Skip to main content
QUICK REVIEW

[论文解读] A Plural Decentralized Identity Frontier: Abstraction v. Composability Tradeoffs in Web3

Shrey Jain, Leon Erichsen|arXiv (Cornell University)|Aug 24, 2022
Blockchain Technology Applications and Security被引用 4
一句话总结

本文探讨了Web3去中心化身份系统中抽象性与组合性之间的权衡,认为当前的DID v1.0等标准规定不足,从而允许多种互补的实现方式,例如基于区块链的证书(如灵魂绑定代币)和去中心化标识符。文章主张DID/VC与SBT等范式之间的差异在很大程度上是表面性的,二者均面临类似挑战——尤其是非同意验证——而SBT可被视为一种专注于智能合约组合性、隐私保护和审查抵抗的VC演进。

ABSTRACT

In this article, we explore the tension between abstraction and composability in web3 today, specifically within identity solutions, and argue that the current standard DID v1.0 is sufficiently under specified, allowing for many methods and instantiations, including blockchain based certificates. We view experiments today in web3 identity as additive and complementary, and argue that often cited differences are of degree and more in form, less in substance. By way of illustration, we compare decentralized naming services and blockchain based identity certificates such as soulbound tokens (SBTs) to decentralized identifiers (DIDs) and verifiable credentials (VCs). Both paradigms, to the extent they can be meaningfully differentiated, share similar potential as well as challenges. Specifically, we refer to fears about non consensual verification (scarlet letters) and show DID method iterations are not immune by issuing an innocuous public scarlet letter to a DIDs associated public address for anyone to see. Moreover, we argue that because SBTs are unspecified, one could characterize SBTs as an iteration, or extension, of VCs that additionally aspire to achieve composability with web3 smart contracts for correct execution of code, privacy, coercion resistance, and censorship resistance. We offer research paths for how VCs can also achieve these properties. We do not comment on cost, scalability, transferability, or common knowledge as they have been previously reviewed.

研究动机与目标

  • 分析Web3去中心化身份解决方案中抽象性与组合性之间的张力。
  • 论证当前标准(如DID v1.0)规定不足,从而允许多种互补的实现方式。
  • 证明身份范式(如DID/VC与SBT)之间的明显差异,往往只是程度上的不同,而非本质区别。
  • 研究非同意验证(如“通红字母”)在不同身份模型中的风险。
  • 探讨可验证凭证如何在不引入新原 primitive 的前提下,实现与灵魂绑定代币类似的特性——如与智能合约的组合性、隐私保护以及胁迫抵抗。

提出的方法

  • 将去中心化命名服务、基于区块链的身份证书(如灵魂绑定代币)、DID和可验证凭证作为竞争的身份范式进行比较。
  • 通过展示即使DID也可被颁发带有可见公开标识符的凭证,从而实现非同意验证,分析其影响,例如作为“通红字母”的公开显示。
  • 将灵魂绑定代币(SBTs)重新定义为一种优先关注与Web3智能合约组合性的可验证凭证(VCs)的扩展。
  • 提出可通过增强可验证凭证以支持智能合约集成、隐私保护操作以及对胁迫和审查的抵抗。
  • 使用概念性与说明性示例(如公开的“通红字母”)突出不同身份模型之间的共性漏洞。
  • 依赖概念建模与比较分析,而非形式化密码学证明或实现基准测试。

实验结果

研究问题

  • RQ1DID/VC与SBT等去中心化身份模型之间的差异,在多大程度上代表了根本性的架构差异,还是仅是程度上的变化?
  • RQ2非同意验证机制(如通过DID公开地址显示的“通红字母”)如何影响不同身份系统中的隐私与自主权?
  • RQ3可验证凭证能否被扩展以实现与灵魂绑定代币相同的组合性、隐私保护和审查抵抗特性?
  • RQ4当前标准(如DID v1.0)在多大程度上规定不足?这种不足如何在Web3身份中促成多种互补的实现方式?
  • RQ5身份元数据(如公开地址)的可见性对去中心化系统中信任与胁迫抵抗能力有何影响?

主要发现

  • 当前的DID v1.0规范规定得足够模糊,从而允许去中心化身份实现的多元前沿,包括基于区块链的证书。
  • 非同意验证(如通过DID的公开地址显示“通红字母”)并非SBT独有,标准DID系统中同样可能发生。
  • 灵魂绑定代币(SBTs)可被理解为一种专门针对与Web3智能合约组合性的可验证凭证(VCs)的扩展。
  • 隐私、胁迫抵抗与审查抵抗等核心挑战在各类身份模型中是共通的,表明某一范式中的改进可被适配至其他范式。
  • 可通过增强可验证凭证以支持智能合约集成与隐私保护操作,从而在不引入新原 primitive 的前提下,实现类似SBT的特性。
  • DID/VC与SBT之间的区别更多体现在形式与实现重点上,而非根本性的架构分歧。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。