A Modular Three Layered Architecture for Blockchain-Enabled Self-Sovereign Identity in Health Information Exchange
摘要
User control, privacy, interoperability, and governance remain persistent challenges in Health Information Exchange (HIE), despite the growing demand for secure and patient-centric data sharing. Blockchain-enabled Self-Sovereign Identity (BC–SSI) has emerged as a promising paradigm; however, existing implementations remain heterogeneous, tightly coupled to specific infrastructures, and lack reusable healthcare-oriented architectural guidance.
This study derives a modular reference architecture for BC–SSI-enabled healthcare systems using a Design Science Research Methodology approach. First, healthcare-driven requirements (R1–R16) are identified through the synthesis of literature, regulatory frameworks, expert insights, and patient-oriented studies. Second, two representative BC–SSI frameworks (Walt.id and Hyperledger Indy/Aries) are comparatively examined through proof-of-concept (PoC) implementations based on a Norwegian electronic prescription workflow. The evaluation applies a 3+1 architectural view model adapted from the 4+1 approach to identify recurring runtime interaction patterns, structural dependencies, capability gaps, and healthcare-specific architectural limitations.
The findings indicate that while both frameworks support core SSI credential lifecycle capabilities, neither fully addresses healthcare-specific requirements such as policy-based consent enforcement, identity binding, interoperability orchestration, data minimization, runtime standards validation, and coordinated trust management. In response, this study proposes a framework-agnostic three-layer conceptual architecture comprising Access & Trust, Privacy & Policy, and Validation & Integration layers.
The proposed architecture is evaluated at the design level through structural traceability analysis, comparative feasibility assessment, runtime interaction modeling, and architectural threat analysis. While operational deployment and empirical performance validation remain future work, the study establishes a reusable architectural foundation for interoperable, policy-aware, and security-oriented BC–SSI-enabled HIE systems.