Existing digital identity management systems fail to deliver the desirable properties of control by the users of their own identity data, credibility of disclosed identity data, and network-level anonymity. The recently proposed Self-Sovereign Identity (SSI) approach promises to give users these properties. However, we argue that without addressing privacy at the network level, SSI systems cannot deliver on this promise. In this paper we present the design and analysis of our solution TCID, created in collaboration with the Dutch government. TCID is a system consisting of a set of components that together satisfy seven functional requirements to guarantee the desirable system properties. We show that the latency incurred by network-level anonymization in TCID is significantly larger than that of identity data disclosure protocols but is still low enough for practical situations. We conclude that current research on SSI is too narrowly focused on these data disclosure protocols.
翻译:现有的数字身份管理系统未能提供用户自己身份数据的适当控制特性、被披露的身份数据的可信度和网络匿名性。最近提出的自我主权身份(SSI)方法有望使用户获得这些特性。然而,我们认为,如果不在网络一级处理隐私问题,SSI系统就无法实现这一承诺。在本文件中,我们介绍了与荷兰政府合作建立的TCID解决方案的设计和分析。TCID是一个由一组组成部分组成的系统,它共同满足了7项功能要求,以保障理想系统特性。我们表明,在TCID的网络一级匿名化所产生的时间长度大大大于身份数据披露协议,但对于实际情况来说仍然不够。我们的结论是,目前对SSI的研究过于狭隘地侧重于这些数据披露协议。