Self-Sovereign Identity (SSI) harbors a structural blind spot that limits its evolution, the lack of a standardized workflow for issuing Multi-Issuer Verifiable Credentials (MultiIssVC). This limitation hampers collaborative certificate issuance, a crucial aspect of the Web3 ecosystem. SSI, which aids collaboration among entities, would greatly benefit from a standardized Multi-Issuer mechanism, especially for large-scale applications like supply chain management and the upcoming European Battery Passport regulation in 2027. In SSI, holders present Verifiable Credentials (VCs) issued by trusted entities, represented by Decentralized Identifiers (DIDs) for verification via Verifiable Data Registries (VDRs) like blockchains. However, most DID methods do not support multi-signature keys, further restricting collaborative issuance. To address this pressing issue, we propose the OrchestraBLS protocol, which augments any DID with Boneh-Lynn-Shacham (BLS) keys, allowing multiple Issuers to sign and issue a MultiIssVC jointly. In our approach, each Issuer's Proof of Ownership (PoO) to its DID-specific key is preceded by a Proof of Possession phase to prevent rogue-key attacks. An orchestrator aggregates the individual signatures and PoOs to generate a final MultiIssVC. Following further refinements of the protocol, we plan to detail an extension of the Veramo framework to demonstrate reduced time and storage overhead compared to issuing separate VCs with the same claims on commodity and IoT devices.

From Solo Issuing to an Orchestra: Design and Seamless Augmentation of Self-Sovereign Identity for Multi-Signature Verifiable Credentials

Calogero Turco
;
Laura Ricci
2026-01-01

Abstract

Self-Sovereign Identity (SSI) harbors a structural blind spot that limits its evolution, the lack of a standardized workflow for issuing Multi-Issuer Verifiable Credentials (MultiIssVC). This limitation hampers collaborative certificate issuance, a crucial aspect of the Web3 ecosystem. SSI, which aids collaboration among entities, would greatly benefit from a standardized Multi-Issuer mechanism, especially for large-scale applications like supply chain management and the upcoming European Battery Passport regulation in 2027. In SSI, holders present Verifiable Credentials (VCs) issued by trusted entities, represented by Decentralized Identifiers (DIDs) for verification via Verifiable Data Registries (VDRs) like blockchains. However, most DID methods do not support multi-signature keys, further restricting collaborative issuance. To address this pressing issue, we propose the OrchestraBLS protocol, which augments any DID with Boneh-Lynn-Shacham (BLS) keys, allowing multiple Issuers to sign and issue a MultiIssVC jointly. In our approach, each Issuer's Proof of Ownership (PoO) to its DID-specific key is preceded by a Proof of Possession phase to prevent rogue-key attacks. An orchestrator aggregates the individual signatures and PoOs to generate a final MultiIssVC. Following further refinements of the protocol, we plan to detail an extension of the Veramo framework to demonstrate reduced time and storage overhead compared to issuing separate VCs with the same claims on commodity and IoT devices.
2026
979-8-4007-2294-3
File in questo prodotto:
File Dimensione Formato  
3748522.3779844.pdf

accesso aperto

Tipologia: Versione finale editoriale
Licenza: Creative commons
Dimensione 583.64 kB
Formato Adobe PDF
583.64 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11568/1361969
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
social impact