Overview
ISO/TR 23249:2022 - Blockchain and distributed ledger technologies: Overview of existing DLT systems for identity management provides a descriptive, non‑normative survey of how distributed ledger technologies (DLT) are used to create, manage, present and revoke identity attributes. It summarizes architectures, actor roles, common interfaces and existing identity systems and frameworks (e.g., uPort, DIF, Alastria ID, ESSIF, Sovrin / Hyperledger stacks, KTDI, LACChain, Masterchain). Target audiences include academics, solution architects, developers, regulators and standards bodies.
Keywords: ISO/TR 23249:2022, blockchain identity management, DLT systems for identity, decentralized identity, self‑sovereign identity (SSI), DID, verifiable credentials (VC).
Key topics and technical considerations
ISO/TR 23249:2022 focuses on descriptive analysis and design considerations rather than prescriptive requirements. Major technical topics include:
- Authority models: top‑down (centralized issuance) vs bottom‑up (user‑controlled identifiers).
- Identifier origination schemes: bring‑your‑own‑address, credential registries, global or anchor registries and hybrid approaches.
- Custody and delegation: key custody models, custodians, social/key recovery, delegated interactions and custodial services.
- Credential architectures: issuance, storage, presentation, selective disclosure and revocation mechanisms.
- Privacy and cryptography: use of zero‑knowledge proofs (ZKP), pairwise/pseudonymous identifiers and selective disclosure patterns.
- Actors and interfaces: roles (issuers, subjects, verifiers, custodians), data stores, and common APIs (e.g., CHAPI, DID/VC related interfaces).
- Architectural patterns: on‑chain vs off‑chain data, anchoring strategies, bundling/anchors, decentralized key management and storage (e.g., IPFS references).
- Taxonomies and frameworks: coverage of NIST taxonomic approaches, Trust Over IP, and mapping to existing DLT identity systems.
Practical applications
ISO/TR 23249:2022 helps stakeholders understand how to apply DLT to identity use cases such as:
- User authentication and access control for web services and enterprise systems.
- Self‑Sovereign Identity (SSI) deployments enabling user‑centric control of identifiers and verifiable credentials.
- Cross‑border digital identity and travel credentials (e.g., Known Traveller Digital Identity concepts).
- KYC / AML processes where verifiable credentials streamline onboarding while protecting privacy.
- IoT and device identity management for secure, verifiable device attributes.
- Interoperability planning across multiple DLT networks and governance models.
Who should use this document
- Solution architects and developers designing DLT identity systems
- Policy makers, regulators and auditors assessing identity approaches
- Standards organizations and consortia seeking alignment
- Researchers and educators comparing existing DLT identity implementations
Related standards and frameworks
The report references and maps to existing standards and initiatives such as ISO 22739 (vocabulary), W3C Decentralized Identifiers (DID) and Verifiable Credentials (VC) concepts, NIST taxonomies, Trust Over IP (ToIP), and regional frameworks like ESSIF and EBSI.
For implementers, ISO/TR 23249:2022 is a practical reference to evaluate architectures, privacy trade‑offs and interoperability pathways for blockchain‑based identity management.