Self-Sovereign Identity (SSI) aspires to create a standardised identity layer for the Internet by placing citizens at the centre of their data, thereby weakening the grip of big tech on current digital identities. However, as millions of both physical and digital identities are lost annually, it is also necessary for SSIs to possibly be revoked to prevent misuse. Previous attempts at designing a revocation mechanism typically violate the principles of SSI by relying on central trusted components. This lack of a distributed revocation mechanism hampers the development of SSI. In this paper, we address this limitation and present the first fully distributed SSI revocation mechanism that does not rely on specialised trusted nodes. Our novel gossip-based propagation algorithm disseminates revocations throughout the network and provides nodes with a proof of revocation that enables offline verification of revocations. We demonstrate through simulations that our protocol adequately scales to national levels.
翻译:自我主权身份(SSI)希望通过将公民置于数据中心,为互联网建立一个标准化的身份层,将公民置于其数据中心,从而削弱对当前数字身份的掌握,从而削弱大科技对当前数字身份的控制。然而,由于每年损失数百万个物理和数字身份,SSI也有必要撤销这些身份,以防止滥用。以前设计撤销机制的尝试通常违反SSI原则,依靠中央信任的组成部分。这种缺乏分布式撤销机制阻碍了SSI的发展。在本文中,我们处理了这一限制,并提出了第一个完全分布式SSI撤销机制,不依赖专门信任的节点。我们新的八卦传播算法在整个网络中传播撤销行为,并提供撤销证据,以便从网上核查撤销行为。我们通过模拟来证明我们的协议在国家一级有适当的尺度。