Back to Search
Start Over
DID We Miss Anything?: Towards Privacy-Preserving Decentralized ID Architecture
- Source :
- IEEE Transactions on Dependable and Secure Computing; November 2023, Vol. 20 Issue: 6 p4881-4898, 18p
- Publication Year :
- 2023
-
Abstract
- Decentralized Identity (DID) is emerging as a new digital identity management scheme that promises users complete control of their personal data and identification without central authority involvement. The World Wide Web Consortium (W3C) has drafted the DID standard and provided reference implementations. We conduct a security analysis of the W3C DID standard and the reference universal resolver implementation, focusing on user privacy in the DID resolving process. The universal resolver is the key component in the architecture that processes DID requests and DID document retrievals. Our analysis demonstrates that privacy issues can arise due to the imprudent design of the universal resolver. Furthermore, we found that side-channels in the DID document caching schemes of real-world DID services can entail privacy concerns. Motivated by our security analysis, we present a novel DID resolving design, called Oblivira, to enable obliviously DID resolving. Oblivira is a secure resolving agent with a small footprint that enforces the universal resolver to resolve requests without knowing their content. We also propose a privacy-preserving DID document caching scheme that eliminates side-channels. Our evaluation results show that Oblivira only incurs approximately 2.6% of overhead on average with different resolver settings (3, 6, and 12 threads).
Details
- Language :
- English
- ISSN :
- 15455971
- Volume :
- 20
- Issue :
- 6
- Database :
- Supplemental Index
- Journal :
- IEEE Transactions on Dependable and Secure Computing
- Publication Type :
- Periodical
- Accession number :
- ejs64507756
- Full Text :
- https://doi.org/10.1109/TDSC.2023.3235951