diff --git a/index.html b/index.html index 544584a51..7f657ae03 100644 --- a/index.html +++ b/index.html @@ -503,6 +503,20 @@

Ecosystem Overview

[=verifiable credentials=] also provide benefit.

+

+The ecosystem provided in this specification is in contrast to a typical +two-party, or federated identity provider, model. An identity provider, +sometimes abbreviated as IdP, is a system for creating, maintaining, +and managing identity information for [=holders=], while providing +authentication services to [=relying party=] applications within a federation or +distributed network. In a federated identity model, the [=holder=] is tightly +bound to the identity provider. This specification does not use the "identity +provider", "federated identity", or "relying party" terminology unless comparing +or mapping the concepts in this document to other specifications. This +specification decouples the identity provider concept into two distinct +concepts: the [=issuer=] and the [=holder=]. +

+

In many cases the [=holder=] of a [=verifiable credential=] is the subject, but in certain cases it is not. For example, a parent (the [=holder=]) might hold @@ -597,11 +611,6 @@

Terminology

credential used in this specification differs from, NIST's definitions of credential. - -
data minimization
-
-The act of limiting the amount of shared data strictly to the minimum -necessary to successfully accomplish a task or goal.
decentralized identifier
@@ -651,30 +660,6 @@

Terminology

from them. A holder is often, but not always, a [=subject=] of the [=verifiable credentials=] they are holding. Holders store their [=credentials=] in [=credential repositories=]. -
-
identity
-
-The means for keeping track of [=entities=] across contexts. Digital -identities enable tracking and customization of [=entity=] interactions -across digital contexts, typically using identifiers and properties. Unintended -distribution or use of identity information can compromise privacy. Collection -and use of such information should follow the principle of -[=data minimization=]. -
-
identity provider
-
-An identity provider, sometimes abbreviated as IdP, is a system for -creating, maintaining, and managing identity information for [=holders=], -while providing authentication services to [=relying party=] applications -within a federation or distributed network. In this case the [=holder=] is -always the [=subject=]. Even if the [=verifiable credentials=] are bearer -[=credentials=], it is assumed the [=verifiable credentials=] remain with -the [=subject=], and if they are not, they were stolen by an attacker. This -specification does not use this term unless comparing or mapping the concepts in -this document to other specifications. This specification decouples the -[=identity provider=] concept into two distinct concepts: the [=issuer=] -and the [=holder=].
issuer