Abstract
We evaluate a bundle of specifications from the Self-Sovereign Identity (SSI) paradigm to construct an authentication protocol for the Web. We demonstrate how relevant standards such as W3C Verifiable Credentials (VC), W3C Decentralised Identifiers (DIDs), and components of the Hyperledger Aries Framework are to be assembled methodologically into a protocol. We make those assumptions from standard trust models explicit that underlie the derived protocol, and verify security and privacy properties, notably secrecy, authentication, and unlinkability. This enables us to formally justify the additional precision that we urge these specifications to consider, to ensure that implementors of SSI-based systems do not neglect security-critical controls.
Original language | English |
---|---|
Title of host publication | WWW '24: Proceedings of the ACM on Web Conference 2024 |
Pages | 1620–1631 |
Number of pages | 12 |
ISBN (Electronic) | 9798400701719 |
DOIs | |
Publication status | Published - 13 May 2024 |
Event | WWW '24: The ACM Web Conference 2024 - Singapore Duration: 13 May 2024 → 17 May 2024 |
Conference
Conference | WWW '24: The ACM Web Conference 2024 |
---|---|
City | Singapore |
Period | 13/05/24 → 17/05/24 |
Keywords
- web standards
- self-sovereign identity
- formal verification