首页> 外文会议>IFIP WG 11.2 International conference on information security theory and practice >SSI-AWARE: Self-sovereign Identity Authenticated Backup with Auditing by Remote Entities
【24h】

SSI-AWARE: Self-sovereign Identity Authenticated Backup with Auditing by Remote Entities

机译:SSI-AWARE:具有远程实体审核功能的自我主权身份验证备份

获取原文

摘要

The self-sovereign identity (SSI) model entails the full responsibility and sovereignty of a user regarding his identity data. This identity data can contain private data which is solely known to the user. The user himself is therefore required to manage the whole lifecycle of his private data, including the backup and restore. We show that prior work on how to backup and restore the user's identity data does not meet the requirements of the SSI setting, and we present the first solution which does meet the requirements. Authenticated backup with auditing by remote entities (AWARE) combines SSI sustaining aspects and extends them to create a truly self-sovereign backup-and-restore protocol. In AWARE, trusted, physically met humans, called custodians, hold a secure device. Custodians with a secure device offer an offline backup possibility and a secure channel. The backup and restore are audited by commits on a publicly accessible distributed ledger. These commits are answered by auditing services which are required during restore. Only some auditing services hold relevant data for a restore. The self sovereignty of the user lies in the exclusive information which auditing services hold relevant data. AWARE is the first backup-and-restore mechanism that fully complies with the SSI model. We perform an in-depth security-risk analysis of AWARE, showing a risk rating which is comparable to the best risk rating o related non-SSI-compliant backup-and-restore mechanisms. We instantiate the AWARE protocol with cryptographic primitives providing a high security level of 256-bit. We show its implementation feasibility by providing a simulation of AWARE, and conclude with an estimated performance analysis on a microcontoller architecture based on our simulation and implementation results in the literature.
机译:自主权身份(SSI)模型要求用户承担有关其身份数据的全部责任和主权。该身份数据可以包含用户唯一知道的私有数据。因此,用户本人需要管理其私有数据的整个生命周期,包括备份和还原。我们显示,有关如何备份和还原用户身份数据的现有工作不符合SSI设置的要求,并且我们提出了第一个满足要求的解决方案。通过远程实体审核(AWARE)进行身份验证的备份结合了SSI的支持方面,并对其进行了扩展,以创建真正的自主权备份和还原协议。在AWARE中,可信任的,在物理上遇到的人(称为保管人)拥有安全的设备。具有安全设备的保管人提供了离线备份的可能性和安全通道。备份和还原由可公开访问的分布式分类帐上的提交审核。这些提交由还原期间所需的审核服务来回答。只有某些审核服务会保存相关数据以进行还原。用户的自我主权在于审计服务保存相关数据的专有信息。 AWARE是第一个完全符合SSI模型的备份和还原机制。我们对AWARE进行了深入的安全风险分析,显示的风险等级可与相关的不符合SSI的备份和还原机制的最佳风险等级相媲美。我们使用加密原语实例化AWARE协议,以提供256位的高安全级别。我们通过提供AWARE的仿真来展示其实现的可行性,并基于我们在仿真中的仿真和实现结果对微控制器架构进行估算的性能分析,以得出结论。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号