A Verifiable Credentials System with Privacy-Preserving Based on Blockchain
- 1 College of Information Science and Technology, Jinan University, Guangzhou, China
Abstract
Decentralized identity authentication is generally based on blockchain, with the protection of user privacy as the core appeal. But traditional decentralized credential system requires users to show all the information of the entire credential to the verifier, resulting in unnecessary overexposure of personal information. From the perspective of user privacy, this paper proposed a verifiable credential scheme with selective disclosure based on BLS (Bohen- Lynn-Shacham) aggregate signature. Instead of signing the credentials, we sign the claims in the credentials. When the user needs to present the credential to verifier, the user can select a part of but not all claims to be presented. To reduce the number of signatures of claims after selective disclosure, BLS aggregate signature is achieved to aggregate signatures of claims into one signature. In addition, our scheme also supports the aggregation of credentials from different users. As a result, verifier only needs to verify one signature in the credential to achieve the purpose of batch verification of credentials. We analyze the security of our aggregate signature scheme, which can effectively resist aggregate signature forgery attack and credential theft attack. The simulation results show that our selective disclosure scheme based on BLS aggregate signature is acceptable in terms of verification efficiency, and can reduce the storage cost and communication overhead. As a result, our scheme is suitable for blockchain, which is strict on bandwidth and storage overhead.
- W3C-VC (2021) Verifiable Credentials Data Model 1.0. Technical Report. https://www.w3.org/TR/vc-data-model
- Takemiya, M. and Vanieiev, B. (2018) Sora Identity: Secure, Digital Identity on the Blockchain. 2018 IEEE 42nd Annual Computer Software and Applications Conference, Volume 2, 582-587. https://doi.org/10.1109/COMPSAC.2018.10299
- Brunner, C., Gallersdörfer, U., Knirsch, F., Engel, D. and Matthes, F. (2020) DID and VC: Untangling Decentralized Identifiers and Verifiable Credentials for the Web of Trust. 2020 the 3rd International Conference on Blockchain Technology and Applications, Xi’an, 14-16 December 2020, 61-66. https://doi.org/10.1145/3446983.3446992
- García-Rodríguez, J., Moreno, R.T., Bernabé, J.B. and Skarmeta, A. (2021) Towards a Standardized Model for Privacy-Preserving Verifiable Credentials. The 16th International Conference on Availability, Reliability and Security, Vienna, 17-20 August 2021, 1-6. https://doi.org/10.1145/3465481.3469204
- Chen, Y.-C., Tso, R., Mambo, M., Huang, K. and Horng, G. (2015) Certificateless Aggregate Signature with Efficient Verification. Security and Communication Networks, 8, 2232-2243. https://doi.org/10.1002/sec.1166
- Lux, Z.A., Thatmann, D., Zickau, S. and Beierle, F. (2020) Distributed Ledger-Based Authentication with Decentralized Identifiers and Verifiable Credentials. 2020 2nd Conference on Blockchain Research & Applications for Innovative Networks and Services (BRAINS), Paris, 28-30 September 2020, 71-78. https://doi.org/10.1109/BRAINS49436.2020.9223292
- Boneh, D., Gentry, C., Lynn, B. and Shacham, H. (2003) Aggregate and Verifiably Encrypted Signatures from Bilinear Maps. In: International Conference on the Theory and Applications of Cryptographic Techniques, Springer, Berlin, 416-432. https://doi.org/10.1007/3-540-39200-9_26
- David, C. (1985) Security without Identification: Transaction Systems to Make Big Brother Obsolete. Communications of the ACM, 28, 1030-1044. https://doi.org/10.1145/4372.4373
- Chaum, D. and Evertse, J.-H. (1987) A Secure and Privacy-Protecting Protocol for Transmitting Personal Information between Organizations. In: Conference on the Theory and Application of Cryptographic Techniques, Springer, Berlin, 118-167. https://doi.org/10.1007/3-540-47721-7_10
- WeBank (2021) Weidentity. https://weidentity.readthedocs.io/zh_CN/latest/docs/one-stop-experience.html
- Bauer, D., Blough, D.M. and Cash, D. (2008) Minimal Information Disclosure with Efficiently Verifiable Credentials. Proceedings of the 4th ACM Workshop on Digital Identity Management, New York, October 2008, 15-24. https://doi.org/10.1145/1456424.1456428