DSR Knowledge LibraryReusable design knowledge and grounded research support
HomeLibraryChatGive feedback โ†—

DSR Knowledge Library

Research prototype ยท Native Open Knowledge Format

LibraryChatImprintPrivacyEvaluation survey โ†—
Library/Papers/Designing a Framework for Digital KYC Processes Built on Blockchain-Based Self-Sovereign Identity

Research paper

Designing a Framework for Digital KYC Processes Built on Blockchain-Based Self-Sovereign Identity

The paper derives six design objectives (16 sub-requirements) for an SSI-based eKYC framework and demonstrates how blockchain-based self-sovereign identity can solve KYC challenges without violating data-protection regulation, deriving three nascent design principles that theorize blockchain's role for SSI: use blockchain only for public data, anticipate an ecosystem of various ledgers, and enable decentralization at the edge.

Paper
OverviewDSR gridPaper design mapDesign knowledgePublication metadata

01

Overview

Publication metadata and narrative from the current library record.

Authors
Vincent Schlatt, Johannes Sedlmeir, Simon Feulner, Nils Urbach
Year
2022
Venue
Information & Management 59 (2022) 103553
Methodology
Design science research; six solution objectives from literature and regulation; expert interviews (ex ante and ex post evaluation).
DOI
10.1016/j.im.2021.103553
Design knowledge
View design knowledge on GitHub
bankingblockchaindesign-science-researchidentity-ssikyckyc-framework-ssiverifiable-credentials

Summary

The paper derives six design objectives (16 sub-requirements) for an SSI-based eKYC framework and demonstrates how blockchain-based self-sovereign identity can solve KYC challenges without violating data-protection regulation, deriving three nascent design principles that theorize blockchain's role for SSI: use blockchain only for public data, anticipate an ecosystem of various ledgers, and enable decentralization at the edge.

Artifact

An SSI-based electronic KYC (eKYC) framework and architecture for banks.

Methodology

Design science research; six solution objectives from literature and regulation; expert interviews (ex ante and ex post evaluation).

02

DSR grid

Six dimensions represented in the current paper record.

01

Problem description

KYC processes are costly, inefficient and inconvenient; blockchain is proposed as a remedy, but it is unclear how to exploit its advantages without violating data-protection regulation and customer privacy.

02

Input knowledge

Self-sovereign identity and verifiable credentials; network-effects theory; GDPR/eIDAS regulation; prior DSR in the domain.

03

Research process

Design science research: six main objectives and 16 associated requirements derived from literature and regulation, with ex ante and ex post expert interviews for evaluation.

04

Key concepts

Banking, digital certificate, digital wallet, decentralized identity, distributed ledger technology, verifiable credential.

05

Solution description

An SSI-based electronic KYC (eKYC) framework and architecture that uses the blockchain mainly for public data with bilateral off-chain exchange. Solution-space representation: Instantiation (framework/architecture) plus six design objectives and three nascent design principles.

06

Output knowledge

Six design objectives (efficiency, regulatory compliance, decentralization, trust, privacy, user experience) with 16 associated requirements, and three nascent design principles theorizing blockchain's role for SSI.

03

Paper design map

The default semantic design map canonicalizes stored design relationships; Raw links retains the complete technical Markdown-link view.

Design-knowledge map

25 stored concepts / 16 canonical semantic relationships

Concept types
Design Objectives
Design Requirements
Design Principles
Press enter or space to select a node.You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

04

Design knowledge

Directly linked concepts, grouped by their represented design-knowledge category.

6 Design Objectives

design-knowledge/kyc-framework-ssi-do1

Objective 1 - Efficiency

To allow for increased process efficiency, three requirements had to be satisfied: end-to-end digital processing of relevant documents, automation of manual processes, and standardized exchange of eKYC documents.

bankingdesign-objectiveidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-do2

Objective 2 - Regulatory compliance

Compliance with regulations is a key objective of the KYC process; the Money Laundering Act (MLA), GDPR, and electronic Identification, Authentication, and Trust Services (eIDAS) are particularly relevant regulations for a digital KYC process.

bankingdesign-objectiveidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-do3

Objective 3 - Decentralization

A viable solution for an improved eKYC process must avoid central storage of customer data and prevent lock-in effects that could result in the aggregation of market power.

bankingdesign-objectiveidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-do4

Objective 4 - Trust

A key goal of banks is to make eKYC documents reusable in registrations of a customer at different banks, requiring acceptance of KYC documents attested by other banks, validity checks, and authenticity checks.

bankingdesign-objectiveidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-do5

Objective 5 - Privacy

Protecting customers' privacy is a key feature of an eKYC process, requiring compliance with the need to know principle and data minimization.

bankingdesign-objectiveidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-do6

Objective 6 - User experience

The most important objective from the users' perspective is seamless user experience, requiring low complexity, availability of different user interfaces, and backup, recovery, and support.

bankingdesign-objectiveidentity-ssikyc+2

3 Design Principles

design-knowledge/kyc-framework-ssi-dp1

DP1 - Utilize blockchain only for public data

Use blockchain in SSI processes only for public data: organizations should repeatedly request and verify attributes through bilateral communication channels and read from, rather than write to, the ledger.

bankingdesign-principleidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-dp2

DP2 - Anticipate an ecosystem of various ledgers

Do not assume a single shared ledger; anticipate an ecosystem of various distributed ledgers, since SSI practice and interoperability requirements span multiple ledgers.

bankingdesign-principleidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-dp3

DP3 - Enable decentralization at the edge

Ensure that users can store their verifiable credentials on an infrastructure of their choice, supporting user autonomy and decentralization at the edge of the SSI architecture.

bankingdesign-principleidentity-ssikyc+2

16 Design Requirements

design-knowledge/kyc-framework-ssi-r1-1

R1.1 - End-to-end digital processing of relevant documents

The end-to-end digital processing of relevant documents is a prerequisite for automating process steps and reducing friction.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r1-2

R1.2 - Automation of manual processes

In the current KYC process, many steps involving the validation of data are conducted manually; the de facto automation of manual processes is a key requirement.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r1-3

R1.3 - Standardized exchange of eKYC documents

A standardized exchange of eKYC documents is crucial to allow for the efficient integration of eKYC checks that have been conducted at other institutions.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r2-1

R2.1 - Money Laundering Act (MLA)

The Money Laundering Act (MLA) provides banks with specific requirements regarding the identification of customers and the storage of their records, and requires banks to determine and document customer risk.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r2-2

R2.2 - GDPR

The GDPR applies to the processing of any data regarding natural persons and poses requirements such as privacy by design, portability, the right to erasure, transparency, purpose limitation, data minimization, accuracy, storage limitation, information integrity, and confidentiality.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r2-3

R2.3 - eIDAS

eIDAS imposes requirements on electronic means of identification, such as compliance with certain security levels (level of assurance) and the cross-border interoperability of systems.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r3-1

R3.1 - Avoid central storage of customer data

A viable solution for an improved eKYC process must avoid central storage of customer data, since silos of customer data are an attractive target for attackers.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r3-2

R3.2 - Prevent lock-in effects

Banks do not want to risk becoming dependent on a centralized eKYC service provider; the system must be constructed to prevent lock-in effects that could result in the aggregation of market power.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r4-1

R4.1 - Acceptance of KYC documents attested by other banks

A key goal of banks is to make eKYC documents reusable in registrations of a customer at different banks; thus, acceptance of KYC documents attested by other banks is required.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r4-2

R4.2 - Validity checks

The documents must be tamper-proof, so a further requirement is that validity checks of these documents are feasible.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r4-3

R4.3 - Authenticity checks

The customer needs to be able to convince the bank that the KYC-related documents presented were not stolen, sold, or shared; the identity of the customer and their connection with the documents must have a high level of assurance.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r5-1

R5.1 - Need to know principle

Compliance with the 'need to know' principle: only the customers themselves and entities relevant to the KYC process must have access to customers' personal data.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r5-2

R5.2 - Data minimization

Not only the parties involved in the KYC process but also the de facto data exchanged should be restricted to what is necessary, because digital data are much easier to collect and abuse than their analog counterparts.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r6-1

R6.1 - Low complexity

The eKYC process must be convenient, so that customers are not discouraged from registering at the new bank; low complexity is a major requirement for user experience.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r6-2

R6.2 - Availability of different user interfaces

The variety of devices on which a customer can perform the eKYC process must be respected, so the availability of different user interfaces is important.

bankingdesign-requirementidentity-ssikyc+2
design-knowledge/kyc-framework-ssi-r6-3

R6.3 - Backup, recovery, and support

The user experience should include exception handling, for instance if a device that stores the customer data is lost or stolen, requiring backup, recovery, and support features.

bankingdesign-requirementidentity-ssikyc+2

05

Publication metadata

Additional metadata represented in the current library record.

Show additional metadata+
{
  "type": "paper",
  "title": "Designing a Framework for Digital KYC Processes Built on Blockchain-Based Self-Sovereign Identity",
  "description": "The paper derives six design objectives (16 sub-requirements) for an SSI-based eKYC framework and demonstrates how blockchain-based self-sovereign identity can solve KYC challenges without violating data-protection regulation, deriving three nascent design principles that theorize blockchain's role for SSI: use blockchain only for public data, anticipate an ecosystem of various ledgers, and enable decentralization at the edge.",
  "resource": "https://doi.org/10.1016/j.im.2021.103553",
  "authors": "Vincent Schlatt, Johannes Sedlmeir, Simon Feulner, Nils Urbach",
  "year": 2022,
  "venue": "Information & Management 59 (2022) 103553",
  "methodology": "Design science research; six solution objectives from literature and regulation; expert interviews (ex ante and ex post evaluation).",
  "dsr_grid": true,
  "dsr_solution_space": "Instantiation (framework/architecture) plus six design objectives and three nascent design principles.",
  "tags": [
    "kyc-framework-ssi",
    "identity-ssi",
    "kyc",
    "banking",
    "verifiable-credentials",
    "design-science-research",
    "blockchain"
  ]
}