COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity
Listen
Radio episode about this paper
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity".
Elias: The COD-ssi framework introduces a novel approach to Self-Sovereign Identity (SSI) that enforces mutual privacy during credential exchange by allowing Verifiers to selectively disclose a subset of claims without revealing…
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: So, we're looking at this paper titled "COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity," and the authors are Onofri, De Salve, Mori, Ricci, Di Pietroa. It sounds like they're tackling a specific weakness in how Selective Disclosure works within the SSI framework.
Elias: Yeah, it seems like they are proposing a way to make sure that even when a Verifier asks for data, the Holder doesn't know exactly what data is being requested or disclosed. The title itself hints at this mutual privacy aspect, which is pretty significant because we usually focus on protecting the Holder from their own data exposure.
Priya: From my side, I’m curious about what this means practically; does it actually solve a problem that's currently causing issues for data exchange? I'm hoping to see some tangible evidence of how this mechanism works in real-world scenarios involving sensitive information.
Nadia: Exactly, Priya, because right now, the literature shows that selective disclosure is mostly about protecting the Holder from themselves; COD-ssi seems designed to flip that dynamic by making the Verifier's selection process also private.
Elias: Precisely; it introduces a mechanism using Oblivious Pseudorandom Functions to achieve this mutual privacy during the exchange process, which is a technical shift in how we think about key derivation and disclosure.
The paper's summary: Nadia: Reading the abstract of "COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity," it boils down to this: they are fixing the gap where Verifiers could learn internal decision-making criteria or business rules by observing which claims a Holder is willing to expose.
Elias: It’s about ensuring that the Holder retains control over which claims are eligible for verification, but the Verifier's specific selection remains hidden from them, which is achieved through their proposed workflow.
Priya: I see the core idea: the Holder picks a subset of claims they want to expose, and then the Verifier chooses up to a certain number of those claims without the Holder knowing which ones were picked for disclosure. That sounds like it could be very useful for auditing AI systems where we need precise data checks.
Nadia: It moves beyond just protecting the Holder's privacy during disclosure; it's about making the Verifier’s query selection itself private, which is a crucial step in maintaining trust in decentralized environments.
Elias: The technical summary points to using Oblivious Pseudorandom Functions to obliviously derive decryption keys for claims, ensuring that the Holder doesn't learn which specific claim keys were used during verification.
The paper's improvements: Nadia: The authors introduce a few key improvements centered on this COD-ssi framework, specifically showing how it handles selective disclosure with obliviousness and oblivious key derivation simultaneously.
Elias: They outline the workflow where the Holder selects N claims, and the Verifier requests up to No claims without revealing which ones were selected, and then they use OPRF to derive those decryption keys obliviously. That's a very specific mechanism for achieving what they set out to do.
Priya: The paper shows that this setup satisfies two main objectives: selective disclosure with obliviousness and oblivious key derivation, which seems like a very clean way to formalize these privacy goals mathematically.
Nadia: And the security foundation is pretty solid, relying on three core primitive assumptions: the UC-secure nature of the underlying OPRF protocol, AES-GCM for encryption confidentiality and authenticity, and SHA-three commitments being secure in the ROM <ref:2604.10685#pg1>.
Elias: The formal verification under Theorem one establishes that this protocol satisfies Definition one against any Probabilistic Polynomial Time adversary, assuming those three primitives hold up in a standard compositional methodology <ref:2604.10685#pg1>.
Conclusion: Nadia: So, to wrap up the COD-ssi paper, the main implication is providing a robust way to enforce Verifier privacy during credential exchange by making the selection process itself blind to the Holder.
Elias: It establishes that achieving selective disclosure with obliviousness and oblivious key derivation is technically feasible within an SSI model under standard security assumptions.
Priya: I think this has big implications for regulated environments where we need precise auditing capabilities without revealing internal operational details to the auditors, especially when dealing with complex AI models.
Nadia: It certainly opens up new avenues for how decentralized identity systems can handle sensitive data exchange while maintaining strict privacy boundaries between different parties in the verification process.
Elias: And they do point out a limitation, which is that their current construction doesn't cryptographically bind together the tuple containing v i, x i, k i, (IV i, y i, u i) when a malicious Holder acts maliciously during the presentation creation phase.
Priya: That's important to hear; it means for now, they suggest solutions like issuer-assisted VP generation or using trusted environments to enforce that correct linkage between those components if we want to fully mitigate the risk of a malicious Holder tampering with the data itself.
Nadia: Well, that's all for this deep dive into "COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity." We’ll be back next time when we look at how these security primitives apply to model restriction and accountability in offensive AI governance.
Computer, Electrical and Mathematical Sciences and Engineering Division, King Abdullah University of Science and Technology · Institute of Applied Sciences and Intelligent Systems, National Research Council of Italy (CNR) · Istituto di Informatica e Telematica, National Research Council of Italy (CNR) · Department of Computer Science, University of Pisa
cs.CR, cs.CY, cs.DC, cs.ET
Submitted: 2026-04-12
Updated: 2026-04-12
Comments: 27 pages, 10 Figures, 2 Tables
Journal ref: Computer Security -- ESORICS 2026. Lecture Notes in Computer Science, vol 16969. Springer, Cham
DOI: 10.1007/978-3-032-38695-3_11
Code: https://github.com/paulmillr/noble-curves
License: http://creativecommons.org/licenses/by-sa/4.0/
Importance score: 83/100
The gist: The COD-ssi framework introduces a novel approach to Self-Sovereign Identity (SSI) that enforces mutual privacy during credential exchange by allowing Verifiers to selectively disclose a subset of
Key concepts
- Oblivious Pseudorandom Functions (OPRFs)
- These are cryptographic functions used to allow a Verifier to derive decryption keys without knowing which specific input data (claims) was selected by the Holder. This ensures that the Verifier can check a claim's validity without learning the details of the selection process.
- Selective Disclosure with Obliviousness
- This is COD-ssi's core goal: letting a Holder choose which parts of their identity to show (selective disclosure) while making sure the Verifier cannot figure out exactly which pieces were chosen (obliviousness). This protects the Holder's internal decision-making from being exposed.
- Verifiable Presentation (VP)
- A VP is the package containing encrypted claims that a Holder presents to a Verifier. In COD-ssi, each claim value is encrypted using a key derived through an OPRF, making it possible for the Verifier to verify the data without seeing the raw claim values directly.
Terminology
Summary
The COD-ssi framework introduces a novel approach to Self-Sovereign Identity (SSI) that enforces mutual privacy during credential exchange by allowing Verifiers to selectively disclose a subset of claims without revealing which specific claims were accessed to the Holder. This mechanism is crucial because current selective disclosure methods primarily protect the Holder, leaving Verifiers vulnerable to learning sensitive internal decision-making criteria or business rules.
How it works
The COD-ssi model leverages Oblivious Pseudorandom Functions (OPRFs) to achieve this mutual privacy. The workflow involves several key steps:
-
The Holder selects a subset of claims they are willing to expose, denoted as N claims out of a total set N.
-
The Verifier declares access requires
No claims from this admissible set, without revealing which ones.
-
The Holder prepares a Verifiable Presentation (VP) where each claim value is encrypted under a key derived via the OPRF from its hash commitment, specifically:
ki = FmskVP (xi), where xi = H(vi∥ti).
-
During verification, the Verifier engages in an OPRF protocol to
obliviously derive the corresponding decryption keys ki without revealing which claims were selected.
This design ensures that the Holder retains control over which claims are eligible for verification, while the Verifier’s specific selection remains hidden. The framework is designed to satisfy two complementary objectives: Selective disclosure with obliviousness
and Oblivious key derivation.
Security Foundation
The security of COD-ssi is formally verified under a standard compositional methodology, relying on three core primitive assumptions. The main security theorem (Theorem 1) establishes that the protocol satisfies Definition 1 against any Probabilistic Polynomial Time (PPT) adversary. This proof sketch relies on:
((
The underlying OPRF protocol being UC-secure
or secure in the ROM against malicious adversaries, using constructions like 2HashDH.
((
The symmetric encryption primitive (AES-GCM) providing IND-CPA confidentiality and INT-CTXT authenticity.
((
The selective disclosure mechanism (SHA-3 commitments) being secure in the ROM.
Adversarial Setting and Guarantees
The threat model considers three internal roles: a Malicious Verifier (AV), a Malicious Holder (AS), and an External malicious adversary. The security statements derived from this model include:
-
Confidentiality of non-disclosed claims: An adversary that does not obtain the correct claim key ki learns
no information on vi beyond trivial leakage.
-
Integrity and authenticity: Any modification of encrypted credential data is
detected by the Verifier with overwhelming probability.
-
Client (Verifier) obliviousness: A malicious Holder cannot distinguish which claim indices were queried beyond what is implied by policy-triggered actions, such as
quota exhaustion.
-
Issuer verifiability: The validity of each claim remains
cryptographically verifiable against the Issuer’s signature in the corresponding VC.
Performance and Feasibility
Experimental results demonstrate that provable mutual privacy can be achieved with only moderate computational and communication overhead.
The study evaluates performance across different numbers of claims (N), showing:
(1) Claim level:
The cost of hashing and verifying a claim is negligible, but encryption (cf. ll.8–11 from Algorithm 1) and decryption (cf. ll.11–14 from Algorithm 2) dominate per-claim processing.
For example, encryption requires an average of 7.6 ms
for a VC with 2 claims on the Holder side, while decryption averages 6.3 ms
on the Verifier side.
(2) Presentation level:
The overhead introduced by COD-ssi is measurable but manageable: disclosure times range from a few milliseconds to under two seconds for presentations containing up to 128 claims.
Storage requirements remain between a few kilobytes and roughly 1 MB for the same setting.
Limitations and Future Directions
The primary limitation identified is the vulnerability arising when the Holder behaves maliciously during VP creation. Specifically, the current construction does not cryptographically bind together the tuple vi, xi, ki, (IVi, yi, ui).
This means a malicious Holder could potentially encrypt a modified claim value while keeping the Issuer commitment unchanged. Mitigations discussed include:
-
Issuer-assisted VP generation to validate constructions at presentation time.
-
A
Trusted VP-generation environment
using secure enclaves or trusted wallet engines to enforce correct linkage between components. -
Zero-knowledge proofs of correct encryption, though this introduces
significant computational cost.
The paper concludes by suggesting future research directions, including extending COD-ssi to alternative selective-disclosure paradigms like encrypted credential schemes and integrating publicly auditable VP specifications for regulatory compliance verification.
Improvements for AI systems
As a fastidious researcher, I have analyzed the COD-ssi framework. This solution fundamentally solves a critical privacy gap in Self-Sovereign Identity (SSI) by enforcing mutual privacy during credential exchange, specifically addressing Verifier privacy while maintaining Holder control over disclosure policies.
Here are the specific improvements and capabilities this paper enables for AI systems:
) Improvement 1: Enforced Mutual Privacy in Sensitive Data Exchange
The core improvement is the introduction of COD-ssi, which leverages Oblivious Pseudorandom Functions (OPRF) to allow a Verifier to selectively access a subset of claims from a Verifiable Presentation (VP) without revealing the specific claims accessed to the Holder.
-
What it does: It ensures that the act of querying for specific data points does not leak information about which data points are being queried. This is achieved by having the Holder obliviously derive decryption keys for only the requested claims, while remaining unaware of those requests.
-
Improved AI System Capability: AI systems (e.g., medical diagnostic tools, financial risk assessment models) can securely ingest and process sensitive proprietary data from multiple sources (VCs) without exposing their internal decision-making logic or strategic plans to the verifier, even if the verifier's query is highly specific.
) Improvement 2: Granular, Policy-Bound Data Minimization for Verifiers
The framework formalizes a strict constraint: the Verifier can request at most 'No' claims from a set of 'N' available claims without knowing which ones were selected. This prevents over-querying
attacks where an adversary tries to map out the entire dataset by requesting a superset of data.
-
What it does: It allows regulated entities (like financial institutions or researchers) to define exactly how much information is needed for a specific task ('No' claims) while hiding the actual selection from the subject (Holder).
-
Improved AI System Capability: AI models used in compliance auditing or risk scoring can operate under GDPR/HIPAA constraints. For instance, a credit scoring AI can be audited by a financial regulator to confirm that only exactly three specific attributes (e.g., income, debt-ratio, delinquency count) are accessed for a loan decision, without the bank revealing its proprietary risk model structure or internal thresholds.
) Improvement 3: Protection Against Malicious Verifiers
The security proof explicitly addresses a malicious Verifier (AV). The framework ensures that even if the Verifier attempts to learn which claims were queried, they cannot gain any information beyond what is implied by pre-defined policy-observable events (like quota exhaustion).
-
What it does: It provides a strong guarantee against an attacker actively trying to infer data by observing the protocol transcript.
-
Improved AI System Capability: In decentralized or multi-party AI environments where multiple entities might be acting as verifiers, this protects the integrity of the data exchange. An external auditing agent (Verifier) cannot compromise the privacy of internal operational parameters being used by a Holder (Holder), even if that agent tries to adapt its queries based on previous results.
) Improvement 4: Efficiency-Aware Selective Disclosure
The experimental results show that provable mutual privacy can be achieved with moderate computational and communication overhead,
and the complexity scales linearly with the number of claims (N). Furthermore, the system distinguishes between efficient Batch Mode and flexible Adaptive Mode.
-
What it does: It provides a practical method for implementing high-security disclosure without incurring prohibitive latency or storage costs.
-
Improved AI System Capability: Allows for real-time applications (e.g., in clinical settings) where data access must be near instantaneous (milliseconds). The ability to use Batch Mode optimizes communication rounds, making the system viable for high-throughput verification scenarios.
) Improvement 5: Resilience Against Malicious Holders
While the framework's creation phase is vulnerable to a malicious Holder tampering with encryption/key derivation, it provides a clear roadmap (Issuer assistance or Trusted Environments) for mitigating this.
-
What it does: It identifies the precise point of failure (VP creation) and suggests solutions like Issuer-assisted generation or secure enclaves to enforce correct data binding.
-
Improved AI System Capability: For critical AI infrastructure, this allows developers to design systems that are robust against insider threats (Malicious Holder), ensuring that the Verifier cannot force the system to decrypt unauthorized or modified data subsets.
Abstract
The Self-Sovereign Identity (SSI) paradigm is instrumental for decentralised identity management, allowing an entity to create, manage, and present their digital credentials without relying on centralised authorities. Credential selective disclosure is one of the most attractive privacy-preserving features of SSI, allowing users to reveal only the minimum necessary information from their credentials. However, current selective disclosure mechanisms primarily focus on protecting the privacy of credential Holders, while offering limited protection to the Verifiers of credentials. Indeed, the specific credential information requested by a Verifier can inadvertently reveal to credential Holders sensitive information, including internal decision-making criteria, business rules, or strategic plans. In this work, we address this threat by proposing, to the best of our knowledge, the first approach that enforces mutual privacy in credential exchanges. To this end, we introduce COD-ssi (Claim Oblivious Disclosure for SSI), a novel framework that leverages Oblivious Pseudorandom Functions to allow Verifiers to selectively access a subset of claims without revealing which specific claims were accessed to the credential Holder. The security of our solution is formally verified and its feasibility is assessed through the experimental evaluation of our open-source prototype implementation. These results show that provable mutual privacy in the context of SSI can be achieved with just moderate computational and communication overhead.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs