Programmable Governance for Group-Controlled Decentralized Identifiers

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Segat, Carlo, Garzo, Sandro Rodriguez, Küpper, Axel
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866911045513117696
author Segat, Carlo
Garzo, Sandro Rodriguez
Küpper, Axel
author_facet Segat, Carlo
Garzo, Sandro Rodriguez
Küpper, Axel
contents Self-Sovereign Identity (SSI) is a paradigm for digital identity management that offers unique privacy advantages. A key technology in SSI is Decentralized Identifiers (DIDs) and their associated metadata, DID Documents (DDOs). DDOs contain crucial verification material such as the public keys of the entity identified by the DID (i.e., the DID subject) and are often anchored on a distributed ledger to ensure security and availability. Long-lived DIDs need to support updates (e.g., key rotation). Ideally, only the DID subject should authorize DDO updates. However, in practice, update capabilities may be shared or delegated. While the DID specification acknowledges such scenarios, it does not define how updates should be authorized when multiple entities jointly control a DID (i.e., group control). This article examines the implementation of an on-chain, trustless mechanism enabling DID controllers under group control to program their governance rules. The main research question is the following: Can a technical mechanism be developed to orchestrate on-chain group control of a DDO in a ledger-agnostic and adaptable manner?
format Preprint
id arxiv_https___arxiv_org_abs_2507_06001
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Programmable Governance for Group-Controlled Decentralized Identifiers
Segat, Carlo
Garzo, Sandro Rodriguez
Küpper, Axel
Networking and Internet Architecture
Self-Sovereign Identity (SSI) is a paradigm for digital identity management that offers unique privacy advantages. A key technology in SSI is Decentralized Identifiers (DIDs) and their associated metadata, DID Documents (DDOs). DDOs contain crucial verification material such as the public keys of the entity identified by the DID (i.e., the DID subject) and are often anchored on a distributed ledger to ensure security and availability. Long-lived DIDs need to support updates (e.g., key rotation). Ideally, only the DID subject should authorize DDO updates. However, in practice, update capabilities may be shared or delegated. While the DID specification acknowledges such scenarios, it does not define how updates should be authorized when multiple entities jointly control a DID (i.e., group control). This article examines the implementation of an on-chain, trustless mechanism enabling DID controllers under group control to program their governance rules. The main research question is the following: Can a technical mechanism be developed to orchestrate on-chain group control of a DDO in a ledger-agnostic and adaptable manner?
title Programmable Governance for Group-Controlled Decentralized Identifiers
topic Networking and Internet Architecture
url https://arxiv.org/abs/2507.06001