Digital ID
In short: A digital proof of the identity of a person, device or system — the electronic equivalent of an identity document.
In more detail: Digital identities range from simple user accounts (email + password) through certificate-based identities (e.g. a client certificate that uniquely identifies a device) to state-issued electronic IDs (e.g. the online ID function of the German identity card, eIDAS at EU level). The required level of trust differs depending on the use case — a simple forum account needs less rigorous identity verification than online banking access.
In Depth
Digital identities can be classified by level of trust and technical basis:
Low - email + password (the user simply claims who they are)
Medium - email + password + 2FA, or certificate-based device ID
High - state-issued eID with a chip (e.g. the online ID function),
qualified electronic signature (legally equivalent to a
handwritten signature)
The EU regulation eIDAS (“electronic IDentification, Authentication and trust Services”) governs Europe-wide how digital identities and electronic signatures are legally recognised, and ensures, for example, that a German online ID is also accepted by authorities in other EU countries. The planned EU Digital Identity Wallet is meant to standardise this further in future — a kind of digital wallet for identity documents, driving licence, certificates etc., managed directly on the smartphone.
A central design problem of digital identities is the balance between security and privacy: the more attributes a system uses to verify identity, the more reliable it is, but also the more personal data is processed in the process — which in turn falls under the GDPR and has to be protected accordingly.
Selective disclosure and zero-knowledge proofs
A modern design principle for digital identities is “selective disclosure”: instead of showing the complete ID with all its data at every check, a person should only reveal exactly what’s needed for the respective purpose — e.g. when buying alcohol, only prove “is over 18” without revealing date of birth, address or name. Technically, this is increasingly implemented via cryptographic zero-knowledge proofs: methods that prove a statement is true (e.g. “age ≥ 18”) without disclosing the underlying data itself (the exact date of birth). The planned EU Digital Identity Wallet is meant to support exactly such selective proofs.
Risks of centralised digital identities
A point of discussion with state digital identity systems is the danger of centralisation: a single, all-encompassing digital identity system would be a particularly attractive target — a successful break-in could theoretically compromise millions of identities at once or be misused for surveillance purposes. Federated or decentralised approaches (in which different credentials lie independently of each other with different bodies instead of in a single central database) are therefore often considered preferable from a data protection point of view, even if they’re technically more complex to implement.
Digital identity of machines
Besides people, systems/devices also need digital identities: an IoT device or a server typically identifies itself to other systems via a certificate or a cryptographic key (machine-to-machine authentication), not via passwords. In distributed systems (e.g. microservices communicating with each other), a robust device/service identity is often just as critical as user authentication — a compromised service with a valid certificate can pose as a trusted participant on the internal network.
See also: Identity, Authentication