- From: Christian Hommrich <christian.hommrich@trailprotocol.org>
- Date: Sun, 21 Jun 2026 13:25:44 +0200
- To: public-credentials@w3.org
- Cc: amsaalegal@gmail.com, msporny@digitalbazaar.com
- Message-ID: <CANVCHRXp+3ZLXNg5GGLu5QEWhAZg7OsDKeF58z9+zXyYYasOHQ@mail.gmail.com>
Hi Amir, hi Manu, thanks Amir for the welcome and for the scope clarification. Framing this around cryptographic continuity, rather than any single suite, is the right level, and it maps cleanly onto what JCS-based DID-method implementers face across key rotation and PQC transitions alike. Manu, thanks for the pointers. The Quantum-Resistant VC spec is directly relevant on our side, since it already defines an mldsa44-jcs-2024 cryptosuite, so a migration pattern that aligns its JCS guidance with that existing cryptosuite, rather than inventing anything new, is exactly the additive path our implementers would follow. The forgery-defense work belongs in the related-work set too. Agreed that both should be referenced. As the next step Amir described, I will add a comment on issue #260 raising the points most relevant from a JCS deployment: canonical-byte determinism across a dual-proof transition (specifically whether both proofs commit to the same canonical form), and verifier behavior when only one of the two proofs validates. Where useful, I can share JCS canonicalization test vectors from our existing eddsa-jcs-2023 implementation. Glad to take part as a contributor and reviewer, asynchronously, if and as the work item is adopted. Best regards, Christian Hommrich did:trail method (registered in the W3C DID Extensions registry) On Sat, Jun 20, 2026 05:05 PM, Amir Hameed <amsaalegal@gmail.com> wrote: > Hi Christian, hi Manu, > > > Thank you both for the thoughtful feedback. > > Christian, I very much appreciate your interest in contributing. Your > observations around canonical-byte stability, verifier behavior during > transition, and implementation-focused test vectors are exactly the kinds > of practical deployment concerns I hope this work item can capture. It is > particularly valuable to have perspectives from JCS-based deployments and > DID-method implementers, and I would be glad to have your participation as > a contributor and reviewer should the work item move forward. > > Manu, thank you for pointing to the Quantum-Resistant VC and Forgery > Defense work. Those specifications are highly relevant reference points and > should absolutely be reflected in the document as related work and > implementation experience. > > One clarification on scope: the intent of this work item is not to define > or recommend any particular cryptographic suite, nor to modify existing > Data Integrity or Verifiable Credentials specifications. Instead, the focus > is on cryptographic continuity, migration guidance, verifier behavior, > interoperability, and operational deployment considerations that remain > applicable across different cryptographic suites, including post-quantum > transitions, routine key rotations, and future algorithm changes. > > I see the existing cryptosuites, proof mechanisms, and emerging > post-quantum work as important building blocks. The goal here is to > document patterns, trade-offs, implementation guidance, and operational > considerations that help organizations apply those capabilities > successfully over long time horizons. > > Given the global and multidisciplinary nature of the topic, my expectation > is that participation will be largely asynchronous, allowing contributors > from different regions, organizations, and technical backgrounds to > participate without requiring constant real-time coordination. > > As the work item is still in the proposal stage and has not yet been > adopted, I would encourage anyone interested in contributing, reviewing, > providing implementation experience, test vectors, deployment perspectives, > or editorial feedback to comment on the issue directly and express their > interest. Establishing community support and identifying potential > contributors early will help ensure that any future work can proceed > smoothly and reflect a broad range of perspectives. > > Thank you again for the feedback, references, and willingness to > contribute. > > > Best regards, > > Amir Hameed Mir > Sirraya Labs > > On Sat, 20 Jun 2026 at 6:37 PM, Manu Sporny <msporny@digitalbazaar.com> > wrote: > >> On Sat, Jun 20, 2026 at 8:17 AM Christian Hommrich >> <christian.hommrich@trailprotocol.org> wrote: >> > I have a direct interest in getting it right, and I would be glad to >> join as a contributor >> >> Hey Christian, thank you for volunteering and I agree with the value >> of what you identified. >> >> You probably already know this exists, but if you don't, we do have a >> quantum-resistant spec on the standards track at W3C: >> >> https://www.w3.org/TR/vc-di-quantum-resistant-1.0/#introduction >> >> which does define JCS cryptosuites: >> >> >> https://www.w3.org/TR/vc-di-quantum-resistant-1.0/#cryptosuite-mldsa44-jcs-2024 >> >> ... and you will also want to pay attention to the forgery defense >> work, in addition to what you mentioned: >> >> https://w3c.github.io/vc-forgery-defense/#abstract >> >> Each of those things is something that should also be mentioned in the >> document that you and Amir are working on. >> >> -- manu >> >> -- >> Manu Sporny - https://www.linkedin.com/in/manusporny/ >> Founder/CEO - Digital Bazaar, Inc. >> https://www.digitalbazaar.com/ >> >
Received on Sunday, 21 June 2026 11:26:01 UTC