SearcharxivSearch

arXiv subjects

Francesco Bruschi

Publications and source records attributed to Francesco Bruschi.

3 recordsLinked to original sources

Self-Sovereign Identity and eIDAS 2.0: An Analysis of Control, Privacy, and Legal Implications

European digital identity initiatives are grounded in regulatory frameworks designed to ensure interoperability and robust, harmonized security standards. The evolution of these frameworks culminates in eIDAS 2.0, whose origins trace back to the Electronic Signatures Directive 1999/93/EC, the first EU-wide legal foundation for the use of electronic signatures in cross-border electronic transactions. As technological capabilities advanced, the initial eIDAS 1.0 framework was increasingly criticized for its limitations and lack of comprehensiveness. Emerging decentralized approaches further exposed these shortcomings and introduced the possibility of integrating innovative identity paradigms, such as Self-Sovereign Identity (SSI) models. In this article, we contribute to the ongoing legal and policy debate on the European Digital Identity Framework by analyzing key provisions of eIDAS 2.0 and its accompanying recitals, drawing on a systematic literature review guided by defined Research Questions (RQ). This work employs a structured methodological approach that combines descriptive and comparative analysis, systematic gap analysis supported by a defined scoring matrix, and normative analysis to evaluate the compatibility of SSI properties with eIDAS 2.0 regulation, as operationalized via its Architecture and Reference Framework (ARF). Furthermore, we assess the ARF's guidelines and examine the extent to which it aligns with SSI. The analysis adopts a complementary perspective demonstrating how the regulation can be further developed to better support SSI in the future by identifying existing limitations and potential adoption opportunities within the current legal foundations of the framework.

cs.CR

Enabling SSI-Compliant Use of EUDI Wallet Credentials through Trusted Execution Environment and Zero-Knowledge Proof

The passing of the eIDAS amendment marks an important milestone for EU countries and changes how they must manage digital credentials for both public services and businesses. Italy has led in adopting eIDAS, first with CIE and SPID identity schemes, and now with the Italian Wallet (IO app) aligned to eIDAS 2.0. Self-Sovereign Identity (SSI) is a decentralized model born from the success of Distributed Ledgers, giving individuals full control over their digital identity. The current eIDAS 2.0 and its implementation acts diverge from SSI principles, rendering the European Digital Identity Wallet (EUDIW) centralized and merely user-centric, prioritizing security and legal protection over true self-sovereignty. This paper proposes an architecture that enables the use of IT Wallet credentials and services in an SSI-compliant environment through Trusted Execution Environments and Zero-Knowledge Proofs.

cs.ET

A Private Smart Wallet with Probabilistic Compliance

We propose a privacy-preserving smart wallet with a novel invitation-based private onboarding mechanism. The solution integrates two levels of compliance in concert with an authority party: a proof of innocence mechanism and an ancestral commitment tracking system using bloom filters for probabilistic UTXO chain states. Performance analysis demonstrates practical efficiency: private transfers with compliance checks complete within seconds on a consumer-grade laptop, and overall with proof generation remaining low. On-chain costs stay minimal, ensuring affordability for all operations on Base layer 2 network. The wallet facilitates private contact list management through encrypted data blobs while maintaining transaction unlinkability. Our evaluation validates the approach's viability for privacy-preserving, compliance-aware digital payments with minimized computational and financial overhead.

cs.CR