All that is Solid Melts into Air: Towards Decentralized Cryptographic Access Control
Harry Halpin · Proceedings of the 17th International Conference on Availability, Reliability and Security · 2022
Access control languages are traditionally based on centralized trust models when achieving their security goals. One important reason for a lack of decentralized trust models for access control has been difficulties in referring to and accessing cryptographic key material in a decentralized fashion. This lack of a working and secure decentralized public key infrastructure could be fatal for projects like Berners-Lee’s Solid. To solve this problem, we propose repurposing the access control scheme SDSI (Simple Distributed Security Infrastructure). SDSI is a long-standing and well-studied alternative to the hierarchical PKI infrastructure, but it failed to be adopted due to problems with key discovery and revocation, both of which can be solved with blockchain technology. In this concept note, we outline the next steps for how SDSI could be used as a decentralized trust model using blockchain technology.