Design Considerations for Protection of Blockchain based Digital Identity Ecosystem

被引:0
|
作者
Pillai, Akshay [1 ]
Wat, Vishal Saras [1 ]
Ramachandran, Arunkumar Vasanthakumary [1 ]
机构
[1] Bosch Global Software Technol Pvt Ltd, Bangalore, Karnataka, India
来源
关键词
Digital Identity; Blockchain; Security; Attacks; Costs;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Digital identity provides mechanisms for personally identifying information (PII) to be asserted and verified in digital services and transactions. Self-sovereign identities (SSI) are digital identities that allow users to self-manage their digital identities and have full control over it without depending on third-party providers to store and centrally manage the data. To utilize the full potential of digital identity to enable personalized services and efficient transactions, blockchain technology is being proposed to manage digital identity in a decentralized manner as the means to achieve the holy grail. While it certainly has promise, the growing number of threats on the blockchain ecosystem and traditional identity management system call for a systematic approach towards securing the identity management on based on blockchain. In this work, we study the existing attacks and vulnerabilities and present possible hypothetical attack scenarios which may get executed in future by these vulnerabilities. We have analyzed the attacks scenarios with comparison of attack cost and benefits of the attacker and comparison of mitigation cost and damage cost of each attack. We focus on the different attacks and usecases on the blockchain based digital identity systems which would help developers to secure their designs. We describe each attack with its mechanism, usecase(s), benefits and requirements of the attacker for successful attack with the possible damage scenarios and consequences, comparison of attack cost and benefits, comparison of mitigation cost and damage cost, possible mitigation and some security measures for each attack.
引用
收藏
页码:100 / 112
页数:13
相关论文
共 50 条
  • [1] Protection Guidelines for Blockchain Based Digital Identity
    Pillai, Akshay
    Saraswat, Vishal
    Ramachandran, Arunkumar Vasanthakumary
    [J]. HYBRID INTELLIGENT SYSTEMS, HIS 2021, 2022, 420 : 636 - 646
  • [2] Attacks on Blockchain Based Digital Identity
    Pillai, Akshay
    Saraswat, Vishal
    Ramachandran, Arunkumar Vasanthakumary
    [J]. BLOCKCHAIN AND APPLICATIONS, 2022, 320 : 329 - 338
  • [3] Blockchain user digital identity big data and information security process protection based on network trust
    Wang, Feng
    Gai, Yongjie
    Zhang, Haitao
    [J]. JOURNAL OF KING SAUD UNIVERSITY-COMPUTER AND INFORMATION SCIENCES, 2024, 36 (04)
  • [4] Blockchain-id: the construction of a digital identity based on blockchain technology to ensure the universalization of the right to identity
    Beck, Cesar
    Boff, Murilo Manzoni
    Piaia, Thami Covatti
    [J]. REVISTA BRASILEIRA DE DIREITO, 2022, 18 (03):
  • [5] Integrating Digital Identity and Blockchain
    Buccafurri, Francesco
    Lax, Gianluca
    Russo, Antonia
    Zunino, Guillaume
    [J]. ON THE MOVE TO MEANINGFUL INTERNET SYSTEMS, OTM 2018, PT I, 2018, 11229 : 568 - 585
  • [6] A Blockchain-based Trustworthy Cloud Services Digital Ecosystem
    Bellini, Emanuele
    Aversa, Iolanda
    Cimato, Stelvio
    Esposito, Antonio
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON CYBER SECURITY AND RESILIENCE (IEEE CSR), 2022, : 118 - 124
  • [7] Sora Identity: Secure, Digital Identity on the Blockchain
    Takemiya, Makoto
    Vanieiev, Bohdan
    [J]. 2018 IEEE 42ND ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC 2018), VOL 2, 2018, : 582 - 585
  • [8] Blockchain-based Privacy Protection Unified Identity Authentication
    Zheng, Yue
    Li, Yarong
    Wang, Zhen
    Deng, Chunhua
    Luo, Yili
    Li, Yixin
    Ding, Jianwei
    [J]. 2019 INTERNATIONAL CONFERENCE ON CYBER-ENABLED DISTRIBUTED COMPUTING AND KNOWLEDGE DISCOVERY (CYBERC), 2019, : 42 - 49
  • [9] RETRACTED: Digital Identity Verification and Management System of Blockchain-Based Verifiable Certificate with the Privacy Protection of Identity and Behavior (Retracted Article)
    Song, Zhiming
    Wang, Guiwen
    Yu, Yimin
    Chen, Taowei
    [J]. SECURITY AND COMMUNICATION NETWORKS, 2022, 2022
  • [10] An Infrastructure for Service Accountability based on Digital Identity and Blockchain 3.0
    Furfaro, Angelo
    Argento, Luciano
    Sacca, Domenico
    Angiulli, Fabrizio
    Fassetti, Fabio
    [J]. IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (IEEE INFOCOM 2019 WKSHPS), 2019, : 632 - 637