A novel key management framework for secure and scalable decentralized identity systems

Yükleniyor...
Küçük Resim

Tarih

Bölüm / Program

Computer Engineering Programme

Dergi Başlığı

Dergi ISSN

Cilt Başlığı

Yayıncı

Graduate School

Özet

In today's digital landscape, managing identities securely and privately is a significant challenge. Users often maintain multiple identities across various platforms, leading to privacy concerns, data breaches, and identity theft. A centralized approach to identity management can expose sensitive information and weaken user control over personal data. This situation has driven the need for decentralized identity (DID) systems. The rapid adoption of decentralized identity systems has introduced significant challenges in managing cryptographic keys securely and efficiently, particularly in large-scale implementations such as national identity programs. Traditional key management approaches often struggle with scalability, security isolation, recovery, and delegation, posing risks to the integrity and usability of decentralized identity solutions. This study proposes a novel key management framework that integrates the hierarchical deterministic (HD) key management, Hardware Security Modules (HSMs), and key wrapping mechanisms to provide a scalable and secure solution for decentralized identity systems. The proposed framework leverages BIP32 hierarchical deterministic key derivation, enabling efficient management of cryptographic keys by deriving multiple keys from a single master seed. This method significantly reduces the complexity of managing individual keys and enhances security by maintaining strict key isolation. The Hardware Security Module (HSM) serves as a root of trust, securely storing the Key Encryption Key (KEK) and performing cryptographic operations, including key wrapping and unwrapping. Key wrapping ensures that master seeds can be stored externally without compromising security, facilitating scalability without burdening the HSM with excessive storage requirements. The framework addresses five key challenges in decentralized identity management: Scalability by supporting large-scale key storage with external key-wrapped master seeds, Security isolation by implementing hierarchical key derivation structures, Recovery by securely restoring keys through deterministic derivation, Secure delegation by enabling hierarchical access control, and Complexity reduction by centralizing key management under a single master seed. A comprehensive security analysis demonstrates the framework's resilience against various attack vectors, including side-channel attacks, cryptanalytic attacks, insider threats, and quantum computing threats. By leveraging HSMs with FIPS 140-2 Level 4 certification, secure algorithm selection for key wrapping, and multi-factor authentication mechanisms, the proposed approach significantly enhances security compared to existing decentralized identity key management solutions. We analyze the security and performance of BIP32 vs. SLIP10 in an HSM environment, measuring key derivation speed, transaction signing efficiency, and resistance to attacks. Our results show that SLIP10 offers stronger security guarantees, while BIP32 remains dominant due to blockchain compatibility. Also, for the first time in the literature, performance comparison of BIP32 and SLIP10 algorithms on HSM is performed. The primary contributions of this study to the literature are as follows: It presents a framework design that integrates BIP32, HSMs, and key wrapping techniques for secure and scalable key management in decentralized identity systems. It demonstrates how the proposed framework addresses the challenges of scalability, recovery, security isolation, secure delegation, and complexity in decentralized identity management. It provides a detailed security analysis of the framework, including a threat model and discussion of security properties. It delivers a comparative analysis of BIP32 (ECDSA) and SLIP10 (EdDSA) in HSM environments. It presents empirical evaluations of key derivation speed, signing latency, and computational efficiency. This research presents the first known integration of BIP32-based key derivation with HSMs and key wrapping for decentralized identity systems, providing a robust and scalable key management framework. The findings of this study have significant implications for national identity infrastructures, digital authentication mechanisms, and blockchain-based identity management systems, offering a secure, efficient, and scalable approach to decentralized identity key management. Future research will focus on prototype implementation, performance testing, and integration of post-quantum cryptographic algorithms to further enhance the framework's resilience against emerging threats.

Tanım

Thesis (M.Sc.) -- İstanbul Technical University, Graduate School, 2025

Dergi veya Seri

ISSN

ISBN

Haklar

Anahtar Kelimeler

decentralized identity systems

Alıntı

Onay

Gözden geçir

Tamamlayıcı Bilgiler

Referans Gösteren

0

Views

0

Downloads