Selected Talks

15 of 15 talks

2026

2026Oral presentationPortugueseRNP

Digital Identity 2.0: How Your University Can Lead the Transformation

Frederico Schardong

RNP Forum 2026 · Brasília, Brasil

GT-BAITAAcademic Interoperability BusDigital IdentityIdentity FederationRNP

CAFe connects more than 330 institutions and is the largest academic federation in Latin America, yet it currently has 338 identity providers for only 52 service providers, and more than 40 of those belong to RNP itself. The talk compares those numbers with SURFconext, in the Netherlands, and WAYF, in Denmark, to show that CAFe is used as a gateway to RNP services rather than as a platform for collaboration between universities. The reasons appear in the more than 60 interviews conducted by GT-BAITA, which reveal infrastructure difficulties in running Shibboleth, weeks of SAML configuration per application and approval processes that stall adoption. The presentation shows how the Academic Interoperability Bus intends to reverse that picture, with a management system that simplifies publishing services in CAFe and in eduGAIN. The invitation is for each university to take an active part in that transformation rather than wait for it.

2026Oral presentationPortugueseWith recordingLabREC/LabSEC

The SERP Trust Federation

Frederico Schardong

Civil Registry Academic Workshop · UFSC

SERPIdRCOpenID FederationTrust FederationCivil Registry

IdRC handles end user authentication in the ON-RCPN ecosystem, with around 120 client applications, 6 million users and 250 thousand authentications per day. The talk shows that this infrastructure does not answer a different and equally important question, that of whether one service can trust another, within the same national operator or across operators. Starting from that gap, the presentation discusses why trust between SERP services is a problem of its own, today solved statically at each integration. The proposal uses OpenID Federation to evaluate policies and resolve chains of trust dynamically and verifiably. The horizon is a marketplace in which services from different national operators can discover and trust one another without manual agreements.

2026Oral presentationPortugueseWith recordingRNP

GT-BAITA: An Academic Interoperability Bus

Frederico Schardong

27th RNP Workshop · Praia do Forte, Bahia, Brasil

Digital Identity ManagementGT-BAITABAITAAcademic Interoperability BusInteroperabilityTrust Infrastructures

Publishing a service in CAFe today requires bureaucratic approval processes, weeks of SAML configuration and an operational burden that many institutions cannot sustain. The talk presents GT-BAITA, a project building an academic interoperability bus to turn that journey into a task of minutes. The work started from more than 60 interviews with CAFe operators, managers and IT teams at federated institutions and end users, which made it possible to map the pain points of each group. The proposal replaces the rigid, centralised structure built on SAML with a hierarchical federation based on OpenID Federation, with management and observability for whoever publishes services. More than a CAFe 2.0, the goal is to foster active sharing between federated institutions.

2025

2025Oral presentationPortugueseWith recordingRNP/CT-GId

Identity in Motion: A Report from the Internet Identity Workshop

Frederico Schardong

9th 2025 meeting of CT-GId, the Identity Management Technical Committee · online

Internet Identity WorkshopIIWDigital IdentityUnconferenceAgentic Identity

The Internet Identity Workshop has been held twice a year since 2005, follows the unconference format and has published its proceedings since 2008. This is a report from edition 41, in the autumn of 2025, which brought together 284 participants and 149 sessions proposed during the event itself, among developers, consultants, regulators, researchers and representatives of governments and of the United Nations. The talk recounts how a session with only three participants produced more contributions than presentations to far larger audiences, with direct encouragement to turn the work into a technical standard. It also summarises the themes that dominated the edition, with an emphasis on the identity of artificial intelligence agents, state endorsed digital identity and machine readable privacy terms.

2025Oral presentationEnglishInternet Identity Workshop

Building a National-Scale IdP: Shortcomings of OIDC

Frederico Schardong, Brendon V. R. Silva, Ricardo Custódio

Internet Identity Workshop · Mountain View, CA, USA

OpenID ConnectOIDCElectronic IdentityDigital IdentityOpenID Connect for Authentication ContextOIDC4AC

This presentation reports on the implementation of Brazil's Civil Registry Digital Identity (IdRC), serving potentially over 200 million users, and analyzes practical shortcomings of OpenID Connect (OIDC) in this context. We identify gaps in assurance representation, authentication context preservation, and the expression of authentication requirements. To address these issues, we propose OpenID Connect for Authentication Context (OIDC4AC), a backward-compatible extension that introduces structured authentication context and declarative factor negotiation, improving auditability, interoperability, and policy alignment for large-scale identity infrastructures.

2025Oral presentationPortugueseRNP/CT-GId

WGID -> SBGID

Frederico Schardong

In-person meeting of CT-GId · Foz do Iguaçu, Brasil

Digital Identity ManagementWGIDSBGIDScientific CommunityScientific Events

The Workshop on Digital Identity Management was born inside a security symposium, but identity management is a larger field than information security, with dimensions of governance, trust, user experience, interoperability and regulation. The talk supports that argument with the ISO/IEC 24760 and 29100 standards, with the scope of laws such as the Brazilian data protection act and eIDAS, and with the workshop's own call for papers, which is broader than that of the symposium hosting it. It then proposes turning the workshop into a symposium of its own, SBGID, with full papers and undergraduate and early research tracks, taking advantage of what a small community offers, such as low cost, no parallel sessions and more time per presentation. The proposal discusses where and when this would happen, with 2027 as a realistic horizon, and closes with the two hard questions, whether the community is already large enough and whether it has the stamina to sustain an event of its own.

2025Oral presentationPortugueseWith recordingRNP/CT-GId

From Self-Sovereign Identity to Fiduciary Identity: A Journey Towards Greater User Privacy and Usability

Frederico Schardong

6th 2025 meeting of CT-GId, the Identity Management Technical Committee · online

Digital IdentitySelf-Sovereign IdentityFiduciary IdentityIdentity GovernanceTrust InfrastructuresVerifiable Credentials

The talk critically examines the Self-Sovereign Identity paradigm, discussing its contributions, its practical limitations and the challenges of adopting it in institutional, regulatory and large scale settings. From that analysis it presents Fiduciary Identity as an evolution of existing models, grounded in the notions of responsibility, duty of care and the asymmetry of power between issuers, providers and identity holders. The work proposes a conceptual repositioning of digital identity, stressing the need for governance structures, institutional trust and explicit legal guarantees, especially where public services, critical infrastructure and the authentication of automated agents are involved. The contribution is to bring technical, legal and ethical aspects together into a conceptual basis for digital identity models that are more robust, auditable and aligned with the public interest.

2025Oral presentationPortugueseWith recordingLabSEC/UFSC

Electronic Authentication of Brazil's Civil Registry

Frederico Schardong

Civil Registry Academic Workshop · Florianópolis, Brazil

Civil RegistryDigital IdentityIdRCTrust InfrastructureDigital CitizenshipInformation SecurityInteroperabilityData ProtectionDigital Public ServicesIdentity Governance

The talk discusses the role of the Civil Registry as strategic digital identity infrastructure in Brazil, highlighting its historical, legal and technological relevance in guaranteeing fundamental rights and in delivering digital public services. It presents the IdRC initiative as a structuring effort to position the Civil Registry as a trusted issuer of digital identity, aligned with the principles of legal certainty, data protection, interoperability and technological sovereignty. The debate stresses the challenges of digitalisation at national scale and the importance of coordination between academia, government and registry offices in consolidating a trustworthy digital identity ecosystem oriented to the public interest.

2025Oral presentationPortugueseINTIC

Is This Document Fake? Digital Signatures: The Invisible Seal that Guarantees the Authenticity and Integrity of Digital Documents

Frederico Schardong

National Internet Governance Forum 2025 · online

Digital SignatureElectronic SignatureDigital CertificationDocument IntegrityMozambique

Digital documents circulate easily, but it is not always clear how to check whether what arrives is authentic and has not been altered along the way. The talk explains what a digital signature is and why it works as an invisible seal of authenticity and integrity. It then compares the types of electronic signature, simple, advanced and qualified, showing what each one guarantees about identifying the signer and where each of them makes sense. It closes on the digital certification infrastructure that underpins those guarantees and on the advanced signature service available in Mozambique.

2023

2023Oral presentationPortugueseWith recordingRNP

Less Digital Certification and More Electronic Identity: ICPEdu and CAFe in an Inclusive Digital Signer

Frederico Schardong

Meeting of the Special Interest Group on Digital Identity Management (SIG-GId) · online

Digital SignatureICPEduCAFeDigital CertificationElectronic Identity

ICPEdu has issued 186 thousand certificates since 2020, of which around 42 thousand are still active, while CAFe gathers a million users. The talk starts from that gap to argue that users do not want to hold a digital certificate, they want to sign a document. The proposal is an inclusive PDF signer that requires no knowledge of digital certification and imposes no unnecessary interactions, relying instead on the identity the person already has in the academic federation. The architecture combines the identity providers of CAFe with the ICPEdu certification authority and a signing service, in a solution with a filed patent.

2023Oral presentationEnglishWith recordingLaboratoire de Recherche en Sécurité Informatique @ Université du Québec en Outaouais

Self-Sovereign Identity: A New Paradigm for Identity Management and Its Open Challenges

Frederico Schardong

Identité numérique et cybersécurité · Québec, Canada

Self-Sovereign IdentitySSIDigital Identity ManagementDecentralized IdentityTrust ModelsIdentity AutonomyCybersecurity

This talk introduces Self-Sovereign Identity (SSI) as an alternative paradigm for digital identity management aimed at overcoming limitations of centralized and federated models. Building on conceptual and historical perspectives of identity, it outlines the core principles of SSI, including user autonomy, privacy-preserving credential presentation, and reduced reliance on identity providers. The presentation also addresses common misconceptions about SSI and highlights open challenges identified in the literature, such as the absence of a consensual definition, trust modeling, usability, and migration from existing identity systems.

2022

2022Oral presentationPortugueseWith recordingRNP/CT-GId

Self-Sovereign Identity: What it is and what it is not

Frederico Schardong

1st 2022 meeting of CT-GId, the Identity Management Technical Committee · online

Self-Sovereign IdentityDigital IdentitySSIVerifiable CredentialsDecentralisationIdentity Governance

The talk offers a conceptual analysis of Self-Sovereign Identity, clarifying its founding principles and distinguishing what actually characterises this model of digital identity from mistaken readings and misuses of the term. It discusses central concepts such as holder control, decentralisation, portability, the use of verifiable credentials and the separation between identification, authentication and authorisation. It also addresses the technical, institutional and regulatory limits of SSI, stressing that using a blockchain or a digital wallet is not by itself enough to make a system self-sovereign. The contribution is to mature the debate by proposing objective criteria for assessing SSI solutions, reinforcing the importance of governance, institutional trust and alignment with legal and social requirements.

2021

2021Oral presentationPortugueseWith recordingIFRS

Introduction to Secure Software Development

Frederico Schardong

V Teaching, Research and Outreach Showcase · online

Secure Software DevelopmentSecurity by DesignRisk AnalysisThreat ModellingWeb ApplicationsSoftware EngineeringSecurity Best PracticesSoftware Life CycleOWASP

The talk covers the principles and core practices of secure software development, presenting security as a requirement that cuts across the entire software life cycle. It discusses security by design and security by default, risk analysis, threat modelling, input validation, access control and sound dependency management. The material stresses that secure development practices have to be paired with testing, code review and continuous monitoring. The closing argument is that security belongs inside software engineering processes, rather than in reactive approaches based on isolated fixes or late audits.

2021Round tablePortugueseWith recordingRNP

Challenges and Perspectives for Adopting Decentralised Digital Identity

Maria T. Aarão, Fernando Marino, Frederico Schardong, Arlindo Conceição

22nd RNP Workshop · online

Decentralised Digital IdentityIdentity GovernanceInteroperabilityTrust InfrastructuresVerifiable CredentialsRegulationDigital Public Services

The session discusses the main technical, institutional and regulatory challenges to adopting decentralised digital identity in real settings, particularly at national scale and in public services. It examines limitations related to interoperability between solutions, governance of decentralised ecosystems, usability for end users and integration with legacy identity infrastructure. The debate also covers trust, accountability and legal compliance, exposing the tension between technical decentralisation and legal and institutional requirements. It closes with perspectives on how these models may evolve, pointing to the need for open standards, clear governance arrangements and coordination between academia, the public sector and industry to make adoption sustainable and aligned with the public interest.

2021Oral presentationPortugueseWith recordingLabSEC/UFSC

Philosophical Perspectives on Identity

Frederico Schardong

LabSEC weekly meeting · online

PhilosophyIdentityAbsolute IdentityRelative IdentityIdentity over TimeCriteria of IdentitySimilarityVaguenessMetaphysics of IdentityEndurantismPerdurantism

The talk explores the concept of identity from a philosophical perspective, critically discussing the notions of absolute identity, relative identity and identity over time. It presents classic problems from the metaphysics of identity, such as the paradoxes of change, the Ship of Theseus and the Problem of the Many, examining different criteria of identity and the role of conceptual vagueness. The work contrasts three dimensional theories, based on endurance, with four dimensional ones, based on perdurance and stage theory, looking at how each deals with intrinsic and extrinsic change in objects. It closes on the relation between identity and similarity, arguing for a contextual, observer dependent and potentially vague view of identity, with direct implications for how identity is understood in computational and digital systems.