A novel key management framework for secure and scalable decentralized identity systems

dc.contributor.advisorBahtiyar, Şerif
dc.contributor.authorYıldız, Mert
dc.contributor.authorID941590
dc.contributor.departmentComputer Engineering Programme
dc.date.accessioned2026-06-09T12:55:46Z
dc.date.issued2025
dc.descriptionThesis (M.Sc.) -- İstanbul Technical University, Graduate School, 2025
dc.description.abstractIn today's digital landscape, managing identities securely and privately is a significant challenge. Users often maintain multiple identities across various platforms, leading to privacy concerns, data breaches, and identity theft. A centralized approach to identity management can expose sensitive information and weaken user control over personal data. This situation has driven the need for decentralized identity (DID) systems. The rapid adoption of decentralized identity systems has introduced significant challenges in managing cryptographic keys securely and efficiently, particularly in large-scale implementations such as national identity programs. Traditional key management approaches often struggle with scalability, security isolation, recovery, and delegation, posing risks to the integrity and usability of decentralized identity solutions. This study proposes a novel key management framework that integrates the hierarchical deterministic (HD) key management, Hardware Security Modules (HSMs), and key wrapping mechanisms to provide a scalable and secure solution for decentralized identity systems. The proposed framework leverages BIP32 hierarchical deterministic key derivation, enabling efficient management of cryptographic keys by deriving multiple keys from a single master seed. This method significantly reduces the complexity of managing individual keys and enhances security by maintaining strict key isolation. The Hardware Security Module (HSM) serves as a root of trust, securely storing the Key Encryption Key (KEK) and performing cryptographic operations, including key wrapping and unwrapping. Key wrapping ensures that master seeds can be stored externally without compromising security, facilitating scalability without burdening the HSM with excessive storage requirements. The framework addresses five key challenges in decentralized identity management: Scalability by supporting large-scale key storage with external key-wrapped master seeds, Security isolation by implementing hierarchical key derivation structures, Recovery by securely restoring keys through deterministic derivation, Secure delegation by enabling hierarchical access control, and Complexity reduction by centralizing key management under a single master seed. A comprehensive security analysis demonstrates the framework's resilience against various attack vectors, including side-channel attacks, cryptanalytic attacks, insider threats, and quantum computing threats. By leveraging HSMs with FIPS 140-2 Level 4 certification, secure algorithm selection for key wrapping, and multi-factor authentication mechanisms, the proposed approach significantly enhances security compared to existing decentralized identity key management solutions. We analyze the security and performance of BIP32 vs. SLIP10 in an HSM environment, measuring key derivation speed, transaction signing efficiency, and resistance to attacks. Our results show that SLIP10 offers stronger security guarantees, while BIP32 remains dominant due to blockchain compatibility. Also, for the first time in the literature, performance comparison of BIP32 and SLIP10 algorithms on HSM is performed. The primary contributions of this study to the literature are as follows: It presents a framework design that integrates BIP32, HSMs, and key wrapping techniques for secure and scalable key management in decentralized identity systems. It demonstrates how the proposed framework addresses the challenges of scalability, recovery, security isolation, secure delegation, and complexity in decentralized identity management. It provides a detailed security analysis of the framework, including a threat model and discussion of security properties. It delivers a comparative analysis of BIP32 (ECDSA) and SLIP10 (EdDSA) in HSM environments. It presents empirical evaluations of key derivation speed, signing latency, and computational efficiency. This research presents the first known integration of BIP32-based key derivation with HSMs and key wrapping for decentralized identity systems, providing a robust and scalable key management framework. The findings of this study have significant implications for national identity infrastructures, digital authentication mechanisms, and blockchain-based identity management systems, offering a secure, efficient, and scalable approach to decentralized identity key management. Future research will focus on prototype implementation, performance testing, and integration of post-quantum cryptographic algorithms to further enhance the framework's resilience against emerging threats.
dc.description.degreeM.Sc.
dc.identifier.urihttps://hdl.handle.net/11527/75800
dc.language.isoeng
dc.publisherGraduate School
dc.sdg.typeGoal 9: Industry, Innovation and Infrastructure
dc.subjectdecentralized identity systems
dc.titleA novel key management framework for secure and scalable decentralized identity systems
dc.title.alternativeGüvenli ve ölçeklenebilir dağıtık kimlik sistemleri için yeni bir anahtar yönetim mimarisi
dc.typeMaster Thesis

Dosyalar

Orijinal paket

Şimdi gösterimde1 - 1 of 1
Yükleniyor...
Küçük Resim
Adı:
941590.pdf
Boyut:
1.015,24 KB
Format:
Adobe Portable Document Format

Lisans paketi

Şimdi gösterimde1 - 1 of 1
Yükleniyor...
Küçük Resim
Adı:
license.txt
Boyut:
1,58 KB
Format:
Item-specific license agreed upon to submission
Description: