Authenticate mDL Issuer using the access certificate (IACA)
Mandatory
ARF section 6.6.2.1 point 1 and section 6.6.2.2
Verify authenticity of mDL
Mandatory
ARF section 6.6.2.1 point 5 and section 6.6.2.5
Download the mDL Issuer Access CA Trusted List(s) from the relevant Trusted List Provider(s)
Mandatory
ARF section 6.6.2.2
Checks registration certificate or the online service of the Registrar indicated in the access certificate
Mandatory
ARF section 6.6.2.2 specifies that "Wallet Unit checks the registration information contained in the registration certificate (if available in the Issuer metadata) or in the online service of the Registrar indicated in the access certificate."
According to section 6.3.2.3 in ISO/IEC 18013-5, if the EUDI Wallet supports NFC for device engagement then it shall support Static Handover, Negotiated Handover, or both.
Data Device Retrieval using BLE for Proximity Presentation Flow¶
Specification
Optionality
Description and Reference
mdoc central client mode
Optional
Section 8.3.3.1.1.1 in ISO/IEC 18013-5 implies that this mode is optional.
mdoc peripheral server mode
Optional
As above
BLE L2CAP
Optional
Refer to Proximity Verifier relevant specification
Security Mechanism and Trust Relationships for Device Retrieval for Proximity/Remote (DC API) Presentation Flow¶
Specification
Optionality
Description and Reference
Session Encryption
Mandatory (assumed) for proximity Conditional for remote
For offline interactions, a session-based encryption mechanism directly encrypts the mDL response.
Issuer data authentication
Mandatory
According to ISO/IEC 18013-5, section 9.1.2, the purpose of issuer data authentication is to confirm that the mdoc data is issued by the issuing authority and that it has not changed since issuance. Section 9.3.1 also applies, specifying this as a mandatory capability. Issuer data authentication is implemented by way of a digital signature over mDL data, using a public-private (asymmetric) key pair.
mdoc authentication (device binding)
Mandatory
According to section 9.1.3 in ISO/IEC 18013-5 the security objective of mDL authentication is to prevent cloning of the mDL and to mitigate man in the middle attacks.
mdoc Reader authentication
Mandatory for proximity Optional for remote
According to section 9.1.4 in ISO/IEC 18013-5, mDL Reader authentication uses information stored in the mDL Reader to confirm that the mDL Reader and the mDL Reader Request are authenticated. Section 7.1.2 states that "An mDL may require mdoc reader authentication (see 9.1.4) before releasing data elements not marked as mandatory in Table 5. An mDL shall not require mdoc reader authentication as a precondition for the release of any of the mandatory data elements. An mDL may offer functionality to the mDL holder to pre-authorise the release of mandatory data elements selected by the mDL holder to mDL readers using mdoc reader authentication."
Refer to Proximity Verifier relevant specification
Digital Credentials Query Language (DCQL)
Mandatory
OpenID4VP v1.0 chapter 6 specifies a JSON-encoded query language that allows the Verifier to request Presentations that match the query. OpenID4VP introduced DCQL in Draft 22. Therefore, DCQL is not supported in Draft 18.
Authorization Response for Remote Presentation Flow¶
ARF in Annex 2 VCR_19 states that "A Wallet Unit SHOULD regularly check the revocation status of its PIDs, attestations, and WUAs, and notify the User if a PID, attestation, or WUA (i.e. the Wallet Unit itself), is revoked."
Digital Credentials API for Remote Presentation Flow¶
Specification
Optionality
Description and Reference
Device Request
Optional
Refer to Remote Verifier relevant specification DC API is optional according to ARF section 4.4.3.1
Device Response
Optional
Refer to Remote Verifier relevant specification Refer above for optionality
HPKE single shot encryption /decryption
Optional
Refer to Remote Verifier relevant specification Refer above for optionality
Session Transcript
Optional
Refer to Remote Verifier relevant specification Refer above for optionality
SerializedOrigin in Session Transcript
Optional
Refer above for optionality Annex C.5 in ISO/IEC 18013-57 states that the mdoc (wallet) shall use the origin received from the user agent to determine the SerializedOrigin value. If the mdoc (wallet) does not receive the origin from the user agent, it shall abort the transaction.
Support for at least one of these methods is mandatory. ↩↩↩↩↩↩
Support for one of the handover methods or both. ↩↩