论文标题

NSSIA:一种新的自我主持身份方案

NSSIA: A New Self-Sovereign Identity Scheme with Accountability

论文作者

Lyu, Qiuyun, Cheng, Shaopeng, Li, Hao, Liu, Junliang, Shen, Yanzhao, Wang, Zhen

论文摘要

自我主持身份(SSI)是一种用于身份管理的新分布方法,通常用于解决用户缺乏对其身份的控制的问题。但是,在最现有的SSI计划中,过度追求自我主权阻碍了对攻击者的制裁。为了处理恶意行为,一些SSI计划引入了问责机制,但他们牺牲了用户的隐私。此外,现有SSI方案中的数字身份(静态字符串或可更新链)是第三方可执行程序(移动应用程序,智能合约等)的输入,以实现身份读取,存储和证明,用户的自我主张被削弱了。为了解决上述问题,我们提出了一种新的自我主权身份方案,以在隐私和问责制之间取得平衡,并摆脱对第三方计划的依赖。在我们的计划中,生成一个和唯一的特定于个人的可执行代码作为数字化身,供每个人在没有第三方计划的情况下与网络空间中的其他人互动,其中生物识别技术的嵌入可以增强其身份的唯一性和用户控制。此外,基于Shamir(T,N)阈值算法和财团区块链的联合责任机制旨在限制每个监管机构的权力并保护用户的隐私。最后,我们根据计算,存储和区块链气体的成本分析了安全性,SSI属性并进行详细的实验。分析结果表明,我们的方案抵抗已知的攻击并实现所有六个SSI属性。与最先进的方案相比,广泛的实验结果表明,服务器存储,区块链存储和区块链气体的成本更大,但对于实际情况仍然足够低。

Self-Sovereign Identity (SSI) is a new distributed method for identity management, commonly used to address the problem that users are lack of control over their identities. However, the excessive pursuit of self-sovereignty in the most existing SSI schemes hinders sanctions against attackers. To deal with the malicious behavior, a few SSI schemes introduce accountability mechanisms, but they sacrifice users' privacy. What's more, the digital identities (static strings or updatable chains) in the existing SSI schemes are as inputs to a third-party executable program (mobile app, smart contract, etc.) to achieve identity reading, storing and proving, users' self-sovereignty are weakened. To solve the above problems, we present a new self-sovereign identity scheme to strike a balance between privacy and accountability and get rid of the dependence on the third-party program. In our scheme, one and only individual-specific executable code is generated as a digital avatar-i for each human to interact with others in cyberspace without a third-party program, in which the embedding of biometrics enhances uniqueness and user control over their identity. In addition, a joint accountability mechanism, which is based on the shamir (t, n) threshold algorithm and a consortium blockchain, is designed to restrict the power of each regulatory authority and protect users' privacy. Finally, we analyze the security, SSI properties and conduct detailed experiments in term of the cost of computation, storage and blockchain gas. The analysis results indicate that our scheme resists the known attacks and fulfills all the six SSI properties. Compared with the state-of-the-art schemes, the extensive experiment results show that the cost is larger in server storage, blockchain storage and blockchain gas, but is still low enough for practical situations.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源