Towards Next-Generation Self-Sovereign Identity: Resilience, Privacy, and Trust in Decentralized Identity Systems

Loading...
Thumbnail Image

Authors

Soltani, Reza

Journal Title

Journal ISSN

Volume Title

Publisher

Abstract

Self-Sovereign Identity (SSI) has emerged as a promising paradigm for digital identity, shifting control of identity data from centralized intermediaries to individuals. However, its widespread adoption is impeded by open challenges in key management, fine-grained access control, regulatory alignment, and support for emerging Web 3.0 use cases. This dissertation investigates three overarching research questions: (1) How can users securely manage and recover their cryptographic keys in SSI applications in a way that is both privacy-preserving and usable? (2) How can users ensure that personal data is shared strictly according to their access preferences and consent? (3) Has SSI matured sufficiently to serve as a viable identity layer for contemporary digital ecosystems, including financial services and NFT-based platforms?

To answer these questions, the dissertation combines conceptual modeling, systems design, and prototype implementation. First, it proposes and implements a practical key backup and recovery model for SSI wallets based on threshold secret sharing and decentralized key custodians, with optional biometric-derived factors. A prototype demonstrates that the scheme can improve resilience against key loss while limiting custodial trust and preserving user privacy.

Second, the dissertation introduces a Data Capsule model that embeds user-defined access policies proposed by the users directly with encrypted data to control who and under what conditions the data can be access. The propose solution leverages decentralized identifiers, verifiable credentials, attribute-based encryption, and blockchain-based registries. This architecture enables selective disclosure, policy-based access, and auditable consent, and is evaluated in terms of performance and deployability on resource-constrained devices.

Third, the dissertation designs SSI-based architectures for Know Your Customer (KYC) procedures and NFT authenticity in Web 3.0 environments. The KYC framework supports reusable, privacy-preserving credentials and reputation-based trust, while the NFT framework binds tokenized assets to verifiable identities and credentials, mitigating fraud and enhancing provenance. Through these use case specific designs the dissertation validates the maturity of SSI and its applications.

Across these contributions, the dissertation offers a comprehensive survey of SSI foundations, platforms, privacy engineering techniques, and regulatory frameworks, and synthesizes their implications for real-world deployments. The results indicate that SSI can serve as a robust identity layer for diverse applications, provided that key recovery, access policies, governance, and user experience are carefully engineered.

Description

Keywords

Computer science

Citation