Self-Sovereign Identity for Organizations: Requirements for Enterprise Software

In recent years, the decentralized identity management approach known as Self-Sovereign Identity (SSI) has gained popularity. It aims to give individuals and organizations more control over their identities and credentials. Unfortunately, the adoption of SSI is impeded because the SSI community freq...

पूर्ण विवरण

ग्रंथसूची विवरण
मुख्य लेखकों: Ricardo Bochnia, Daniel Richter, Jurgen Anke
स्वरूप: लेख
भाषा:English
प्रकाशित: IEEE 2024-01-01
श्रृंखला:IEEE Access
विषय:
ऑनलाइन पहुंच:https://ieeexplore.ieee.org/document/10379079/
_version_ 1826938544159981568
author Ricardo Bochnia
Daniel Richter
Jurgen Anke
author_facet Ricardo Bochnia
Daniel Richter
Jurgen Anke
author_sort Ricardo Bochnia
collection DOAJ
description In recent years, the decentralized identity management approach known as Self-Sovereign Identity (SSI) has gained popularity. It aims to give individuals and organizations more control over their identities and credentials. Unfortunately, the adoption of SSI is impeded because the SSI community frequently overlooks the requirements of organizations. The organization’s roles as an issuer, verifier, and especially as a holder of Verifiable Credentials (VCs) remain largely unexplored. This is partly because SSI emerged as a user-centric approach focusing on privacy benefits for individuals who act as credential holders. To address this issue, we conducted a multi-method study to identify an initial set of general requirements for organizational SSI software. We used a triangulation approach consisting of a literature review, expert interviews, and product analysis. As a result, we present a comprehensive set of requirements grouped into three main categories: credential management, organizational identity and relationships, and additional requirements. We also examined potential constraints to SSI development and wider adoption in organizational settings. Furthermore, we present gaps between the found organizational-centric requirements and current SSI solutions. Thus, these requirements can serve as a starting point for developing better-tailored SSI software, which represents organizational needs and use cases more closely than current solutions.
first_indexed 2024-03-08T12:53:46Z
format Article
id doaj.art-dbc6451e6cef4a6e9a2d3a73958187f6
institution Directory Open Access Journal
issn 2169-3536
language English
last_indexed 2025-02-17T18:58:40Z
publishDate 2024-01-01
publisher IEEE
record_format Article
series IEEE Access
spelling doaj.art-dbc6451e6cef4a6e9a2d3a73958187f62024-12-11T00:01:49ZengIEEEIEEE Access2169-35362024-01-01127637766010.1109/ACCESS.2023.334909510379079Self-Sovereign Identity for Organizations: Requirements for Enterprise SoftwareRicardo Bochnia0https://orcid.org/0009-0007-4317-1810Daniel Richter1https://orcid.org/0000-0003-1549-5467Jurgen Anke2https://orcid.org/0000-0002-9324-9387Digital Service Systems Group, HTWD – University of Applied Sciences, Dresden, GermanyDigital Service Systems Group, HTWD – University of Applied Sciences, Dresden, GermanyDigital Service Systems Group, HTWD – University of Applied Sciences, Dresden, GermanyIn recent years, the decentralized identity management approach known as Self-Sovereign Identity (SSI) has gained popularity. It aims to give individuals and organizations more control over their identities and credentials. Unfortunately, the adoption of SSI is impeded because the SSI community frequently overlooks the requirements of organizations. The organization’s roles as an issuer, verifier, and especially as a holder of Verifiable Credentials (VCs) remain largely unexplored. This is partly because SSI emerged as a user-centric approach focusing on privacy benefits for individuals who act as credential holders. To address this issue, we conducted a multi-method study to identify an initial set of general requirements for organizational SSI software. We used a triangulation approach consisting of a literature review, expert interviews, and product analysis. As a result, we present a comprehensive set of requirements grouped into three main categories: credential management, organizational identity and relationships, and additional requirements. We also examined potential constraints to SSI development and wider adoption in organizational settings. Furthermore, we present gaps between the found organizational-centric requirements and current SSI solutions. Thus, these requirements can serve as a starting point for developing better-tailored SSI software, which represents organizational needs and use cases more closely than current solutions.https://ieeexplore.ieee.org/document/10379079/Enterprise SSIenterprise walletidentity management systemorganizational walletorganizational SSIself-sovereign identity
spellingShingle Ricardo Bochnia
Daniel Richter
Jurgen Anke
Self-Sovereign Identity for Organizations: Requirements for Enterprise Software
IEEE Access
Enterprise SSI
enterprise wallet
identity management system
organizational wallet
organizational SSI
self-sovereign identity
title Self-Sovereign Identity for Organizations: Requirements for Enterprise Software
title_full Self-Sovereign Identity for Organizations: Requirements for Enterprise Software
title_fullStr Self-Sovereign Identity for Organizations: Requirements for Enterprise Software
title_full_unstemmed Self-Sovereign Identity for Organizations: Requirements for Enterprise Software
title_short Self-Sovereign Identity for Organizations: Requirements for Enterprise Software
title_sort self sovereign identity for organizations requirements for enterprise software
topic Enterprise SSI
enterprise wallet
identity management system
organizational wallet
organizational SSI
self-sovereign identity
url https://ieeexplore.ieee.org/document/10379079/
work_keys_str_mv AT ricardobochnia selfsovereignidentityfororganizationsrequirementsforenterprisesoftware
AT danielrichter selfsovereignidentityfororganizationsrequirementsforenterprisesoftware
AT jurgenanke selfsovereignidentityfororganizationsrequirementsforenterprisesoftware