论文标题
一个新的隐私保护和可扩展的撤销方法,用于自我主权身份 - 尚不存在完美的撤销方法
A new Privacy Preserving and Scalable Revocation Method for Self Sovereign Identity -- The Perfect Revocation Method does not exist yet
论文作者
论文摘要
数字身份在我们的数字生活中起着至关重要的作用。如今,使用的数字身份是基于中央架构的。中央数字身份提供商控制并了解我们的数据,从而控制我们的身份。自我主权身份(SSI)基于分散的数据存储和数据交换体系结构,该架构唯一控制其数据和身份。大多数已发行的证书都需要撤销的可能性。对于中央数字身份,撤销很容易。在分散体系结构中,撤销更具挑战性。可以使用不同的方法来完成撤销列表,压缩列表和加密蓄能器。撤销方法必须保留隐私,并且必须扩展。本文概述了有关可用撤销方法的概述,包括一个调查来定义要求,根据要求评估不同的撤销组,突出显示方法的缺点,并引入了一种称为链接有效性验证凭证的新撤销方法。
Digital Identities are playing an essential role in our digital lives. Today, used Digital Identities are based on central architectures. Central Digital Identity providers control and know our data and, thereby, our Identity. Self Sovereign Identities (SSI) are based on a decentralized data storage and data exchange architecture, where the user is in sole control of his data and identity. Most of the issued credentials need the possibility of revocation. For a Central Digital Identity, revocation is easy. In decentral architectures, revocation is more challenging. Revocation can be done with different methods e.g. lists, compressed lists and cryptographic accumulators. A revocation method must be privacy preserving and must scale. This paper gives an overview about the available revocation methods, include a survey to define requirements, assess different revocation groups against the requirements, highlights shortcomings of the methods and introduce a new revocation method called Linked Validity Verifiable Credentials.