eu-digital-identity-wallet / eudi-doc-architecture-and-reference-framework

The European Digital Identity Wallet
https://eu-digital-identity-wallet.github.io/eudi-doc-architecture-and-reference-framework/
Other
431 stars 60 forks source link

DC4EU Feedback: Clarifications on cryptographic proofs based on hardware-bound keys and keys association mechanisms #225

Open DC4EU-Consortium opened 4 months ago

DC4EU-Consortium commented 4 months ago

Undoubtedly, the design choices made to cryptographically associate wallet instance attestations with the credential holder’s binding, using hardware-bound keys in one or multiple WSCDs, are pivotal for establishing trust in the issuer-holder-verifier chain. While these choices primarily impact wallet implementation, they are also crucial for the validation of corresponding attestations at the issuer and verifier sides and for the implementation of the protocol profile.

As the landscape of cryptographic primitives evolves rapidly, incorporating novel approaches such as Split-ECDSA and HDK, which exhibit diverse security properties and dependencies on the WSCD, it is essential for the forthcoming White Paper on WTE and the relevant ARF topic to adopt a flexible and forward-compatible approach. This will ensure the long-term relevance of the document, allowing the Large Scale Pilot (LSP) project to explore and provide feedback on alternative emerging technologies that could offer viable solutions.

ad-Orange commented 4 months ago

We think that BBS# would be a better approach because in addition to splitting, and HDK, it would offer full unlinkability