Tamga Network

Chapter 1 · 3/4

Three models of digital identity

The central account, "sign in with X" and the person's wallet: the pros and cons of each.

5 min

There are three basic ways to prove who you are online. We use all of them every day; what differs is where the data lives and who is in control.

Central accountA password per siteData kept by the siteEvery site keeps its own data“Sign in with X”An intermediaryIt sees every loginEasy, but one point of controlThe person's walletCredentials on the phoneThe person consentsNo intermediary, the person decides
Three models of digital identity. Europe and Tamga chose the third.

1. The central account

You open a separate account for each site: username, password, sometimes your personal details. The site keeps them in its own database. It is simple, but every site means another password and another pile of data. When a site is breached, your data goes with it. And proving your identity usually still means uploading a photocopy.

2. "Sign in with X"

"Sign in with Google" or a government's e-government login are examples of this model. An A service that verifies who you are and tells websites on your behalf.knows you and tells sites "this is that person". It removes the password burden, but at a price: the intermediary sees every login and knows which site you visited when. If it goes down or cuts access, everything that depends on it stops. Its reach is usually limited to its own country or company.

3. The person's wallet

In the third model, credentials live in a An app that keeps digital credentials, and the keys needed to use them, on the phone.on the person's phone. The university issues the diploma, the state the ID, the organiser the ticket, directly to the person. When a site or a gate asks for something, the person sees what is requested and, if they approve, only that is shared. The verifier checks the credential's signature without asking the issuer. No intermediary watches each login.

This model has three strengths:

  • The person is in control. They decide what to share.
  • Less data travels. Only what is needed; an age check may not even need the birth date.
  • It crosses borders. With shared rules, a credential is checked the same way in every country.

The models are not mutually exclusive

The wallet model does not wipe out the others overnight. A site can still keep its own account, but when the account is opened, identity is verified with signed information from the wallet instead of a photocopy. What changes is the source of trust: no longer an intermediary's word or a copy, but the issuer's signature.

Summary

  • With central accounts data piles up at every site; with federated login the intermediary sees every login.
  • In the wallet model the person holds the credential and consents; the verifier checks the signature without asking the issuer.
  • The EU and Tamga Network chose the wallet model; with shared rules credentials cross borders.

Go deeper

Technical details and binding rules: