안전한 비식별화 및 데이터 외부 공유를 제공하는 탈중앙형 자기 주권 신원 모델
- Alternative Title
- Decentralized Self-Sovereign Identity Model Providing Secure De-identification and External Sharing of Data
- Abstract
- As digital services increased, a digital identity solution that can accurately identify an offline human or device on an online network has been required. The existing digital identity adopted a centralized form based on PKI (Public Key Infrastructure), so there were problems such as SPoF (Single Point of Failure), performance bottleneck, and dishonest TTP (Trusted Third Party). Decentralized identities, such as DID solve this problem by issuing digital identities over a decentralized network. However, there was a problem in that it has difficult to guarantee strong ownership of personal information. Decentralized identity works presented in this background is a SSI (Self-Sovereign Identity) solution, which can guarantee the strongest self-sovereignty according to the life cycle of identity data, including the right to consent, erasure, and rectification.
However, it only depended on ZKP (Zero Knowledge Proof)'s prior agreement for de-identification of identity data, and there is a problem that it is impossible to provide de-identification data without the consent of the data subject due to excessively strong self-sovereignty. These shortcomings are not suitable for the latest digital processing standards trends such as GDPR (General Data Protection Regulation) and the big data industry.
In this thesis, we propose a system model that generates restructured VC (Verifiable Crdential) to realize secure de-identification of credentials including identity attributes and external sharing of data in a decentralized SSI service. In the proposed model, the holder creates a hash digest that will act as proof of the transaction, and verifier whether a transaction is made by passing it to the entities that come into contact with the holder, such as the issuer and the verifier. Also, after verification of the normal credential is finished, the verifier can issue the restructured VC in which the holder's DID is replaced with the verifier's DID through ZKP verification result. The restructured VCs are information that replaces the holder's DID, and can be think of as non-identification data with the identifier removed, and can be provided to external entities for non-profit purposes (research, academic, statistics, etc.) without consent.
We provide a detailed process and use case for the proposed model. In addition, it is finally determined whether the proposed model is suitable for the actual SSI architecture through qualitative analysis based on GDPR and domestic personal information protection act and quantitative analysis of the increasing issuing time required.
- Author(s)
- 조강우
- Issued Date
- 2022
- Awarded Date
- 2022. 2
- Type
- Dissertation
- Publisher
- 부경대학교
- URI
- https://repository.pknu.ac.kr:8443/handle/2021.oak/24305
http://pknu.dcollection.net/common/orgView/200000600204
- Alternative Author(s)
- Kang Woo Cho
- Affiliation
- 부경대학교 대학원
- Department
- 대학원 정보보호학과
- Advisor
- 신상욱
- Table Of Contents
- I. 서론 1
1. 연구배경 1
2. 연구 내용 및 구성 5
II. 관련 연구 8
1. Decentralized Identity 8
2. Self-Sovereign Identity(SSI) 9
3. SOVRIN 12
4. Zero Knowledge Proof(ZKP) 14
III. ZKP 기반 Restructured VC를 생성하는 SSI 기법 19
1. 가정 및 위협 모델 19
2. 제안 시스템 21
3. 제안 시스템의 유즈 케이스 34
IV. 안전한 SSI에서의 Restructured VC 구현 및 분석 40
1. 구현 내용 40
2. 분석 53
V. 결론 63
참고 문헌 65
- Degree
- Master
-
Appears in Collections:
- 대학원 > 정보보호학과
- Authorize & License
-
- Files in This Item:
-
Items in Repository are protected by copyright, with all rights reserved, unless otherwise indicated.