w3c / automotive

W3C Automotive Working Group Specifications
Other
146 stars 68 forks source link

Vehicle identity claim optional in AGT and AT. #431

Closed UlfBj closed 2 years ago

UlfBj commented 2 years ago

https://rawcdn.githack.com/UlfBj/automotive/cb6fda7c3942448ff05a2705b66c0486017cfa2a/spec/VISSv2_Core.html

UlfBj commented 2 years ago

Must it always be so that if VIN is present in the AGT, then it must also be present in the AT?

I think it is a reasonable requirement. It may lead to a scenario where the signature validation is an implicit validation of that the token is used at the correct vehicle, and thus the VIN validation is redundant. But it also keeps the door closed for the case that no such validation is done. A simplified logic with the potential cost of a redundant validation.