CanDID: Can-Do Decentralized Identity with Legacy Compatibility, Sybil-Resistance, and Accountability
Deepak Maram, Harjasleen Malvai, Fan Zhang, Nerla Jean-Louis, Alexander Frolov, Tyler Kell, Tyrone Lobban, Christine Moy, Ari Juels, Andrew Miller
Abstract
We present CanDID, a platform for practical, userfriendly realization of decentralized identity, the idea of empowering end users with management of their own credentials. While decentralized identity promises to give users greater control over their private data, it burdens users with management of private keys, creating a significant risk of key loss. Existing and proposed approaches also presume the spontaneous availability of a credential-issuance ecosystem, creating a bootstrapping problem. They also omit essential functionality, like resistance to Sybil attacks and the ability to detect misbehaving or sanctioned users while preserving user privacy. CanDID addresses these challenges by issuing credentials in a user-friendly way that draws securely and privately on data from existing, unmodified web service providers. Such legacy compatibility similarly enables CanDID users to leverage their existing online accounts for recovery of lost keys. Using a decentralized committee of nodes, CanDID provides strong confidentiality for user's keys, real-world identities, and data, yet prevents users from spawning multiple identities and allows identification (and blacklisting) of sanctioned users. We present the CanDID architecture and report on experiments demonstrating its practical performance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4d5011f2-8b2d-4796-9885-e2c1cfba6ee0Cited by top-tier papers12
- DECO: Liberating Web Data Using Decentralized Oracles for TLSFan Zhang, Deepak Maram, Harjasleen Malvai, Steven Goldfeder et al.CCS 2020 · 110 citations
- An empirical study of blockchain system vulnerabilities: modules, types, and patternsXiao Yi, Daoyuan Wu, Lingxiao Jiang, Yuzhou Fang et al.FSE 2022 · 22 citations
- EVOKE: Efficient Revocation of Verifiable Credentials in IoT NetworksCarlo Mazzocca, Abbas Acar, A. Selcuk Uluagac, Rebecca MontanariUSENIX Security 2024 · 22 citations
- zkLogin: Privacy-Preserving Blockchain Authentication with Existing CredentialsFoteini Baldimtsi, Konstantinos Kryptos Chalkias, Yan Ji, Jonas Lindstrøm et al.CCS 2024 · 21 citations
- Secret Key Recovery in a Global-Scale End-to-End Encryption SystemGraeme Connell, Vivian Fang, Rolfe Schmidt, Emma Dauterman et al.OSDI 2024 · 19 citations
Builds on6
- Town Crier: An Authenticated Data Feed for Smart ContractsFan Zhang, Ethan Cecchetti, Kyle Croman, Ari Juels et al.CCS 2016 · 668 citations
- Coconut: Threshold Issuance Selective Disclosure Credentials with Applications to Distributed LedgersAlberto Sonnino, Mustafa Al-Bassam, Shehar Bano, Sarah Meiklejohn et al.NDSS 2019 · 218 citations
- HoneyBadgerMPC and AsynchroMix: Practical Asynchronous MPC and its Application to Anonymous CommunicationDonghang Lu, Thomas Yurek, Samarth Kulshreshtha, Rahul Govind et al.CCS 2019 · 120 citations
- DECO: Liberating Web Data Using Decentralized Oracles for TLSFan Zhang, Deepak Maram, Harjasleen Malvai, Steven Goldfeder et al.CCS 2020 · 110 citations
- CHURP: Dynamic-Committee Proactive Secret SharingSai Krishna Deepak Maram, Fan Zhang, Lun Wang, Andrew Low et al.CCS 2019 · 106 citations
Related papers
- Braid: Sybil-Resistant Decentralized Identity with Trustless Key Recovery and Non-Transferable Anonymous CredentialsRui Song, Tianyu Zheng, Shang Gao, Guyue Li et al.CCS 2026
- Fully Anonymous Decentralized Identity Supporting Threshold Traceability with Practical BlockchainYizhong Liu, Zedan Zhao, Boyu Zhao, Feiang Ran et al.WWW 2025 · 6 citations
- SyRA: Sybil-Resilient Anonymous Signatures with Applications to Decentralized IdentityElizabeth C. Crites, Aggelos Kiayias, Markulf Kohlweiss, Amirreza SarenchehCCS 2025
- SSI, from Specifications to Protocol? Formally Verify Security!Christoph H.-J. Braun, Ross Horne, Tobias Käfer, Sjouke MauwWWW 2024 · 4 citations
- Strong Authentication without Temper-Resistant Hardware and Application to Federated IdentitiesZhenfeng Zhang, Yuchen Wang, Kang YangNDSS 2020
