PUKYONG

안전한 비식별화 및 데이터 외부 공유를 제공하는 탈중앙형 자기 주권 신원 모델

Metadata Downloads
Alternative Title
Decentralized Self-Sovereign Identity Model Providing Secure De-identification and External Sharing of Data
Abstract
As digital services increased, a digital identity solution that can accurately identify an offline human or device on an online network has been required. The existing digital identity adopted a centralized form based on PKI (Public Key Infrastructure), so there were problems such as SPoF (Single Point of Failure), performance bottleneck, and dishonest TTP (Trusted Third Party). Decentralized identities, such as DID solve this problem by issuing digital identities over a decentralized network. However, there was a problem in that it has difficult to guarantee strong ownership of personal information. Decentralized identity works presented in this background is a SSI (Self-Sovereign Identity) solution, which can guarantee the strongest self-sovereignty according to the life cycle of identity data, including the right to consent, erasure, and rectification.
However, it only depended on ZKP (Zero Knowledge Proof)'s prior agreement for de-identification of identity data, and there is a problem that it is impossible to provide de-identification data without the consent of the data subject due to excessively strong self-sovereignty. These shortcomings are not suitable for the latest digital processing standards trends such as GDPR (General Data Protection Regulation) and the big data industry.
In this thesis, we propose a system model that generates restructured VC (Verifiable Crdential) to realize secure de-identification of credentials including identity attributes and external sharing of data in a decentralized SSI service. In the proposed model, the holder creates a hash digest that will act as proof of the transaction, and verifier whether a transaction is made by passing it to the entities that come into contact with the holder, such as the issuer and the verifier. Also, after verification of the normal credential is finished, the verifier can issue the restructured VC in which the holder's DID is replaced with the verifier's DID through ZKP verification result. The restructured VCs are information that replaces the holder's DID, and can be think of as non-identification data with the identifier removed, and can be provided to external entities for non-profit purposes (research, academic, statistics, etc.) without consent.
We provide a detailed process and use case for the proposed model. In addition, it is finally determined whether the proposed model is suitable for the actual SSI architecture through qualitative analysis based on GDPR and domestic personal information protection act and quantitative analysis of the increasing issuing time required.
Author(s)
조강우
Issued Date
2022
Awarded Date
2022. 2
Type
Dissertation
Publisher
부경대학교
URI
https://repository.pknu.ac.kr:8443/handle/2021.oak/24305
http://pknu.dcollection.net/common/orgView/200000600204
Alternative Author(s)
Kang Woo Cho
Affiliation
부경대학교 대학원
Department
대학원 정보보호학과
Advisor
신상욱
Table Of Contents
I. 서론 1
1. 연구배경 1
2. 연구 내용 및 구성 5
II. 관련 연구 8
1. Decentralized Identity 8
2. Self-Sovereign Identity(SSI) 9
3. SOVRIN 12
4. Zero Knowledge Proof(ZKP) 14
III. ZKP 기반 Restructured VC를 생성하는 SSI 기법 19
1. 가정 및 위협 모델 19
2. 제안 시스템 21
3. 제안 시스템의 유즈 케이스 34
IV. 안전한 SSI에서의 Restructured VC 구현 및 분석 40
1. 구현 내용 40
2. 분석 53
V. 결론 63
참고 문헌 65
Degree
Master
Appears in Collections:
대학원 > 정보보호학과
Authorize & License
  • Authorize공개
Files in This Item:

Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.