China RealDID: Verifiable Credentials Anchored in Legal Identity
arXiv SecurityArchived Aug 11, 2026✓ Full text saved
arXiv:2608.07846v1 Announce Type: new Abstract: Verifiable credentials (VCs) and decentralized identifiers (DIDs) enable selective disclosure but lack legal anchoring: without a trusted identity root, verifiers cannot distinguish a genuine holder from a fabricated identity. State identity systems provide biometric-grounded verification but impose three costs: verifiers must collect subjects' full personally identifiable information, infrastructure concentrates on a single API, and the state obse
Full text archived locally
✦ AI Summary· Claude Sonnet
Computer Science > Cryptography and Security
[Submitted on 8 Aug 2026]
China RealDID: Verifiable Credentials Anchored in Legal Identity
Yifan He
Verifiable credentials (VCs) and decentralized identifiers (DIDs) enable selective disclosure but lack legal anchoring: without a trusted identity root, verifiers cannot distinguish a genuine holder from a fabricated identity. State identity systems provide biometric-grounded verification but impose three costs: verifiers must collect subjects' full personally identifiable information, infrastructure concentrates on a single API, and the state observes every transaction. We present China RealDID, a three-layer architecture -- CTID (centralized legal identity), RealDID (decentralized anchor on an open permissioned blockchain), and VCs with SD-JWT-based selective disclosure -- evaluated against five adversary classes and six security goals. The central mechanism is a content-blind government relay: the state authenticates participants and counter-signs every credential but cannot read the payload, encrypted by the issuer to the holder's public key. We describe the VC lifecycle, triple-signature chain, open template registry, and the architecture's metadata-level privacy limits, including the credential graph at the relay and presentation linkability from single-DID reuse. The design yields an asymmetric, state-bounded trust model: the state cannot impersonate or read contents; the user cannot fabricate identity or evade metadata observation. We analyze alignment with China's Personal Information Protection Law and the EU's GDPR, including the tension between immutable registries and erasure rights, and discuss generalizability through cross-border deployments with Singapore and Hong Kong.
Subjects: Cryptography and Security (cs.CR); Computers and Society (cs.CY)
ACM classes: K.6.5; K.4.1
Cite as: arXiv:2608.07846 [cs.CR]
(or arXiv:2608.07846v1 [cs.CR] for this version)
https://doi.org/10.48550/arXiv.2608.07846
Focus to learn more
Submission history
From: Yifan He [view email]
[v1] Sat, 8 Aug 2026 01:20:28 UTC (1,090 KB)
Access Paper:
view license
Current browse context:
cs.CR
< prev | next >
new | recent | 2026-08
Change to browse by:
cs
cs.CY
References & Citations
NASA ADS
Google Scholar
Semantic Scholar
Export BibTeX Citation
Bookmark
Bibliographic Tools
Bibliographic and Citation Tools
Bibliographic Explorer Toggle
Bibliographic Explorer (What is the Explorer?)
Connected Papers Toggle
Connected Papers (What is Connected Papers?)
Litmaps Toggle
Litmaps (What is Litmaps?)
scite.ai Toggle
scite Smart Citations (What are Smart Citations?)
Code, Data, Media
Demos
Related Papers
About arXivLabs
Which authors of this paper are endorsers? | Disable MathJax (What is MathJax?)