You are here. See how this question connects to other ideas.
Select a node to open its page · Expand to read within the map
One question
Why can one DID lead to two accounts?
A shared identifier does not merge application records or permissions.
Imagine signing in to a photo service and a workshop with the same DID. One stores your photos and sharing settings; the other tracks registration and permission to borrow equipment. Each service maintains its own account. Reusing an identifier does not combine those accounts.
An account is a set of records and rules an application maintains for you. A DID supplies an identifier and associated verification information. The application still decides how to bind it to an account. Switching sign-in methods without a reliable linking process may create a separate account.
What remains after sign-in?
The photo service may establish control of an identifier and locate an account. That tells it nothing about workshop eligibility. The workshop needs appropriate evidence and its own access rules. A training credential likewise grants no automatic access to photos.
Keep four roles separate: identification names a subject, authentication checks evidence presented in an interaction, an account stores application state, and authorization decides which actions are allowed. These distinctions apply to passwords, federated sign-in and DIDs. A DID does not require every service to establish a legal identity; the evidence should match the task.
Reusing an identifier can help maintain a relationship. Moving photos, recovering access and transferring permissions remain separate capabilities.
Book and sources
This lesson develops the questions in Chapter 4 of 《区块链实战》 with later standards. It is not an excerpt.
Check your understanding
Two sites accept the same DID. Does that merge their files and permissions?
No. Linking an identifier does not merge account data, qualifications or authorization rules.
Continue along a learning path
- Identity, permission and a way outStep 1 of 8