Skip to main content
QUICK REVIEW

[Paper Review] Digital Product Passport Management with Decentralised Identifiers and Verifiable Credentials

Ismael Illán García, Francesc D. Muñoz‐Escoí|arXiv (Cornell University)|Oct 21, 2024
Business Process Modeling and Analysis5 citations
TL;DR

This paper analyzes ESPR requirements for digital product passports and proposes a DID/VC-based design to manage DPPs, enabling selective disclosure and self-sovereign identity across product lifecycles.

ABSTRACT

Digital product passports (DPP) have been proposed in the European Ecodesign for Sustainable Products Regulation (ESPR) as a means to keep and provide product information that facilitates product reusage, reparation, and recycling. Thus, DPPs should provide a positive effect on the environmental impact of future manufactured products, preventing waste and promoting a circular economy (CE) model. ESPR settles a set of requirements in collecting and administering product-related data. Decentralised identifiers (DID) and verifiable credentials (VC) are two self-sovereign-identity-related elements that may help in that DPP management since they introduce a decentralised administration of identity that may enhance the overall scalability of the resulting system, improving also its reliability. This paper analyses the ESPR requirements and describes how they may be achieved using DIDs and VCs, assessing their performance in some scenarios.

Motivation & Objective

  • Analyze ESPR requirements for digital product passports (DPPs) and how they shape identity-management needs.
  • Propose a DID/VC-based architecture to implement, manage, and govern DPPs across product lifecycles.
  • Evaluate design choices for product identification, granularity (model/batch/item), and lifecycle maintenance under ESPR constraints.
  • Discuss deployment considerations, security, privacy, and cost implications of the proposed approach.

Proposed method

  • Map ESPR articles and data elements to SSI concepts (DIDs, VCs, VPs).
  • Propose DPP architectures that combine product identifiers (GTIN/ISO-15459) with DIDs and VCs.
  • Present design alternatives for product identification integration with DPPs (D01.1, D01.2, D01.3).
  • Define granularities (model/batch/item) and corresponding data-storage strategies (DID documents vs. registries).
  • Outline maintenance mechanisms including role-based access and credential-based updates during lifecycle transitions.
  • Analyze related work and regulatory requirements to justify a DID/VC-based solution.

Experimental results

Research questions

  • RQ1How can ESPR requirements for DPPs be satisfied using DIDs, VCs, and VPs?
  • RQ2What are viable design options for integrating DIDs with ISO/IEC 15459/GTIN identifiers in DPPs?
  • RQ3How should DPP granularity (model, batch, item) be implemented and stored?
  • RQ4Who should maintain and update DPPs across the product lifecycle, and how can changes be securely managed?
  • RQ5What are the security, privacy, and cost implications of a DID/VC-based DPP architecture?

Key findings

  • DPPs can be effectively implemented using a combination of DIDs, VCs, and VPs to meet ESPR requirements for identity, authenticity, and selective disclosure.
  • DIDs can complement ISO/15459 identifiers without replacing them, enabling flexible product and actor identification.
  • Different granularity options (model, batch, item) require distinct storage and credential strategies, including in-DID documents or verifiable data registries.
  • Lifecycle maintenance of DPPs can be delegated to different actors, with VCs used to record changes (e.g., repairs) when manufacturers are no longer the owner.
  • Security, privacy, and fraud-prevention concerns are addressed by designing immutable, authenticated data flows and role-based access controls.

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.