Global Digital Identity and Public Key Infrastructure
Oleksandr Kurbatov, Pavel Kravchenko, Nikolay Alexandrovich Poluyanenko, Yevhen Demenko, Тетяна Кузнецова · 2020
This paper proposes the concept of building a decentralized identifi- cation system that allows each participant to perform the role of both an identity object and an identity provider, regardless of their technical and legal capabili- ties. The main parameter of significance in the system is the level of trust to- ward the subject by the other participants of the platform and external IDs in- formation consumers. This maintains the ability to fully manage the account and associated PII for their owner through the use of a cryptographic signature mechanism: changes to key data, PII and identifiers can be made at any time. The proposed system does not change the existing model of trust for large pro- viders of identification services, but it allows to increase the objectivity of in- formation about identifiers and PII of their owners by the possibility of verifica- tion of a separate identifier to each of the participants of the platform, followed by recording the results of verification in the chain of blocks. The use of block- chain technology and a consensus-reaching mechanism make it possible to syn- chronize the sequence of events in the system. The described global digital identity system positions itself as a source of information about global entities of specific subjects, and related personal data sets and established identifiers, while allowing the end-user of information to make independent conclusions about the level of trust of these identifiers based on related transactions. The system described is compatible with the digital asset management infrastructure and current identification tools. Thus, the system accomplishes a number of im- portant tasks: reducing the threshold for using digital identifiers, allowing their ubiquitous use; the ability to verify the identifier and prove its compliance without the need to build a trusted infrastructure (only cryptography and other participants` votes); reducing the likelihood of certificate substitution attacks; increase the objectivity of information about the identifiers used.