
digital identity
civic infrastructure
asia-east
2025-cohort-5

Mashbean
Taiwan
Mashbean (X: @mashbean) is A Taiwanese physician turned Decentralized Architect, with a background in managing DAOs and blockchain projects, including Taiwan's first DAO, FAB DAO(opens in a new tab). His research focuses on developing digital identity systems that can provide reliable services while maintaining the decentralized principles that make blockchain protocols robust and trustworthy. By applying these same principles to national identity infrastructure, his work aims to create more resilient systems for public goods support and civic engagement.
In 1993, The New Yorker published a cartoon by Peter Steiner with the famous line "On the Internet, nobody knows you're a dog." For 30 years, the internet has lacked a clear and widely adopted digital identity verification mechanism. That absence lowered the cost of participation and enabled a degree of anonymity that many experienced as freedom, but it also created serious governance and risk challenges.
Today, we might update the line to reflect our reality: "On the Internet, nobody knows if you are a human or a robot." Whether or not online users are bots has become a major issue for everyday internet life and for democratic systems.
In Taiwan, where I served in the newly established Ministry of Digital Affairs (moda) from 2023 to 2025, we experienced bot attacks, information manipulation, and ideological propaganda. These cyber threats have a visible impact on social platforms and public deliberation, and foreign interference has amplified polarization. I do not think this is unique to Taiwan. Similar dynamics can be found elsewhere.
At the same time, from an online safety perspective, governments are increasingly requiring online identity verification. China(opens in a new tab) was an early adopter of real-name systems and maintains mandatory verification rules across many services. Australia(opens in a new tab) and the UK(opens in a new tab) require online services to adopt age verification. The mainstream solution to digital identity so far has been centralized databases and identification infrastructure, where government entities or private service providers collect, store, and verify necessary information. Verifiers rely on and query national or corporate databases for verification events.
However, there are major challenges with this centralized identity model. First, large amounts of concentrated personal information contained in centralized databases constitute honeypots, and they become targets of data breaches.
For example, in 2025, an anonymous social platform called Tea became the center of a crisis. Tea is a platform where women can anonymously share warnings about men on dating apps who may be high risk. In other words, users disclose alleged problems associated with specific men. The Tea application suffered a data breach(opens in a new tab), exposing sensitive user information, including user selfies and government ID photos used in verification, images from posts, and private messages. Users on 4chan subsequently weaponized the leaked data for doxxing and further distribution, causing widespread fear among Tea users.
Data leaks, however, are not limited to private services. Taiwan's household and health databases have faced recurring risks(opens in a new tab). India's widely known Aadhaar(opens in a new tab) identity system has also been associated with large breach risks.
Second, centralized databases can be a tool for surveillance(opens in a new tab). Governments (or Big Tech) can track instances of credential use, further extracting personal data and behavioral signals. Regimes(opens in a new tab) can also integrate facial recognition, mobile location tracking, social media censorship, and predictive policing systems into a large-scale infrastructure that can monitor, censor, or persecute ethnic minorities, human rights defenders, and ordinary citizens.
If digital identity becomes a centralized surveillance portal, digitization risks turning people into objects of real-time management, and civil rights can be redefined at the interface.
Third, systemic reliance on monolithic, centralized platforms risks surrendering national digital sovereignty. Digital wallets, biometric logins, mobile payments, and identity verification tools are rapidly consolidating into the hands of a few large platforms. The most obvious examples are Apple Wallet and Google Wallet. Because they control the iOS and Android ecosystems, regulators have pointed to their structural market advantages, and courts have questioned whether they function as de facto monopoly gateways.
If digital driver's licenses, boarding passes, financial credentials, professional qualifications, and health insurance records all concentrate inside a single Big Tech app, and if many services accept only that app, then we are gradually outsourcing national digital sovereignty and competitive space to a few tech giants.
In recent years, public awareness around digital privacy and human rights has grown significantly. When a government digitizes identity documents, citizens naturally do not want the government to track every instance of credential use. This principle is often described as "no phone home." At the same time, a new concept has gained traction: self-sovereign identity (SSI). It emphasizes that users should fully control their identities. The core idea is that credentials are held and presented directly by the user or citizen, and verifiers do not need to query national or corporate databases for every verification event. This protects user privacy and preserves sovereignty across both online and offline settings.
One technical standard aligned with self-sovereign identity is the verifiable credential model. The model allows credentials to be issued directly to individuals and verified peer-to-peer, eliminating the need for a centralized database that records usage history. This framework frequently leverages zero-knowledge proofs — an advanced privacy-enhancing technology that has gained strong recognition among developers — to enable cryptographic verification without exposing sensitive personal information like exact dates of birth or home addresses.
This is also an international trend. A notable case is Bhutan. In May 2026, Bhutan anchored its National Digital Identity (NDI) system to the Ethereum public blockchain, becoming the first country to attach national digital identity directly to a permissionless decentralized blockchain. The purpose was to ensure that national identity credentials can be verified beyond borders without permission. In other words, a Bhutanese citizen should be able to use a verifiable credential to interact directly with overseas services without relying on layers of bilateral memoranda. According to the system's implementers, Bhutan did not put personal data on the blockchain. Instead, it places issuer-related information on the blockchain so verifiers anywhere can confirm authenticity, thereby establishing digital trust. This highlights an important shift: the subject is the citizen while the state plays the role of attesting authenticity, rather than centrally controlling all data. State digital services are fundamentally changing.
One of the largest efforts is underway in the European Union. The EU launched the EU Digital Identity Wallet (EUDI Wallet) framework and requires every EU member state to provide this service to all citizens and residents by 2027, capable of holding national identity documents. In particular, Germany's innovation agency SPRIND has treated the national wallet and EUDI as a state-level project and demanded support for zero-knowledge proofs. The idea is to prove only necessary information, for example that I am over 18 or that I hold a license, rather than handing over a full identity card with a birth date and an address. At re:publica in Berlin in 2025, senior officials in the German government responsible for digitization and modernization argued(opens in a new tab) that universal access to a user-controlled digital identity wallet that can hold ID cards, driver's licenses, and transportation tickets is a key aspect of the digital state and that the EUDI wallet is a core tool for European digital sovereignty.
Switzerland requires that the e-ID be issued directly by the state rather than outsourced to a single large private provider, to prevent identity infrastructure from becoming a new monopoly platform. The e-ID will be delivered through the swiyu wallet(opens in a new tab) model — a free, voluntary, and open-source system that allows the public and industry to inspect and reuse the code, reducing black-box risk. The Swiss government publicly commits to unlinkability, meaning that credentials used in different service contexts cannot be linked to track behavioral trails. This signals that privacy protection is not a slogan, but it is already in the design specification.
The state of Utah in the United States passed SB260, known as the Personal Digital Identity Amendments, with bipartisan support. The bill makes a meaningful legal shift, where identity is no longer framed as something the state grants you but something you claim, which the state recognizes and attests to, and participation is optional. In this framing, digital identity is treated as an inherent right of a natural person, not a number system newly created by the government. This positioning compels the government to recognize that personal autonomy and privacy come first, and that the government provides verification services rather than comprehensive administrative control.
The principles of self-sovereign identity are also being taken up by Big Tech. Apple Wallet has expanded its identity capabilities in iOS 26. This update has enabled US passport support on iPhones and brought services related to Real ID further into the Apple ecosystem. Meanwhile, Google Wallet also provides passport integration and supports zero-knowledge verification. For example, a UK passport can be added to Google Wallet and used to prove legal adulthood for event tickets or alcohol purchases without revealing personal data.
Two years ago, during my time in the Taiwanese government, I proposed a Taiwan Digital Identity architecture with a very similar structure and built on a public blockchain. It likewise emphasized self-sovereignty, safety, and simplicity. After I left, the work moved forward, and I have continued to help in an external role. Our work has now evolved into the Taiwan digital identity wallet sandbox, which is already online. A demo can be accessed here(opens in a new tab). If you want to try issuing credentials yourself, you can apply for an account and test within the sandbox. I also collaborated with friends to build vc.mashbean.net(opens in a new tab) and issued a Mashbean card. With the card, you can participate in specific forums as a simple proof of concept.
Despite these positive examples, the SSI movement is still unstable and has some challenges.
The first challenge is that the identity stack itself must be technically sound and credibly neutral, and some critical standards and pilots fall short. Approaches and properties like open source, verifiability, privacy by default, zero-knowledge proofs, unlinkability, and minimal disclosure are foundational building blocks required to achieve true credible neutrality. Without them, an identity system cannot be universally trusted, as it remains vulnerable to architectural manipulation by authoritarian regimes or platform monopolies.
A notable example occurred with ISO/IEC 18013-5, the international mobile driver's license standard. The specification contained a design element that looked like a backdoor, allowing the issuing state or organization to enable user footprint tracking without the user's knowledge. In June 2025, it was flagged by standards developers and triggered a significant concern leading to a "no phone home" petition. ISO developers acknowledged that the item had been included to meet some countries' requirements, and they promised to remove it.
Second, institutional trust and cross-border recognition remain unresolved. A sound technical stack can ensure that a system is secure, but it cannot alone determine whether an issuing entity possesses legitimate, real-world authority. Establishing this legitimacy requires trust lists — authenticated directories of authorized issuers (and notably whether or not a trustless, permissionless public blockchain can become part of the solution is worth sustained discussion). Today, however, a global digital identity trust framework has not solidified. The reason is that digital identity is not only commercial. It is geopolitical. Political differences across states matter.
Third and relatedly, we currently face severe standardization fragmentation. As industry standards and policy frameworks evolve, competition over the underlying architecture is intensifying. We can see the World Wide Web Consortium (W3C), the FIDO Alliance, the Internet Engineering Task Force (IETF), and the OpenID Foundation all advancing multiple standards that are still unfinished or not fully released. The International Organization for Standardization (ISO) has its own system.
In this regard, I want to note that blockchain developers are largely absent from standards communities in practice, even though the decentralized identifier standard originally emerged from early blockchain identity ideas. Many traditional standards participants keep their distance from blockchain ecosystems. From my perspective, Ethereum and these organizations are far closer in ideology and direction than people assume. Closing the misunderstanding has become urgent.
What illustrates these challenges was a major gathering that took place in July 2025 in Geneva, Switzerland, called the Global Digital Collaboration Conference(opens in a new tab). It was widely viewed as the first large-scale event centered on digital identity, bringing more than a thousand people representing organizations like the UN, WTO, World Bank, OECD, W3C, OpenID Foundation, Google, Huawei, Mastercard, and Visa. The main focus was addressing interoperability gaps and privacy issues, but the conference failed to produce a clear conclusion. With fractured standards, state and corporate interests, and individual rights on the table, positions remained deeply divided.
We can perhaps learn from the earlier experiences and successes in global open standards, like the Domain Name System (DNS). The Internet Corporation for Assigned Names and Numbers (ICANN) and its community govern domains through the ccNSO, the gNSO, and broader multistakeholder participation. Domains are not treated as purely governmental affairs. ICANN operates on multistakeholder governance rather than the multilateral logic of the United Nations system. The two logics are very different. ICANN also sustains a positive economic ecosystem, which then supports policy work that is not always profitable, such as Universal Acceptance (UA), Internationalized Domain Names (IDN), and youth capacity-building.
There are, of course, many related and unique nuances at the national level. As part of the Taiwanese government, we asked ourselves many of these fundamental questions: Can we protect public choice through open source, minimal disclosure, and zero-knowledge proofs, so that Taiwan can defend digital sovereignty and individual privacy in external negotiations? Can we build this wallet-based trust architecture in a format that international partners can understand, trust, and interoperate with, so that Taiwanese citizens, companies, and professional services can be recognized in the global digital economy without constantly having to re-explain who we are?
If the answer is yes, then we are not simply meeting someone else's specifications. We are laying the foundation for sustainable, exportable, and trustworthy public infrastructure for the next generation of democratic society. That is digital trust, and it is the governance blueprint Taiwan must propose proactively.
After leaving the Ministry of Digital Affairs in 2025, with support from the Ethereum Foundation Next Billion Fellowship, I started the Bonds project, a nonprofit initiative that can be found at bonds.tw(opens in a new tab).
At Bonds, we hope to accomplish three goals. First, I believe there is an ideal path for digital identity, but sovereign states and large companies carry too much baggage and too many constraints. Small, nonprofit projects can make more innovative moves and even conduct more forward-looking research. To that end, we built a demonstration mobile app for backing up government IDs. Taiwan faces layered geopolitical risks, and natural disaster scenarios require offline verification. Recently, typhoons caused network outages in at least one county, which highlighted the importance of offline verification. More crucial are man-made disaster scenarios. We need a new digital trust architecture that can withstand geopolitical risks, especially malicious online actors and digital surveillance.
Second, we developed a conceptual architecture and a series of diagrams, alongside a technical stack that remains under development. The proposed stack uses Taiwan's electronic identification and signature mechanism, TW FidO, to authenticate access to the government's MyData platform and retrieve national identification data. This information is then transformed into verifiable credentials within Bonds, an application built on self-sovereign identity principles. We also incorporated more advanced zero-knowledge technologies that have yet to be widely adopted in Taiwan or in many government-led digital identity deployments across the European Union. The purpose was to provide a concrete demonstration of how digital identity systems could achieve both interoperability and unlinkability. To complement the technical work, we published a policy-oriented article grounded in Taiwan's institutional context. It explains why Taiwan and the broader international community should seriously consider zero-knowledge proofs as a means of preventing unwanted correlation across transactions, while proposing a federated trust-list model to support interoperability. The detailed technical stack and policy proposal are available in our lightpaper, "Bond for the Future: A Path to Interoperable Yet Unlinkable Digital Identity."(opens in a new tab)
Third, beyond the policy paper and app, we believe this stage also requires a broader public understanding of zero-knowledge proofs and new digital identity concepts. We developed a simple story on the website, designed for elementary and middle school students to understand what digital identity is. Using the honeypot metaphor comparing big honeypots and small honeypots, we explain distributed and decentralized identity, pluralistic identity, and new models of digital trust. The content also covers Taiwan and international case studies. Internationally, there are many data breaches related to digital identity that deserve systematic analysis. In Taiwan, however, there are still relatively few complete and systematic discussions of the issue. After all, if children can grasp the concept of self-sovereign identity, perhaps the civil service and the broader public can understand it more easily.
Lastly, as a new Fellow at Harvard University's Allen Lab for Democracy Renovation, I presented a project titled "From State-Issued Credentials to Citizens Proving Themselves: How Digital Identity Transforms Digital Civic Infrastructure." The project moves beyond the conventional framing of digital identity as an instrument for accessing government services. It examines, from a citizen-centred perspective, what an ideal digital identity system should look like, how it could enable people to prove relevant claims about themselves across civic contexts, and how such infrastructure should be approached in policy and institutional design. The accompanying article(opens in a new tab) and presentation(opens in a new tab) are available online.
Most recently, we completed an experiment integrating the zkID team's product and Taiwan's digital identity wallet (TW DIW) into the Bonds project. The full development report and source code are available here(opens in a new tab).

Mexico
identity
america-latin
america-central
2021-cohort-1
Chuy explores government-issued documents on chain in Argentina and other LatAm countries.

Taiwan
digital identity
civic infrastructure
asia-east
2025-cohort-5
Mashbean researched robust digital identity in Taiwan, with a focus on resilience and decentralized infrastructure.