论文标题
自我主张身份作为一项服务:实践中的体系结构
Self-Sovereign Identity as a Service: Architecture in Practice
论文作者
论文摘要
自我主持身份(SSI)已获得了很大的兴趣。它使物理实体能够保留所有权和控制其数字身份,这自然形成了概念分散的体系结构。在分布式分类帐技术(DLT)的支持下,可以在实践中实施这种概念下放的体系结构,并进一步带来技术优势,例如隐私保护,安全增强,高可用性。但是,开发这种相对较新的身份模型具有高成本和风险,并具有不确定性。为了促进基于DLT的SSI在实践中的使用,我们将自我主持的身份作为服务(SSIAAS),这一概念使系统,尤其是系统群集,可以轻松地采用SSI作为其标识,身份验证和授权的身份模型。我们通过详细阐述服务概念,SSI和DLT来实施SSIAAS平台和SSI服务来提出实用的体系结构。此外,我们提供了一种用于构建和定制SSI服务的体系结构,并提供一组架构模式,并提供相应的评估。此外,我们以SELFID为基于我们提议的体系结构的SSIAAS平台SelfID证明了我们提出的架构的可行性。
Self-sovereign identity (SSI) has gained a large amount of interest. It enables physical entities to retain ownership and control of their digital identities, which naturally forms a conceptual decentralized architecture. With the support of the distributed ledger technology (DLT), it is possible to implement this conceptual decentralized architecture in practice and further bring technical advantages such as privacy protection, security enhancement, high availability. However, developing such a relatively new identity model has high costs and risks with uncertainty. To facilitate the use of the DLT-based SSI in practice, we formulate Self-Sovereign Identity as a Service (SSIaaS), a concept that enables a system, especially a system cluster, to readily adopt SSI as its identity model for identification, authentication, and authorization. We propose a practical architecture by elaborating the service concept, SSI, and DLT to implement SSIaaS platforms and SSI services. Besides, we present an architecture for constructing and customizing SSI services with a set of architectural patterns and provide corresponding evaluations. Furthermore, we demonstrate the feasibility of our proposed architecture in practice with Selfid, an SSIaaS platform based on our proposed architecture.