Skip to content

The Seven Laws of Identity

ユーザーによる制御と同意

EN:
Digital identity systems should reveal identifying information only with the user’s consent. Users should understand what information is being shared, with whom, and for what purpose. Whenever possible, they should remain in control of that disclosure.

JA:
デジタル・アイデンティティ・システムは、原則としてユーザーの同意のもとで個人を識別する情報を開示すべきです。ユーザーは、何の情報が、誰に、何の目的で共有されるのかを理解できる必要があります。可能な限り、その開示をユーザー自身がコントロールできるべきです。

2. Limited Disclosure for Limited Use

限定された用途のための限定的な情報開示

EN:
An identity system should disclose the minimum amount of identifying information necessary for a particular purpose. Collecting or sharing more information than required increases privacy and security risks. Data disclosure should therefore be proportional to its intended use.

JA:
アイデンティティ・システムは、特定の目的を達成するために必要な最小限の情報だけを開示すべきです。必要以上の情報を収集・共有すると、プライバシーやセキュリティのリスクが高まります。そのため、情報開示は利用目的に見合った範囲に限定されるべきです。

3. The Law of Fewest Parties

最小限の関係者の法則

EN:
Identity information should be shared with as few parties as possible. An identity architecture should minimize unnecessary intermediaries and organizations that gain access to personal information. Fewer parties generally means less opportunity for misuse, leakage, or unwanted correlation.

JA:
アイデンティティ情報を共有する相手は、可能な限り少なくすべきです。アーキテクチャ上も、個人情報にアクセスする不要な仲介者や組織を減らす必要があります。関係者が少ないほど、情報の悪用、漏えい、意図しない名寄せのリスクを抑えられます。

4. Directed Identity

方向づけられたアイデンティティ

EN:
Identity systems should support both public identifiers and identifiers intended only for specific relationships. A person does not always need to use the same identifier with every service. Different identifiers can help prevent unrelated services from correlating a user’s activities.

JA:
アイデンティティ・システムは、公開される識別子だけでなく、特定の相手との関係だけで使用する識別子も扱えるべきです。すべてのサービスで同じ識別子を使う必要はありません。相手ごとに異なる識別子を利用することで、サービス間での不要な名寄せを防ぐことができます。

5. Pluralism of Operators and Technologies

事業者と技術の多元性

EN:
A universal identity system should support multiple identity providers, technologies, platforms, and trust models. No single technology or organization can satisfy every identity use case. Different systems therefore need ways to coexist and interoperate.

JA:
普遍的なアイデンティティ・システムは、複数のIdentity Provider、技術、プラットフォーム、信頼モデルを受け入れられるべきです。単一の技術や組織だけですべてのユースケースを満たすことはできません。そのため、異なる仕組みが共存し、相互運用できることが重要です。

6. Human Integration

人間との統合

EN:
The human user must be treated as part of the identity system, not as something outside it. Interfaces should help users recognize who they are interacting with and what security-sensitive action is taking place. This is particularly important for resisting phishing and impersonation.

JA:
人間のユーザー自身もアイデンティティ・システムの一部として考える必要があります。ユーザーが「誰とやり取りしているのか」「どのような重要な操作をしようとしているのか」を認識できるUIが必要です。特に、フィッシングやなりすましへの対策として重要な原則です。

7. Consistent Experience Across Contexts

コンテキストをまたいだ一貫したユーザー体験

EN:
Users should have a consistent and understandable identity experience across different applications, devices, and contexts. They should be able to recognize familiar identity interactions even when the underlying technologies differ. Consistency helps users make safer and more predictable decisions.

JA:
異なるアプリケーション、デバイス、利用状況であっても、ユーザーが一貫して理解できるアイデンティティ体験を提供すべきです。背後で使われる技術が異なっていても、ユーザーから見た操作や意味は認識しやすいものである必要があります。一貫性は、ユーザーが安全で予測可能な判断をする助けになります。