Rethinking Self-Sovereign Identity Principles: An Actor-Oriented Categorization of Requirements
This paper addresses the lack of user perspective in existing Decentralized Identity research by decomposing SSI principles into 24 requirements mapped to key actors, introducing a dependency model to formalize their interactions, and providing the first structured model for DI/SSI system architectures that integrates user-centered needs with responsibility and ownership specifications.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you are trying to prove who you are. In the old days, you had to carry a physical wallet full of papers (birth certificates, driver's licenses, credit cards) issued by different governments and banks. If you lost your wallet, you were in big trouble. If a bank got hacked, your identity could be stolen.
Decentralized Identity (DI) and Self-Sovereign Identity (SSI) are like a magical, digital wallet that you control completely. No central bank or government holds your data; you do. You can show a "digital ID" to a store, a doctor, or a website without them needing to know your whole life story, just the specific fact they need (e.g., "I am over 21," without revealing your address).
However, building these digital wallets is tricky. The paper you shared is like a blueprint for architects and engineers. It asks: "Who is actually responsible for what in this new system?"
Here is the paper explained in simple terms, using a Digital Passport Party analogy.
The Cast of Characters (The Actors)
To understand the paper, imagine a party where people are exchanging digital ID cards. There are four main characters:
- The Data Owner (You): The person holding the wallet. You are the boss.
- The Issuer (The Stamp): The entity that gives you the ID (like a government issuing a passport or a university issuing a diploma).
- The Verifier (The Bouncer): The person checking your ID (like a bouncer at a club or a bank checking your credit).
- The System (The Venue): The invisible infrastructure (like the blockchain or the internet) that makes the party happen.
The Problem: Who Does What?
Before this paper, experts had a list of "Good Things" (Requirements) that a digital ID system should have, like "It must be secure," "It must be private," or "It must be easy to use."
But they didn't clearly say who is responsible for making those things happen.
- Analogy: Imagine a restaurant. Everyone agrees the food should be "hot." But who is responsible? The chef? The waiter? The oven manufacturer? If the food is cold, who do we blame?
- This paper fixes that confusion. It breaks down 24 "Good Things" (called NFRs) and assigns a specific job to each character.
The 24 Rules (Simplified)
The authors took complex technical rules and turned them into 24 simple duties. Here are a few examples of how they assigned the blame and glory:
- Accessibility (Can you find your ID?):
- Who is responsible? You (The Owner).
- Why? It's your wallet. If you can't find your digital ID, that's on you.
- Authenticity (Is the ID real?):
- Who is responsible? The Issuer (The Stamp).
- Why? They put the digital "stamp" on it. If the stamp is fake, the Issuer messed up.
- Privacy (Don't share too much info):
- Who is responsible? You AND The Bouncer.
- Why? You must choose what to share, but the Bouncer must agree not to ask for unnecessary info (like asking for your mother's maiden name just to buy a soda).
- Security (Keep the bad guys out):
- Who is responsible? The System (The Venue).
- Why? The venue provides the walls and locks. You can't build the walls yourself; you just walk through the door.
The "Dependency Map" (The Trust Chain)
The paper introduces a Dependency Model. This is a map showing who relies on whom.
- Analogy: Think of a relay race.
- You rely on the Issuer to give you a valid baton (ID).
- The Bouncer relies on You to hand over the baton.
- The Bouncer also relies on the Issuer to have made a good baton in the first place.
The paper draws lines between these people to show that even though you don't "trust" the Issuer in a personal way (like trusting a friend), you depend on them to do their job correctly for the system to work.
Why This Matters
The main takeaway of the paper is that You (The Data Owner) are the most important person in this system.
- You hold the keys.
- You decide who sees what.
- You are responsible for keeping your own data safe.
The paper proves that for Self-Sovereign Identity to work, the system must be built around your control, not the control of big companies. It gives engineers a clear checklist: "If you are building a digital ID system, make sure the 'Issuer' handles authenticity, the 'System' handles security, and 'You' handle control."
Summary in One Sentence
This paper is a rulebook for a digital identity revolution, clearly assigning the job of "keeping your data safe, private, and usable" to the right people, ensuring that you remain the boss of your own digital life.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.