DID Document Creation and Storage: Blockchain vs. IPFS

DID Document Creation and Storage Through Blockchain for Digital Product Passport

Decentralized Identifiers, commonly known as DIDs, can support secure identity management and trusted data exchange within a Digital Product Passport ecosystem. A DID allows an organization, product, component, or digital service to be identified without relying entirely on a centralized identity provider. The associated DID Document can contain verification methods, public keys, service endpoints, authentication information, and links to systems where relevant product data is stored.

For Digital Product Passports, DID technology can help companies establish a verifiable connection between a product identity and its associated compliance, sustainability, technical, and supply chain information. The following sections explain two possible approaches for creating, signing, certifying, and storing DID Documents: direct blockchain storage and decentralized storage through the InterPlanetary File System, or IPFS.

DID Document Creation and Direct Blockchain Storage

1. Start Event

The process begins when a company initiates the registration of a Decentralized Identifier. This may happen when a Digital Product Passport is created for a product, product model, batch, component, or other identifiable asset.

Before registration begins, the company should define the information that will be referenced by the DID, the responsible data owner, the verification method, and the systems used to store the related product information.

2. DID Resolver Creates the DID Document

The DID Resolver generates the DID Document associated with the newly created identifier. The document may include public verification keys, authentication methods, service endpoints, and links to the databases containing the Digital Product Passport information.

To improve system resilience, the DID Document can include two service links:

  • A main database URL used as the primary source of product data
  • A backup database URL used when the primary system is unavailable

This structure helps companies maintain access to important passport information even when one database or server experiences technical disruption.

3. URL Monitoring

After the service endpoints have been added, the resolver system monitors the availability of the main URL. Continuous monitoring allows the system to detect outages, connectivity issues, or service interruptions.

When the main URL remains available, users and connected systems can continue accessing the product data through the primary endpoint. When the main URL becomes unavailable, the monitoring system identifies the interruption and triggers a predefined response.

4. Switching to the Backup URL

If the main service endpoint cannot be reached, the resolver switches to the backup URL. This fallback mechanism supports continuity and reduces the risk that Digital Product Passport information becomes temporarily inaccessible.

The backup system should contain synchronized or sufficiently current information to ensure that users can still retrieve the required data. Companies should also regularly test the fallback process to confirm that the backup endpoint remains operational.

5. Document Signing

Once the DID Document has been prepared, the company signs it using its private cryptographic key. The digital signature helps demonstrate that the document was issued or approved by the organization controlling the corresponding DID.

The private key must be protected through appropriate security controls. Unauthorized access to the key could allow a third party to create, modify, or sign documents in the company’s name. Key management, access control, backup, and revocation processes are therefore essential parts of the technical architecture.

6. Embedding Certification and Signature

The DID Resolver embeds the relevant certification information and digital signature into, or associates them with, the DID Document. These elements allow connected systems to verify the document’s authenticity and determine whether it has been altered after signing.

Certification data may also help establish the relationship between the DID controller and the organization responsible for the Digital Product Passport.

7. Storing the DID Document on Ethereum or Polygon

A smart contract is deployed on a blockchain network such as Ethereum or Polygon. The smart contract defines how the DID Document is registered, updated, retrieved, or verified.

The DID Document, or selected information representing it, is then published through the smart contract. Blockchain storage can provide a timestamped and tamper-evident record of the document. Any later updates should follow a controlled process so that the history of changes remains traceable.

Direct on-chain storage may provide strong integrity and transparency, but companies should carefully consider storage costs, data size, privacy, confidentiality, and regulatory requirements before publishing information directly on a public blockchain.

8. End Event

The process concludes when the DID Document has been signed, certified, and successfully published on Ethereum or Polygon. The document can then be resolved and verified by authorized users, Digital Product Passport platforms, supply chain partners, customers, authorities, or other connected systems.

This model provides a resilient process for DID creation and blockchain-based verification, supported by primary and backup service endpoints.

Explanation of DID Document Creation and Storage on IPFS for Digital Product Passport

An alternative approach is to store the complete DID Document on IPFS while publishing only its cryptographic reference on a blockchain.

1. Start Event

The company begins the DID registration process for the relevant product or digital asset.

2. DID Resolver Creates the DID Document

The DID Resolver generates the document and includes the necessary verification methods, service endpoints, and links to both the main and backup databases.

3. URL Monitoring

The resolver monitors the primary URL to confirm that the associated Digital Product Passport data remains accessible.

4. Switching to the Backup URL

If the main URL becomes unavailable, the resolver redirects requests to the backup endpoint to maintain service continuity.

5. Document Signing

The company signs the DID Document using its private key. This signature enables verification of the document’s origin and integrity.

6. Embedding Certification and Signature

The DID Resolver adds or references the certification and signature information required to verify the document.

7. Storage on IPFS

The complete DID Document is uploaded to IPFS. IPFS stores and retrieves content using a content identifier, commonly called an IPFS hash. This hash is generated from the document’s content.

If the DID Document is modified, the content identifier also changes. This makes it possible to detect whether the stored document differs from the version that was originally registered.

The IPFS hash is then published on Ethereum or Polygon through a smart contract. The blockchain record acts as a verifiable reference to the document stored on IPFS.

This hybrid architecture keeps larger document content outside the blockchain while using blockchain technology to protect integrity, traceability, and verification.

8. End Event

The process ends when the DID Document has been stored on IPFS and its corresponding content identifier has been securely registered on Ethereum or Polygon.

Comparing the Two Approaches

Direct blockchain storage places the DID Document, or a substantial part of it, on the blockchain itself. This can provide high transparency and tamper resistance, but may increase transaction costs and create challenges when the document contains large, confidential, or frequently updated information.

The IPFS-based approach stores the full document in a decentralized file system and places only the hash on the blockchain. This can reduce blockchain storage requirements while still enabling users to verify that the retrieved document matches the registered version.

The appropriate approach depends on factors such as document size, update frequency, confidentiality, transaction costs, availability requirements, governance, and applicable legal obligations.

Digital Product Passport Services

ComplyMarket supports companies in planning and developing Digital Product Passport solutions for product compliance, sustainability, supply chain data, technical documentation, and regulatory information management.

To understand how ComplyMarket can support the development of your Digital Product Passport, visit the relevant Digital Product Passport services page or contact the ComplyMarket team directly.

Intellectual Property Warning

ComplyMarket solutions are protected by intellectual property rights and may be covered by patents or patent applications. Any unauthorized use, reproduction, implementation, or distribution without prior written permission from ComplyMarket may result in legal action.

Comments

Leave a comment or ask a question

Loading verification...