For the FIDO Alliance, the central constraint on digital identity is clear: Organisations and platforms must strengthen security without placing an additional burden on users. As digital services rapidly expand and become more sophisticated, online identity verification remains at a crossroads.
According to FIDO CTO Nishant Kaushik, the promise of trust in digital identity is easy to describe: Every person should be able to prove who they are or what they are entitled to without being forced to reveal more than necessary, give up choice or control, memorise fragile secrets, or repeat the same clunky onboarding process every time they encounter a new organisation.
“Businesses and public services should be able to verify trustworthy claims and engage with their customers quickly, securely, and at scale,” he said during a keynote at the inaugural FIDO Authenticate APAC conference in Singapore.
Kaushik noted that users don’t inherently trust a service or platform because it’s digital. Instead, trust comes from a fair user experience and clear privacy boundaries.
“What we’ve seen and learned is that trust is not a feature; it is an outcome. We cannot simply put together a set of technical capabilities and hope to achieve trust. It requires carefully designing systems around a set of principles that guide policy, governance, and implementation,” he said.
Building blocks
To Kaushik, the primary requirement for any digital identity ecosystem is respect for human dignity. Technology is not neutral, he said, and identity systems shape how people are seen, sorted, included, and excluded.
“A system is not meaningfully optional if choosing an alternative route means three-hour waits, extra fees, unsupported providers, shrinking branch access, failing technology, or staff who cannot help people solve their problems. Trust weakens quickly when digital choice becomes practical coercion,” Kaushik stressed.
Data minimisation is an equally important principle for any digital identity system. Kaushik cited instances in which users take a long time to prove their identity because of stringent controls.
“People should not have to hand over their entire life history just to prove a single fact: that they’re an adult or that they’re a resident and can claim a discount. Their ability to make a purchase shouldn’t have to depend on divulging the maximum amount of personally identifiable information to complete the transaction,” he said.
Pluralism is also needed to foster trust in digital identity systems.
“Public-sector systems are an important part of the ecosystem, especially when it comes to foundational identity, but trust is often strengthened when people can choose among providers and interaction models. Trusted identity ecosystems can therefore emerge and thrive only when different institutional models are involved, including both public- and private-sector parties,” Kaushik said.
Scaling trust
For trust to scale, Kaushik said, good architecture must meet operational reality. He described this as systems working repeatedly, affordably, and inclusively across large populations and many service providers, over billions of interactions and transactions, while remaining simple to use.
“Scalability is achieved when ordinary people can use systems confidently without training manuals or repeated failures. Adoption must also be simple for businesses. That means reducing the integration burden, which requires open standards, implementation profiles, conformance testing and certification, sustainable governance, and shared assurance language,” he said.
According to Kaushik, people travelling from one country to another should not discover that a digitally stored licence, qualification, permit, or entitlement becomes unusable the moment it crosses a national or sectoral boundary.
“When systems speak different languages, people are pushed back towards paper, manual reviews, lengthy processes, and exclusion,” he warned.
Ultimately, the strongest argument for trusted digital identity is not that it makes existing systems more efficient, but that it provides access to services, jobs, finance, mobility, education, and participation in the broader economy and society, Kaushik said.
“Trust will only scale when adoption scales,” he remarked.
To this end, Kaushik called on public- and private-sector stakeholders to ensure that every new verifier, issuer, wallet provider, and user does not have to negotiate everything from first principles.
“We have to focus on utility. Not every identity interaction needs to look like opening a bank account,” he noted.
Lessons learned
Reflecting on the FIDO Alliance’s campaign to increase passkey adoption, Kaushik said the effort required more than technical correctness. The work involved removing friction through implementation guidance, deployment frameworks, user-first design, conformance programmes, consistent branding and recognisable UX patterns, government and industry engagement, and awareness campaigns for individuals.
“Digital identity is not merely administrative infrastructure. It is often a precondition for accessing rights, protections, and opportunities. Digital wallets and verifiable credentials can expand opportunities for individuals when they are implemented with openness and restraint,” he emphasised.
The digital ecosystem is now closer to delivering digital identity that preserves privacy, is driven by consent, and is interoperable. Kaushik attributed this progress to the convergence of three principles: phishing-resistant authentication, portable and verifiable credentials, and exchanges mediated by browsers and wallets.
“Verifiable digital credentials, or VDCs, introduce resilience at the data layer,” Kaushik explained. “Instead of relying on a single identity provider at the moment of a transaction, they allow identity claims to be verified independently and offline, if needed, without live calls to issuers or dependencies on central systems.”
VDCs also improve security at the data layer, he added. Their inherent cryptographic verification is said to prevent tampering, while issuer signatures ensure authenticity. Selective disclosure, said Kaushik, minimises data exposure, and in credential-centric payment systems, the transaction, the intent behind it, the relying party, and the authenticator can be cryptographically bound together.
“I think it’s cool that we’re improving security, not by adding more controls, but by redesigning the system to remove weaknesses,” Kaushik said.
















