Smart Contract Federated Identity Management without Third Party\n Authentication Services
Abstract
Federated identity management enables users to access multiple systems using\na single login credential. However, to achieve this a complex privacy\ncompromising authentication has to occur between the user, relying party (RP)\n(e.g., a business), and a credential service provider (CSP) that performs the\nauthentication. In this work, we use a smart contract on a blockchain to enable\nan architecture where authentication no longer involves the CSP. Authentication\nis performed solely through user to RP communications (eliminating fees and\nenhancing privacy). No third party needs to be contacted, not even the smart\ncontract. No public key infrastructure (PKI) needs to be maintained. And no\nrevocation lists need to be checked. In contrast to competing smart contract\napproaches, ours is hierarchically managed (like a PKI) enabling better\nvalidation of attribute providers and making it more useful for large entities\nto provide identity services for their constituents (e.g., a government) while\nstill enabling users to maintain a level of self-sovereignty.\n
Community
0 commentsNo discussion yet
Be the first to share a question or observation.