Publications

2024Theses and dissertationsEnglish

Pioneering the Future of Electronic Identity: From Post-Quantum Cryptography to Fiduciary Principles

Universidade Federal de Santa Catarina · Florianópolis, Brazil

Abstract

The security, privacy, and functionality of online interactions are integrally tied to Electronic IDentity (e-ID). As foundational components, Identity Provider (IdP) and Service Provider (SP) have traditionally been separated, an architecture further enhanced by standards such as Open Authorization 2.0 (OAuth 2.0) and OpenID Connect (OIDC). These protocols are critical in streamlining end-user authentication and authorization across digital platforms. Concurrently, the emergent Self-Sovereign Identity (SSI) paradigm redefines user privacy by empowering individuals with direct control over their e-IDs without intermediary oversight by IdPs, thereby preventing undue surveillance and data access by SPs. This thesis addresses pressing challenges in e-ID management, emphasizing the urgent need for Post-Quantum Cryptography (PQC) to safeguard authentication systems against the theoretical threat of quantum computing. Through advanced modifications to OAuth 2.0 and OIDC, particularly in their cryptographic foundations — JSON Web Key and Transport Layer Security (TLS) — this work pioneers the development of quantum-resistant methodologies. The proposed quantum-safe protocols are evaluated in a comprehensive real-world OIDC case study to validate their effectiveness and practicality. In addition to fortifying current standards, this research critically assesses the relatively nascent field of SSI. A thorough systematic literature review is conducted, culminating in a novel, meticulously crafted taxonomy of SSI. This taxonomy categorizes existing scholarly and practical efforts and identifies persistent gaps and future research directions. By rigorously analyzing emergent themes and findings from the literature, this thesis provides a roadmap for deepening the theoretical and practical understanding of SSI frameworks. Exploring practical implementations of SSI, the thesis also tackles the inherent challenges of utilizing distributed ledger technology for identity management. The focus is improving the efficiency and accuracy of searching metadata stored on blockchain systems commonly employed in SSI solutions. A novel search mechanism is proposed and empirically validated, demonstrating superior performance over existing methods for natural language processing tasks, thereby enhancing the operational feasibility of blockchain in supporting complex identity queries. The theoretical contributions of this thesis are further augmented by the introduction of the Role-Artifact-Function (RAF) framework. This dual-layer conceptual model, consisting of a meta-metamodel and a metamodel, provides a robust structure for examining and contrasting e-ID models. Through detailed application, the RAF framework aids in elucidating the ontological structures underlying various identity models, offering a comprehensive analytical tool that advances the discourse on e-ID. Lastly, the thesis confronts the user-centric challenges associated with SSI, particularly the complexities related to user interactions and management of cryptographic credentials. To address these issues, the innovative Fiduciary Identity model is introduced. Inspired by fiduciary legal principles, this model reduces user burden by automating consent processes and delegating decision-making to trusted entities, simplifying interactions and enhancing user experience in e-ID transactions.

Materials

Reference