Objective
Enhance the credential download flow to support multiple cryptographic binding methods when binding a credential to the wallet/holder key.
This will allow issuers to use different supported key-binding representations depending on their credential issuance requirements.
Methods in Scope
The following cryptographic binding methods should be supported:
did:jwk
did:key
jwk
Out of Scope
The following method is not included in this implementation:
Expected Behaviour
During the credential download/issuance flow:
- The wallet should be able to provide the supported binding method expected by the issuer.
- The credential binding should correctly associate the issued credential with the holder/wallet key.
- The selected binding method should be handled consistently throughout the credential issuance flow.
- Existing supported credential download flows should continue to work without regression.
Acceptance Criteria
Test Scenarios
| Binding Method |
Expected Result |
did:jwk |
Credential is successfully issued and bound to the holder key |
did:key |
Credential is successfully issued and bound to the holder key |
jwk |
Credential is successfully issued and bound to the holder key |
cose_key |
Not supported / out of scope |
Notes
The implementation should ensure that the cryptographic binding method is preserved correctly from the credential issuance request through credential issuance and subsequent credential usage.
Objective
Enhance the credential download flow to support multiple cryptographic binding methods when binding a credential to the wallet/holder key.
This will allow issuers to use different supported key-binding representations depending on their credential issuance requirements.
Methods in Scope
The following cryptographic binding methods should be supported:
did:jwkdid:keyjwkOut of Scope
The following method is not included in this implementation:
cose_keyExpected Behaviour
During the credential download/issuance flow:
Acceptance Criteria
did:jwkcryptographic binding during credential download.did:keycryptographic binding during credential download.jwkcryptographic binding during credential download.cose_keyis not processed as part of this implementation.Test Scenarios
did:jwkdid:keyjwkcose_keyNotes
The implementation should ensure that the cryptographic binding method is preserved correctly from the credential issuance request through credential issuance and subsequent credential usage.