interoperability for ECDH+KDF+HMAC AKA DVS
Nobody has claimed this yet.
- Dominant language
- Shell
- Stars
- 112
- Forks
- 38
- Avg merge
- 12d 19h
- Merged PRs (30d)
- 4
Description
It's certainly not the first time the general concept has come up but https://github.com/oauth-wg/oauth-selective-disclosure-jwt/issues/574 makes a request for "interoperability for ECDH-HMAC signatures on key binding JWT" from @Razumain. Many opinions were expressed therein but it is pretty clear that nothing significant is going into SD-JWT at the 11th hour, even if that was the appropriate layer. There remains some disagreement over the actual appropriate layer to the various parts of what might be needed. But, despite @paulbastian stating "the important pieces in OpenID4VP do exist", I am not at all convinced that anything close to interoperability could be achieved without at least some additional guidance in the presentation protocol layer, which is OpenID4VP.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Read the linked oauth-selective-disclosure-jwt issue 574 first, then examine the OpenID4VP presentation-protocol layer discussed here. Identify which ECDH, KDF, and HMAC key-binding details require interoperability guidance and where the layer boundaries remain disputed. Done means the required protocol guidance and its appropriate layer are agreed.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, cryptography, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100