LOGBOOK

HELP

Quiz Entry - updated: 2026.09.17

What defines a user-centric (decentralised) identity?

The user controls their digital identity and holds their own personal data, never a central service; there is no central store of identity data or authentication means, and the issuer is not involved when the identity is used, so it receives no usage data.

Issuer issues a credential once to the holder, who presents it to the relying party; the issuer is not contacted at usage time

* The issuer hands over the credential once and is out of the loop whenever it is used. *

Three properties follow from one another:

  1. The user is in possession of the identity and its data. Nothing about them sits in a central account that some service operates.
  2. No central storage of identity data and authentication means, so there is no honeypot for attackers and no single point of failure for the user.
  3. The issuer is out of the loop at usage time. It issued the credential once; whenever the user presents it to a relying party, the issuer is not contacted and learns nothing about where or how often the identity is used.

The price is that responsibilities move to the user: they must keep the credential safe, back it up and handle loss, tasks a central service used to do for them.

Go deeper:

From Quiz: IAM / IAM Models: Topologies, Federation and Provisioning | Updated: Sep 17, 2026