Abstract
We evaluate a bundle of specifications from the Self-Sovereign Identity (SSI) paradigm to construct an authentication protocol for the Web. We demonstrate how relevant standards such as W3C Verifiable Credentials (VC), W3C Decentralised Identifiers (DIDs), and components of the Hyperledger Aries Framework are to be assembled methodologically into a protocol. We make those assumptions from standard trust models explicit that underlie the derived protocol, and verify security and privacy properties, notably secrecy, authentication, and unlinkability. This enables us to formally justify the additional precision that we urge these specifications to consider, to ensure that implementors of SSI-based systems do not neglect security-critical controls.
| Original language | English |
|---|---|
| Title of host publication | WWW '24: Proceedings of the ACM on Web Conference 2024 |
| Pages | 1620–1631 |
| Number of pages | 12 |
| ISBN (Electronic) | 9798400701719 |
| DOIs | |
| Publication status | Published - 13 May 2024 |
| Event | WWW '24: The ACM Web Conference 2024 - Singapore Duration: 13 May 2024 → 17 May 2024 |
Conference
| Conference | WWW '24: The ACM Web Conference 2024 |
|---|---|
| City | Singapore |
| Period | 13/05/24 → 17/05/24 |
Funding
This research was partially funded by the COST (European Cooperation in Science and Technology) Action on Distributed Knowledge Graphs (CA19134) and partially supported by the German federal ministry of education and research (BMBF) in MANDAT (FKZ 16DTM107B).
Keywords
- web standards
- self-sovereign identity
- formal verification
Fingerprint
Dive into the research topics of 'SSI, from specifications to protocol? Formally verify security!'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver