arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

China RealDID:锚定法律身份的可验证凭证

China RealDID: Verifiable Credentials Anchored in Legal Identity

Yifan He

arXiv 2608.07846首次发表:更新:

AI 中文总结

本文提出China RealDID三层架构,结合CTID、RealDID与SD-JWT型VCs,解决现有VCs/DIDs缺乏法律锚定的问题,契合中欧数据法规,具跨境部署通用性。

AI 中文摘要

可验证凭证(VCs)与去中心化标识符(DIDs)支持选择性披露,但缺乏法律锚定:若无可信身份根,验证者无法区分真实持有者与伪造身份。国家身份系统提供基于生物识别的验证,但会带来三类成本:验证者必须收集主体的全部个人可识别信息,基础设施集中于单一API,且国家可观测每笔交易。本文提出China RealDID,这是一个三层架构——CTID(中心化法律身份)、RealDID(开放许可区块链上的去中心化锚点)以及基于SD-JWT的选择性披露VCs,针对五类对手和六项安全目标进行评估。核心机制是内容盲政府中继:国家对参与者进行身份验证并对每份凭证进行副署,但无法读取由发行方用持有者公钥加密的载荷。本文描述了VC生命周期、三重签名链、开放模板注册表,以及该架构在元数据层面的隐私限制,包括中继处的凭证图和单DID复用带来的展示可链接性。该设计形成了非对称、受国家约束的信任模型:国家无法冒充或读取内容;用户无法伪造身份或规避元数据观测。本文分析了其与《中国个人信息保护法》和欧盟GDPR的契合度,包括不可变注册表与被遗忘权之间的张力,并讨论了通过与新加坡、香港跨境部署实现的通用性。

英文摘要

Verifiable credentials (VCs) and decentralized identifiers (DIDs) enable selective disclosure but lack legal anchoring: without a trusted identity root, verifiers cannot distinguish a genuine holder from a fabricated identity. State identity systems provide biometric-grounded verification but impose three costs: verifiers must collect subjects' full personally identifiable information, infrastructure concentrates on a single API, and the state observes every transaction. We present China RealDID, a three-layer architecture -- CTID (centralized legal identity), RealDID (decentralized anchor on an open permissioned blockchain), and VCs with SD-JWT-based selective disclosure -- evaluated against five adversary classes and six security goals. The central mechanism is a content-blind government relay: the state authenticates participants and counter-signs every credential but cannot read the payload, encrypted by the issuer to the holder's public key. We describe the VC lifecycle, triple-signature chain, open template registry, and the architecture's metadata-level privacy limits, including the credential graph at the relay and presentation linkability from single-DID reuse. The design yields an asymmetric, state-bounded trust model: the state cannot impersonate or read contents; the user cannot fabricate identity or evade metadata observation. We analyze alignment with China's Personal Information Protection Law and the EU's GDPR, including the tension between immutable registries and erasure rights, and discuss generalizability through cross-border deployments with Singapore and Hong Kong.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑