Skip to main content
QUICK REVIEW

[Paper Review] Digital identity architectures: comparing goals and vulnerabilities

Callum Mole, Ed Chalstrey|arXiv (Cornell University)|Feb 20, 2023
Digital and Cyber Forensics4 citations
TL;DR

This paper evaluates digital identity architectures by comparing centralized and decentralized models against core goals of functionality, privacy, and operational resilience. It identifies that while centralized systems offer usability and governance advantages, decentralized models enhance privacy and resilience, and advocates for hybrid designs enhanced by privacy-enhancing technologies (PETs) like homomorphic encryption and differential privacy to balance security, scalability, and user rights.

ABSTRACT

Digital identity systems have the promise of efficiently facilitating access to services for a nation's citizens while increasing security and convenience. There are many possible system architectures, each with strengths and weaknesses that should be carefully considered. This report first establishes a set of goals and vulnerabilities faced by any identity system, then evaluates the trade-offs of common digital identity architectures, principally comparing centralised and decentralised systems.

Motivation & Objective

  • To establish a comprehensive evaluation framework for digital identity systems based on functional, privacy-related, and operational goals.
  • To analyze trade-offs between centralized and decentralized digital identity architectures in real-world deployment contexts.
  • To assess how privacy-enhancing technologies (PETs) can mitigate vulnerabilities in both architectural models.
  • To identify practical design compromises that balance security, usability, scalability, and user rights in national digital identity systems.
  • To guide policymakers and architects toward resilient, privacy-preserving identity systems through evidence-based evaluation of existing models.

Proposed method

  • Develops a multi-dimensional evaluation framework based on Cameron’s Laws of Identity and the World Bank’s ID4D principles, focusing on functional, privacy, and operational goals.
  • Classifies digital identity architectures along a centralization-decentralization spectrum, analyzing their strengths and weaknesses across key criteria.
  • Evaluates the role of privacy-enhending technologies (PETs), including homomorphic encryption, secure multiparty computation (MPC), differential privacy, and secure enclaves.
  • Applies PETs to specific use cases such as biometric verification, access control logging, and attribute-based authentication to preserve data confidentiality.
  • Proposes hybrid architectures that integrate centralized governance with decentralized trust mechanisms to reduce systemic risks.
  • Uses threat modeling to assess vulnerabilities such as single points of failure, data breaches, and misuse of centralized authority.

Experimental results

Research questions

  • RQ1How do centralized and decentralized digital identity architectures compare in meeting core functional, privacy, and operational goals?
  • RQ2What are the primary vulnerabilities inherent in centralized identity systems, and how can they be mitigated through technical and regulatory means?
  • RQ3To what extent can privacy-enhancing technologies (PETs) improve the security and privacy of both centralized and decentralized identity systems?
  • RQ4What trade-offs exist between usability, scalability, governance, and privacy in real-world digital identity deployments?
  • RQ5How can hybrid identity architectures effectively combine the strengths of centralization and decentralization while minimizing their respective risks?

Key findings

  • Centralized identity systems offer strong usability and governance but are vulnerable to single points of failure, data breaches, and misuse of centralized authority.
  • Decentralized self-sovereign identity models enhance privacy and resilience by eliminating central trust points, but face challenges in usability, governance, and system-wide coordination.
  • Privacy-enhancing technologies such as homomorphic encryption and differential privacy can enable secure computation on sensitive identity data without exposing raw information.
  • Secure enclaves and MPC can protect data in untrusted environments, such as cloud-hosted identity services, reducing insider threat risks.
  • Differential privacy requires careful query design and access control, limiting the number of authorized queries and administrators to preserve statistical privacy.
  • A hybrid approach—combining centralized governance with decentralized data control and PETs—offers a viable path toward scalable, secure, and privacy-preserving national identity systems.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.