An Assessment of Blockchain Identity Solutions: Minimizing Risk and Liability of Authentication

Rima Rana, Razieh Nokhbeh Zaeem, K. S. Barber
{"title":"An Assessment of Blockchain Identity Solutions: Minimizing Risk and Liability of Authentication","authors":"Rima Rana, Razieh Nokhbeh Zaeem, K. S. Barber","doi":"10.1145/3350546.3352497","DOIUrl":null,"url":null,"abstract":"Personally Identifiable Information (PII) is often used to perform authentication and acts as a gateway to personal and organizational information. One weak link in the architecture of identity management services is sufficient to cause exposure and risk identity. Recently, we have witnessed a shift in identity management solutions with the growth of blockchain. Blockchain—the decentralized ledger system—provides a unique answer addressing security and privacy with its embedded immutability. In a blockchain-based identity solution, the user is given the control of his/her identity by storing personal information on his/her device and having the choice of identity verification document used later to create blockchain attestations. Yet, the blockchain technology alone is not enough to produce a better identity solution. The user cannot make informed decisions as to which identity verification document to choose if he/she is not presented with tangible guidelines. In the absence of scientifically created practical guidelines, these solutions and the choices they offer may become overwhelming and even defeat the purpose of providing a more secure identity solution.We analyze different PII options given to users for authentication on current blockchain-based solutions. Based on our Identity Ecosystem model, we evaluate these options and their risk and liability of exposure. Powered by real world data of about 6,000 identity theft and fraud stories, our model recommends some authentication choices and discourages others. Our work paves the way for a truly effective identity solution based on blockchain by helping users make informed decisions and motivating blockchain identity solution providers to introduce better options to their users.CCS CONCEPTS• Security and privacy → Privacy protections; • Social and professional topics → Privacy policies; • Applied computing → Digital cash.","PeriodicalId":171168,"journal":{"name":"2019 IEEE/WIC/ACM International Conference on Web Intelligence (WI)","volume":"77 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2019-10-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"25","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2019 IEEE/WIC/ACM International Conference on Web Intelligence (WI)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3350546.3352497","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 25

Abstract

Personally Identifiable Information (PII) is often used to perform authentication and acts as a gateway to personal and organizational information. One weak link in the architecture of identity management services is sufficient to cause exposure and risk identity. Recently, we have witnessed a shift in identity management solutions with the growth of blockchain. Blockchain—the decentralized ledger system—provides a unique answer addressing security and privacy with its embedded immutability. In a blockchain-based identity solution, the user is given the control of his/her identity by storing personal information on his/her device and having the choice of identity verification document used later to create blockchain attestations. Yet, the blockchain technology alone is not enough to produce a better identity solution. The user cannot make informed decisions as to which identity verification document to choose if he/she is not presented with tangible guidelines. In the absence of scientifically created practical guidelines, these solutions and the choices they offer may become overwhelming and even defeat the purpose of providing a more secure identity solution.We analyze different PII options given to users for authentication on current blockchain-based solutions. Based on our Identity Ecosystem model, we evaluate these options and their risk and liability of exposure. Powered by real world data of about 6,000 identity theft and fraud stories, our model recommends some authentication choices and discourages others. Our work paves the way for a truly effective identity solution based on blockchain by helping users make informed decisions and motivating blockchain identity solution providers to introduce better options to their users.CCS CONCEPTS• Security and privacy → Privacy protections; • Social and professional topics → Privacy policies; • Applied computing → Digital cash.
区块链身份解决方案评估:最小化认证风险和责任
个人可识别信息(PII)通常用于执行身份验证,并充当个人和组织信息的网关。身份管理服务体系结构中的一个薄弱环节就足以导致身份暴露和风险。最近,随着区块链的发展,我们见证了身份管理解决方案的转变。区块链——分散的分类账系统——以其嵌入的不变性提供了解决安全和隐私问题的独特答案。在基于区块链的身份解决方案中,用户可以通过将个人信息存储在他/她的设备上,并选择以后用于创建区块链认证的身份验证文档,来控制自己的身份。然而,仅凭区块链技术还不足以产生更好的身份解决方案。如果没有向用户提供具体的指导方针,他/她就无法就选择哪一种身份验证文件作出明智的决定。在缺乏科学创建的实用指南的情况下,这些解决方案和它们提供的选择可能会变得压倒性,甚至会破坏提供更安全的身份解决方案的目的。我们分析了用户在当前基于区块链的解决方案上进行身份验证的不同PII选项。基于我们的身份生态系统模型,我们评估了这些选项及其暴露的风险和责任。基于大约6000个身份盗窃和欺诈故事的真实世界数据,我们的模型推荐了一些身份验证选择,并劝阻了其他选择。我们的工作为基于区块链的真正有效的身份解决方案铺平了道路,帮助用户做出明智的决策,并激励区块链身份解决方案提供商向用户介绍更好的选择。•安全和隐私→隐私保护;•社交和专业话题→隐私政策;•应用计算→数字现金。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信