New Work Item Proposal
Include Link to Abstract or Draft
The current draft specification is available here
https://docs.google.com/document/d/1htujrb-_1kh8tkV4MXYRmZ44m_D7yFrY09aFJkAz7io/
List Owners
The people who will be responsible for progressing this work item are
David Chadwick, Crossword Cybersecurity david.chadwick@crosswordcybersecurity.com
Mark Haine, Considrd.Consulting mark@considrd.consulting
Work Item Questions
- Explain what you are trying to do using no jargon or acronyms.
The W3C Verifiable Credentials Data Model defines the Evidence property as
"Evidence can be included by an issuer to provide the verifier with additional supporting information in a verifiable credential. This could be used by the verifier to establish the confidence with which it relies on the claims in the verifiable credential." Each Evidence property is specified by defining its globally unique type (specified as a URI) followed by any specific properties required by this type.
The OIDF "OpenID Connect for Identity Assurance 1.0" draft specification, available here:
https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html
has defined the data model for making statements about the verification status of the claims transferred in OpenID Connect.
This proposal will use the verification statements defined by OpenID for Identity Assurance to apply to the claims made by the verifiable credential issuer about the subject of the verifiable credential. This will require a unique Evidence type to be defined for OpenID4IA, followed by the verification statements.
- How is it done today, and what are the limits of the current practice?
This is not being done today as no Evidence property types have been defined.
- What is new in your approach and why do you think it will be successful?
This proposal is taking two standards, namely W3C Verifiable Credentials Data Model and OIDF OpenID Connect for Identity Assurance, and defining how the latter can be used to provide Evidence about the verifiable credential subject's claims that are being asserted by the VC issuer.
- How are you involving participants from multiple skill sets and global locations in this work item? (Skill sets: technical, design, product, marketing, anthropological, and UX. Global locations: the Americas, APAC, Europe, Middle East.)
Many different experts from a wide range of organisations have been involved in specifying the OpenID Connect for Identity Assurance draft specification. Appendix B (https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#section-appendix.b) of this document lists over 25 experts.
Similarly many different experts have been involved in specifying the W3C Verifiable Credentials Data Model.
The current work item welcomes any of the above, and indeed anyone from the CCG, to contribute to how these two standards might leverage each other, as is being proposed here.
- What actions are you taking to make this work item accessible to a non-technical audience?
Both standards have already been widely publicised at conferences such as EIC 2022 and Identiverse (e.g. see https://www.youtube.com/watch?v=ZSGyav5w34U). Furthermore the OIDF has widely publicised its call for action, available here: https://openid.net/2022/08/25/oidc4ida-overview-call-to-action/
New Work Item Proposal
Include Link to Abstract or Draft
The current draft specification is available here
https://docs.google.com/document/d/1htujrb-_1kh8tkV4MXYRmZ44m_D7yFrY09aFJkAz7io/
List Owners
The people who will be responsible for progressing this work item are
David Chadwick, Crossword Cybersecurity david.chadwick@crosswordcybersecurity.com
Mark Haine, Considrd.Consulting mark@considrd.consulting
Work Item Questions
The W3C Verifiable Credentials Data Model defines the Evidence property as
"Evidence can be included by an issuer to provide the verifier with additional supporting information in a verifiable credential. This could be used by the verifier to establish the confidence with which it relies on the claims in the verifiable credential." Each Evidence property is specified by defining its globally unique type (specified as a URI) followed by any specific properties required by this type.
The OIDF "OpenID Connect for Identity Assurance 1.0" draft specification, available here:
https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html
has defined the data model for making statements about the verification status of the claims transferred in OpenID Connect.
This proposal will use the verification statements defined by OpenID for Identity Assurance to apply to the claims made by the verifiable credential issuer about the subject of the verifiable credential. This will require a unique Evidence type to be defined for OpenID4IA, followed by the verification statements.
This is not being done today as no Evidence property types have been defined.
This proposal is taking two standards, namely W3C Verifiable Credentials Data Model and OIDF OpenID Connect for Identity Assurance, and defining how the latter can be used to provide Evidence about the verifiable credential subject's claims that are being asserted by the VC issuer.
Many different experts from a wide range of organisations have been involved in specifying the OpenID Connect for Identity Assurance draft specification. Appendix B (https://openid.net/specs/openid-connect-4-identity-assurance-1_0.html#section-appendix.b) of this document lists over 25 experts.
Similarly many different experts have been involved in specifying the W3C Verifiable Credentials Data Model.
The current work item welcomes any of the above, and indeed anyone from the CCG, to contribute to how these two standards might leverage each other, as is being proposed here.
Both standards have already been widely publicised at conferences such as EIC 2022 and Identiverse (e.g. see https://www.youtube.com/watch?v=ZSGyav5w34U). Furthermore the OIDF has widely publicised its call for action, available here: https://openid.net/2022/08/25/oidc4ida-overview-call-to-action/