My Journey Through the World of Self-Sovereign Identity: A Bachelor Thesis Breakdown


Journey to SSI: An Introduction

Since 2017, my fascination with Blockchain Technology and Distributed Ledgers has grown, leading me to delve into the DeFi Talents program at the Financial Business School in Frankfurt. This journey took a significant turn when I decided to focus my thesis on these interests during a practical semester abroad at the University of Algarve, Portugal. However, the path was not without its hurdles. Challenges arose, notably with a supervisor who diverted my focus more towards frontend development than my thesis research. Coupled with a full-time job and additional coursework, these obstacles necessitated a plea for an extension upon return from my internship abroad. Unfortunately, it was denied, leaving me to complete my thesis in a mere six weeks. Despite these trials, I managed to achieve a commendable grade of 2.0 under the German grading system.

Day of Submission of my Thesis
Day of Submission of my Thesis

Research Questions

My thesis explored the user friendliness coupled with the technical of decentralization and its effects on folks like you and me actually wanting to use it. The big questions on my mind were:

  1. How can we make SSI more user-friendly and get more people on board?
  2. In the world of SSI, how do we keep our private data safe, sound, and recoverable?
  3. What are the real perks and pitfalls of decentralization when it comes to managing and securing our digital selves?

Before we jump into the nitty-gritty of my findings, let’s get everyone up to speed on what SSI is all about. Then, I’ll lay out the answers I uncovered to these burning questions.

Background on SSI

At its core, SSI is about empowering users with the ultimate authority over their identity and data, transitioning from traditional, centralized identity providers to a decentralized model. This shift promises a more secure, interoperable, and user-controlled digital existence, where each individual can manage their digital footprint with transparency and without intermediaries.

My thesis scrutinized the current literature of SSI to enhance user-friendliness, safeguard private data, and navigate the intricacies of decentralization. These focal points shed light on the pressing need for a more inclusive, secure, and user-centric approach to digital identity management, setting the stage for a future where digital autonomy is not just a concept but a lived reality.

What is Self-Sovereign Identity?

As of today (February 28, 2024), we’re in a bit of a Wild West scenario when it comes to pinning down exactly what SSI means—no official playbook, so to speak. However, the compass most of us are navigating by points to Christopher Allen’s insightful piece online, which has become something of a north star in the SSI conversation. Diving into his thoughts, along with digesting the insights from 22 research papers, has helped me craft my own take on what SSI is all about, filtered through my lens and presented in my own words.

  1. Existence - “Users must have an independent existence.” A fundamental requirement is that individuals must have an independent physical existence that is separate from their digital representation. It is impossible for a person to exist solely in the virtual world, and thus, any digital identity must be grounded in the physical reality of the individual.
  2. Control - “Users must control their identities.” Individuals should have the freedom to manage their identity attributes in any way they choose, as they hold complete authority over their identity data. It is important to note that this does not prevent entities from making claims about other entities and that a distinction should be made between identifiers and identities. The management of identifiers should be the responsibility of the user themselves. Furthermore, a distinction must also be made between control and ownership of the data. While a user may exercise control over an identity claim issued to them, they may not necessarily be the owner of that claim. For example, a student identification number is issued by the university and may be revoked by the university. However, the user should have the ability to control and share their identification number under their own conditions.
  3. Access - “Users must have access to their own data.” This principle of gatekeeper-free identity management posits that no third-party entity should control or restrict access to an individual’s identity data without their knowledge and consent. It is important to note that this principle does not imply that the individual has the ability to modify all of the claims associated with their identity, but rather that they should be informed of any changes or modifications made to their identity data. Furthermore, this principle applies to each individual entity with respect to their own identity, rather than imposing it on others.
  4. Transparency - “Systems and algorithms must be transparent.” In order to meet the criteria for transparency in identity management, the algorithms, procedures, and processes used in the model should be made visible to identity holders. The use of free, open-source, and well-known frameworks can be a logical approach to satisfy this requirement. By making the algorithms available for public examination, evaluation, and avoiding vendor lock-ins, transparency can be enhanced.
  5. Persistence - “Identities must be long-lived.” In accordance with the principles of identity management, it is imperative that the identity data persists over a prolonged duration unless the identity holder explicitly decommissions it. It should be acknowledged that the process of identity formation is a continuous one and hence the identity management model must be flexible enough to facilitate the identity holders to obtain, modify, or remove their identity data as and when needed. For instance, an individual’s name and address can change over the course of their lifetime. It should be noted that the identity holder may not necessarily control all of the claims associated with their identity; other entities may make claims about the identity holder, but such claims should not be central to the identity itself.
  6. Portability - “Information and services about identity must be transportable.” The capability to transport identity data from one location to another is a crucial aspect for the longevity of identity data. This portability ensures that identity data is not locked into a single third-party entity, even if the third-party service provider intends to act in the best interest of the identity holder. The identity holder should have the seamless ability to move their identity data to another location.
  7. Interoperability - “Identities should be as widely usable as possible.” In the context of identity management, it is essential for identity data to be accessible and usable by a wide range of entities across various boundaries, jurisdictions, and architectures. This criterion supports the accessibility and persistence of identity attributes, which can be leveraged by multiple parties to enable interoperability and data exchange. The usability of identity data is particularly important in complex systems where multiple parties need to access and use the same data in a seamless and secure manner. By making identity data widely consumable, it is possible to foster innovation, facilitate cross-border transactions, and create a more efficient and effective identity management ecosystem.
  8. Consent - “Users must agree to the use of their identity.” It is imperative that the identity holder has a clear understanding and provides explicit consent regarding the usage of their identity data. This principle emphasizes the importance of informed consent, empowering users to have control over the release of their personal information and ensuring transparency.
  9. Minimalization - “Disclosure of claims must be minimized.” To ensure privacy, it is imperative to disclose only the minimum amount of identity data required for a specific task. To achieve this goal, a range of privacy-preserving techniques such as selective disclosure, specialized signature schemes, and range proofs are used to ensure that only the essential data is revealed. These techniques help to maintain confidentiality and integrity by reducing the risk of exposure of sensitive personal data.
  10. Protection - “The rights of users must be protected.” In the SSI model, the identity holders are the focal point of the architecture. It is crucial to uphold the rights of identity holders at all times. In cases where there is a dispute between the identity holder and the network, the network should prioritize preserving the identity holder’s rights. Furthermore, the SSI architecture should be arranged in a decentralized manner to prevent potential censorship and monopolies.

Components & Stakeholder

Components of a Blockchain-Based SSI System
Components of a Blockchain-Based SSI System

Investigated SSI-Lifecycle

SLR Main Body View
SLR Main Body View

Dezentralization and Usability

Identity Owner

Exploring the avenues for enhancing usability and user experience for Identity Owners reveals innovative strategies, for instance through the advancement of agents and automation policies. Agents, divided into device and cloud categories, offer varied operational and storage capabilities. Device agents provide local storage of keys and credentials, ensuring immediate data control for users. Conversely, cloud agents, which can be either a third-party service or self-hosted, introduce flexibility in data management, but as well a potential point of centralization and security concerns. The advent of “smart agents,” equipped with AI for minimal-input credential management, underscores a interesting evolution. These agents promise to simplify the SSI navigation, merging decision support with security and convenience. The deployment environment of these agents—locally or cloud-based—impacts the centralization dynamic. Even locally operated AI agents, if opaque in their coding, could pose sovereignty risks to the identity owner. Transitioning AI agents to open-source models could mitigate such risks by promoting transparency and community involvement, thus adhering to SSI’s principles of decentralization and user empowerment.

Another way to increase the usability is the use of biometric traits. A face recognition or fingerprint can be used to access our sovereign digital identity and perform operations. Despite some folks worrying about privacy, the convenience of using biometrics as a authentication method are winning many over and do not introduce a note worthy point of centralization.

One scientific paper proposed an interesting idea, a system where shopping not only saves you money but also puts you in control of your data while doing so. Here, you earn points like you would with a loyalty card, but there’s a twist. You get to choose exactly what info you share. Want to keep your hygiene purchases private? No problem. This system keeps you in the loop about how your data’s used, offering discounts and it could offer further incentives like lottery access as a thank you.

Integrating familiar Authentication & Authorization protocols with SSI systems offers a promising avenue to enhance usability and foster wider adoption. By weaving together the security and control afforded by SSI with the widespread familiarity of protocols like OAuth 2.0, users can enjoy a seamless and intuitive experience managing their digital identities. This integration allows users to leverage their existing knowledge and comfort with traditional authentication mechanisms, reducing the learning curve associated with adopting new technologies. For example, by utilizing OAuth 2.0 within SSI systems, users can authenticate and grant permissions in a manner they’re already accustomed to, such as logging in with their email or social media accounts. This familiarity significantly boosts the user-friendliness of SSI systems, making digital identity management more accessible to a broader audience. From a service provider’s perspective, incorporating established protocols into SSI systems simplifies the development process. It enables the creation of secure, interoperable services that can communicate efficiently with a user’s digital identity. However, the integration of these familiar protocols with SSI systems introduces considerations regarding decentralization. Traditional authentication protocols often rely on centralized servers and databases, which can conflict with the decentralized ethos of SSI. This integration, while enhancing usability, necessitates a careful examination of how it impacts the decentralization principle central to SSI. In my opinion it does significantly infringe upon the ten core principles that define SSI.

For widespread adoption of SSI, it’s likely that major tech corporations such as Microsoft, Google, and Facebook will emerge as trusted third parties (TTPs), offering support and services tailored to identity owners needs. Opting for TTPs presents a strategic choice for identity owners to delegate specific controls, trading a measure of decentralization and autonomy for enhanced usability. These TTPs, envisioned as digital stewards, would play a role in managing, securing, and recovering digital identities. However, maintaining user sovereignty over personal data, including the ability to revoke access or delegation at will, remains paramount.

Speaking of backup and recovery, let’s find out which options there are to securely backup and recover data in an SSI ecosystem.

Backup & Recovery 🗝️

In the digital age, keeping track of our digital keys and identities can feel like a juggling act. That’s where the Reminisce Technique swings in, bringing a blend of personal touch and technological savvy to the table. Picture this: your most treasured moments, those breathtaking sunsets, joyous birthday gatherings, or thrilling escapades, doubling as the guardians of your digital realm. Beyond mere nostalgia, this technique capitalizes on our innate knack for visual memory, using the geographical essence of personal snapshots to fortify digital security. It effectively morphs your cherished photo collection into a digital stronghold, ensuring your private keys are both secure and retrievable. And if privacy concerns flash across your mind, fret not. You’re in the driver’s seat, with full discretion over your photo data’s storage, ensuring only you can access the metadata for wallet backup.

The delegate list or quorum-based key recovery method introduces a communal approach to securing and retrieving digital identities. It involves creating a network of trusted individuals—be it friends, family, or organizations—who can assist in recovering access to your digital keys should they be lost. This method enhances security through decentralization, requiring consensus among selected delegates to initiate recovery, thereby reducing dependency on a single recovery point. Applying safeguards like timelocks ensures that recovery actions are deliberate, safeguarding against both internal and external threats. This strategy not only strengthens security but also distributes trust, increasing decentralization proportionally to the number of delegates required for recovery.

Lastly, in an era where digital sophistication defines our online interactions, the pen and paper method stands out as a beautifully simple, yet profoundly secure way to backup and recover our most critical digital assets, like private keys or mnemonic phrases. This method harks back to the basics, inviting us to jot down our digital secrets in a physical notebook, safeguarding them from the vulnerabilities inherent in digital storage. This timeless approach offers a unique blend of security and simplicity. By transcribing our digital keys onto paper, we create a physical backup immune to hacking, digital corruption, or the whims of technology. It’s a personal vault that requires no electricity, no internet, and is accessible only by those who can physically reach it. Yet, its strength is also its vulnerability. The physical nature of this method demands meticulous care in storage and secrecy. It’s crucial to keep this notebook in a safe, perhaps even a locked drawer or a safe deposit box, to prevent it from falling into the wrong hands or being destroyed by accidents like fire or water damage.

Issuer

Credentials as a Service (CaaS) simplifies the credential issuance process for issuers by offloading the complexities of managing a private infrastructure. This approach enhances usability and security, leveraging cloud services and Trusted Execution Environments (TEEs) to handle the issuer’s private keys securely. However, the adoption of CaaS introduces considerations around decentralization. CaaS represents a shift towards a more centralized model for credential management. While it streamlines the issuance process and potentially increases the system’s scalability and flexibility, reliance on cloud services and control over the issuer’s private keys by a third party could concentrate power and control, moving away from the decentralized ethos of SSI. This centralization may raise concerns about single points of failure, the potential for misuse of power, and the risk of creating new gatekeepers in the digital identity ecosystem.

However, this centralization can be mitigated by employing distributed cloud services and ensuring that the CaaS providers adhere to strict security and privacy standards, including the use of TEEs. Additionally, transparency in the operations of CaaS providers and the option for issuers to choose between different CaaS offerings could help maintain a level of decentralization within the SSI framework.

Summary & Conclusion ⚖️

The endeavor to promote SSI is reminiscent of the challenges encountered in introducing new digital solutions, such as money transfer applications, during the digitalization wave. To truly realize the vision of SSI, it is imperative to balance the drive for technological innovation with a commitment to user-centric design. This approach will not only facilitate wider adoption but also ensure that the shift to SSI is marked by a seamless integration into the fabric of everyday life, promoting a digital society that values privacy, security, and user agency. From my point of view to ease the transition for users, the journey towards broad acceptance of SSI may involve the strategic incorporation of centralized elements. These intermediary steps are envisioned not as end goals but as bridges towards a more decentralized identity management paradigm. The ultimate aim is to cultivate an ecosystem where technology serves to empower users, ensuring their control over personal data while fostering an inclusive environment that supports all stakeholders, including verifiers and issuers.


My original thesis with all references can be found :prose-a[here]{href=“/pdf/self_sovereign_identity_thesis” target=“_blank”}.