Skip to content

Support Multiple Cryptographic Binding Methods During Credential Download #718

Description

@swatigoel

Objective

Enhance the credential download flow to support multiple cryptographic binding methods when binding a credential to the wallet/holder key.

This will allow issuers to use different supported key-binding representations depending on their credential issuance requirements.

Methods in Scope

The following cryptographic binding methods should be supported:

  1. did:jwk
  2. did:key
  3. jwk

Out of Scope

The following method is not included in this implementation:

  • cose_key

Expected Behaviour

During the credential download/issuance flow:

  • The wallet should be able to provide the supported binding method expected by the issuer.
  • The credential binding should correctly associate the issued credential with the holder/wallet key.
  • The selected binding method should be handled consistently throughout the credential issuance flow.
  • Existing supported credential download flows should continue to work without regression.

Acceptance Criteria

  • Support did:jwk cryptographic binding during credential download.
  • Support did:key cryptographic binding during credential download.
  • Support jwk cryptographic binding during credential download.
  • Ensure the correct holder/wallet key is bound to the issued credential.
  • Validate the binding method received/requested during the issuance flow.
  • Add unit and integration test coverage for all three supported methods.
  • Verify backward compatibility with existing credential issuance flows.
  • Ensure unsupported cose_key is not processed as part of this implementation.
  • Document the supported cryptographic binding methods and limitations.

Test Scenarios

Binding Method Expected Result
did:jwk Credential is successfully issued and bound to the holder key
did:key Credential is successfully issued and bound to the holder key
jwk Credential is successfully issued and bound to the holder key
cose_key Not supported / out of scope

Notes

The implementation should ensure that the cryptographic binding method is preserved correctly from the credential issuance request through credential issuance and subsequent credential usage.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or request

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions