Skip to main content
QUICK REVIEW

[Paper Review] Decentralized Identifiers and Self-sovereign Identity in 6G

Sandro Rodriguez Garzon, Hakan Yildiz|arXiv (Cornell University)|Dec 17, 2021
Advanced Wireless Communication Technologies11 references4 citations
TL;DR

This paper proposes integrating Decentralized Identifiers (DIDs) and Self-Sovereign Identity (SSI) into 6G networks to enable secure, privacy-preserving, and decentralized identity and access management across multi-stakeholder, zero-trust environments. By replacing centralized public key infrastructures with distributed ledger-based DIDs and verifiable credentials, the approach eliminates single points of failure, enhances cross-domain interoperability, and supports compliance with privacy regulations like GDPR.

ABSTRACT

A key challenge for mobile network operators in 6G is to bring together and orchestrate a variety of new emerging players of today's mobile ecosystems in order to provide economically viable and seamless mobile connectivity in form of a multi-stakeholder service. With each new player, be it a cloud, edge or hardware provider, the need for interfaces with secure authentication and authorization mechanisms increases, as does the complexity and operational costs of the public key infrastructures required for the identity and key management. While today's centralized public key infrastructures have proven to be technically feasible in confined and trusted spaces, they do not provide the required security for access control once centralized identity providers must be avoided because of limited cross-domain interoperability, national data protection legislation, or geopolitical-strategic reasons. Recent decentralized identity management concepts, such as the W3C recommendation of Decentralized Identifiers, provide a secure, tamper-proof, and cross-domain identity management alternative for future multi-stakeholder 6G networks without relying on centralized identity provider or certification authorities. This article introduces the concept of Decentralized Identifiers together with the principles of Self-sovereign Identity and discusses opportunities and potential benefits of their application and usage for cross-domain and privacy-preserving identity and key management in 6G networks.

Motivation & Objective

  • To address the growing complexity and security limitations of centralized public key infrastructures (PKIs) in 6G's multi-stakeholder, multi-domain environments.
  • To enable cross-domain, interoperable authentication and authorization without relying on centralized identity providers or globally trusted certification authorities (CAs).
  • To support privacy-preserving identity management compliant with regulations like GDPR by allowing individuals and systems to control their own identity data.
  • To explore the integration of DIDs and verifiable credentials (VCs) across the access, management, and application planes in 6G networks.
  • To identify technical, governance, and scalability challenges in deploying distributed ledger technology (DLT) for large-scale 6G identity systems.

Proposed method

  • Proposes the use of Decentralized Identifiers (DIDs) as cryptographically secure, resolvable, and self-contained identifiers that do not require a centralized registry.
  • Introduces Self-Sovereign Identity (SSI) principles, enabling identity owners (IS) to control their identity data and issue verifiable credentials (VCs) without relying on centralized authorities.
  • Replaces traditional PKI-based authentication with DID-based mutual authentication using verifiable credentials issued by trusted entities such as MNOs or government authorities.
  • Uses distributed ledger technology (DLT) to store and verify DID documents and credential revocation lists, ensuring tamper-resistance and decentralization.
  • Applies JSON Web Tokens (JWTs) and SBA-based service discovery (via NRF) enhanced with VCs to enable secure, stateless service access across network functions.
  • Envisions a trust model where MNOs act as issuers of context-based VCs (e.g., location) and verifiers of third-party VCs (e.g., social security numbers), reducing reliance on external verification services.

Experimental results

Research questions

  • RQ1How can decentralized identity management with DIDs and SSI replace centralized PKIs in 6G networks to improve security and reduce operational costs?
  • RQ2In what ways can DIDs and verifiable credentials enable cross-domain, interoperable authentication and authorization across multiple trust domains in 6G?
  • RQ3How can SSI and DIDs support privacy-by-design principles in 6G, particularly in compliance with GDPR and similar data protection regulations?
  • RQ4What are the technical and architectural challenges of integrating DLT-based identity systems into existing and future 6G network functions and slices?
  • RQ5How can MNOs and other stakeholders leverage DIDs and VCs to create new trust-based, privacy-preserving services and revenue models?

Key findings

  • DID-based identity management eliminates the need for centralized identity providers and globally trusted CAs, reducing attack surface and operational complexity.
  • Verifiable credentials (VCs) enable secure, privacy-preserving exchange of identity attributes between entities, such as MNOs and OTT services, without exposing raw personal data.
  • The use of DIDs and SSI allows MNOs to act as trusted issuers of context-based VCs (e.g., location) and verifiers of third-party credentials, streamlining onboarding and reducing reliance on external verification.
  • Replacing JWTs with VCs in the SBA-based service discovery process enhances trust and verifiability, as VCs are cryptographically bound and independently verifiable by relying parties.
  • The integration of DIDs and SSI supports zero-trust architecture (ZTA) principles by enabling decentralized, cryptographically verifiable authentication across heterogeneous, distributed network components.
  • Despite the benefits, significant open challenges remain in scaling DLT-based systems to support billions of identities, ensuring low-latency synchronization, and defining governance models across competing stakeholders in PLMN ecosystems.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.