adorsys / adorsys/status-list-server
#RF-BLOG-03: OpenID4VCI and OpenID4VP for the EUDI Wallet Era — A Rust Cloud Wallet Architecture
- Langage dominant
- Rust
- Étoiles
- 22
- Forks
- 5
- Merge moyen
- 2 j 11 h
- PR mergées (30 j)
- 47
Description
## #RF-BLOG-03 — OpenID4VCI and OpenID4VP for the EUDI Wallet Era
**Type:** Child Story / Blog Post
**Parent:** Epic #515 (#RF-BLOG-01)
**Status:** Ready to draft (pitch as secondary)
**Project:** [`ADORSYS-GIS/cloud-identity-wallet`](https://github.com/ADORSYS-GIS/cloud-identity-wallet)
### Hook / one-liner
The team behind a cloud-hosted, multi-tenant Rust wallet behind OpenID4VCI/OpenID4VP breaks down the architecture — issuance (authorization-code + pre-authorized-code), presentation, credential formats (SD-JWT, ISO 18013-5 mdoc, W3C VC), and a KMS/HSM key-management design where DEKs are wrapped at rest.
### Why this post
Positions adorsys as SSI thought leader against the eIDAS/EUDI backdrop (every EU state must offer a wallet; OpenID Foundation EUDIW hub). Timely and strategic.
### Content hints
- Component blueprint: API gateway → wallet core domain → OpenID4VC adapters → encrypted storage → event/audit bus (`cloud-wallet-events`).
- **Key architecture**: Key Manager API, key cache with eviction, wrapped DEKs, KMS master key never seen by the service.
- **Multi-tenant isolation** + how stateless handlers and externally-wrapped state enable scale-out and failover (another instance can take over pending flows).
- Standards context: OpenID4VCI, OpenID4VP, EUDI ARF, eIDAS 2.0.
### Acceptance criteria
- [ ] ~1000–1500 words, original
- [ ] Includes key-management diagram
- [ ] Correctly frames EUDI/eIDAS regulatory context
- [ ] Author bio + repo links included
_Part of epic #515 (#RF-BLOG-01)._
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.