A Universal System for OpenID Connect Sign-ins with Verifiable Credentials and Cross-Device Flow

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Hoops, Felix, Matthes, Florian
Format: Preprint
Publié: 2024
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866913199017689088
author Hoops, Felix
Matthes, Florian
author_facet Hoops, Felix
Matthes, Florian
contents Self-Sovereign Identity (SSI), as a new and promising identity management paradigm, needs mechanisms that can ease a gradual transition of existing services and developers towards it. Systems that bridge the gap between SSI and established identity and access management have been proposed but still lack adoption. We argue that they are all some combination of too complex, locked into specific ecosystems, have no source code available, or are not sufficiently documented. We propose a comparatively simple system that enables SSI-based sign-ins for services that support the widespread OpenID Connect or OAuth 2.0 protocols. Its handling of claims is highly configurable through a single policy and designed for cross-device authentication flows involving a smartphone identity wallet. For external interfaces, we solely rely on open standards, such as the recent OpenID for Verifiable Credentials standards. We provide our implementation as open-source software intended for prototyping and as a reference. Also, we contribute a detailed technical discussion of our particular sign-in flow. To prove its feasibility, we have successfully tested it with existing software and realistic hardware.
format Preprint
id arxiv_https___arxiv_org_abs_2401_09488
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle A Universal System for OpenID Connect Sign-ins with Verifiable Credentials and Cross-Device Flow
Hoops, Felix
Matthes, Florian
Cryptography and Security
Software Engineering
Self-Sovereign Identity (SSI), as a new and promising identity management paradigm, needs mechanisms that can ease a gradual transition of existing services and developers towards it. Systems that bridge the gap between SSI and established identity and access management have been proposed but still lack adoption. We argue that they are all some combination of too complex, locked into specific ecosystems, have no source code available, or are not sufficiently documented. We propose a comparatively simple system that enables SSI-based sign-ins for services that support the widespread OpenID Connect or OAuth 2.0 protocols. Its handling of claims is highly configurable through a single policy and designed for cross-device authentication flows involving a smartphone identity wallet. For external interfaces, we solely rely on open standards, such as the recent OpenID for Verifiable Credentials standards. We provide our implementation as open-source software intended for prototyping and as a reference. Also, we contribute a detailed technical discussion of our particular sign-in flow. To prove its feasibility, we have successfully tested it with existing software and realistic hardware.
title A Universal System for OpenID Connect Sign-ins with Verifiable Credentials and Cross-Device Flow
topic Cryptography and Security
Software Engineering
url https://arxiv.org/abs/2401.09488