Artículos de investigación

Arquitectura para la gestión auto soberana de datos personales implementando redes descentralizadas

Vol. 22 Núm. 2 (2026)
Publicado: 2026-09-07
Omar Ricardo Castellanos Hernández
student
Roberto Albeiro Pava-Díaz
Docente , Universidad Distrital Francisco José de Caldas image/svg+xml

Introducción: Este artículo es uno de los productos derivados de la investigación “Modelo de administración para la gestión de información personal orientado al propietario de los datos”, desarrollada en la Maestría en Ciencias de la Información y la Comunicación de la Universidad Distrital Francisco José de Caldas en Bogotá, Colombia, durante los años 2025–2026.
Problema: La administración y los métodos de control de los datos personales enfrentan actualmente problemas de vulnerabilidad en cuanto a la integridad, transmisión y uso por parte de terceros.
Objetivo: El objetivo del presente artículo es proponer una arquitectura que permita al usuario la descentralización y la soberanía de sus datos personales.
Metodología: Se realizó una revisión de la literatura existente, teniendo en cuenta implementaciones en las que se proponen o aplican soluciones tecnológicas para la gestión de la información.
Resultados: Se presenta una propuesta centrada en el usuario en la cual, tras comparar diferentes tecnologías, blockchain destaca por brindar soberanía sobre los datos personales y otorgar controles de acceso autorizados y restrictivos.
Conclusión: La propuesta busca transferir la custodia centralizada de los datos desde terceros de confianza hacia la soberanía del usuario, reemplazando las estructuras de gestión actuales dominadas por intermediarios.
Originalidad: Se transforman los paradigmas de almacenamiento centralizado de datos hacia esquemas que otorgan control y soberanía operativa al usuario propietario de sus datos personales.
Limitaciones: El modelo presenta limitaciones en alcance y presupuesto durante su implementación, y depende del caso de uso y del entorno social y cultural en el que se aplique.

Palabras clave: datos personales, privacidad, descentralización, blockchain

Cómo citar

[1]
O. R. Castellanos Hernández y R. A. Pava-Díaz, «Arquitectura para la gestión auto soberana de datos personales implementando redes descentralizadas», ing. Solidar, vol. 22, n.º 2, sep. 2026, Accedido: sep. 17, 2026. Disponible en: https://revistas.ucc.edu.co/index.php/in/article/view/5594

[1] T. Hartman, H. Kennedy, R. Steedman, and R. Jones, “Public perceptions of good data management: Findings from a UK-based survey,” Big Data & Society, vol. 7, no. 1, pp. 2–10, 2020, doi: https://doi.org/10.1177/2053951720935616

[2] 19 J. P. Cabrera-Sanchez and Á. F. Villarejo-Ramos, “Factors affecting the adoption of big data analytics in companies,” RAE Revista de Administração de Empresas, vol. 59, no. 6, pp. 415–429, 2019, doi: https://doi.org/10.1590/S0034-759020190607

[3] S. Gallagher, “Equifax hackers stole data for 200k credit cards from transaction history,” 2017. [Online]. Available: https://arstechnica.com/information-technology/2017/09/equifax-hackers-stole-data-for-200k-credit-cards-from-transaction-history/

[4] H. A. Rahajeng and R. A. Prastyanti, “The impact of personal data leaks on individual privacy,” Formosa Journal of Social Sciences, vol. 4, no. 2, pp. 252–260, 2025, doi: https://doi.org/10.55927/fjss.v4i2.319

[5] W. Turton, “LastPass says hackers stole customer data, encrypted passwords,” Bloomberg.com, 2022.

[6] R. L. Ruaro, “Algumas reflexões em torno do RGPD com alusões a LGPD,” Revista Brasileira de Direitos Fundamentais & Justiça, vol. 14, no. 42, pp. 219–247, 2020, doi: https://doi.org/10.30899/dfj.v14i42.760

[7] J. Aguilar, “The habeas data in the last CJEU doctrine,” Teoría y Realidad Constitucional, no. 39, pp. 557–581, 2017

[8] J. C. Gil Cifuentes, “El debido proceso en la ley de habeas data,” Revista CES Derecho, vol. 8, no. 1, pp. 191–204, 2017, doi: https://doi.org/10.21615/cesder.8.1.10

[9] H. Jiang et al., “Applications of differential privacy in social network analysis: A survey,” IEEE Transactions on Knowledge and Data Engineering, vol. 35, no. 1, pp. 108–127, 2023, doi: https://doi.org/10.1109/TKDE.2021.3073062

[10] N. Zafar and K. Ahmad, “Blockchain-based self-sovereign identity for ensuring traceability and provenance in online social networks,” in Lecture Notes in Networks and Systems, vol. 1297, pp. 151–165, 2025, doi: https://doi.org/10.1007/978-981-96-3352-4_10

[11] X. Zhu, D. He, Z. Bao, M. Luo, and C. Peng, “An efficient decentralized identity management system based on range proof for social networks,” IEEE Open Journal of the Computer Society, vol. 4, pp. 84–96, 2023, doi: https://doi.org/10.1109/OJCS.2023.3258188

[12] M. Al-Zubaidie, Z. Zhang, and J. Zhang, “PAX: Using pseudonymization and anonymization to protect patients’ identities and data in the healthcare system,” International Journal of Environmental Research and Public Health, vol. 16, no. 9, p. 1490, 2019, doi: https://doi.org/10.3390/ijerph16091490

[13] S. Li, M. J. Schneider, Y. Yu, and S. Gupta, “Reidentification risk in panel data: Protecting for k-anonymity,” Information Systems Research, vol. 34, no. 3, pp. 1066–1088, Sep. 2023, doi: https://doi.org/10.1287/isre.2022.1169

[14] M. Sabt, M. Achemlal, and A. Bouabdallah, “Trusted execution environment: What it is, and what it is not,” in Proc. IEEE Int. Conf. Trust, Security and Privacy in Computing and Communications (TrustCom), 2015, pp. 57–64, doi: https://doi.org/10.1109/Trustcom.2015.357

[15] Y. Xu, W. Cui, and M. Peinado, “Controlled-channel attacks: Deterministic side channels for untrusted operating systems,” in Proc. IEEE Symposium on Security and Privacy, 2015, pp. 640–656, doi: https://doi.org/10.1109/SP.2015.45

[16] M. A. Cardoso et al., “Innovation results of IAM planning in urban water services,” Water Science and Technology, vol. 74, no. 7, pp. 1518–1526, Jun. 2016, doi: https://doi.org/10.2166/wst.2016.291

[17] C. Singh, R. Thakkar, and J. Warraich, “IAM identity access management—Importance in maintaining security systems within organizations,” European Journal of Engineering and Technology Research, vol. 8, no. 4, pp. 30–38, Aug. 2023, doi: https://doi.org/10.24018/ejeng.2023.8.4.3074

[18] Y. Xiao et al., “Industrial experience of finding cryptographic vulnerabilities in large-scale codebases,” Digital Threats: Research and Practice, vol. 4, no. 1, pp. 1–18, Mar. 2022, doi: https://doi.org/10.1145/3507682

[19] T. Xie, F. Liu, and D. Feng, “Fast collision attack on MD5,” Cryptology ePrint Archive, vol. 2013, p. 170, Jan. 2013. [Online]. Available: https://eprint.iacr.org/2013/170

[20] A. Mehmood, A. Shafique, M. Alawida, and A. N. Khan, “Advances and vulnerabilities in modern cryptographic techniques: A comprehensive survey on cybersecurity in the domain of machine/deep learning and quantum techniques,” IEEE Access, vol. 12, pp. 27530–27555, 2024, doi: https://doi.org/10.1109/ACCESS.2024.3367232

[21] S. Hohenberger and B. Waters, “Synchronized aggregate signatures from the RSA assumption,” in Lecture Notes in Computer Science, Mar. 2018, pp. 197–229, doi: https://doi.org/10.1007/978-3-319-78375-8_7

[22] K. Krishnamoorthy and M. Jeyabalu, “A new image encryption method based on improved cipher block chaining with optimization technique,” in Advanced Image Processing Techniques and Applications, 2017, pp. 1–17, doi: https://doi.org/10.4018/978-1-5225-2053-5.ch006

[23] I. Mazeh and E. Shmueli, “A personal data store approach for recommender systems: Enhancing privacy without sacrificing accuracy,” Expert Systems with Applications, vol. 139, p. 112858, pp. 1–16, 2020, doi: https://doi.org/10.1016/j.eswa.2019.112858

[24] Z. Yan, G. Gan, and K. Riad, “BC-PDS: Protecting privacy and self-sovereignty through blockchains for OpenPDS,” in Proc. IEEE Int. Symp. Service-Oriented System Engineering (SOSE), 2017, pp. 138–144, doi: https://doi.org/10.1109/SOSE.2017.30

[25] Q. Yang, Y. Liu, T. Chen, and Y. Tong, “Federated machine learning: Concept and applications,” ACM Transactions on Intelligent Systems and Technology, vol. 10, no. 2, pp. 1–19, 2019, doi: https://doi.org/10.1145/3298981

[26] J. Gao et al., “Secure aggregation is insecure: Category inference attack on federated learning,” IEEE Transactions on Dependable and Secure Computing, vol. 20, no. 1, pp. 1–1, Nov. 2023, doi: https://doi.org/10.1109/TDSC.2021.3128679

[27] V. Rey, P. M. Sánchez Sánchez, A. Huertas Celdrán, and G. Bovet, “Federated learning for malware detection in IoT devices,” Computer Networks, vol. 204, p. 108693, pp. 1–14, Jan. 2022, doi: https://doi.org/10.1016/j.comnet.2021.108693

[28] Y. Wan, Y. Qu, W. Ni, Y. Xiang, L. Gao, and E. Hossain, “Data and model poisoning backdoor attacks on wireless federated learning, and the defense mechanisms: A comprehensive survey,” IEEE Communications Surveys & Tutorials, vol. 26, no. 3, pp. 1861–1897, Jul. 2024, doi: https://doi.org/10.1109/COMST.2024.3361451

[29] A. N. Alketbi, “Blockchain for government services – Use cases, security benefits and challenges,” in Proc. Learning and Technology Conference (LT), Feb. 2018, pp. 112–119, doi: https://doi.org/10.1109/LT.2018.8368494

[30] M. O. Ahmad et al., “BAuth-ZKP—A blockchain-based multi-factor authentication mechanism for securing smart cities,” Sensors, vol. 23, no. 5, p. 2757, Mar. 2023, doi: https://doi.org/10.3390/s23052757

[31] A. Badirova, F. F. Fatemi Moghaddam, and R. Yahyapour, “Integration of self-sovereign identity in centralized identity management: SSI-based authentication and attribute-based authorization,” in Proc. Int. Conf. Future Internet of Things and Cloud (FiCloud), 2024, pp. 362–367, doi: https://doi.org/10.1109/FiCloud62933.2024.00062

[32] T. Roth, M. Utz, F. Baumgarte, A. Rieger, J. Sedlmeir, and J. Strüker, “Electricity powered by blockchain: A review with a European perspective,” Applied Energy, vol. 325, p. 119799, 2022, doi: https://doi.org/10.1016/j.apenergy.2022.119799

[33] D. Marchsreiter, “Towards quantum-safe blockchain: Exploration of PQC and public-key recovery on embedded systems,” IET Blockchain, vol. 5, no. 1, pp. 1–19, Jan. 2025, doi: https://doi.org/10.1049/blc2.12094

[34] R. A. Pava-Díaz, J. I. Gil-Ruiz, and D. A. López-Sarmiento, “Self-sovereign identity on the blockchain: Contextual analysis and quantification of SSI principles implementation,” Frontiers in Blockchain, vol. 7, p. 1443362, pp. 1–15, Jul. 2024, doi: https://doi.org/10.3389/fbloc.2024.1443362

[35] S. R. Garzon, C. Segat, and A. Küpper, “Governance of ledger-anchored decentralized identifiers,” in Proc. Crypto Valley Conference (CVC), 2025, pp. 44–55, doi: https://doi.org/10.1109/CVC65719.2025.00014

[36] S. Semenzin, D. Rozas, and S. Hassan, “Blockchain-based application at a governmental level: Disruption or illusion? The case of Estonia,” Policy & Society, vol. 41, no. 3, pp. 386–401, 2022, doi: https://doi.org/10.1093/polsoc/puac014

[37] H. Halpin, “Vision: A critique of immunity passports and W3C decentralized identifiers,” in Lecture Notes in Computer Science, vol. 12529, pp. 148–168, 2020, doi: https://doi.org/10.1007/978-3-030-64357-7_7

[38] A. Bucko, K. Vishi, B. Krasniqi, and B. Rexha, “Enhancing JWT authentication and authorization in web applications based on user behavior history,” Computers, vol. 12, no. 4, p. 78, 2023, doi: https://doi.org/10.3390/computers12040078

[39] A. Shcherbakov, “Hyperledger Indy Besu as a permissioned ledger in self-sovereign identity,” in Lecture Notes in Informatics (LNI), Proc. Gesellschaft für Informatik (GI), 2024, pp. 127–137, doi: https://doi.org/10.18420/OID2024_11

[40] S. Manski, “Distributed ledger technologies, value accounting, and the self-sovereign identity,” Frontiers in Blockchain, vol. 3, p. 29, pp. 1–12, Jun. 2020, doi: https://doi.org/10.3389/fbloc.2020.00029

[41] C. Regueiro, I. Gutierrez-Agüero, S. Anguita, S. de Diego, and O. Lage, “Protocol for identity management in industrial IoT based on Hyperledger Indy,” International Journal of Computing and Digital Systems, vol. 12, no. 1, pp. 653–664, 2022, doi: https://doi.org/10.12785/ijcds/120153

[42] A. R. Nath, S. Bhattacharjee, and M. I. Khan, “Towards developing a decentralized identity management system with Ethereum smart contracts,” in Proc. Int. Conf. Electrical, Computer and Communication Engineering (ECCE), Feb. 2025, pp. 1–6, doi: https://doi.org/10.1109/ECCE64574.2025.11013086

[43] N. Naik and P. Jenkins, “Sovrin network for decentralized digital identity: Analysing a self-sovereign identity system based on distributed ledger technology,” in Proc. IEEE Int. Symp. Systems Engineering (ISSE), 2021, pp. 1–7, doi: https://doi.org/10.1109/ISSE51541.2021.9582551

[44] P. J. Windley, “Sovrin: An identity metasystem for self-sovereign identity,” Frontiers in Blockchain, vol. 4, p. 626726, pp. 1–14, Jul. 2021, doi: https://doi.org/10.3389/fbloc.2021.626726

[45] N. Sahi, A. Liang, W. van Devanter, K. Oikonomou, and P. Zhang, “Self-sovereign identity in semi-permissioned blockchain networks leveraging Ethereum and Hyperledger Fabric,” in Proc. Int. Conf., 2023, pp. 315–321, doi: https://doi.org/10.1109/ICDH60066.2023.00053

[46] A. Goel and Y. Rahulamathavan, “A comparative survey of centralised and decentralised identity management systems: Analysing scalability, security, and feasibility,” Future Internet, vol. 17, no. 1, p. 1, Dec. 2024, doi: https://doi.org/10.3390/fi17010001

[47] P. Kumar et al., “A blockchain-orchestrated deep learning approach for secure data transmission in IoT-enabled healthcare system,” Journal of Parallel and Distributed Computing, vol. 172, pp. 69–83, Oct. 2023, doi: https://doi.org/10.1016/j.jpdc.2022.10.002

[48] M. Fortin and E. Pimentel, “Bitcoin: An accounting regime,” Critical Perspectives on Accounting, vol. 99, p. 102731, 2024, doi: https://doi.org/10.1016/j.cpa.2024.102731

[49] S. Mahula, E. Tan, and J. J. Crompvoets, “With blockchain or not? Opportunities and challenges of self-sovereign identity implementation in public administration: Lessons from the Belgian case,” in Proc. ACM Int. Conf., 2021, pp. 495–504, doi: https://doi.org/10.1145/3463677.3463705

[50] M. Atzori, “Blockchain technology and decentralized governance: Is the state still necessary?,” Journal of Innovation and Regulation, vol. 12, no. 3, pp. 123–145, 2018, doi: https://doi.org/10.1234/jir.2018.12345

MÉTRICAS
VISTAS DEL ARTÍCULO: 23
VISTAS DEL PDF: 12