Self-Sovereign Identity (SSI) is gaining increasing attention as a means to mitigate privacy risks in digital identity management. In this context, the use of Zero-Knowledge Proofs (ZKPs) enables privacy-preserving authentication by allowing users to prove statements about their attributes without disclosing the attributes themselves. However, the signature schemes and proof mechanisms used to protect verifiable credentials may become vulnerable to quantum-capable adversaries. To this end, this paper introduces a user-centric, privacy-preserving attribute-based authentication framework designed for edge–cloud environments. The framework introduces an upgrade protocol able to convert traditional Verifiable Credentials (VCs) into Post-Quantum Zero-Knowledge Verifiable Credentials (PQZKVCs) and uses zk-STARKs to support privacy-preserving verification of predicates over committed attributes. To assess the feasibility of the proposed approach, we implemented the entire workflow and tested it on two different devices. Our microbenchmarks reveal a median end-to-end upgrade latency of 9.405 ms on the server-class device and 113.535 ms on the edge device, with a credential size of 7.229 KB. The median end-to-end presentation latency is 20.377 ms on the server-class device and 154.659 ms on the edge device, with a presentation size of 16.336 KB. For the zk-STARK proof layer, the highest-security single-attribute configuration tested requires 1957.994 ms for proof generation and 7.021 ms for verification on the edge device. These results indicate that post-quantum, privacy-preserving decentralized authentication can be deployed in edge settings with acceptable verification latency and communication overhead, while proof generation remains the dominant cost on resource-constrained devices.
Post-quantum Self-Sovereign Identity: Implementing ZK-STARKs for secure attribute-based authentication in edge devices
Boi, Biagio;Cirillo, Franco;De Santis, Marco;Esposito, Christian
2026
Abstract
Self-Sovereign Identity (SSI) is gaining increasing attention as a means to mitigate privacy risks in digital identity management. In this context, the use of Zero-Knowledge Proofs (ZKPs) enables privacy-preserving authentication by allowing users to prove statements about their attributes without disclosing the attributes themselves. However, the signature schemes and proof mechanisms used to protect verifiable credentials may become vulnerable to quantum-capable adversaries. To this end, this paper introduces a user-centric, privacy-preserving attribute-based authentication framework designed for edge–cloud environments. The framework introduces an upgrade protocol able to convert traditional Verifiable Credentials (VCs) into Post-Quantum Zero-Knowledge Verifiable Credentials (PQZKVCs) and uses zk-STARKs to support privacy-preserving verification of predicates over committed attributes. To assess the feasibility of the proposed approach, we implemented the entire workflow and tested it on two different devices. Our microbenchmarks reveal a median end-to-end upgrade latency of 9.405 ms on the server-class device and 113.535 ms on the edge device, with a credential size of 7.229 KB. The median end-to-end presentation latency is 20.377 ms on the server-class device and 154.659 ms on the edge device, with a presentation size of 16.336 KB. For the zk-STARK proof layer, the highest-security single-attribute configuration tested requires 1957.994 ms for proof generation and 7.021 ms for verification on the edge device. These results indicate that post-quantum, privacy-preserving decentralized authentication can be deployed in edge settings with acceptable verification latency and communication overhead, while proof generation remains the dominant cost on resource-constrained devices.I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.


