Back to Search Start Over

DID We Miss Anything?: Towards Privacy-Preserving Decentralized ID Architecture

Authors :
Huh, Siwon
Shim, Myungkyu
Lee, Jihwan
Woo, Simon S.
Kim, Hyoungshick
Lee, Hojoon
Source :
IEEE Transactions on Dependable and Secure Computing; November 2023, Vol. 20 Issue: 6 p4881-4898, 18p
Publication Year :
2023

Abstract

Decentralized Identity (DID) is emerging as a new digital identity management scheme that promises users complete control of their personal data and identification without central authority involvement. The World Wide Web Consortium (W3C) has drafted the DID standard and provided reference implementations. We conduct a security analysis of the W3C DID standard and the reference universal resolver implementation, focusing on user privacy in the DID resolving process. The universal resolver is the key component in the architecture that processes DID requests and DID document retrievals. Our analysis demonstrates that privacy issues can arise due to the imprudent design of the universal resolver. Furthermore, we found that side-channels in the DID document caching schemes of real-world DID services can entail privacy concerns. Motivated by our security analysis, we present a novel DID resolving design, called Oblivira, to enable obliviously DID resolving. Oblivira is a secure resolving agent with a small footprint that enforces the universal resolver to resolve requests without knowing their content. We also propose a privacy-preserving DID document caching scheme that eliminates side-channels. Our evaluation results show that Oblivira only incurs approximately 2.6% of overhead on average with different resolver settings (3, 6, and 12 threads).

Details

Language :
English
ISSN :
15455971
Volume :
20
Issue :
6
Database :
Supplemental Index
Journal :
IEEE Transactions on Dependable and Secure Computing
Publication Type :
Periodical
Accession number :
ejs64507756
Full Text :
https://doi.org/10.1109/TDSC.2023.3235951