Please use this identifier to cite or link to this item: https://www.um.edu.mt/library/oar/handle/123456789/121939
Full metadata record
DC FieldValueLanguage
dc.date.accessioned2024-05-08T09:06:14Z-
dc.date.available2024-05-08T09:06:14Z-
dc.date.issued2023-
dc.identifier.citationJain, S. (2023). Decentralised identity and access management model: a self-sovereign identity solution for enterprises and employees: empowering employees with data subject rights and transparent control over their shared credentials and attributes using private or permissioned blockchain technology (Master's dissertation).en_GB
dc.identifier.urihttps://www.um.edu.mt/library/oar/handle/123456789/121939-
dc.descriptionM.Sc.(Melit.)en_GB
dc.description.abstractEnterprises are affected by data breaches and associated overheads. The classical identity and access management models rely on centralised third-party certificate authority for authentication, leading to a single point of failure. In these systems, the access control systems are either role-based or attribute-based with limited attention to employee identity information. Cloud-based identity provider solutions necessitate data sharing for access permission handling, the data may be stored securely but can be misused without transparent processing and consent management. These systems store copious amounts of sensitive employee data which makes them lucrative for malicious attackers. Decentralised identity systems, particularly self-sovereign identity systems propose solutions. Designed using public permissioned blockchains, self-sovereign identity systems allow the users to gain complete control of their identifiers and personal data which is stored locally with the users. While SSI models exist for customers and patients, employee data security is often overlooked. This study critically reviews classical identity systems in the context of employee identity systems, access control policies and data subject rights. It explores decentralised identity systems and the necessary components for self-sovereign identity functionality. The model leverages privacy-preserving standardised technologies by aggregating these technologies inspired by existing systems, like decentralised identifiers, verifiable credentials, smart contracts and zero-knowledge proofs along with private permissioned Hyperledger Fabric. This model aligns with European General Data Protection Regulation principles and data subject rights, enabling employees to access both the internal database and service application through decentralised identifiers and verifiable presentations. This dissertation constitutes a qualitative desk-based research analysing employee privacy and security concerns in classical identity management systems, decentralised identity systems, decentralised access control and the association of technical components with regulatory compliance. Employing thematic analysis of the research articles through inductive and deductive coding techniques to prepare a theoretical framework. The research aims to assess the potential and challenges in permissioned self-sovereign identity ecosystems and introduces a conceptual model addressing concerns about employee data protection and control.en_GB
dc.language.isoenen_GB
dc.rightsinfo:eu-repo/semantics/restrictedAccessen_GB
dc.subjectBlockchains (Databases)en_GB
dc.subjectDatabase securityen_GB
dc.subjectOnline identitiesen_GB
dc.subjectSmart contractsen_GB
dc.subjectEuropean Parliament. General Data Protection Regulationen_GB
dc.subjectData protection -- Law and legislation -- European Union countriesen_GB
dc.titleDecentralised identity and access management model : a self-sovereign identity solution for enterprises and employees : empowering employees with data subject rights and transparent control over their shared credentials and attributes using private or permissioned blockchain technologyen_GB
dc.typemasterThesisen_GB
dc.rights.holderThe copyright of this work belongs to the author(s)/publisher. The rights of this work are as defined by the appropriate Copyright Legislation or as modified by any successive legislation. Users may access this work and can make use of the information contained in accordance with the Copyright Legislation provided that the author must be properly acknowledged. Further distribution or reproduction in any format is prohibited without the prior permission of the copyright holder.en_GB
dc.publisher.institutionUniversity of Maltaen_GB
dc.publisher.departmentCentre for Distributed Ledger Technologiesen_GB
dc.description.reviewedN/Aen_GB
dc.contributor.creatorJain, Siddharth (2023)-
Appears in Collections:Dissertations - CenDLT - 2023

Files in This Item:
File Description SizeFormat 
2318DLTDLT590005075983_1.PDF
  Restricted Access
1.97 MBAdobe PDFView/Open Request a copy


Items in OAR@UM are protected by copyright, with all rights reserved, unless otherwise indicated.