Analyzing and comparing the security of self-sovereign identity management systems through threat modeling

被引:3
|
作者
Gruener, Andreas [1 ]
Muehle, Alexander [1 ]
Lockenvitz, Niko [1 ]
Meinel, Christoph [1 ]
机构
[1] Univ Potsdam, Hasso Plattner Inst HPI, D-14482 Potsdam, Germany
关键词
723 Computer Software; Data Handling and Applications;
D O I
10.1007/s10207-023-00688-w
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The concept of Self-Sovereign Identity (SSI) promises to strengthen the security and user-centricity of identity management. Since any secure online service relies on secure identity management, we comparatively analyze the intrinsic security of SSI. Thus, we adopt a hybrid threat modeling approach comprising STRIDE, attack trees, and ratings towards this unique context. Data flow diagrams of the isolated, centralized and the SSI model serve as the foundation for the assessment. The evolution of the paradigms shows an increasing complexity in security zones and communication paths between the components. We identified 35 threats to all SSI components and 15 protection measures that reduce the threats' criticality. As a result, our research shows that the SSI paradigm's threat surface is significantly higher compared to the traditional models. Besides the threat assessment on model level, the adapted methodology can evaluate a specific implementation. We analyzed uPort with a restricted scope to its user agent. Thus, 2 out of 10 threats were not properly addressed, leading to potential spoofing, denial, or repudiation of identity actions.
引用
收藏
页码:1231 / 1248
页数:18
相关论文
共 50 条
  • [41] Elesto Protocol: Self-Sovereign Identity System
    Giacobino, Andrea
    Grierson, David
    Sora, Gianguido
    Singh, Har Preet
    Schäffner, Martin
    McHale, Patrick
    Maggs, Simon
    [J]. 2022 IEEE 1ST GLOBAL EMERGING TECHNOLOGY BLOCKCHAIN FORUM: BLOCKCHAIN & BEYOND, IGETBLOCKCHAIN, 2022,
  • [42] Matching Metadata on Blockchain for Self-Sovereign Identity
    Schardong, Frederico
    Custodio, Ricardo
    Pioli, Laercio
    Meyer, Joao
    [J]. BUSINESS PROCESS MANAGEMENT WORKSHOPS, BPM 2021, 2022, 436 : 421 - 433
  • [43] Decentralized Self-sovereign Identity Management System: Empowering Datacenters Through Compact Cancelable Template Generation
    Yu, Junwei
    Li, Shaowen
    Ding, Yepeng
    Sato, Hiroyuki
    [J]. ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2023, PT VII, 2024, 14493 : 292 - 303
  • [44] Digital Identity Infrastructures: a Critical Approach of Self-Sovereign Identity
    Alexandra Giannopoulou
    [J]. Digital Society, 2023, 2 (2):
  • [45] A Blockchain and Self-Sovereign Identity Empowered Digital Identity Platform
    Bandara, Eranga
    Liang, Xueping
    Foytik, Peter
    Shetty, Sachin
    De Zoysa, Kasun
    [J]. 30TH INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS (ICCCN 2021), 2021,
  • [46] DT-SSIM: A Decentralized Trustworthy Self-Sovereign Identity Management Framework
    Samir, Efat
    Wu, Hongyi
    Azab, Mohamed
    Xin, Chunsheng
    Zhang, Qiao
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2022, 9 (11) : 7972 - 7988
  • [47] Service Applicable Blockchain-based Self-Sovereign Identity Management System
    Kim, Jeongheon
    Choi, Minji
    Lee, Chaehyeon
    Woo, Jongsoo
    Hong, James Won-Ki
    [J]. 2023 IEEE INTERNATIONAL CONFERENCE ON BLOCKCHAIN AND CRYPTOCURRENCY, ICBC, 2023,
  • [48] PT-SSIM: A Proactive, Trustworthy Self-Sovereign Identity Management System
    Fathalla, Efat Samir
    Azab, Mohamed
    Xin, Chunsheng
    Wu, Hongyi
    [J]. IEEE INTERNET OF THINGS JOURNAL, 2023, 10 (19) : 17155 - 17169
  • [49] An Automatized Identity and Access Management System for IoT Combining Self-Sovereign Identity and Smart Contracts
    Naghmouchi, Montassar
    Ben Ayed, Hella Kaffel
    Laurent, Maryline
    [J]. FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2021, 2022, 13291 : 208 - 217
  • [50] Blockchain-Based Identity Management System and Self-Sovereign Identity Ecosystem: A Comprehensive Survey
    Ahmed, Md Rayhan
    Islam, A. K. M. Muzahidul
    Shatabda, Swakkhar
    Islam, Salekul
    [J]. IEEE ACCESS, 2022, 10 : 113436 - 113481