Digital identity ecosystems are rapidly transforming the landscape of identity management. Self-Sovereign Identity (SSI) promises to enhance the individual’s agency over their identity; and related concepts form core parts of the EU’s upcoming eIDAS 2.0 regulation. Yet, this privacy-preserving technology must become less privacy-preserving for one overlooked party – credential issuers. Issuers are trusted to validate users’ attributes and attest to them. Thus, a compromised or misbehaving issuer is an immense threat, being able to issue credentials that allow them to impersonate anyone. We address this concern by introducing Credential Issuance Transparency (CIT), a transparency framework for the issuance of identifying credentials. We take concepts from the Web PKI’s Certificate Transparency (CT), such as using public append-only logs, but adapt them to a privacy-preserving SSI world. In contrast to CT, the public logs of CIT disclose no information about a credential or its subject. Still, genuine subjects can monitor the log to discover mis-issued credentials that would allow an attacker to impersonate them; and empowered by non-interactive zero-knowledge proofs, verifiers can mandate correct logging. CIT is practical. It adds a neglectable overhead of less than 2 ms to credential showing. Daily monitoring for mis-issuance requires less than 1 GB of data to be downloaded, and less than 10 s of computation to be invested. This makes CIT an important step towards SSI’s organizational acceptance and real-world feasibility.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Credential Issuance Transparency: A Privacy-Preserving Audit Log of Credential Issuance

  • Edona Fasllija,
  • Jakob Heher,
  • Stefan More

摘要

Digital identity ecosystems are rapidly transforming the landscape of identity management. Self-Sovereign Identity (SSI) promises to enhance the individual’s agency over their identity; and related concepts form core parts of the EU’s upcoming eIDAS 2.0 regulation. Yet, this privacy-preserving technology must become less privacy-preserving for one overlooked party – credential issuers. Issuers are trusted to validate users’ attributes and attest to them. Thus, a compromised or misbehaving issuer is an immense threat, being able to issue credentials that allow them to impersonate anyone. We address this concern by introducing Credential Issuance Transparency (CIT), a transparency framework for the issuance of identifying credentials. We take concepts from the Web PKI’s Certificate Transparency (CT), such as using public append-only logs, but adapt them to a privacy-preserving SSI world. In contrast to CT, the public logs of CIT disclose no information about a credential or its subject. Still, genuine subjects can monitor the log to discover mis-issued credentials that would allow an attacker to impersonate them; and empowered by non-interactive zero-knowledge proofs, verifiers can mandate correct logging. CIT is practical. It adds a neglectable overhead of less than 2 ms to credential showing. Daily monitoring for mis-issuance requires less than 1 GB of data to be downloaded, and less than 10 s of computation to be invested. This makes CIT an important step towards SSI’s organizational acceptance and real-world feasibility.