What we think about Verifiable Credentials (VCs) and Self-Sovereign Identity (SSI)

By Agora Citizen Network (@agoracitizen.network)
Published:

The internet was originally created to connect computers, not humans. The design choices of the past render today's internet inadequate in safeguarding ethical and democratic values. User data is collected, owned, and managed by a handful of powerful organizations, leading to a reality where your digital identities are defined by what Google knows about you. Meanwhile, trust is broken on the internet—without a thorough background check, nothing can be verified or trusted. Social media platforms have become breeding grounds of misinformation, scams, hate speech, and bots.

Self-Sovereign Identity (SSI), or Decentralized Identity, represents a suite of human-centric technologies designed to empower individuals with full control over their digital identities and personal data. Users granularly decide what information they share, allowing them to, for instance, verify their age without exposing their entire ID card or prove to landlords that their income is sufficient without handing over their bank statements.

The W3C-standardized Verifiable Credentials Data Model defines a trust relationship involving three key roles: the Issuer, Holder, and Verifier. For illustration, a government (Issuer) issues a passport (Credential) to a citizen (Holder). Traditionally, when a citizen checks in at a hotel (Verifier), they must physically hand over their passport to the receptionist, who then verifies and copies the passport. This process is time-consuming and susceptible to security risks, such as fraud and identity theft. Verifiable Credentials offer a significantly more secure and seamless authentication process.

Several democracies are actively developing VC-based digital credentials to empower their citizens. In alignment with the eIDAS 2.0 regulation, the European Commission is realizing its vision of a cross-border European Digital Identity for all EU residents by 2027.

At present, various types of Verifiable Credentials are in development, each carrying its unique advantages and limitations. Balancing the delicate trade-off between security and privacy can be challenging. As of today, BBS+ Verifiable Credentials are the most private, because they are the only type of VCs that can achieve Issuer Unlinkability, on top of Selective Disclosure and Verifier Unlinkability:

Two Use-Cases:

The distinction between security-based and privacy-based VCs reflects the direction that the community is currently taking. However, within the next 5-10 years, there is a possibility that the two VCs would merge, particularly with the development of performant general-purpose client-side zkVMs (see the ZKP section).

Data can optionally be addressed via its semantics (JSON-LD, RDF, etc.)

Advantages:

Limitations:

Could it be useful for our requirements?

SSI and the privacy-preserving flavors of Verifiable Credentials are the crucial credential infrastructure that we need to provide an authentication system that is both privacy-preserving and protects against bots and sybil attacks, with comprehensive support for hard security issues such as account recovery and revocation. Verifiable Credentials are also highly interoperable across protocols, which is a wanted feature.