A Critique of Immunity Passports and W3C Decentralized Identifiers

11/30/2020
by   Harry Halpin, et al.
0

Due to the widespread COVID-19 pandemic, there has been a push for `immunity passports' and even technical proposals. Although the debate about the medical and ethical problems of immunity passports has been widespread, there has been less inspection of the technical foundations of immunity passport schemes. These schemes are envisaged to be used for sharing COVID-19 test and vaccination results in general. The most prominent immunity passport schemes have involved a stack of little-known standards, such as Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) from the World Wide Web Consortium (W3C). Our analysis shows that this group of technical identity standards are based on under-specified and often non-standardized documents that have substantial security and privacy issues, due in part to the questionable use of blockchain technology. One concrete proposal for immunity passports is even susceptible to dictionary attacks. The use of `cryptography theater' in efforts like immunity passports, where cryptography is used to allay the privacy concerns of users, should be discouraged in standardization. Deployment of these W3C standards for `self-sovereign identity' in use-cases like immunity passports could just as well lead to a dangerous form identity totalitarianism.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
08/02/2019

A Taxonomic Approach to Understanding Emerging Blockchain Identity Management Systems

Identity management systems (IDMSs) are widely used to provision user id...
research
04/16/2022

Is Blockchain for Internet of Medical Things a Panacea for COVID-19 Pandemic?

The outbreak of the COVID-19 pandemic has deeply influenced the lifestyl...
research
03/01/2023

Self-Sovereign Identity for Trust and Interoperability in the Metaverse

With the advancement in computing power and speed, the Internet is being...
research
04/06/2020

Certifying Provenance of Scientific Datasets with Self-sovereign Identity and Verifiable Credentials

In order to increase the value of scientific datasets and improve resear...
research
10/03/2022

Decentralized nation, solving the web identity crisis

The web of today whether you prefer to call it web 2.0, web 3.0, web 5.0...
research
12/31/2017

Cyclic group based mutual authentication protocol for RFID system

Widespread deployment of RFID system arises security and privacy concern...
research
04/30/2018

Comparative Analysis and Framework Evaluating Web Single Sign-On Systems

We perform a comprehensive analysis and comparison of 14 web SSO systems...

Please sign up or login with your details

Forgot password? Click here to reset