Research Articles

Architecture for self-sovereign management of personal data implementing decentralized networks

Vol. 22 No. 2 (2026)
Published: 07-09-2026
Omar Ricardo Castellanos Hernández
student
Roberto Albeiro Pava-Díaz
Docente , Francisco José de Caldas District University image/svg+xml

Introduction: This article is one of the derived products of the research project “Administration Model for Personal Information Management Oriented to the Data Owner”, conducted within the Master’s in Information and Communication Sciences at Universidad Distrital Francisco José de Caldas in Bogotá, Colombia, during the years 2025–2026.
Problem: Current administration and control methods for personal data face vulnerabilities related to integrity, transmission, and third-party use.
Objective: The objective of this article is to propose an architecture that enables users to achieve decentralization and sovereignty over their personal data.
Methodology: A review of the existing literature was conducted, considering implementations in which technological solutions for information management are proposed or applied.
Results: A user-centered proposal is presented in which, after comparing different technologies, blockchain stands out for providing sovereignty over personal data and enabling authorized and restrictive access controls.
Conclusion: The proposal shifts centralized data custody from third parties to user sovereignty, replacing current intermediary-dominated management structures.
Originality: The proposal challenges centralized data storage paradigms by conferring ownership and operational sovereignty to the users to whom the data belong.
Limitations: The model is limited by scope and budget constraints during implementation and depends on the specific use case and the prevailing socio-cultural context.

Keywords: personal data, privacy, decentralization, blockchain

How to Cite

[1]
omar_ricardo Castellanos Hernández and R. A. Pava-Díaz, “Architecture for self-sovereign management of personal data implementing decentralized networks”, ing. Solidar, vol. 22, no. 2, Sep. 2026, Accessed: Sep. 17, 2026. Available: https://revistas.ucc.edu.co/index.php/in/article/view/5594

[1] T. Hartman, H. Kennedy, R. Steedman, and R. Jones, “Public perceptions of good data management: Findings from a UK-based survey,” Big Data & Society, vol. 7, no. 1, pp. 2–10, 2020, doi: https://doi.org/10.1177/2053951720935616

[2] 19 J. P. Cabrera-Sanchez and Á. F. Villarejo-Ramos, “Factors affecting the adoption of big data analytics in companies,” RAE Revista de Administração de Empresas, vol. 59, no. 6, pp. 415–429, 2019, doi: https://doi.org/10.1590/S0034-759020190607

[3] S. Gallagher, “Equifax hackers stole data for 200k credit cards from transaction history,” 2017. [Online]. Available: https://arstechnica.com/information-technology/2017/09/equifax-hackers-stole-data-for-200k-credit-cards-from-transaction-history/

[4] H. A. Rahajeng and R. A. Prastyanti, “The impact of personal data leaks on individual privacy,” Formosa Journal of Social Sciences, vol. 4, no. 2, pp. 252–260, 2025, doi: https://doi.org/10.55927/fjss.v4i2.319

[5] W. Turton, “LastPass says hackers stole customer data, encrypted passwords,” Bloomberg.com, 2022.

[6] R. L. Ruaro, “Algumas reflexões em torno do RGPD com alusões a LGPD,” Revista Brasileira de Direitos Fundamentais & Justiça, vol. 14, no. 42, pp. 219–247, 2020, doi: https://doi.org/10.30899/dfj.v14i42.760

[7] J. Aguilar, “The habeas data in the last CJEU doctrine,” Teoría y Realidad Constitucional, no. 39, pp. 557–581, 2017

[8] J. C. Gil Cifuentes, “El debido proceso en la ley de habeas data,” Revista CES Derecho, vol. 8, no. 1, pp. 191–204, 2017, doi: https://doi.org/10.21615/cesder.8.1.10

[9] H. Jiang et al., “Applications of differential privacy in social network analysis: A survey,” IEEE Transactions on Knowledge and Data Engineering, vol. 35, no. 1, pp. 108–127, 2023, doi: https://doi.org/10.1109/TKDE.2021.3073062

[10] N. Zafar and K. Ahmad, “Blockchain-based self-sovereign identity for ensuring traceability and provenance in online social networks,” in Lecture Notes in Networks and Systems, vol. 1297, pp. 151–165, 2025, doi: https://doi.org/10.1007/978-981-96-3352-4_10

[11] X. Zhu, D. He, Z. Bao, M. Luo, and C. Peng, “An efficient decentralized identity management system based on range proof for social networks,” IEEE Open Journal of the Computer Society, vol. 4, pp. 84–96, 2023, doi: https://doi.org/10.1109/OJCS.2023.3258188

[12] M. Al-Zubaidie, Z. Zhang, and J. Zhang, “PAX: Using pseudonymization and anonymization to protect patients’ identities and data in the healthcare system,” International Journal of Environmental Research and Public Health, vol. 16, no. 9, p. 1490, 2019, doi: https://doi.org/10.3390/ijerph16091490

[13] S. Li, M. J. Schneider, Y. Yu, and S. Gupta, “Reidentification risk in panel data: Protecting for k-anonymity,” Information Systems Research, vol. 34, no. 3, pp. 1066–1088, Sep. 2023, doi: https://doi.org/10.1287/isre.2022.1169

[14] M. Sabt, M. Achemlal, and A. Bouabdallah, “Trusted execution environment: What it is, and what it is not,” in Proc. IEEE Int. Conf. Trust, Security and Privacy in Computing and Communications (TrustCom), 2015, pp. 57–64, doi: https://doi.org/10.1109/Trustcom.2015.357

[15] Y. Xu, W. Cui, and M. Peinado, “Controlled-channel attacks: Deterministic side channels for untrusted operating systems,” in Proc. IEEE Symposium on Security and Privacy, 2015, pp. 640–656, doi: https://doi.org/10.1109/SP.2015.45

[16] M. A. Cardoso et al., “Innovation results of IAM planning in urban water services,” Water Science and Technology, vol. 74, no. 7, pp. 1518–1526, Jun. 2016, doi: https://doi.org/10.2166/wst.2016.291

[17] C. Singh, R. Thakkar, and J. Warraich, “IAM identity access management—Importance in maintaining security systems within organizations,” European Journal of Engineering and Technology Research, vol. 8, no. 4, pp. 30–38, Aug. 2023, doi: https://doi.org/10.24018/ejeng.2023.8.4.3074

[18] Y. Xiao et al., “Industrial experience of finding cryptographic vulnerabilities in large-scale codebases,” Digital Threats: Research and Practice, vol. 4, no. 1, pp. 1–18, Mar. 2022, doi: https://doi.org/10.1145/3507682

[19] T. Xie, F. Liu, and D. Feng, “Fast collision attack on MD5,” Cryptology ePrint Archive, vol. 2013, p. 170, Jan. 2013. [Online]. Available: https://eprint.iacr.org/2013/170

[20] A. Mehmood, A. Shafique, M. Alawida, and A. N. Khan, “Advances and vulnerabilities in modern cryptographic techniques: A comprehensive survey on cybersecurity in the domain of machine/deep learning and quantum techniques,” IEEE Access, vol. 12, pp. 27530–27555, 2024, doi: https://doi.org/10.1109/ACCESS.2024.3367232

[21] S. Hohenberger and B. Waters, “Synchronized aggregate signatures from the RSA assumption,” in Lecture Notes in Computer Science, Mar. 2018, pp. 197–229, doi: https://doi.org/10.1007/978-3-319-78375-8_7

[22] K. Krishnamoorthy and M. Jeyabalu, “A new image encryption method based on improved cipher block chaining with optimization technique,” in Advanced Image Processing Techniques and Applications, 2017, pp. 1–17, doi: https://doi.org/10.4018/978-1-5225-2053-5.ch006

[23] I. Mazeh and E. Shmueli, “A personal data store approach for recommender systems: Enhancing privacy without sacrificing accuracy,” Expert Systems with Applications, vol. 139, p. 112858, pp. 1–16, 2020, doi: https://doi.org/10.1016/j.eswa.2019.112858

[24] Z. Yan, G. Gan, and K. Riad, “BC-PDS: Protecting privacy and self-sovereignty through blockchains for OpenPDS,” in Proc. IEEE Int. Symp. Service-Oriented System Engineering (SOSE), 2017, pp. 138–144, doi: https://doi.org/10.1109/SOSE.2017.30

[25] Q. Yang, Y. Liu, T. Chen, and Y. Tong, “Federated machine learning: Concept and applications,” ACM Transactions on Intelligent Systems and Technology, vol. 10, no. 2, pp. 1–19, 2019, doi: https://doi.org/10.1145/3298981

[26] J. Gao et al., “Secure aggregation is insecure: Category inference attack on federated learning,” IEEE Transactions on Dependable and Secure Computing, vol. 20, no. 1, pp. 1–1, Nov. 2023, doi: https://doi.org/10.1109/TDSC.2021.3128679

[27] V. Rey, P. M. Sánchez Sánchez, A. Huertas Celdrán, and G. Bovet, “Federated learning for malware detection in IoT devices,” Computer Networks, vol. 204, p. 108693, pp. 1–14, Jan. 2022, doi: https://doi.org/10.1016/j.comnet.2021.108693

[28] Y. Wan, Y. Qu, W. Ni, Y. Xiang, L. Gao, and E. Hossain, “Data and model poisoning backdoor attacks on wireless federated learning, and the defense mechanisms: A comprehensive survey,” IEEE Communications Surveys & Tutorials, vol. 26, no. 3, pp. 1861–1897, Jul. 2024, doi: https://doi.org/10.1109/COMST.2024.3361451

[29] A. N. Alketbi, “Blockchain for government services – Use cases, security benefits and challenges,” in Proc. Learning and Technology Conference (LT), Feb. 2018, pp. 112–119, doi: https://doi.org/10.1109/LT.2018.8368494

[30] M. O. Ahmad et al., “BAuth-ZKP—A blockchain-based multi-factor authentication mechanism for securing smart cities,” Sensors, vol. 23, no. 5, p. 2757, Mar. 2023, doi: https://doi.org/10.3390/s23052757

[31] A. Badirova, F. F. Fatemi Moghaddam, and R. Yahyapour, “Integration of self-sovereign identity in centralized identity management: SSI-based authentication and attribute-based authorization,” in Proc. Int. Conf. Future Internet of Things and Cloud (FiCloud), 2024, pp. 362–367, doi: https://doi.org/10.1109/FiCloud62933.2024.00062

[32] T. Roth, M. Utz, F. Baumgarte, A. Rieger, J. Sedlmeir, and J. Strüker, “Electricity powered by blockchain: A review with a European perspective,” Applied Energy, vol. 325, p. 119799, 2022, doi: https://doi.org/10.1016/j.apenergy.2022.119799

[33] D. Marchsreiter, “Towards quantum-safe blockchain: Exploration of PQC and public-key recovery on embedded systems,” IET Blockchain, vol. 5, no. 1, pp. 1–19, Jan. 2025, doi: https://doi.org/10.1049/blc2.12094

[34] R. A. Pava-Díaz, J. I. Gil-Ruiz, and D. A. López-Sarmiento, “Self-sovereign identity on the blockchain: Contextual analysis and quantification of SSI principles implementation,” Frontiers in Blockchain, vol. 7, p. 1443362, pp. 1–15, Jul. 2024, doi: https://doi.org/10.3389/fbloc.2024.1443362

[35] S. R. Garzon, C. Segat, and A. Küpper, “Governance of ledger-anchored decentralized identifiers,” in Proc. Crypto Valley Conference (CVC), 2025, pp. 44–55, doi: https://doi.org/10.1109/CVC65719.2025.00014

[36] S. Semenzin, D. Rozas, and S. Hassan, “Blockchain-based application at a governmental level: Disruption or illusion? The case of Estonia,” Policy & Society, vol. 41, no. 3, pp. 386–401, 2022, doi: https://doi.org/10.1093/polsoc/puac014

[37] H. Halpin, “Vision: A critique of immunity passports and W3C decentralized identifiers,” in Lecture Notes in Computer Science, vol. 12529, pp. 148–168, 2020, doi: https://doi.org/10.1007/978-3-030-64357-7_7

[38] A. Bucko, K. Vishi, B. Krasniqi, and B. Rexha, “Enhancing JWT authentication and authorization in web applications based on user behavior history,” Computers, vol. 12, no. 4, p. 78, 2023, doi: https://doi.org/10.3390/computers12040078

[39] A. Shcherbakov, “Hyperledger Indy Besu as a permissioned ledger in self-sovereign identity,” in Lecture Notes in Informatics (LNI), Proc. Gesellschaft für Informatik (GI), 2024, pp. 127–137, doi: https://doi.org/10.18420/OID2024_11

[40] S. Manski, “Distributed ledger technologies, value accounting, and the self-sovereign identity,” Frontiers in Blockchain, vol. 3, p. 29, pp. 1–12, Jun. 2020, doi: https://doi.org/10.3389/fbloc.2020.00029

[41] C. Regueiro, I. Gutierrez-Agüero, S. Anguita, S. de Diego, and O. Lage, “Protocol for identity management in industrial IoT based on Hyperledger Indy,” International Journal of Computing and Digital Systems, vol. 12, no. 1, pp. 653–664, 2022, doi: https://doi.org/10.12785/ijcds/120153

[42] A. R. Nath, S. Bhattacharjee, and M. I. Khan, “Towards developing a decentralized identity management system with Ethereum smart contracts,” in Proc. Int. Conf. Electrical, Computer and Communication Engineering (ECCE), Feb. 2025, pp. 1–6, doi: https://doi.org/10.1109/ECCE64574.2025.11013086

[43] N. Naik and P. Jenkins, “Sovrin network for decentralized digital identity: Analysing a self-sovereign identity system based on distributed ledger technology,” in Proc. IEEE Int. Symp. Systems Engineering (ISSE), 2021, pp. 1–7, doi: https://doi.org/10.1109/ISSE51541.2021.9582551

[44] P. J. Windley, “Sovrin: An identity metasystem for self-sovereign identity,” Frontiers in Blockchain, vol. 4, p. 626726, pp. 1–14, Jul. 2021, doi: https://doi.org/10.3389/fbloc.2021.626726

[45] N. Sahi, A. Liang, W. van Devanter, K. Oikonomou, and P. Zhang, “Self-sovereign identity in semi-permissioned blockchain networks leveraging Ethereum and Hyperledger Fabric,” in Proc. Int. Conf., 2023, pp. 315–321, doi: https://doi.org/10.1109/ICDH60066.2023.00053

[46] A. Goel and Y. Rahulamathavan, “A comparative survey of centralised and decentralised identity management systems: Analysing scalability, security, and feasibility,” Future Internet, vol. 17, no. 1, p. 1, Dec. 2024, doi: https://doi.org/10.3390/fi17010001

[47] P. Kumar et al., “A blockchain-orchestrated deep learning approach for secure data transmission in IoT-enabled healthcare system,” Journal of Parallel and Distributed Computing, vol. 172, pp. 69–83, Oct. 2023, doi: https://doi.org/10.1016/j.jpdc.2022.10.002

[48] M. Fortin and E. Pimentel, “Bitcoin: An accounting regime,” Critical Perspectives on Accounting, vol. 99, p. 102731, 2024, doi: https://doi.org/10.1016/j.cpa.2024.102731

[49] S. Mahula, E. Tan, and J. J. Crompvoets, “With blockchain or not? Opportunities and challenges of self-sovereign identity implementation in public administration: Lessons from the Belgian case,” in Proc. ACM Int. Conf., 2021, pp. 495–504, doi: https://doi.org/10.1145/3463677.3463705

[50] M. Atzori, “Blockchain technology and decentralized governance: Is the state still necessary?,” Journal of Innovation and Regulation, vol. 12, no. 3, pp. 123–145, 2018, doi: https://doi.org/10.1234/jir.2018.12345

MÉTRICAS
ARTICLE VIEWS: 23
PDF VIEWS: 12