What is a centralized identity database?

Definition

A centralized identity database can make verification and administration consistent by keeping core records in one place. It may contain names, documents, identifiers, verification results, account links, biometrics, or audit history depending on its purpose.

Centralization also concentrates risk and creates a valuable target for attackers, insiders, legal demands, surveillance, and cross-service reuse. Protections include strict scope, separation, encryption, access logging, short retention, independent oversight, and designs that prove an attribute without retaining complete identity evidence.

ELI5

A centralized identity database keeps many people's identity information in one main system. This can simplify checks, but one failure can expose or affect many records at once.

For example, a database that connects government documents with AI accounts could help a service identify users. If breached or repurposed, it could also reveal which account belongs to each person.

Frequently asked questions

Why are centralized identity databases attractive targets?

They can contain large volumes of valuable identity evidence and account links, so one successful breach or misuse can affect many people.

What alternatives can reduce identity centralization?

Alternatives include data minimization, decentralized or user-held credentials, attribute proofs, separation of records, local verification, short retention, and anonymous access for low-risk uses.

Videos explaining centralized identity database

  1. Taylor Lorenz beside the headline Anonymous AI Use at Risk