An identifier issued, controlled, and resolvable only through a central authority—such as an email address bound to a provider, a username on a platform, a government-issued number, or a domain name under registry control. Centralised identifiers are the architectural opposite of decentralised identifiers: the issuing authority can revoke, reassign, surveil, or lose them, creating single points of failure and lock-in, but also offering simple governance, accountability, and recovery paths that self-sovereign schemes must engineer explicitly.

Semantic Classification

Content

Definition

A centralised identifier is one whose existence, meaning, and resolution all depend on a single controlling authority. Your email address exists at your provider’s pleasure; your platform username lives in one company’s database; your National Insurance number is issued and interpreted by the state; a domain name persists only while the registry and registrar honour it. In every case, someone other than the subject holds the master record, and the identifier’s usefulness flows entirely through that party’s infrastructure.

The category is defined by contrast with the Decentralised Identifier (DID). A DID is generated by its subject, bound to cryptographic keys the subject controls, and resolvable without asking any single institution; a centralised identifier inverts each property. The authority can revoke or reassign it (account suspension, number recycling), observe every act of authentication that touches it (login telemetry), and lose it wholesale (breach, registry failure). Architecturally this concentrates risk into a Single Point of Failure: when the issuer is compromised or simply discontinues a service, every dependent credential, login, and relationship breaks at once. The pattern also produces lock-in—identifiers cannot be moved between providers, so switching costs accumulate around them.

Yet centralisation is not merely a defect. Central authorities offer properties that self-sovereign systems must painstakingly rebuild: account recovery when a user forgets a password, dispute resolution and legal accountability, uniqueness guarantees enforced by a registry, and a single place to apply regulation such as sanctions screening or age verification. The Domain Name System and the Certificate Authority hierarchy behind TLS show the model at its most successful—globally consistent naming and trust, purchased at the price of trusted intermediaries.

Current Landscape

Practically all deployed identity today is centralised or federated (a variant in which one authority, such as a social-login provider, vouches for the identifier to many relying parties—concentrating rather than removing central control). The decentralised alternative is advancing through the W3C DID Core standard, the EU’s eIDAS 2.0 digital identity wallets, and verifiable-credential pilots, but adoption remains early and most “decentralised” deployments still anchor to centralised registries or wallets operated by large vendors.

The realistic trajectory is hybrid: high-assurance roots (government eID, banking KYC) remain centralised for accountability, while portable, user-held credentials layer on top for privacy-preserving presentation. Understanding centralised identifiers as a distinct class—with their specific failure modes of revocation, surveillance, lock-in, and single-point compromise—is what makes the trade-offs of that hybrid legible, rather than treating decentralisation as an end in itself.

Recent developments:

  • DID standard maturing: the W3C published the First Public Working Draft of Decentralized Identifiers (DIDs) v1.1 in January 2025 and continued the Recommendation-track work into 2026, explicitly positioning DIDs as decoupled from centralised registries, identity providers and certificate authorities.

  • eIDAS 2.0 rollout: the EU’s European Digital Identity Wallet (EUDIW) programme advanced through its Architecture and Reference Framework, with the EDPS issuing TechDispatch #3/2025 (15 December 2025) analysing digital-identity-wallet designs including W3C DIDs and Verifiable Credentials.

  • Centralisation persists in practice: even nominally decentralised deployments still commonly anchor to centralised or federated registries and vendor-operated wallets, so most identity in production remains centralised or federated (single-sign-on providers concentrating rather than removing central control).

  • Infrastructure fragility as evidence: the 20 October 2025 AWS US-EAST-1 DNS outage disrupted authentication and login flows for thousands of centralised services, underscoring how identifier resolution bound to one operator’s infrastructure inherits that operator’s failure modes.

    Sources:

  • https://www.w3.org/TR/did-1.1/

  • https://www.edps.europa.eu/data-protection/our-work/publications/techdispatch/2025-12-15-techdispatch-32025-digital-identity-wallets_en