Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[VC Security & Trust Document] Does a presentation require holder binding? #12

Open
Macke opened this issue Aug 10, 2023 · 0 comments
Open

Comments

@Macke
Copy link

Macke commented Aug 10, 2023

Imported from AB/Connect bitbucket: https://bitbucket.org/openid/connect/issues/2014

Original Reporter: danielfett

Regarding this open question: “Should a "presentation" always mean/require cryptographic holder binding? Should these use cases where it is not required covered by the protocol?”

Giuseppe De Marco

2023-03-06

it may depends by use cases.

presenting personal identification data, for authentication purpose, or verifiable attestation of attributes, for instance: diploma use cases and any other attestation, like mDL. In these cases the binding of the owner and the proof of it’s willing during the presentation is a mandatory requirement.

there are other cases where the VC is a cinema ticket, a parking ticket, laundry ticket and other cases where the credentials may be shared between different holders. In this cases there would not be the security requirement of the binding and that’s up to the nature of the credentials and service it is required to be used on.

usually, these VC/services, should be like disposable tickets, to be used only once.

Different cases are subscriptions or VCs which, by their very nature, must be resubmitted from time to time.

@danielfett danielfett removed bug Something isn't working major labels Aug 14, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants