Washington State
House of Representatives
Office of Program Research
BILL
ANALYSIS
State Government & Tribal Relations Committee
SB 5534
Brief Description: Concerning the use of verifiable credentials.
Sponsors: Senators Brown and Wagoner.
Brief Summary of Bill
  • Requires, by December 1, 2022, that the Consolidated Technology Services Agency (also known as WaTech), the departments of Health and Licensing, institutions of higher education, and the Secretary of State to each report which programs, services, and projects may be well-suited to the use of verifiable credentials as a means of improving efficiency, customer experience, and safeguarding privacy.
  • Requires WaTech to create a process for developing a recommended trust framework for verifiable credentials (trust framework) in Washington, by October 1, 2022.
  • Requires WaTech to develop and submit the trust framework, and any recommendations on legislation to implement the trust framework, to the Legislature by December 1, 2023.
Hearing Date: 2/21/22
Staff: Desiree Omli (786-7105).
Background:

Blockchain Technology.
Adopted in Washington in 2020, the Uniform Electronic Transaction Act defines "blockchain" as a cryptographically secured, chronological, and decentralized consensus ledger or consensus database maintained via internet, peer-to-peer network, or other similar interaction.  Blockchains are a type of database used to securely process and track the distribution of data across a large number of computers.  Blockchain technology encrypts the contents of a record or a transaction, plus a few key pieces of metadata (such as the timestamp and the parties involved), into an output known as a hash, which is a short digest, or unique digital fingerprint, of the record.  Changing the information recorded in a blockchain, or adding information to a blockchain, requires all the networks to cross-reference each other and a majority of the network to validate the information, thereby reaching "consensus," before the information entered is validated.  This process allows the networks to identify potential tampering with information in a single block.  In the private sector, while blockchain technology is most commonly associated with the cryptocurrency Bitcoin, other evolving applications can include insurance policies, property and real estate records, copyrights and licenses, supply chain tracking, and transactions in the financial services industry.
 
Trust Framework.
According to the National Institute of Standards and Technology (NIST) under the United States Department of Commerce, a "trust framework" is a set of rules and policies that govern how the members of the framework will operate and interact, including conducting identity management responsibilities, sharing identity information, using identity information that has been shared with them, protecting and securing identity information, performing specific roles, and managing liability and legal issues.  In the context of identity verification, the NIST explains that a trust framework is used in federated identity management where organizations that share a common user base and transaction types develop a means to allow users to sign on and access multiple services through shared login and authentication processes.  In other words, users are able to access the systems and applications of multiple organizations using one login credential.  Organizations must trust the federated identity management processes of the other participating organizations in order to allow access to users that were authenticated by another entity.  The rules for federated identity management are known as trust frameworks.

Summary of Bill:

By December 1, 2022, the Consolidated Technology Services (also known as WaTech), Department of Health, Department of Licensing, institutions of higher education, and the Secretary of State must each submit a report to the Legislature detailing which of the agency's programs, services, and projects may be well-suited for the use of verifiable credentials as a means for improving efficiency, customer experience, and safeguarding privacy.  "Verifiable credential" is defined as a tamper-evident credential that has authorship which can be cryptographically verified.
 
In preparing its report to the Legislature, the named agencies must consult with appropriate technology industry representatives, including a Washington-based trade association, to ensure that the agencies are informed of the basic definitions and standards used by the technology industry in Washington for verifiable credentials.
 
By October 1, 2022, WaTech must develop a process for creating a recommended trust framework for verifiable credentials in Washington.  The process should include public and private sectors and must involve participation with technology industry representatives, consumer protection advocates, and other similar stakeholders.
 
By December 1, 2023, WaTech must submit to the appropriate committees of the Legislature a recommended trust framework and any recommendations for legislation necessary to enact or implement the trust framework.

Appropriation: None.
Fiscal Note: Available.
Effective Date: The bill takes effect 90 days after adjournment of the session in which the bill is passed.