[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-seo-246881-105":3,"detail-sidebar-cat-1-en-105":80,"doc-detail-246881-en":126},{"code":4,"msg":5,"data":6},0,"ok",{"site_id":7,"language":8,"slug":9,"title":10,"keywords":11,"description":12,"schema_data":13,"social_meta":73,"head_meta":75,"extra_data":77,"updated_unix":79},105,"en","functional-requirements-for-decentralized-and-self-sovereign-identities-arxiv-260324250-v1","Functional Requirements for Decentralized and Self-Sovereign Identities - arXiv 2603.24250 v1","","Centralized identity management systems face persistent security and privacy risks, which has driven interest in Decentralized Identity (DI) and Self-Sovereign Identity (SSI) alternatives. However, real adoption remains limited because evaluation of whether systems meet promised qualities lacks transparency and reproducibility. The work derives functional requirements (FR) as the necessary first step toward an evaluation approach that can be repeated and validated using established requirements engineering methods.",{"@graph":14,"@context":72},[15,34,55],{"@type":16,"itemListElement":17},"BreadcrumbList",[18,23,27,31],{"item":19,"name":20,"@type":21,"position":22},"https://docshare.wps.com","Home","ListItem",1,{"item":24,"name":25,"@type":21,"position":26},"https://docshare.wps.com/template/","Template",2,{"item":28,"name":29,"@type":21,"position":30},"https://docshare.wps.com/template/general/","General",3,{"item":32,"name":10,"@type":21,"position":33},"https://docshare.wps.com/template/functional-requirements-for-decentralized-and-self-sovereign-identities-arxiv-260324250-v1/246881/",4,{"url":32,"name":10,"@type":35,"image":36,"author":41,"headline":10,"publisher":44,"fileFormat":47,"inLanguage":8,"description":12,"dateModified":48,"datePublished":49,"encodingFormat":47,"isAccessibleForFree":50,"interactionStatistic":51},"DigitalDocument",{"url":37,"@type":38,"width":39,"height":40},"https://docshare.wps.com/thumbnails/functional-requirements-for-decentralized-and-self-sovereign-identities-arxiv-260324250-v1/246881.png","ImageObject",442,249,{"name":42,"@type":43},"Riley","Person",{"url":19,"name":45,"@type":46},"DocShare","Organization","application/pdf","2026-09-21","2026-09-12",true,{"@type":52,"interactionType":53,"userInteractionCount":26},"InteractionCounter",{"@type":54},"ViewAction",{"@type":56,"mainEntity":57},"FAQPage",[58,64,68],{"name":59,"@type":60,"acceptedAnswer":61},"Why is decentralized and self-sovereign identity adoption still limited?","Question",{"text":62,"@type":63},"Adoption remains limited because evaluations of compliance with promised qualities (such as privacy or decentralization) are often not transparent and not reproducible.","Answer",{"name":65,"@type":60,"acceptedAnswer":66},"What problem does the paper address in existing DI/SSI research?",{"text":67,"@type":63},"It addresses the lack of systematic operationalization of non-functional requirements (NFR) and SSI principles, and the resulting ambiguous, non-reproducible evaluation results.",{"name":69,"@type":60,"acceptedAnswer":70},"How do the authors propose improving evaluation of DI/SSI systems?",{"text":71,"@type":63},"They derive functional requirements (FR) for a generalized DI/SSI use case, providing a formal operational basis that supports building a transparent and reproducible evaluation framework.","https://schema.org",{"og:url":32,"og:type":74,"og:title":10,"og:site_name":45,"og:description":12},"article",{"robots":76,"canonical":32},"index,follow",{"doc_id":78,"site_id":7},246881,1789961909,{"code":4,"msg":81,"data":82},"success",[83,88,93,98,103,108,113,118,123],{"id":84,"doc_module":22,"doc_module_name":25,"category_name":85,"show_sort_weight":86,"slug":87},11,"Presentations",90,"presentations",{"id":89,"doc_module":22,"doc_module_name":25,"category_name":90,"show_sort_weight":91,"slug":92},12,"Resumes",80,"resumes",{"id":94,"doc_module":22,"doc_module_name":25,"category_name":95,"show_sort_weight":96,"slug":97},14,"Invoices",70,"invoices",{"id":99,"doc_module":22,"doc_module_name":25,"category_name":100,"show_sort_weight":101,"slug":102},15,"Posters",60,"posters",{"id":104,"doc_module":22,"doc_module_name":25,"category_name":105,"show_sort_weight":106,"slug":107},16,"Social Media",50,"social-media",{"id":109,"doc_module":22,"doc_module_name":25,"category_name":110,"show_sort_weight":111,"slug":112},17,"Forms",40,"forms",{"id":114,"doc_module":22,"doc_module_name":25,"category_name":115,"show_sort_weight":116,"slug":117},18,"Letters",30,"letters",{"id":119,"doc_module":22,"doc_module_name":25,"category_name":120,"show_sort_weight":121,"slug":122},21,"Paper Templates",5,"papers-templates",{"id":124,"doc_module":22,"doc_module_name":25,"category_name":29,"show_sort_weight":4,"slug":125},158,"general-158",{"code":4,"msg":81,"data":127},{"doc_id":78,"user_id":128,"nickname":42,"user_avatar":129,"doc_module":22,"category_id":124,"category_name":29,"doc_title":10,"doc_description":12,"doc_content":130,"file_id":131,"file_url":132,"file_type":133,"file_size":134,"view_count":26,"is_deleted":4,"is_public":22,"is_downloadable":22,"audit_status":22,"page_count":135,"language":136,"language_code":8,"site_id":7,"html_lang":8,"table_of_contents":137,"faqs":138,"seo_title":139,"seo_description":12,"update_tm":140,"read_time":141},1374391975076,"https://ap-avatar.wpscdn.com/avatar/14000253ca4ec9f6853?x-image-process=image/resize,m_fixed,w_180,h_180&k=1783305029341752051","arXiv :2603 .24250v1 [ cs . SE] 25 Mar 2026  \nFunctional Requirements for Decentralized and Self-Sovereign Identities  \nDaria Schumm [0009−0004−1154−4799] and Burkhard Stiller [0000−0002−7461−7463]  \nUniversity of Zürich  \nBinzmühlestrasse 14, CH—8050 Zürich, Switzerland [schumm, stiller]@[ifi.uzh.ch](ifi.uzh.ch)  \nAbstract. Centralized identity management systems continuously experience security and privacy challenges, motivating the exploration of Decentralized Identity (DI) and Self-Sovereign Identity (SSI) as alternatives. Despite privacy and security benefits to users, the adoption of DI/SSI systems remains limited. One contributing reason is the lack of reproducible approaches to evaluate system compliance with its promised qualities. Derivation of functional requirements (FR) is the first and necessary step to develop such an evaluation approach.  \nPrevious literature on DI/SSI significantly lacks the systematic operationalization of existing non-functional requirements (NFR) or SSI principles. This work addresses this research gap by deriving FR for a generalized DI/SSI use case, which encompasses the fundamental operations of the system. The paper details operationalization methodology, introduces a formalized functional model, and presents a comprehensive set of FR, that can be used for future development and evaluation of DI/SSI systems. As a result, establishing the fundamental step toward a reproducible evaluation framework, rooted in established requirements engineering methods.  \nKeywords: Decentralized Identity · Self-Sovereign Identity · Functional Requirements, Requirements Engineering  \n1 Introduction  \nWith the recent push toward mandatory governmental digital identity systems, public resistance has grown due to concerns about surveillance and data privacy [20, 35] . These concerns continue to escalate with each new incident, such as the Optus and Ticketmaster data breaches [1, 45], exposing the risks of centralized identity management. Decentralized Identity (DI) and Self-Sovereign Identity (SSI) offer an alternative by enabling data owners to retain control over their identity data without reliance on centralized services. Despite the security and privacy benefits for users, adoption remains limited. One contributing reason is the lack of transparent and reproducible approaches to evaluate system compliance with promised qualities (e.g., privacy or decentralization) . Transparent evaluation and communication of compliance to users may facilitate greater trust in a new technology and support real-world adoption.  \n2 Schumm and Stiller  \nTo develop such an evaluation approach, concrete and measurable criteria for DI/SSI system functionality, or functional requirements (FR), must first be established. Existing DI/SSI systems largely build on SSI principles, such as existence, control, and persistence, introduced by [3] . These principles were extended and characterized as requirements that can be used as evaluation criteria by [9] . However, these properties represent non-functional requirements (NFR) and do not provide an operational or systematic basis for system evaluation. Despite this limitation, most prior works (e.g., [2, 5, 9, 12–15, 29, 37, 39]) evaluate DI/SSI systems using NFR, which represent Cameroon’s Laws of Identity [7] and SSI principles [3] . Other works (e.g., [4, 6, 11, 16, 26–28, 31, 32, 38, 43, 44]) do not adhere to any of the requirements. Across the literature, evaluation methodologies are often vague. Authors frequently neglect measurable metrics and fail to explain how the conclusions were derived, leading to ambiguous and non-reproducible results. For example,[5] and [12] conclude that uPort lacks portability without clearly justifying how this conclusion has been reached. Similarly, [29] argues that the requirement of “consistent experience across context” for Sovrin is “hard to say”due to future design choices. Even when explicit evaluation frameworks are proposed, such as in [39","cbCairX9d3U8yJiB","https://ap.wps.com/l/cbCairX9d3U8yJiB","pdf",619584,20,"English","# Introduction\n## Background and motivation\n## Limitations of existing DI/SSI evaluations\n# Schumm and Stiller\n## Need for measurable functional requirements\n## Functional vs non-functional requirements in evaluations\n## Research gap and proposed derivation of FR","[{\"question\":\"Why is decentralized and self-sovereign identity adoption still limited?\",\"answer\":\"Adoption remains limited because evaluations of compliance with promised qualities (such as privacy or decentralization) are often not transparent and not reproducible.\"},{\"question\":\"What problem does the paper address in existing DI/SSI research?\",\"answer\":\"It addresses the lack of systematic operationalization of non-functional requirements (NFR) and SSI principles, and the resulting ambiguous, non-reproducible evaluation results.\"},{\"question\":\"How do the authors propose improving evaluation of DI/SSI systems?\",\"answer\":\"They derive functional requirements (FR) for a generalized DI/SSI use case, providing a formal operational basis that supports building a transparent and reproducible evaluation framework.\"}]","Functional Requirements for Decentralized and Self-Sovereign Identities - arXiv 2603.24250 v1 | PDF",1789238788,7]