View. The way this was received was actually quite interesting because I don’t think people realize that there is a way to leverage the internet that doesn’t rely on having to use these traditional HTTP headers. There is an alternative here. We’ve done this with our own use cases. We’ve rolled this out in a couple of projects.
Thomas Mayfield: The biggest challenge here is to find that there are systems that provide irrefutable data. They were created in scenarios where they had to be. If we look at the origin of KERI and the founder, Sam Smith, his background is in autonomous submersible vehicles that had to have zero tolerance for failure. So it is possible to build these systems that don’t fail, or if they do fail, it is possible to recover from them quickly and keep moving. But what’s very difficult is to try and do that with something that’s already been built without that in scope, which is why we are leveraging things like the secure tunnel to provide a purely KERI-based interaction with the internet. I think what we need to see in the future, and we’re talking with some larger providers of browser technology, this stuff needs to get built into the internet itself. In the same way when you log on to a platform, you can choose which federated identity to use, the same should be true for if you’re trying to communicate in general on the internet, what level of security you want to use.
Thomas Mayfield: If you have the ability to use something like the KERI protocol to secure and make everything you do on the internet end verifiable, then that’s fantastic.
Riley Hughes: I mean, right now, how do you know you’re talking to me? And, you know, I’m not a deepfake level, you know, probabilistic thing, right? And it’s like you’ve said enough things that match close to what I’ve heard you say in person. But so it’s also based on my expectation, you know, how good the AI models and deepfake models are. It’s a probabilistic thing, right? I don’t know that I’m talking to you.
Thomas Mayfield: That’s very true. But I think in the same way you mentioned Visa cards, you should be able to use Visa cards all over the world. But I can clone your Visa card and use it without your permission.
Riley Hughes: Yeah.
Thomas Mayfield: When it comes to digital identity, we need to make sure this isn’t the case. And with something like the Veridian platform, you can ensure it. You can have verifiable, irrefutable interaction with the digital world. You can make these determinations. More than likely I am who I say. We’ve met in person as well, so we have that human basis of trust. Forming that trust in the digital realm is extremely difficult. We can leverage things like cryptography that have been proven as a way to establish that trust. It’s by no means a trivial matter, that’s for sure.
Riley Hughes: Yeah, I hear what you’re saying. The more native to the fundamental primitives of the internet these protocols are, the more we can achieve both in terms of interoperability and security and privacy and things like this. However, from that irrefutable point, it seems like still attaching that to a human is extremely difficult, simply because humans will never be natively a part of the internet. So even if the protocols are natively in the internet, humans will still always interact with an agent. And by agent in this case, I don’t mean an AI agent. I mean a browser or a phone, right? Some client. And unless there’s some kind of continuous biometric authentication by sensors on the device that are doing multiple different types of authentication in the hardware, I could imagine a scenario that’s like the Worldcoin orb, but embedded into every device and constantly running and making sure that it’s me. And that’s like an extreme version of this.
Riley Hughes: But otherwise, any time you’re authenticating somebody, I could do the highest degree of authentication possible using the most secure stuff and then hand my phone over to, you know, my wife, and then she can do the thing that I just authorized. You know, same thing with an AI agent, theoretically, right? This is how a lot of the browser use agents work today, is I log into my proper thing and then it takes my authentication cookie and just runs with it, right? And it just does stuff. How do you think about it, right? Does the Veridian platform solve for this? Do you solve for it somehow in the wallet? or is this just a native part of how we’ll always need to adapt to a situation on the internet?
Thomas Mayfield: If we take a step back, this irrefutability, I mean, it’s achieved today, but it’s achieved in these small sort of silos and industries and ecosystems. So, life today with the ACDC, the vLEI, and a delegated authority, and its well-established root of trust allows you to have these zero-futurable engagements across the internet. You can say with 100% confidence this has either come from the key pair and the controller that is associated with this identifier, and this identifier and this credential is securely rooted all the way up to the root of trust within the GLEIF ecosystem. The challenge here is we need a plethora of verified and qualified trusted service providers. Now, the onus is on the controller in the sense that if I unlock my pass to you and you can do whatever you want, I mean, there’s possibly no way to really solve that.
Riley Hughes: Yeah, but understanding that irrefutability back to the key pair, but not to the human, is, I guess, my point, and that’s sort of, I think, what you’re saying here.
Thomas Mayfield: Yeah. And again, you have that in sort of military and defense applications in use cases, right? So some of the initial research I did in my PhD was using these things called physically unclonable functions, and this is how you have an identifier for something like a land-to-air missile, whereby the serial number on the side of it isn’t actually its identifier. Its identifier is created by the circuitry on the board. And you can have the equivalent of that for a human, whereby it leverages fingerprint, facial recognition, and voice patterns and iris detection if you need that. But there has to be some sort of understanding of what kind of trust parameters you’re working within. Everything is based on the use case and the severity. From a cryptographic approach, you can have this irrefutability today if you wish to have it. It’s getting the adoption and spreading this across and explaining the value of this. But if the controlling keys for an identifier are truly decentralized, whereby they aren’t controlled by a platform or centralized authority, then that is already a huge win.
Riley Hughes: Yep. I think we’re on the same page there, so that’s helpful. It’s a great vision. Some of these things like, you know, do you need constant biometric monitoring or something? I think it’s up to your trust profile. Others would say, do you need this level of security and privacy and sophistication of technology with respect to the ability to pre-rotate keys and all sorts of these types of things? And some would say, well, it depends on your trust profile. However, the counter to that probably is it doesn’t hurt to bake these primitives in at the deepest levels, cost and complexity to develop and things like that. But putting those things aside, there’s no downside in having a more secure, more private thing there. Whereas biometrics and stuff, there are potentially additional things you need to be considering, not the least of which being regulatory and compliance type of things. Have you run into those issues? I mean, you were earlier working with lots of lawyers in the EU to make sure things are squared away.
Riley Hughes: What have you done on the regulatory side that has moved the ball forward for builders interested in building in your ecosystem? Is there anything they can bridge? What have you learned on the regulatory side that would be helpful?
Thomas Mayfield: Because I’ve learned the regulatory is where things get really complex, and a lot of it depends industry to industry. So we’ve looked at digital product passport system example, this innovation and this movement that’s coming in the future, identifying the standards. They are dependent on the industry, the product, where they come from, so on and so forth. But if we take a step back for a second, you mentioned, do we need these things? I mean, depending on your trust profile, my arguments here would be— If we can do them today, which we can, we should be doing. If we really want to bring down those statistics that I mentioned in the beginning, we need to do things like this, or else we just keep falling into the same pattern. I think incentives are a big element here too. Why would you do these things? Regulatory is where you really see the shift in the adoption. Why do people use an LEI? Why do people use a vLEI? Why are people involved in the glyf ecosystem? It’s because they’re regulated to do so.
Thomas Mayfield: And I think, to some extent, regulatory can play a great role when it comes to things to encourage the shift or the innovation and to enhance these systems. But to answer your question about how can builders apply this in the context of regulation, I mean, within the financial sector alone, you can look at the Veridian platform, which is the only current solution that’s integratable with the glyf ecosystem, and you can build a regulatory-compliant KYC solution that’s reusable, more efficient, more secure. And there’s a great opportunity for developers. Our strategy, our vision is to build this tooling in an open source way that allows others to apply it where their expertise or business case is. It’s impossible for us to solve for every use case, but if we can create tooling that can be applied and innovated over, again creating this sort of primitive space foundation for identity that allows you to then roll out those solutions on top of, I mean, that for us is a success and an ultimate goal.
Thomas Mayfield: One lesson I’ve learned is the significance of really understanding the technology, the protocol you’re going to use, and the consequences based on use case. And you mentioned different security and trust profiles, and it’s a huge factor as well. For us, it was about getting buy-in from leadership and explaining to them that if you’re building future-proof systems and you’re going to invest in something, you might as well do it properly from the beginning if you can. Developers shouldn’t be deterred by the path that’s least traveled. There are going to be challenges. Digital identity is extremely complex, and if it was easy, everybody would be doing it. That would be my message to developers from that perspective.
Riley Hughes: Regulation should be viewed as an ally in the fact that it can help drive some of these things forward for the greater good. A lot of projects aim to make decentralized identity as simple as possible, right? Like reduce the complexity so it’s easier to get started and easier to roll ahead. As someone who drank the Kool-Aid of decentralized identity early on and has been in this space for a while, I’m interested. I want to find ways to make it so that it’s not so hard, it’s not so complex, right? To see more of these projects get up and running, but not only get up and running, get significant adoption. The painful observation that I’ve made over the last handful of years is that proprietary, non-interoperable solutions have been more successful than the decentralized identity solutions. And I’m thinking, why are businesses choosing to work with inferior technology, right, or inferior approaches? And I’ve sort of come around to the idea that sometimes superior, inferior is not on the dimension of, like, simplicity is sometimes a feature, right?
Riley Hughes: And ease of adoption and speed of iteration, things like this are a feature. And I talked to somebody a while back who had a proprietary identity network, and I asked them what they thought about verifiable credentials and interoperable protocols, and their response was like, Oh yeah, whatever gets adopted, we’ll just do it. We have a database of tens of millions of users, and, you know, we’ll just, for each entry in the database, issue credential of the following type. And it’s like, you know, whatever gets adopted, we’ll do that. But we can do that migration anytime once it’s ready. And I thought, how should I grapple with this? How should I think about this set of observations? I’ve sort of formed my thoughts on this. I’m curious what your reaction is and how platforms like the Veridian platform can help developers reason about these types of decisions that every product builder is going to be making as they’re determining how to proceed.
Thomas Mayfield: I think one of the largest aspects of this is education. With the Veridium platform, you can use an extremely complex cryptographic protocol. You can create a weighted multi-sig custom threshold identifier in four or five clicks, and I think that’s key. We spent months doing iterative user testing feedback, just something as simple as onboarding onto the wallet. I think there is an element here about complexity or, like you said, simplicity that’s extremely important. We’re not going to get adoption of these things if they’re difficult to use. They need to be as easy or as intuitive as these major providers that exist today, ubiquitous. The Cardano Foundation, in and of itself, has education as one of its pillars. Because we’re from this blockchain space, we’ve already been dealing with the significance of education. We have a Cardano Academy that provides free open-source certification, partnered with organizations around the globe. In providing education, we’ve applied this same thought process to identity.
Thomas Mayfield: With the Veridium platform, not only comes with an app you can download from the App Store and open-source code that’s available from GitHub repositories, it also includes extensive documentation that allow you to understand how to leverage this technology and how easy it can be to do something as complex as creating these complex cryptographic identifiers. But the user experience is fundamental. I mean, if it’s not easy to use, if it’s not intuitive, then you might as well not build it in the first place. And that’s one of the lessons we learned developing Veridium platform.
Riley Hughes: Yeah, I think that makes sense. It’s sort of an impossible question. If anybody’s like the answer on a silver platter, probably I wouldn’t tell the world, right? You’d probably go make a billion dollars on it or something. But I do think that it’s worth considering, as developers are considering how to proceed with this stuff. There’s no other answer that you can give besides it comes down to the user experience and education. And I might add, where do you think the puck is going? What promises do you want to be able to make to your users and be able to keep, right? And that’s connected to the education point. Using decentralized identity, you can make promises sincerely that Proprietary databases can’t make. And those are things, you know, to the extent that users care about those promises, those solutions would gain more adoption, provided that user experience is comparable.
Thomas Mayfield: In hindsight, we’re in this digital age. If we could go back in time, would we have put as much information in things like Facebook? Would we have bridged Gmail and these tools so ubiquitously without a real understanding about sort of the data sovereignty and how these things were potentially being used? I think in hindsight, it’s easy to look back and say, you know, this is why these centralized systems and technologies are so ubiquitous, because they were the front-runners and this was available for people to use. They’re great services. They’re easy to use. It’s a fantastic user experience, and they start slowly becoming centralized repository of these services. And once you’re locked in to some extent from a societal perspective as well, that change is extremely difficult. I think when we talk about the future, like what’s coming or what can we promise or what kind of vision is there, I think one thing is to say that there is an ability now to build verifiable systems. You can do it today, so there’s no real excuse not to be doing it.
Thomas Mayfield: I think the challenge here is if we don’t do it, what does this future look like? We’re going to be faced with either regulations, legal frameworks that will require this collapsing digital trust to be solved. It would make sense that solution, that technology actually empowers society, empowers the users. And if we do this properly, we can create solutions that are better for us, not just easy to use, not just a great experience, but on the whole better for everyone that’s using them. If there was a way for my data that was leveraged by these systems to actually put money in my pocket, then that would be a great enhancement. But all it does at the moment is it puts money in those operators of those systems’ pockets. And I think that whole model, that whole paradigm, that whole framework needs to be spun on its head, so to speak. And I think we’ll inevitably see that in the future. My worry is that… some detrimental events will have to take place for the real motivations to be put in place to change them.
Thomas Mayfield: But if you are passionate enough, if you’re driven enough and inspired enough, you can do this today with things like the Veridian platform.
Riley Hughes: There’s an interesting thought experiment, right? Like you asked earlier in the conversation, if we had baked security into the internet from the beginning, how might the internet be different today? And I think there’s a similar question each person can ask themselves. If you’re a builder and you’re building identity products or integrating identity solutions into your systems, how will the future be different based on the decisions you make with respect to such integration? If we all build things in the way that you’re describing, I think that leads to a very different future than if we go in another route. It’s an interesting thought experiment, and I appreciate you illuminating that for us. The question that we always end with here is: what does the future of identity look like, and why does that matter for the world? You’ve sort of articulated that a little bit, but answer that thought experiment yourself. Imagine everybody is—the world starts shifting toward using more secure and private technologies and irrefutable technologies to build their solutions.
Riley Hughes: How does that change what the future looks like?
Thomas Mayfield: A great question. We could probably do the whole podcast on this. If we were in this era where fraud, impersonation attacks, key compromise, and somewhere quantum security concerns were already solved, and we weren’t having these 30,000 websites breached every day, like I mentioned, or the average data breach costing 5 million US dollars per breach. Think about what that money could go to. Think about how we could actually be flying the costs that we spend to fix this broken technology today, how much good that could do in the world. We spend billions a year on fraud-related incidences. If that’s eliminated from the risk profile, there is so much that could be done with that. It could be applied to humanitarian. It could be applied to disaster relief. It could be applied to poverty, starvation, illness. Imagine what could be possible. It’s almost irresponsible that all of this money goes to solving something that can be solved today if there was the right incentives and motivations behind it.
Thomas Mayfield: But I’d like to think that we’ll eventually get there and really use the efforts, the resources, the funds that we’re doing now to make this legacy technology secure, but we could apply this to so much more.
Riley Hughes: Great. Well, I appreciate that. That’s a vision that is quite inspiring. If our listeners are inspired and want to learn more, where would you point them? How could they get in touch or learn more about the Veridian platform?
Thomas Mayfield: Absolutely. If you want to learn more about the Veridian platform, you can visit our main website, which is veridian.id. There’s a form on there if you’d like to contact us. We have sandboxes available, so if developers want to start working and they don’t want the complexities of spinning up the infrastructure, they just want to download the wallet and onboard, they can fill in a form, contact us, and we’ll reply to you and get you set up to use that sandbox infrastructure. If you’d like to talk about a specific use case, you can email me directly, thomas.mayfield@cardanofoundation.org, or you can go directly to the Cardano Foundation website.
Riley Hughes: Thanks again for joining us. This was a great conversation.
Thomas Mayfield: Thank you, Riley. I hope we get a chance to speak again.
Riley Hughes: Thanks so much for listening. If you enjoyed this content, please share it with others who will benefit from it. I’ve been getting some great feedback on the podcast recently, and since we don’t do a lot of self-promotion or ads or whatever, sharing the word really is the best way to signal to us that the content is valuable and that we should keep doing it. You can find us on YouTube, Apple, Spotify, and wherever else you listen to podcasts. Feel free to reach out to me directly on LinkedIn or X at Riley P. Hughes, and visit Trinsic if you’re interested in building the future of identity. You can also visit trinsic.id/podcast to subscribe to new shows and subscribe to the Future of Identity newsletter, where we’ll share the essential reusable identity news we rely on straight to your inbox.

Kelly Javanmardi
Director of Marketing @ Trinsic
Kelly Javanmardi leads marketing at Trinsic, where she focuses on content, demand generation, and go-to-market. She brings deep B2B and identity-industry experience, including prior marketing leadership at Berbix (acquired by Socure).
Newsletter
Subscribe to weekly insights and updates in the digital ID ecosystem.
