dc.contributor
Universitat Politècnica de Catalunya. Departament d'Enginyeria Telemàtica
dc.contributor
Hernández Serrano, Juan
dc.contributor.author
Aljaro Serrano, Victor
dc.date.accessioned
2026-03-04T03:09:18Z
dc.date.available
2026-03-04T03:09:18Z
dc.date.issued
2025-10-23
dc.identifier
https://hdl.handle.net/2117/456631
dc.identifier
ETSETB-230.199518
dc.identifier.uri
https://hdl.handle.net/2117/456631
dc.description.abstract
This thesis presents the implementation of a complete user workflow covering invitation, registration, login, and account recovery, built around a passwordless authentication sys- tem that leverages Self-Sovereign Identity (SSI) principles. The solution enables secure user management through cryptographic wallets instead of traditional credentials, relying on advanced and industry-grade security standards to ensure a high level of trust and protection in digital identity management. The system integrates JSON Web Tokens (JWT) for verifiable and secure information exchange, EIP-712 structured data signatures to ensure transparency and user consent in signing operations, and ephemeral cryptographic challenges that enable identity verifica- tion without exposing sensitive credentials, effectively mitigating replay attacks. The architecture’s main contribution lies in its practical demonstration of how SSI con- cepts and blockchain-based authentication can be combined to create a decentralized, privacy-preserving, and resilient identity system. It highlights how passwordless work- flows can reduce friction in user onboarding and recovery processes while significantly improving security, usability, and trust in digital identity ecosystems.
dc.format
application/pdf
dc.publisher
Universitat Politècnica de Catalunya
dc.rights
S'autoritza la difusió de l'obra mitjançant la llicència Creative Commons o similar 'Reconeixement-NoComercial- SenseObraDerivada'
dc.subject
Àrees temàtiques de la UPC::Informàtica::Seguretat informàtica::Criptografia
dc.subject
Blockchains (Databases)
dc.subject
Self-Sovereign Identity (SSI)
dc.subject
Passwordless authentication
dc.subject
Digital identity management
dc.subject
Cryptographic wallets
dc.subject
JSON Web Tokens (JWT)
dc.subject
Decentralized architecture
dc.subject
Cadena de blocs (Bases de dades)
dc.title
Enterprise SSI: a Self-Sovereign Identity framework for passwordless authentication