A Blockchain-Based Digital Identity System with Privacy, Controllability, and Auditability

被引:0
作者
Song, Zhiming [1 ,2 ,3 ]
Yan, Enhua [1 ]
Song, Junrong [1 ]
Jiang, Rong [1 ,2 ]
Yu, Yimin [1 ]
Chen, Taowei [1 ]
机构
[1] Yunnan Univ Finance & Econ, Intelligent Applicat Res Inst, Kunming, Yunnan, Peoples R China
[2] Yunnan Key Lab Serv Comp, Kunming, Peoples R China
[3] Yuxi Normal Univ, Yunnan Key Lab Smart City Cyberspace Secur, Yuxi, Peoples R China
关键词
Blockchain; Digital identity; Privacy protection; Controllability; Auditability; LINKABLE RING SIGNATURES; ACCUMULATORS; FRAMEWORK; SCHEME;
D O I
10.1007/s13369-024-09178-0
中图分类号
O [数理科学和化学]; P [天文学、地球科学]; Q [生物科学]; N [自然科学总论];
学科分类号
07 ; 0710 ; 09 ;
摘要
The blockchain-based digital identity system (BDIS) has emerged as a promising alternative to centralized digital identity systems. While BDISs offer numerous advantages such as decentralization and enhanced security, traditional implementations still exhibit weaknesses in ensuring identity authenticity, controllability, and auditability while maintaining privacy. This paper aims to address these challenges by proposing novel approaches. It separates the functions of verifying physical identity and issuing digital credentials into two distinct roles: the identity verifier and the credential provider, employing linkable ring signatures to obscure the verifier's identity and significantly mitigate the risk of identity information leakage-a common issue in traditional schemes where a single entity performs both tasks. Additionally, this paper addresses the overlooked aspect of identity controllability in traditional schemes, especially proactive and passive revocation with privacy in mind, by integrating cryptographic commitments, zero-knowledge proofs, PS randomized signatures, cryptographic accumulators, and AES encryption. This approach ensures privacy while enabling both types of revocation. Furthermore, it tackles the neglected auditability of identity privacy in traditional schemes by combining linkable ring signatures with smart contract events and other technologies, ensuring auditable privacy protection. Fourth, a blockchain smart contract is utilized to manage system parameters and implement on-chain verification of privacy-protected identities, ensuring cross-platform capability, transparent verification, and resilience against single-point failures. A use case is provided, evaluating the system's performance. Comparative analysis and security discussions suggest that the proposed system rectifies deficiencies in current BDISs and offers improved applicability, execution performance, and security.
引用
收藏
页码:7027 / 7051
页数:25
相关论文
共 62 条
  • [1] SCPKI: A Smart Contract-based PKI and Identity System
    Al-Bassam, Mustafa
    [J]. BCC '17: PROCEEDINGS OF THE ACM WORKSHOP ON BLOCKCHAIN, CRYPTOCURRENCIES AND CONTRACTS, 2017, : 35 - 40
  • [2] Hyperledger Fabric: A Distributed Operating System for Permissioned Blockchains
    Androulaki, Elli
    Barger, Artem
    Bortnikov, Vita
    Cachin, Christian
    Christidis, Konstantinos
    De Caro, Angelo
    Enyeart, David
    Ferris, Christopher
    Laventman, Gennady
    Manevich, Yacov
    Muralidharan, Srinivasan
    Murthy, Chet
    Binh Nguyen
    Sethi, Manish
    Singh, Gari
    Smith, Keith
    Sorniotti, Alessandro
    Stathakopoulou, Chrysoula
    Vukolic, Marko
    Cocco, Sharon Weed
    Yellick, Jason
    [J]. EUROSYS '18: PROCEEDINGS OF THE THIRTEENTH EUROSYS CONFERENCE, 2018,
  • [3] Au MH, 2006, LECT NOTES COMPUT SC, V4043, P101
  • [4] Towards blockchain-IoT based shared mobility: Car-sharing and leasing as a case study
    Auer, Sophia
    Nagler, Sophia
    Mazumdar, Somnath
    Mukkamala, Raghava Rao
    [J]. JOURNAL OF NETWORK AND COMPUTER APPLICATIONS, 2022, 200
  • [5] Aydar M, 2020, Arxiv, DOI arXiv:1906.09791
  • [6] Baidu, 2020, Baidu Cloud DID Method
  • [7] PriFoB: A Privacy-aware Fog-enhanced Blockchain-based system for Global Accreditation and Credential Verification
    Baniata H.
    Kertesz A.
    [J]. Journal of Network and Computer Applications, 2022, 205
  • [8] SSIBAC: Self-Sovereign Identity Based Access Control
    Belchior, Rafael
    Putz, Benedikt
    Pernul, Guenther
    Correia, Miguel
    Vasconcelos, Andre
    Guerreiro, Sergio
    [J]. 2020 IEEE 19TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2020), 2020, : 1935 - 1943
  • [9] Buterin Vitalik, 2017, Ethereum Improvement Proposal: Gas cost changes for IO-heavy operations
  • [10] Camenisch J, 2002, LECT NOTES COMPUT SC, V2442, P61