Your Identity is Yours: Take Back Control of Your Identity Using GDPR Compatible Self-Sovereign Identity

N. Naik, Paul Jenkins
{"title":"Your Identity is Yours: Take Back Control of Your Identity Using GDPR Compatible Self-Sovereign Identity","authors":"N. Naik, Paul Jenkins","doi":"10.1109/BESC51023.2020.9348298","DOIUrl":null,"url":null,"abstract":"Digital identity has importance in the digital world representing users in a comparable manner to that of the physical identity in the real world. Digital identity comprises certain personal and confidential attributes related to identity owners, managed through an Identity Management (IDM) system. In most IDM systems, identity owners do not control their own identity and its related personal data. However, Self-Sovereign Identity (SSI) is an emerging IDM system which offers users the ownership and full control over their personal data. In the European Union, General Data Protection Regulation (GDPR) is the basic regulatory environment for anyone involved in processing personal data, whilst SSI is concerned with the requirement of managing identity and its associated personal data. If an SSI system could comply with the key GDPR principles then it could become both a desirable and appropriate IDM solution legally and universally. This paper evaluates this aspect of SSI and analyses SSI compliance and alignment with the key principles of GDPR. Furthermore, it investigates two different types of SSI ecosystems public permissionless blockchain based SSI ecosystem uPort and public permissioned blockchain based SSI ecosystem Sovrin, according to the various defined roles and their compatibility with GDPR roles. Finally, this paper performs the comparative analysis of uPort and Sovrin to assess their compliance with the key principles of GDPR.","PeriodicalId":224502,"journal":{"name":"2020 7th International Conference on Behavioural and Social Computing (BESC)","volume":"7 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2020-11-05","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"14","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2020 7th International Conference on Behavioural and Social Computing (BESC)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/BESC51023.2020.9348298","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 14

Abstract

Digital identity has importance in the digital world representing users in a comparable manner to that of the physical identity in the real world. Digital identity comprises certain personal and confidential attributes related to identity owners, managed through an Identity Management (IDM) system. In most IDM systems, identity owners do not control their own identity and its related personal data. However, Self-Sovereign Identity (SSI) is an emerging IDM system which offers users the ownership and full control over their personal data. In the European Union, General Data Protection Regulation (GDPR) is the basic regulatory environment for anyone involved in processing personal data, whilst SSI is concerned with the requirement of managing identity and its associated personal data. If an SSI system could comply with the key GDPR principles then it could become both a desirable and appropriate IDM solution legally and universally. This paper evaluates this aspect of SSI and analyses SSI compliance and alignment with the key principles of GDPR. Furthermore, it investigates two different types of SSI ecosystems public permissionless blockchain based SSI ecosystem uPort and public permissioned blockchain based SSI ecosystem Sovrin, according to the various defined roles and their compatibility with GDPR roles. Finally, this paper performs the comparative analysis of uPort and Sovrin to assess their compliance with the key principles of GDPR.
你的身份是你的:使用GDPR兼容的自我主权身份夺回你的身份控制权
数字身份在数字世界中以与现实世界中的物理身份相当的方式表示用户具有重要意义。数字身份包括与身份所有者有关的某些个人和机密属性,并通过身份管理系统进行管理。在大多数IDM系统中,身份所有者无法控制自己的身份及其相关的个人数据。然而,自我主权身份(SSI)是一种新兴的IDM系统,它为用户提供了对其个人数据的所有权和完全控制权。在欧盟,通用数据保护条例(GDPR)是涉及处理个人数据的任何人的基本监管环境,而SSI则关注管理身份及其相关个人数据的要求。如果SSI系统能够遵守关键的GDPR原则,那么它就可以成为合法和普遍的理想和适当的IDM解决方案。本文评估了SSI的这一方面,并分析了SSI的合规性以及与GDPR关键原则的一致性。此外,根据不同定义的角色及其与GDPR角色的兼容性,研究了两种不同类型的SSI生态系统,即基于公共无许可区块链的SSI生态系统uPort和基于公共许可区块链的SSI生态系统Sovrin。最后,本文对uPort和Sovrin进行了比较分析,以评估它们对GDPR关键原则的遵从性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信