COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity
summary
The gist
The COD-ssi framework introduces a novel approach to Self-Sovereign Identity (SSI) that enforces mutual privacy during credential exchange by allowing Verifiers to selectively disclose a subset of
In short
COD-ssi introduces a method for Self-Sovereign Identity that ensures mutual privacy during credential exchange. It allows a Holder to selectively share claims while preventing Verifiers from learning which specific claims were accessed, solving the problem where current methods only protect the Holder.
Key concepts
- Oblivious Pseudorandom Functions (OPRFs)
- These are cryptographic functions used to allow a Verifier to derive decryption keys without knowing which specific input data (claims) was selected by the Holder. This ensures that the Verifier can check a claim's validity without learning the details of the selection process.
- Selective Disclosure with Obliviousness
- This is COD-ssi's core goal: letting a Holder choose which parts of their identity to show (selective disclosure) while making sure the Verifier cannot figure out exactly which pieces were chosen (obliviousness). This protects the Holder's internal decision-making from being exposed.
- Verifiable Presentation (VP)
- A VP is the package containing encrypted claims that a Holder presents to a Verifier. In COD-ssi, each claim value is encrypted using a key derived through an OPRF, making it possible for the Verifier to verify the data without seeing the raw claim values directly.
Terminology used across episodes
This episode discusses
- COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity · Paper Radio
The paper
COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity · Read on arXiv
Computer, Electrical and Mathematical Sciences and Engineering Division, King Abdullah University of Science and Technology · Institute of Applied Sciences and Intelligent Systems, National Research Council of Italy (CNR) · Istituto di Informatica e Telematica, National Research Council of Italy (CNR) · Department of Computer Science, University of Pisa
The Self-Sovereign Identity (SSI) paradigm is instrumental for decentralised identity management, allowing an entity to create, manage, and present their digital credentials without relying on centralised authorities. Credential selective disclosure is one of the most attractive privacy-preserving features of SSI, allowing users to reveal only the minimum necessary information from their credentials. However, current selective disclosure mechanisms primarily focus on protecting the privacy of credential Holders, while offering limited protection to the Verifiers of credentials. Indeed, the specific credential information requested by a Verifier can inadvertently reveal to credential Holders sensitive information, including internal decision-making criteria, business rules, or strategic plans. In this work, we address this threat by proposing, to the best of our knowledge, the first approach that enforces mutual privacy in credential exchanges. To this end, we introduce COD-ssi (Claim Oblivious Disclosure for SSI), a novel framework that leverages Oblivious Pseudorandom Functions to allow Verifiers to selectively access a subset of claims without revealing which specific claims were accessed to the credential Holder. The security of our solution is formally verified and its feasibility is assessed through the experimental evaluation of our open-source prototype implementation. These results show that provable mutual privacy in the context of SSI can be achieved with just moderate computational and communication overhead.
DOI: 10.1007/978-3-032-38695-3_11
Transcript
Introduction to the show: ident: Security Radio. Generated commentary on the latest security and cryptography papers.
Nadia: Today's paper: "COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity".
Elias: The COD-ssi framework introduces a novel approach to Self-Sovereign Identity (SSI) that enforces mutual privacy during credential exchange by allowing Verifiers to selectively disclose a subset of claims without revealing…
Nadia: First, who's behind it and why it matters.
Title and authors: Nadia: So, we're looking at this paper titled "COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity," and the authors are Onofri, De Salve, Mori, Ricci, Di Pietroa. It sounds like they're tackling a specific weakness in how Selective Disclosure works within the SSI framework.
Elias: Yeah, it seems like they are proposing a way to make sure that even when a Verifier asks for data, the Holder doesn't know exactly what data is being requested or disclosed. The title itself hints at this mutual privacy aspect, which is pretty significant because we usually focus on protecting the Holder from their own data exposure.
Priya: From my side, I’m curious about what this means practically; does it actually solve a problem that's currently causing issues for data exchange? I'm hoping to see some tangible evidence of how this mechanism works in real-world scenarios involving sensitive information.
Nadia: Exactly, Priya, because right now, the literature shows that selective disclosure is mostly about protecting the Holder from themselves; COD-ssi seems designed to flip that dynamic by making the Verifier's selection process also private.
Elias: Precisely; it introduces a mechanism using Oblivious Pseudorandom Functions to achieve this mutual privacy during the exchange process, which is a technical shift in how we think about key derivation and disclosure.
The paper's summary: Nadia: Reading the abstract of "COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity," it boils down to this: they are fixing the gap where Verifiers could learn internal decision-making criteria or business rules by observing which claims a Holder is willing to expose.
Elias: It’s about ensuring that the Holder retains control over which claims are eligible for verification, but the Verifier's specific selection remains hidden from them, which is achieved through their proposed workflow.
Priya: I see the core idea: the Holder picks a subset of claims they want to expose, and then the Verifier chooses up to a certain number of those claims without the Holder knowing which ones were picked for disclosure. That sounds like it could be very useful for auditing AI systems where we need precise data checks.
Nadia: It moves beyond just protecting the Holder's privacy during disclosure; it's about making the Verifier’s query selection itself private, which is a crucial step in maintaining trust in decentralized environments.
Elias: The technical summary points to using Oblivious Pseudorandom Functions to obliviously derive decryption keys for claims, ensuring that the Holder doesn't learn which specific claim keys were used during verification.
The paper's improvements: Nadia: The authors introduce a few key improvements centered on this COD-ssi framework, specifically showing how it handles selective disclosure with obliviousness and oblivious key derivation simultaneously.
Elias: They outline the workflow where the Holder selects N claims, and the Verifier requests up to No claims without revealing which ones were selected, and then they use OPRF to derive those decryption keys obliviously. That's a very specific mechanism for achieving what they set out to do.
Priya: The paper shows that this setup satisfies two main objectives: selective disclosure with obliviousness and oblivious key derivation, which seems like a very clean way to formalize these privacy goals mathematically.
Nadia: And the security foundation is pretty solid, relying on three core primitive assumptions: the UC-secure nature of the underlying OPRF protocol, AES-GCM for encryption confidentiality and authenticity, and SHA-three commitments being secure in the ROM <ref:2604.10685#pg1>.
Elias: The formal verification under Theorem one establishes that this protocol satisfies Definition one against any Probabilistic Polynomial Time adversary, assuming those three primitives hold up in a standard compositional methodology <ref:2604.10685#pg1>.
Conclusion: Nadia: So, to wrap up the COD-ssi paper, the main implication is providing a robust way to enforce Verifier privacy during credential exchange by making the selection process itself blind to the Holder.
Elias: It establishes that achieving selective disclosure with obliviousness and oblivious key derivation is technically feasible within an SSI model under standard security assumptions.
Priya: I think this has big implications for regulated environments where we need precise auditing capabilities without revealing internal operational details to the auditors, especially when dealing with complex AI models.
Nadia: It certainly opens up new avenues for how decentralized identity systems can handle sensitive data exchange while maintaining strict privacy boundaries between different parties in the verification process.
Elias: And they do point out a limitation, which is that their current construction doesn't cryptographically bind together the tuple containing v i, x i, k i, (IV i, y i, u i) when a malicious Holder acts maliciously during the presentation creation phase.
Priya: That's important to hear; it means for now, they suggest solutions like issuer-assisted VP generation or using trusted environments to enforce that correct linkage between those components if we want to fully mitigate the risk of a malicious Holder tampering with the data itself.
Nadia: Well, that's all for this deep dive into "COD-ssi: Enforcing Mutual Privacy for Credential Oblivious Disclosure in Self Sovereign Identity." We’ll be back next time when we look at how these security primitives apply to model restriction and accountability in offensive AI governance.
More episodes
- 2610.10644-SoK: Failure Modes in Common Criteria Product Evaluation - A Taxonomy and Design-for-Evaluability Guidance
- 2610.10617-MRCert: Towards Post-deployment Patch Robustness Certification for Adversarially Patched Samples via Type-specific Masking
- 2610.10620-When AI Finds Hidden Messages, Does It Report?
- 2610.10625-Safe at One Loop, Risky at Another: Aligning Safety Across Recurrent Depths in Looped Language Models
- 2610.10992-The Hint Weight of ML-DSA Signatures Is Key-Dependent: An Empirical Study across the Three FIPS 204 Parameter Sets
- 2610.10659-Applying Security by Design at the Point of Execution: How Governed Security Requirements Affect the Security of AI-Generated Code
- 2610.10735-DITTO: A Context-aware Pickle-based Pre-Trained Model Scanner for Effective Security Audits
- 2610.10742-BRANCH: Bypassing Multi-Scanner AI Guardrails
- 2610.10752-Detection-Guided Adaptive Purification with Diffusion Models for Robust Audio Deepfake Detection
- 2610.10766-CPU-Auth: Device Fingerprinting for Authentication via DVFS Side-Channel