Draft proposal · No agreement in place · Nothing has been awarded
Utah Life · a proposal to the Utah Board of Higher Education
48,670 students, more Utahns than any other school in the state. UVU is the lead institution on both applications and the first of three universities to come online. It issues from its own keys under its own policy, and it cannot read, hold, or revoke what any other institution issued.
Utah Valley University is the lead institution on two linked applications to the Utah Board of Higher Education and the first of three universities to bring a node online. With 48,670 students it is where the student-facing work happens first: identity, payments, endorsements, reputation, agreements and credentials that a person holds and carries. UVU issues from its own keys under its own policy and cannot read what any other institution issued. Proposed UVU share across both applications: $1,875,000. No agreement exists and nothing has been awarded.
Start here. The rest of this page is how it works and who controls it, which matters, but this is what it is for.
A landlord who needs to know you are enrolled receives enrolled: yes. Not your transcript, not your address history, not your student ID number. You choose the one fact that answers the question, and the rest never leaves your phone.
Tuition, lunch, a parking pass, your paycheck from a campus job. No fee to you, no surcharge, no basis point, and nothing may be passed through to you. Today a $3,000 tuition payment by card costs a student around $88 in fees. Here it costs nothing.
A professor writes you a recommendation and you hold it, signed, verifiable, reusable. It does not live in somebody's inbox or expire when they change jobs. You decide who ever sees it.
Projects finished, hours served, skills demonstrated, all portable and all yours. No rating, no rank, no leaderboard, and nothing anybody can compute about you behind your back. You show what is relevant and keep the rest.
Enrollment forms, housing leases, work agreements, waivers. Cryptographic proof of who signed and exactly what they signed, held by both parties and by neither one alone. No more asking an office to send you back a copy of something you signed.
Certificates, degrees, competencies. Verified in seconds by the next school or the next employer, without anyone phoning a registrar. Two-thirds of Weber State's associate-degree earners come back within a year for another credential, and every one of them currently pays a cost in time to prove something already true.
Campus messaging, groups, and mail running on open protocols, on infrastructure your own university operates. Nobody is mining it, because there is no central place where it all sits.
It has no standing access to anything. When it needs authority it asks for exactly one thing, for one purpose, expiring, and you can take it back with one tap. Everything it did is written down where you can see it.
Everything you use today works the same way. Some company or some office holds your record - your grades, your money, your signature, your messages, your face - and lets you look at it. You are the subject of the file, not the owner of it. That arrangement is not a law of nature; it is a design choice, made when there was no cheap way to prove something was true without a trusted middle. There is now.
A key is the thing only you have, that proves something came from you and nobody else. A node is just the place an institution keeps its own keys, so that no single school and no single company sits in the middle of everyone else - that is the entire mechanism, and everything else here is what it lets a person do: choose which fact to disclose, who receives it and for how long, and walk away from any provider without losing what you earned, because your university holds its own keys rather than renting them.
The best artificial intelligence can remain available, but it becomes a tool you aim not a party you are exposed to.
You are at the centre because that is where the record actually lives. The three universities are peers on one open standard, not branches of a platform: each holds its own keys, each can revoke only what it issued, and none of them can read the others. Take any one away and the other two keep working. Take away the company that built it and all three keep working, because the standard and the test suite are public.
KERI and ACDC · W3C Verifiable Credentials · OpenID4VP · the conformance test suite, published open source
clear.host · contributed background technology · Utah-hosted · more than a decade of prior investment
Everything on this page rests on one small piece of machinery: the keys that prove a record is yours. Four things are worth understanding, because each one answers a question a person actually asks. Where do my keys come from. What happens when one is stolen. What happens when I lose my phone. And how can an assistant use any of this without learning who I am.
One secret on your device quietly produces a separate key for every place you use it. Nobody can connect them.
Retire a key and name its successor without changing who you are on the network.
A lost phone is an inconvenience not the loss of your degree, your money, or your history.
Your own directed intelligence uses a large model without ever handing it who you are.
Shown to the registrar
Shown to campus merchants
Shown to a counterparty
Shown to the comms server
Derivation runs one direction. A key can be produced from the root, but the root cannot be worked backward out of a key. Because each party is handed a different key, two of them comparing notes learn nothing: the registrar and the campus store hold values that look unrelated. This is what an automated system cannot follow. A platform, or a model, that sees your key at one place and your key at another has no mathematical way to know they belong to the same person. There is nothing to stitch. You do not memorize any of this and you never type a key.
Each entry in your record does two jobs. It signs with the key in force at that moment, and it seals a fingerprint of the key that will come next. The successor is committed before it is ever used, so a thief who takes today's key still cannot name tomorrow's. Rotating is a normal event in the log, not a new account.
A verifier replays this log from the beginning. It accepts a signature only if the key was in force at the sequence number where the signature was made.
Not one of these nodes can read your record. They hold a signed log and confirm what order it happened in. No node can issue a key. Only your root can.
Public, or private and non public
This is the difference between directed digital intelligence and artificial intelligence in one picture. Yours runs on your device, reads your record locally, and decides how little to ask. Theirs is very good at language and reasoning, and it gets exactly one scoped grant, under a key that was made for this request and will never be used again. When the grant expires the model holds nothing it could use to find you, and the next request arrives under a different key it has never seen. Public model or private one, the boundary is the same. You direct yours. Theirs hires theirs.
Rotation retires the old key in the same record that names the new one. The theft becomes a dated line in your history instead of the end of it.
The log says which key was in force when, so a transcript signed two years ago still verifies after four rotations. No re-issuance, no fees.
Your university can issue a credential and witness your log. It cannot rotate your keys or sign in your place - and neither can the company that built this.
Every request rides a key made for that request and never used again. Two requests share nothing a model could use to connect them.
Every one of these is a real transaction with a real current cost, which is what makes the measurement meaningful.
Funded inside the awards where the application says so, gated by counsel where noted.
Not in either application. Listed so the roadmap is visible and the scope is honest.
Utah's State-Endorsed Digital Identity statute, SB 275 as amended in February 2026, sets requirements. Digital World's Engineering Specification, the LIFE Standard Reference Architecture, maps each of them to a shipping component and keeps a reference installation in Utah for exactly that purpose. This project is the first independent, instrumented test of whether the mapping holds at population scale.
The statute says identity is inherent to the person rather than conferred by government. The specification's first rule says the same thing in different words: the member always owns the identity, profile, credentials, data, personas, likeness, graphs, relationships and assets; the provider supplies infrastructure, not ownership. The conformance suite this project publishes is what turns that shared sentence into something a state procurement officer can check.
Specification: Digital World Engineering Specification v3, section 16, State-Endorsed Digital Identity. Published at docs.digitalworld.earth. The framework is contributed background technology in both applications; the conformance suite built against it is a funded deliverable released open source.
Held in UVU-controlled hardware security modules. Not held by the industry partner, not held by the network, not escrowed anywhere by default.
Which credentials it issues, to whom, on what evidence, and for how long. Written by UVU, changeable by UVU.
UVU can revoke what UVU issued. That is the whole scope of its revocation authority.
Which campus systems connect, which verifiers are recognized, and what a student sees inside UVU's own app.
UVU cannot read, hold, or revoke a Weber State certificate or a Utah State degree. It can verify one, like any other verifier, if the student chooses to present it.
The credentials live on the student's device. UVU issues them and then does not hold them.
UVU cannot produce a list of where a student presented a UVU credential. Neither can anyone else.
UVU enrolls more Utahns than any other institution in the state. That is the reason this node goes first and goes deepest: no other campus in Utah can run a population-scale deployment study without leaving the state.
UVU is also the home of the principal investigator and the prime recipient on both applications. The student-facing work happens here, the first credential types are issued here, and the six student companies are formed here.
students enrolled, fall 2025
UVUof them Utah residents
UVUgraduate students, past 1,000 for the first time
UVUstudents working on the project across all three nodes
Proposed
The attributes column is the point. A landlord who needs to know a person is enrolled receives enrolled: yes, not a transcript. That is what the statute means by minimum necessary, and measuring whether it holds up in practice is one of the project's research objectives.
Six paid venture fellows pursue six commercialization tracks. A track advances to company formation only if it has one paying or committed customer outside the project. Students own their intellectual property. The industry partner takes no equity, no assignment, and no right of first refusal.
Nothing, and then a subscription the institution can decline.
Students pay no fee, no surcharge, no basis point, and nothing may be passed through to them. The institution pays nothing per transaction either. There is no revenue share anywhere in this model. Earlier drafts of the campus proposal carried a one percent fee on rewards and stored value split between the provider and the university; it has been removed.
Two things make zero credible rather than a slogan. This institution can run its own node, because the specification and the conformance suite are published open source, so hosting is a convenience and not a lock. And the keys stay here whether it self-hosts or subscribes, so buying hosting never means handing over authority. Hosting is the sustainability model after the award, not something the grant pays to build.
Every node runs the same open standard and holds its own keys. A credential issued here verifies anywhere without calling back to this institution, and this institution cannot read or revoke what another node issued.