Analyzing and comparing the security of self-sovereign identity management systems through threat modeling

被引:3
|
作者
Gruener, Andreas [1 ]
Muehle, Alexander [1 ]
Lockenvitz, Niko [1 ]
Meinel, Christoph [1 ]
机构
[1] Univ Potsdam, Hasso Plattner Inst HPI, D-14482 Potsdam, Germany
关键词
723 Computer Software; Data Handling and Applications;
D O I
10.1007/s10207-023-00688-w
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The concept of Self-Sovereign Identity (SSI) promises to strengthen the security and user-centricity of identity management. Since any secure online service relies on secure identity management, we comparatively analyze the intrinsic security of SSI. Thus, we adopt a hybrid threat modeling approach comprising STRIDE, attack trees, and ratings towards this unique context. Data flow diagrams of the isolated, centralized and the SSI model serve as the foundation for the assessment. The evolution of the paradigms shows an increasing complexity in security zones and communication paths between the components. We identified 35 threats to all SSI components and 15 protection measures that reduce the threats' criticality. As a result, our research shows that the SSI paradigm's threat surface is significantly higher compared to the traditional models. Besides the threat assessment on model level, the adapted methodology can evaluate a specific implementation. We analyzed uPort with a restricted scope to its user agent. Thus, 2 out of 10 threats were not properly addressed, leading to potential spoofing, denial, or repudiation of identity actions.
引用
收藏
页码:1231 / 1248
页数:18
相关论文
共 50 条
  • [1] Analyzing and comparing the security of self-sovereign identity management systems through threat modeling
    Andreas Grüner
    Alexander Mühle
    Niko Lockenvitz
    Christoph Meinel
    [J]. International Journal of Information Security, 2023, 22 : 1231 - 1248
  • [2] Model-Driven Security Analysis of Self-Sovereign Identity Systems
    Ding, Yepeng
    Sato, Hiroyuki
    [J]. 2023 IEEE 22ND INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS, TRUSTCOM, BIGDATASE, CSE, EUC, ISCI 2023, 2024, : 1687 - 1694
  • [3] Analyzing Interoperability and Portability Concepts for Self-Sovereign Identity
    Gruner, Andreas
    Muhle, Alexander
    Meinel, Christoph
    [J]. 2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 587 - 597
  • [4] Self-sovereign identity
    Giannopoulou, Alexandra
    Wang, Fennie
    [J]. INTERNET POLICY REVIEW, 2021, 10 (02): : 1 - 10
  • [5] Is Self-Sovereign Identity Really Sovereign?
    Naik, Nitin
    Jenkins, Paul
    [J]. 2022 IEEE INTERNATIONAL SYMPOSIUM ON SYSTEMS ENGINEERING (ISSE), 2022,
  • [6] A Taxonomy of Challenges for Self-Sovereign Identity Systems
    Satybaldy, Abylay
    Ferdous, Md. Sadek
    Nowostawski, Mariusz
    [J]. IEEE ACCESS, 2024, 12 : 16151 - 16177
  • [7] Rezension „Self-Sovereign Identity“
    Jürgen Anke
    [J]. HMD Praxis der Wirtschaftsinformatik, 2023, 60 (2) : 514 - 516
  • [8] Sovrin: An Identity Metasystem for Self-Sovereign Identity
    Windley, Phillip J.
    [J]. FRONTIERS IN BLOCKCHAIN, 2021, 4
  • [9] Decentralizing Identity Management and Vehicle Rights Delegation through Self-Sovereign Identities and Blockchain
    Terzi, Sofia
    Savvaidis, Charalampos
    Sersemis, Athanasios
    Votis, Konstantinos
    Tzovaras, Dimitrios
    [J]. 2021 IEEE 45TH ANNUAL COMPUTERS, SOFTWARE, AND APPLICATIONS CONFERENCE (COMPSAC 2021), 2021, : 1217 - 1223
  • [10] A self-sovereign identity management scheme using smart contracts
    Niu, Jianlin
    Ren, Zhiyu
    [J]. 2020 2ND INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE COMMUNICATION AND NETWORK SECURITY (CSCNS2020), 2021, 336