Using Blockchain in Digital Identity and Access Management Systems : A shift from Centralised to…
Introduction
Using Blockchain in Digital Identity and Access Management Systems : A shift from Centralised to Self-Sovereign Identity
Introduction
Identity management, often known as identity and access management, or IAM, is the act of controlling who can access certain types of information, technology, or services after completing a login process on a website or app. IAM is utilized in many different contexts, such as when a person accesses websites for personal use or when an employee uses technology at work.
But as the world is advancing, the older, less-secure identity management systems have been prone to attacks like data breaches, large-scale hacks and information leaks, hence, there have been increasing regulations about how personal data is collected, stored, used and shared.
Also, there’s no digital equivalent of a driver’s license, birth certificate or a social security number that can prove a person’s online presence and his/her identity. For every organisation, platform and application, the user needs to create a new identity, which in turn becomes problematic and cumbersome as we will see below.
Fortunately, these issues may be successfully resolved by blockchain identity management technology, which improves security, efficiency, data correctness, and accessibility. Blockchain identification solutions are gaining traction because they provide a secure and affordable means of managing digital identities. Users save their credentials and ID information in a decentralized identity wallet application; the blockchain makes it possible to instantaneously verify this information without contacting the issuer. Users have more control over their personal data using ID wallets.
Issues with conventional IAM systems
Lack of Centralised View
IAM systems are generally scattered across multiple applications and platforms, making it difficult to have a holistic insight to the bigger picture.
Federated Systems offer easier options like Single Sign-On (SSO), but the risk is if the password is stolen, all the logged in accounts across platforms are at a risk of exposure.
Even, if using Centralised Systems, they are also prone to data attacks as all the data is kept at a single place, which makes it easier for the attacker to gain access to the personal user data.
Expensive KYC/AML Checks
Users, third parties, and verification organizations are all involved in Know Your Customer onboarding procedures. Financial institutions must adhere to anti-money laundering procedures as a basic necessity, and nearly all nations have stringent AML laws. In 2022, global spending on AML/KYC data and services reached around $1.6 billion.
Conventional methods for confirming a user’s identity, documents, and background are frequently laborious, costly, and manual for all parties involved — especially the KYC company, which needs more resources to swiftly handle the demands of its clients in a variety of industries, such as banks, healthcare providers, and immigration authorities.
Data Control and Ownership
Since users use and log in to multiple platforms and websites everyday, it is a tough task to know what data is being shared with them and what they are sharing with other partners without our consent. We hear details about millions of records of user data leaked in a data breach, these reports are a common occurrences in today’s world and this is the issue that the end-user does not have ownership and control over his/her Personal Identifiable Information(PII).
User-Password Fatigue
An average person keeps around 100 login accounts in his/her lifetime. Handling and creating new accounts become fatiguing to remember and manage that often leads to phishing attacks.
Lack of Multi-Factor Authentication (MFA)
Many IAM systems lack strong authentication methods like MFA, making it easier for unauthorized users to gain access to sensitive data.
Introduction of Blockchain in the IAM landscape (Digital Identity Blockchain and Self-Sovereign Identity)
Digital Identity Blockchain is a revolutionary approach to managing and securing our digital identities. It leverages the power of blockchain technology to create a decentralized, secure, and transparent system for individuals to control their identities and share information selectively. Basically using blockchain is creating a system of self-sovereign IAM systems.
Here’s a number of features over traditional IAM systems that are present in Digital Identity Blockchain:
- Identity Anchors: Known as “identity anchors,” blockchain serves as a safe ledger in which people may record their distinct online personas. Names, dates of birth, and other verifiable traits are among the relevant information contained in these anchors.
- Self-Sovereign Identity: People are in total control of the anchors that define who they are. They are in charge of deciding what data to include, who may access it, and why.
- Decentralized Verification: Blockchain technology allows for safe and transparent identity verification via a network of nodes, doing away with the need for centralized authority. This lowers the possibility of fraud and removes single points of failure.
- Enhanced Security: The authenticity and integrity of identification data are guaranteed by the cryptographic properties of blockchain. Since it is nearly hard to tamper with records, identity theft and data breaches are avoided.
- Interoperability: Standardized protocols make it possible for various blockchain systems to easily exchange identity information and communicate with one another. This encourages broader adoption and makes it easier to establish an international identity ecosystem.
We can see that using blockchain in the IAM systems makes it more secure, scalable and also gives more control to the end-user in consenting to the type and amount of information he/she wants to share to other platforms.

IBM Trusted Identity Solutions
There are mostly two aspects of self-sovereign identity systems or basically Digital IAMs using Blockchain:
- Digital Identifiers(DIDs)
- Verifiable Credentials(VCs)
Let’s have a look on both of them individually!
Understanding Decentralised Identifiers (DIDs)

dock.io
Decentralized Identifiers (DIDs) are a new type of digital identifier that aims to give individuals and organizations more control over their online identities. Unlike traditional identifiers (email, passwords, usernames) , which are often managed by centralized authorities, DIDs are self-owned and controlled by the individual or organization itself.
DIDs enable true self-sovereign identity — lifetime portable digital identity for any person, organization, or thing that can never be taken away.
In brief working of a DID
On the blockchain, a person’s or an organization’s DID serves as their unique character string. This document includes details about the DID owner, including public keys, related services, and additional pertinent information.
DIDs are not managed or issued by a central authority, in contrast to traditional identifiers. DID owners are in total control of the information in their DID document, including what information to include and who can view it. DIDs use cryptography to make sure the data they store is authentic and accurate.
Benefits of DIDs over traditional Identifiers
- Enhanced privacy: DIDs provide users the ability to decide what data they choose to share with various apps and services.
- Enhanced security: DIDs based on blockchain technology are very impervious to hacking and data intrusions.
- Better user experience: DIDs make it possible for users to interact with different services and platforms in a pleasant and seamless way.
- Decreased dependence on third parties: People are no longer able to manage their identities through centralized authority.
- Increased interoperability: DIDs can function on many blockchain systems thanks to standardized protocols.
Understanding Verifiable Credentials(VCs)
Verifiable Credentials (VCs) represent a new category of digital credentials that utilize blockchain technology to provide a transparent, safe, and interoperable means of issuance and verification for individuals and organizations. Compared to conventional paper-based credentials, which are frequently vulnerable to fraud, loss, and inefficiency, they represent a major improvement.
In brief working of a VC
Organizations, such as universities, governments, and businesses, can issue VCs to individuals. These VCs contain information about the individual and their qualifications, achievements, or other relevant data. VCs are stored on the blockchain, which ensures their tamper-proof and verifiable nature. Individuals can access their VCs through secure wallets.
Individuals can present their VCs to service providers or other entities seeking verification. VCs can be easily verified using blockchain technology to confirm their authenticity and integrity.
Relationship between DIDs and VCs
Each DID can have multiple Verifiable Credentials associated with them that are digitally (cryptographically) signed by their issuers like a government driver’s licensing department. DID owners store the credentials themselves on their phones and don’t have to rely on a single provider like Facebook or Google.

dock.io

dock.io
Here as we can see, Public DIDs (Decentralized Identifiers) can be stored on the blockchain. As we already know that DIDs are unique identifiers that are owned and controlled by the individual user and since they are not tied to any central authority that makes them more secure and private than traditional identifiers.
Here are two examples of Verifiable Credentials (VCs) that can be linked to a DID: a university degree and a course certificate. VCs are digital credentials that can be issued and verified using blockchain technology. They provide a secure and tamper-proof way to share credentials with others.
By storing DIDs and VCs on the blockchain, blockchain-based IAM systems can create a more secure, private, and efficient way for users to manage their identities and access privileges.
Not everything should be mined: Why PII should never be stored on a blockchain?
Since blockchain is immutable, once stored information can never be altered. Adding Personally Identifiable Information (PII) to a blockchain would lead to issues with data compliance and privacy laws like GDPR’s “right to be forgotten”.
For example, if a hacker is able to crack the encryption in the next 10 years (highly unlikely though), he will be able to access all the data. Hence never store PII like driver’s license number, back account, social security number, etc.
(Note: Many times PII is confused with Personal Information. Personal information or data can be anything related to an individual and may reveal its identity. However, on the other hand, personally identifiable information is any data related to an individual user to specifically identify a particular individual. All in all, not all personal information is PII, but all PII is personal information that can be used to identify a particular individual.)
Some real-world applications of Blockchain in IAM systems.
- uPort: uPort is an open-source Ethereum based blockchain solution. An identity is created through an app on the user’s phone. This app holds all the data linked to the identity. It also holds the private keys, used to sign attestations and share them with others. Storing the data locally provides control over and access to the identity for the user and enforces them to provide consent before others can use the information.
- EverID: EverID is a user-centric, SSI and value transfer solution based on blockchain technology and the cryptographic underpinnings of that system. In contrast to uPort, EverID’s decentralized system is used to store and confirm user identity data, documentation and bio metrics. EverID facilitates verification of users by multiple third-parties and allows the secure transfer of value between members of the network. This means that claims made by users are provable. The decentralized architecture of the platform also provides personal data ownership which can only be accessed by the user. The individual’s data is recorded in a manner that allows the individual control how it is shared, with whom and for how long (persistence).
- Sovrin: Sovrin network is a public permissioned distributed ledger. This means that users can see the transactions but not necessarily initiate transactions. As a result, the need for proof-of-work is removed. This shows that they use a distributed consensus protocol which focuses more on security and scalability. This solution meets also the requirement of minimalization by enabling selective disclosure of claims using zero-knowledge proofs. Therefore no data will be shared without the user’s consent and this gives the identity owners control over their digital identity.
Use-Case deep dive : Sovrin
(From the official website and their own whitepaper on decentralised identity)
The Sovrin Foundation is a nonprofit organization established to administer the Governance Framework governing the Sovrin Network, a public service utility enabling self-sovereign identity on the internet. The Sovrin Foundation is an independent organization that is responsible for ensuring the Sovrin identity system is public and globally accessible.

IBM Trusted Identity Solutions
IBM and the Sovrin Foundation are two prominent players in the emerging field of Decentralized Identity Management (IAM). Both entities have made significant contributions to the development and implementation of technologies that empower individuals with greater control over their identities and enable secure, privacy-preserving interactions in the digital world.
IBM and Sovrin had partnered together to actively collaborate on technical development and standardization of decentralized identity protocols. Both are actively participating in industry-wide initiatives focused on applying decentralized identity in many fields, such as healthcare, education, etc.

sovrin.org | How it works
Conclusion
Digital Identities and traditional IAMs are one of the oldest and hardest problems on the internet. In Physical world, we can use our physical credentials to prove who we are, but it is not possible on the internet, for example, there’s no digital equivalent of a driver’s license, or a birth certificate to login to a website, or gain access to any platform, even in federated systems. We have to store and create hundreds of passwords and accounts which is prone to attacks.

W3C standard for digital identities
The long going two problems of creating a standardized way of assigning digital identities and to verify the digital signatures of the credential owners is solved by blockchain as it provides a platform which no one owns, but everyone uses, hence it is safe, trustworthy and immutable.

sovrin.org | Decentralised Identity Management
Shifting from storing different identities for a single person for different platforms to a decentralised identity management system makes a huge difference in how easy it will become to handle, manage, access and store user credentials and security will increase manyfolds.
We can see its applications already in many places, and it will only grow from here onwards, not only making anyone’s online presence much more secure, but also seamless across organisations, platforms and applications.
Blockchain to the rescue!
메타데이터
- post_id
- 208e63b3e3df
- slug
- using-blockchain-in-digital-identity-and-access-management-systems-a-shift-from-centralised-to-208e63b3e3df
- url
- https://medium.com/@avrl/using-blockchain-in-digital-identity-and-access-management-systems-a-shift-from-centralised-to-208e63b3e3df
- canonical_url
- https://medium.com/@avrl/using-blockchain-in-digital-identity-and-access-management-systems-a-shift-from-centralised-to-208e63b3e3df
- author_url
- https://medium.com/@avrl
- status
- ok
- fetched_at
- 2026-07-24 19:31:54