{"title":"Decentralized Identifier and Access Control Based Architecture for Privacy-Sensitive Data Distribution Service","authors":"Reiya Oku, K. Shiomoto, Y. Ohba","doi":"10.1109/WF-IoT54382.2022.10152128","DOIUrl":null,"url":null,"abstract":"In today's world, users' privacy-sensitive information is collected and managed by organizations and businesses. However, users do not have the option to choose the information that can be shared, nor can they track the sharing process. To address this limitation, we propose a privacy-sensitive information protection and management architecture that incorporates two emerging technologies: (1) Self-Sovereign Decentralized Identifier (DID), and (2) a policy description language to implement an automated access policy control. The proposed architecture defines a schema for privacy-sensitive information and leverages a policy description language to describe policies for handling the privacy-sensitive information to implement automated distribution of information. Users can prove the authenticity of their personal information without the need for centralized control, such as a public key infrastructure. The transaction records of accessing privacy-sensitive information can be tracked while keeping anonymization; no one can identify the real entity of the transacting party. We implemented a prototype system using Hyperledger Aries, Indy, and Sawtooth Projects for the DID management mechanisms, and Open Policy Agent for an automated access policy control.","PeriodicalId":176605,"journal":{"name":"2022 IEEE 8th World Forum on Internet of Things (WF-IoT)","volume":"31 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-10-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 IEEE 8th World Forum on Internet of Things (WF-IoT)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/WF-IoT54382.2022.10152128","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0
Abstract
In today's world, users' privacy-sensitive information is collected and managed by organizations and businesses. However, users do not have the option to choose the information that can be shared, nor can they track the sharing process. To address this limitation, we propose a privacy-sensitive information protection and management architecture that incorporates two emerging technologies: (1) Self-Sovereign Decentralized Identifier (DID), and (2) a policy description language to implement an automated access policy control. The proposed architecture defines a schema for privacy-sensitive information and leverages a policy description language to describe policies for handling the privacy-sensitive information to implement automated distribution of information. Users can prove the authenticity of their personal information without the need for centralized control, such as a public key infrastructure. The transaction records of accessing privacy-sensitive information can be tracked while keeping anonymization; no one can identify the real entity of the transacting party. We implemented a prototype system using Hyperledger Aries, Indy, and Sawtooth Projects for the DID management mechanisms, and Open Policy Agent for an automated access policy control.