openwallet-foundation / tac

OpenWallet Foundation Technical Advisory Council (TAC) website, including governance documents and meeting minutes
https://tac.openwallet.foundation/
Creative Commons Attribution 4.0 International
17 stars 12 forks source link

OID4VC Due Diligence Task Force #23

Closed hkny closed 4 months ago

hkny commented 1 year ago

Introduction/Background Material

Currently, the OID4VC components for implementing decentralized identities such as OID4VCI and OID4VP are gaining traction, especially in Europe. These specifications are required by the European digital identity Architectural Reference Framework but also getting significant attention outside of Europe.

This task force would investigate the specifications belonging to the OID4VC family thoroughly, check the existing implementations, and start the preliminary work for potentially creating/hosting a reference implementation or a framework that can be used by a wider community for application implementations.

Objectives

List of Deliverables or Work Products

Time to Complete

3 Months

Leader

@hkny @tlodderstedt

Initial Participant List

@hkny @tlodderstedt @sakurann @vikyTM @skounis @troyronda

Remarks/Notes - Profiles

There are also interoperability profiles such as high assurance profile that should be reviewed to ensure the potential wallet ecosystem is interoperable with other implementations that are compatible with the profile.

tlodderstedt commented 1 year ago

I support this proposal. I suggest to extend the scope of the DD to the full range of specs of the OpenID 4 Verifiable Credentials protocol family. Please have a look at https://openid.net/openid4vc/ Further Specs: SIOP v2 was adopted by the EU ARF for pseudonymous authentication with a wallet. OpenID4VP over BLE is an emerging spec for VC presentation in "offline" scenarios via BLE.

tlodderstedt commented 1 year ago

Another item of interest. There is work under way to define an Interoperability profile for OID4VC with SD-JWT VCs. https://vcstuff.github.io/high-assurance-profile/draft-high-assurance-profile-oid4vc-sd-jwt-vc.html That could server as a starting point implement something that can directly be used to build VC-based solutions.

hkny commented 1 year ago

I support this proposal. I suggest to extend the scope of the DD to the full range of specs of the OpenID 4 Verifiable Credentials protocol family. Please have a look at https://openid.net/openid4vc/ Further Specs: SIOP v2 was adopted by the EU ARF for pseudonymous authentication with a wallet. OpenID4VP over BLE is an emerging spec for VC presentation in "offline" scenarios via BLE.

Thanks for the input @tlodderstedt. Extended the task force description accordingly.

tlodderstedt commented 1 year ago

Another note: OpenID Foundation is developing conformance tests for OID4VC. The OWF projects should use them to ensure Interoperability.

tlodderstedt commented 1 year ago

I suggest to not restrict the scope to wallet components only. If would see issuance or verification modules in scope, too. We should do everything we can to support implementation of solutions with OID4VC.

tkuhrt commented 1 year ago

Approved by the TAC on May 31, 2023

tkuhrt commented 1 year ago

Created https://github.com/openwallet-foundation/OID4VC-due-diligence-tf

skounis commented 1 year ago

Hi @tkuhrt

If we are going to create separate repos for each task force, could it be better to prefix them so we identify them easier when we list the repositories in the organization?

For example:

I would also suggest using lowercase for the slag names since they appear in the URL (this is a personal preference)

alenhorvat commented 1 year ago

Hi.

Should we review/discuss https://api-conformance.ebsi.eu/docs/wallet-conformance

There are 19 providers already https://ec.europa.eu/digital-building-blocks/wikis/display/EBSI/Conformant+wallets

and the conformance is being extended to other components.

Could/would the WG benefit from the work?

tlodderstedt commented 1 year ago

Hi,

thanks for bringing this to our attention.

I think it makes sense to review this (and other conformance profiles).

Given the objectives of OWF and this TF, it would be good to know which of those implementations are Open Source.

Please note: the TF kicks off this week (21.6, 5pm CEST).

https://zoom.us/j/96334594470?pwd=QTRnZjdleXNJYWEwcFhDNWV6Q3g2dz09

best regards, Torsten. Am 19. Juni 2023, 13:57 +0200 schrieb Alen Horvat @.***>:

Hi. Should we review/discuss https://api-conformance.ebsi.eu/docs/wallet-conformance There are 19 providers already https://ec.europa.eu/digital-building-blocks/wikis/display/EBSI/Conformant+wallets and the conformance is being extended to other components. Could/would the WG benefit from the work? — Reply to this email directly, view it on GitHub, or unsubscribe. You are receiving this because you were mentioned.Message ID: @.***>

alenhorvat commented 1 year ago

Hi. Nice.

Thank you!