SSIBAC: Self-Sovereign Identity Based Access Control

被引:37
|
作者
Belchior, Rafael [1 ]
Putz, Benedikt [2 ]
Pernul, Guenther [2 ]
Correia, Miguel [1 ]
Vasconcelos, Andre [1 ]
Guerreiro, Sergio [1 ]
机构
[1] Univ Lisbon, Inst Super Tecn, INESC ID, Lisbon, Portugal
[2] Univ Regensburg, Chair Informat Syst, Regensburg, Germany
基金
欧盟地平线“2020”;
关键词
self sovereign identity; decentralized identity; authorization; attribute-based authorization; access control;
D O I
10.1109/TrustCom50675.2020.00264
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Ineffective data management practices pose serious issues to individuals and companies, e.g., risk of identity theft and online exposure. Self-sovereign identity (SSI) is a new identity management approach that ensures users have full control of their personal data. In this work, we alleviate data breach and user privacy problems by showing how SSI can fit within the context of established enterprise identity and access management technologies. In light of recent endeavors, we explore the use of decentralized identifiers, verifiable credentials, and blockchains that support SSI. We propose Self-Sovereign Identity Based Access Control (SSIBAC), an access control model for cross-organization identity management. SSIBAC leverages conventional access control models and blockchain technology to provide decentralized authentication, followed by centralized authorization. The access control process does not require storing user sensitive data. A prototype was implemented and evaluated, processing 55,000 access control requests per second with a latency of 3 seconds.
引用
收藏
页码:1935 / 1943
页数:9
相关论文
共 50 条
  • [1] Secure Access Control Realization Based on Self-Sovereign Identity for Cloud CDM
    Kang, Yunhee
    Park, Young B.
    [J]. APPLIED SCIENCES-BASEL, 2022, 12 (19):
  • [2] An offline mobile access control system based on self-sovereign identity standards
    Enge, Alexander
    Satybaldy, Abylay
    Nowostawski, Mariusz
    [J]. COMPUTER NETWORKS, 2022, 219
  • [3] A Self-Sovereign Identity Approach to Decentralized Access Control with Transitive Delegations
    Vrielynck, Pieter-Jan
    Van hamme, Tim
    Ghostin, Rawad
    Lagaisse, Bert
    Preuveneers, Davy
    Joosen, Wouter
    [J]. PROCEEDINGS OF THE 29TH ACM SYMPOSIUM ON ACCESS CONTROL MODELS AND TECHNOLOGIES, SACMAT 2024, 2024, : 139 - 147
  • [4] Self-sovereign identity
    Giannopoulou, Alexandra
    Wang, Fennie
    [J]. INTERNET POLICY REVIEW, 2021, 10 (02): : 1 - 10
  • [5] Is Self-Sovereign Identity Really Sovereign?
    Naik, Nitin
    Jenkins, Paul
    [J]. 2022 IEEE INTERNATIONAL SYMPOSIUM ON SYSTEMS ENGINEERING (ISSE), 2022,
  • [6] Rezension „Self-Sovereign Identity“
    Jürgen Anke
    [J]. HMD Praxis der Wirtschaftsinformatik, 2023, 60 (2) : 514 - 516
  • [7] Blockchain Empowered and Self-sovereign Access Control System
    Tadjik, Hanif
    Geng, Jiahui
    Jaatun, Martin Gilje
    Rong, Chunming
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON CLOUD COMPUTING TECHNOLOGY AND SCIENCE (CLOUDCOM 2022), 2022, : 74 - 82
  • [8] Blockchain-Based Self-Sovereign Identity: Taking Control of Identity in Federated Learning
    Zeydan, Engin
    Blanco, Luis
    Mangues-Bafalluy, Josep
    Arslan, Suayb S.
    Turk, Yekta
    Yadav, Awaneesh Kumar
    Liyanage, Madhusanka
    [J]. IEEE OPEN JOURNAL OF THE COMMUNICATIONS SOCIETY, 2024, 5 : 5764 - 5781
  • [9] Sovrin: An Identity Metasystem for Self-Sovereign Identity
    Windley, Phillip J.
    [J]. FRONTIERS IN BLOCKCHAIN, 2021, 4
  • [10] A Self-Sovereign Decentralized Identity Platform Based on Blockchain
    Chen, Ya
    Liu, Chao
    Wang, Yu
    Wang, Yazhe
    [J]. 26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,