SSI, from Specifications to Protocol? Formally Verify Security!
Christoph H.-J. Braun, Ross Horne, Tobias Käfer, Sjouke Mauw
Abstract
We evaluate a bundle of specifications from the Self-Sovereign Identity (SSI) paradigm to construct an authentication protocol for the Web. We demonstrate how relevant standards such as W3C Verifiable Credentials (VC), W3C Decentralised Identifiers (DIDs), and components of the Hyperledger Aries Framework are to be assembled methodologically into a protocol. We make those assumptions from standard trust models explicit that underlie the derived protocol, and verify security and privacy properties, notably secrecy, authentication, and unlinkability. This enables us to formally justify the additional precision that we urge these specifications to consider, to ensure that implementors of SSI-based systems do not neglect security-critical controls.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 47566348-2e90-4e13-b6f1-61af44365091Builds on4
- DEEPSEC: Deciding Equivalence Properties in Security Protocols Theory and PracticeVincent Cheval, Steve Kremer, Itsaka RakotonirinaS&P 2018 · 77 citations
- ProVerif with Lemmas, Induction, Fast Subsumption, and Much MoreBruno Blanchet, Vincent Cheval, Véronique CortierS&P 2022 · 61 citations
- SISSI: An Architecture for Semantic Interoperable Self-Sovereign Identity-based Access Control on the WebChristoph H.-J. Braun, Vasil Papanchev, Tobias KäferWWW 2023 · 16 citations
- Composition Kills: A Case Study of Email Sender AuthenticationJianjun Chen, Vern Paxson, Jian JiangUSENIX Security 2020
Related papers
- Fully Anonymous Decentralized Identity Supporting Threshold Traceability with Practical BlockchainYizhong Liu, Zedan Zhao, Boyu Zhao, Feiang Ran et al.WWW 2025 · 6 citations
- What Did Come Out of It? Analysis and Improvements of DIDComm MessagingChristian Badertscher, Fabio Banfi, Jesus DiazCCS 2024 · 8 citations
- Braid: Sybil-Resistant Decentralized Identity with Trustless Key Recovery and Non-Transferable Anonymous CredentialsRui Song, Tianyu Zheng, Shang Gao, Guyue Li et al.CCS 2026
- SyRA: Sybil-Resilient Anonymous Signatures with Applications to Decentralized IdentityElizabeth C. Crites, Aggelos Kiayias, Markulf Kohlweiss, Amirreza SarenchehCCS 2025
- AuthSaber: Automated Safety Verification of OpenID Connect ProgramsTamjid Al Rahat, Yu Feng, Yuan TianCCS 2024 · 1 citation
