Skip to main content
QUICK REVIEW

[论文解读] Identity and Personhood in Digital Democracy: Evaluating Inclusion, Equality, Security, and Privacy in Pseudonym Parties and Other Proofs of Personhood

Bryan Ford|arXiv (Cornell University)|Nov 4, 2020
Internet Traffic Analysis and Secure E-voting参考文献 42被引用 11
一句话总结

本文提出数字人格作为数字民主安全基础的替代方案,引入了假名聚会——定期举行的线下集会,通过发放可更新、保护隐私的数字凭证来证明真实人类的参与。研究表明,尽管现有的身份证明方案(如社交网络或权益证明)易受Sybil攻击影响,但假名聚会可通过实体验证和联邦交叉作证实现抗胁迫性和包容性,尽管可扩展性和抗攻击能力仍是挑战。

ABSTRACT

Digital identity seems like a prerequisite for digital democracy: how can we ensure "one person, one vote" online without identifying voters? But digital identity solutions - ID checking, biometrics, self-sovereign identity, and trust networks - all present flaws, leaving users vulnerable to exclusion, identity loss or theft, and coercion. These flaws may be insurmountable because digital identity is a cart pulling the horse. We cannot achieve digital identity secure enough for the weight of digital democracy, until we build it on a solid foundation of "digital personhood." While identity is about distinguishing one person from another through attributes or affiliations, personhood is about giving all real people inalienable digital participation rights independent of identity, including protection against erosion of their democratic rights through identity loss, theft, coercion, or fakery. We explore and analyze alternative approaches to "proof of personhood" that may provide this missing foundation. Pseudonym parties marry the transparency of periodic physical-world events with the power of digital tokens between events. These tokens represent limited-term but renewable claims usable for purposes such as online voting or liquid democracy, sampled juries or deliberative polls, abuse-resistant social communication, or minting universal basic income in a permissionless cryptocurrency. Enhancing pseudonym parties to provide participants a moment of enforced physical security and privacy can address coercion and vote-buying risks that plague today's E-voting systems. We also examine other proposed approaches to proof of personhood, some of which offer conveniences such as all-online participation. These alternatives currently fall short of satisfying all the key digital personhood goals, unfortunately, but offer valuable insights into the challenges we face.

研究动机与目标

  • 解决数字民主的根本缺陷:在不依赖有缺陷的数字身份系统的情况下,确保一人一票。
  • 识别现有数字身份解决方案(如政府颁发的身份证、生物识别技术、自我主权身份)在保护隐私、平等和安全方面的局限性。
  • 提出数字人格作为所有自然人不可剥夺的权利,独立于身份属性,以实现安全、包容且私密的数字参与。
  • 评估假名聚会作为证明人格的实用、可扩展且抗胁迫的方法在数字治理中的可行性。
  • 分析基于社交信任网络或阈值验证的其他身份证明方案的漏洞,特别是其对Sybil攻击的脆弱性,并评估其长期可行性。

提出的方法

  • 假名聚会是定期举行的线下活动,参与者通过直接观察彼此的物理存在并发放数字凭证来相互验证。
  • 凭证具有时间限制,可更新,并通过密码学方式与一个假名绑定,可用于在线投票、液态民主或协商性会议。
  • 通过联邦化组织结构增强安全性:多个本地活动通过数字证据和目击报告相互交叉验证。
  • 通过在活动期间强制实施物理隐私和匿名性,实现抗胁迫性,防止买票或监视行为。
  • 系统采用阈值机制(例如50%参与率)以减少对真实从属者在群体验证中的依赖,从而最小化攻击面。
  • Sybil攻击分析模型显示,攻击者可通过利润再投资获利,即使在较大群体(例如四人一组)的情况下,若诚实用户增长速度慢于攻击者创建假身份的速度,攻击者最终仍能占据主导地位。

实验结果

研究问题

  • RQ1能否在不依赖国籍、生物识别或财富等身份属性的情况下建立数字人格,以确保包容性和平等性?
  • RQ2在数字投票系统中,如何使身份证明机制具备抗胁迫和抗买票能力?
  • RQ3假名聚会在多大程度上可作为现有数字身份和身份证明方案的安全、可扩展且保护隐私的替代方案?
  • RQ4基于社交信任网络或阈值验证的身份证明方案对Sybil攻击的长期脆弱性如何?
  • RQ5在基于凭证的系统(如基本收入)中,经济激励是否可能被攻击者利用,以随时间推移扩大其Sybil控制?

主要发现

  • 通过在面对面验证活动中强制实施物理隐私和匿名性,假名聚会可实现强大的抗胁迫性。
  • 假名聚会的联邦化模式,结合交叉作证和数字证据,增强了问责性,并减少了对中心化信任的依赖。
  • 即使在较大群体规模(例如四人一组)的情况下,若诚实用户数量的增长速度慢于攻击者创建假身份的速度,Sybil攻击者仍能从诚实用户中获得显著优势。
  • 基于投资的身份证明方案(如权益证明或工作量证明)无法确保平等,因为财富更多的人会获得不成比例的影响力。
  • 社交信任网络和阈值验证机制虽能延缓但无法完全阻止Sybil攻击,特别是当攻击者能将利润再投资以创建更多虚假身份时。
  • 在假名聚会系统中,若攻击者控制10%的身份,由于阈值要求和配对概率,可实现对从属者成本60%的有效折扣,从而实现自维持的Sybil增长。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。