IdentiKey

Sistema / Design de Identidade

Decentralized identity and data sovereignty infrastructure using dCypher proxy re-encryption (recryption) technology to enable user-controlled encrypted cloud storage and sharing. Provides self-sovereign identity with persona management, a cross-account attestation-based social graph and trust/reputation network, self-sovereign single sign-on, blockchain-agnostic wallet functionality, and verifiable data publishing — all with user-custodied private keys and without trusting central intermediaries

Comunidade

Detalhes

Licença Open source (planned — Shift Grant deliverables include releasing open-source tools for developers to integrate dCypher; not yet publicly available)
Status de Dev 🧪 Alpha
Detalhe do Status de Dev Alpha/Development (production-ready dCypher proxy in development with Shift Grant support; planned proof-of-concept integrations with popular storage providers)
Proprietário Duke Jones / Sovereign Technologies (duke@worldtree.io); IdentiKey project (identikey.io)
Órgão de Governança Founder / single maintainer (Duke Jones / Sovereign Technologies)
País USA (Berkeley, California)
Ano de Início 2017
Stack Not publicly disclosed (cryptography-focused; proxy re-encryption / recryption implementation; planned integrations with popular web frameworks for self-authentication)
Financiamento Shift Grant (awarded by Ethereum Foundation and Edge City; d/acc acceleration grant supporting defensive and decentralized innovations)
Última Investigação 9 de mar. de 2026

Domínios de Caso de Uso

Capacidades

Identidade soberana

Sistema / Design de Identidade Atributos

Origens Identity / Data sovereignty (self-sovereign identity + private encrypted cloud storage using proxy re-encryption; inspired by d/acc — decentralized, democratic, differential, defensive acceleration principles)
Banco de Dados User-controlled encrypted cloud storage (no central database; data encrypted per-item so sweeping data breach is impossible; works with existing cloud providers like iCloud, Google Drive via dCypher proxy)
Linguagem de Consulta N/A (data access via permission-based recryption / viewing passes that can be granted and revoked)
Formatos de Dados Encrypted arbitrary data; content-addressed verifiable data registry (data referenced by hash for self-verification); signed attestations with provenance verification
Suporte Móvel Planned (mobile identity management interface as part of Shift Grant deliverables)
Suporte Web Planned (web-based identity dashboard / IdentiKey identity management interface for everyday users)
Aplicativos Nativos Planned (identity wallet applications with per-blockchain plugins for wallet functionality)
Termos Free and open (d/acc principles — decentralized, democratic access)
Fundos Shift Grant amount not publicly disclosed; grant announced May 21, 2025, officially presented during d/acc week at Edge Esmeralda, California, June 2-6, 2025
Baseado Em Proxy re-encryption / Recryption technology (transforms data from one encryption key to another via proxy without proxy accessing plaintext); content-based addressing for verifiable data storage
Autenticação e Identidade Self-sovereign identity with user-generated cryptographic keypairs; multiple personas per user (each persona is a signed DID with self-attested metadata that can be pseudonymous or linked to legal identity); self-sovereign single sign-on via private key authentication integrated with popular web frameworks; persona switching with protections against correlatable data leakage across personas
Modelo de Armazenamento Encrypted cloud storage via dCypher proxy (user-controlled keys; storage provider never sees plaintext even if hacked); verifiable data registry using content-based addressing (hash-referenced, self-verifying); supports existing cloud providers (iCloud, Google Drive)
Interoperabilidade Works with existing cloud storage providers via dCypher proxy integration; blockchain-agnostic wallet functionality (per-blockchain plugins); planned integrations with popular web frameworks for Web2 self-authentication; interoperable data ecosystems with user-controlled read/write permissions to third-party applications
Portabilidade de Dados Full portability (user owns encryption keys; data can move between services; content-addressed storage allows data to be stored in any compatible service)
Governança e Tomada de Decisão Individual/project-led (Duke Jones / Sovereign Technologies)
Padrões de Identidade Self-sovereign identity (SSI) principles; W3C DID (account-published DIDs); Zero-Knowledge Proofs (ZKPs) for anonymized authoritative attestation verification
Métodos DID Suportados Account-published DIDs (self-signed DID documents; specific DID method TBD)
Gestão de Chaves User-custodied private keys stored on-device using secure local storage and device-specific secure enclaves; wallet keys separable from account keys and attachable to different personas; MPC-based multisig without smart contracts for shared account management
Tipos de Credenciais Self-attested metadata (cleartext or encrypted with selective disclosure); cross-account attestations (directed graph between accounts); authoritative attestations (KYC-style, can be anonymized via ZKP); attestation schemas with morphisms across compatible schemas
Método de Verificação Cryptographic signature verification (data signed by author keys for provenance and authenticity); content-hash self-verification for data integrity; ZKP for anonymous proof of authoritative attestations
Recursos de Privacidade Proxy re-encryption (data remains encrypted to service providers); selective disclosure (ZKP to demonstrate proof of a value/signature without disclosing it, hierarchical tree-based public-key encryption, proxy re-encryption for access delegation); per-item encryption (sweeping data breach impossible); real-time AI agent activity feed and control panel
Métodos de Autenticação Private key-based self-authentication (self-sovereign SSO); planned integrations with popular web frameworks for Web2 login experience
Mecanismo de Revogação User-controlled revocation of viewing passes / access permissions at any time; AI agent permissions instantly revocable via control panel
Tipos de Agentes Suportados Humans (interactive, with multiple personas); AI agents (secure delegation of specific data access permissions with real-time activity monitoring); non-interactive entities (via MPC-based multisig)
Tipos de Carteira/Cliente Identity management dashboard (web/mobile planned); blockchain-agnostic wallet with per-blockchain UX plugins; MPC-based multisig for group account management
Mecanismos de Recuperação Federated guardian system (opt-in): user chooses n guardians; recovery key sharded across guardians; recovery requires authenticating with a subset of chosen guardians using multiple methods (username/password, SMS, TOTP, etc.); guardians are trusted entities with professional uptime guarantees; system remains firmly non-custodial
Conformidade / Regulamentações Privacy-first design (zero-knowledge to service providers); d/acc compliant (decentralized, democratic, differential, defensive); reduced attack surface for PII storage; ESIGN Act compatibility for legally binding cryptographic signatures (Ricardian Contracts support)
Protocolos de Troca de Credenciais Verifiable data registry (content-addressed, hash-referenced, signed attestations published to platform-agnostic data storage layer); selective disclosure via ZKP, hierarchical encryption, and proxy re-encryption
Estrutura de Confiança User sovereignty + cryptographic verification (no central authority); attestation-based directed social graph forming decentralized trust/reputation network; authoritative attestations for sybil-resistance (anonymizable via ZKP)
Modelo de Custo Free (d/acc democratic access principles)
Resistência à Censura High (user controls keys; no central authority can revoke access; data encrypted end-to-end; content-addressed storage can use any compatible service)