Hi Dmitri
If the wallet does not trust the verifier then a strict wallet may not let the user send their personal information to an untrustworthy verifier who may abuse this PII (e.g. if the VC is a passport). A lax wallet may ask the user first, Do you really want to send your PII to this untrustworthy verifier?
So the next question is How does the wallet learn that the verifier is trustworthy. Ans. This is the function of the trust infrastructure. But it might be asking too much to build trust infrastructures into Plugfest 3, which is why I suggested it could be Plugfest 4.
Kind regards
David
Hi David,
Can you clarify/expand the question? In the general VC ecosystem, there's no assumption that there's any trust relationship between the wallet and the verifier.(There is the assumption that the wallet will accurately convey to the user the verifier's identity, that is, WHO is asking for the credentials. But that's different from a trust relationship between wallet and verifier.)
Dmitri
On Thu, Feb 9, 2023 at 3:47 PM David Chadwick <d.w.chadwick@truetrust.co.uk> wrote:
Hi Sharon
I am guessing that for this demo (please correct me if I am wrong) the assumption will be that the wallet trusts the verifier and the verifier trusts the wallet. Then plugfest 4 can determine how to integrate trust infrastructures for the open world model where neither trust each other initially.
The next step will be for each protocol group to determine the profile that they will use, because in the OIDC4VP case there are lots of different possibilities and combinations to chose from.
Kind regards
David
On 10/02/2023 07:36, Sharon Leu wrote:
Hi David,
Thanks for your comment. We are anticipating that wallets will generally support one of VPR or OIDC4VP, similar to how the groups in the previous plugfest. Are there other potential details we should note?
sharon
From: David Chadwick <d.w.chadwick@truetrust.co.uk>
Date: Monday, February 6, 2023 at 1:56 PM
To: public-vc-edu@w3.org <public-vc-edu@w3.org>
Subject: Re: Plugfest 3 ProposalHi Sharon
Thankyou for having this discussion at today's meeting. I am sorry I could not attend, but it was at 4am New Zealand time and consequently I was fast asleep in bed.
I agree with the proposed workflow. The devil might be in the details e.g. will it be DIF PEv1, PEv2 or W3C Presentation Request that wallets should support? (FYI we have a solution for limited use cases of this); which status methods should be supported etc.\
I agree that this will need a longer timeline than either of the previous plugfests
Kind regards
David
On 07/02/2023 06:25, Sharon Leu wrote:
Hello vc-edu,
Thank you for your helpful feedback on plugfest 2 and sharing your ideas for plugfest 3. There are many important aspects of VC interop on which we could focus, but as we considered our primary objective – creating functional LERs, we think that the logical next step is to emphasize presentation exchange.
We propose the following workflow:
- Verifier requests a set of credentials from holder
- Holder selects (3) relevant credentials from the wallet
- Holder presents to verifier in form of verifiable presentation
- Verifier verifies the authenticity of the VP (including DID auth on the VP) and individual VCs (including credential status check)
We have noted several other considerations in our slides deck: https://docs.google.com/presentation/d/1SuyKPLmb1KqLPEsfDnzaBtd1GpGjuHH9e04RoWDojC4/edit?usp=sharing (proposed workflow is on slide 5).
Please let us know what you think about this approach – concerns, questions, etc.
Look forward to Plugfest 3, coming soon!
Sharon