Organisation Wallet Suite Features
OpenID for Verifiable Credentials (OpenID4VC - OpenID4VCI and OpenID4VP)
Summary of key features and protocols
| Category | Supported Options |
|---|---|
| Formats Supported |
|
| Issuance Protocols | OpenID4VCI 1.0 with HAIP 1.0 EWC RFC001: Issue Verifiable Credential - v2.0 |
| Issuance Features |
|
| Key Managements | Cryptographic key formats supported are: X.509, JWK, Decentralised Identifier (DID) did:keyThe key storage can be:
|
| Presentation Protocols | OpenID4VP 1.0 with HAIP 1.0, OpenID4VP (Draft 18) ISO/IEC 18013-7 Annex C and the W3C Digital Credentials API (see DC API overview) EWC RFC002: Present Verifiable Credentials - v1.0 |
| Presentation Features |
|
| Signing Algorithms | ECDSA (secp256r1/P-256) with SHA-256 (ES256) |
| Revocation Management | IETF Token Status List:
|
| Trust Managements | X.509 certificate chains, EU Trusted Lists as per ETSI TS 119 612 (XML), Lists of Trusted Entities as per ETSI TS 119 602 (JSON and XML), and trust anchors configured per organisation. See Trust in the Wallet Ecosystem |
| Wallet Provider |
|
| Holder (Organisation Wallet) |
|
| Payments (TS12) | Strong Customer Authentication (SCA) attestations as per TS12: Electronic payments, SCA implementation with the wallet: payment card, payment account, payment service user (issued without user claims, as the rulebook defines), and Strong User Authentication (SUA) user and IBAN credentials. SCA transaction data is validated at presentation. See the payment extensions below. |
EUDI Wallet technical specifications
The Organisation Wallet Suite implements the following EUDI Wallet technical specifications:
| Specification | Organisation Wallet Suite feature |
|---|---|
| TS3: Wallet Unit Attestation | Wallet Provider: WUA with WIA and key attestation; issuers can require key attestation with a specified assurance level |
| TS12: Electronic payments, SCA implementation with the wallet | SCA attestations, SCA transaction data and the payment extensions |
WE BUILD conformance specifications
The Organisation Wallet Suite is built against the WE BUILD conformance specifications, which iGrant.io helps to write (see WE BUILD Consortium). The WE BUILD Conformance Overview of the WE BUILD Interoperability Test Bed lists the Organisation Wallet Suite (wallet, issuer and verifier) with full conformance to the base protocols CS-01 and CS-02.
| Specification | Title | Organisation Wallet Suite feature |
|---|---|---|
| CS-01 | Credential Issuance | OpenID4VCI 1.0 issuer and holder |
| CS-02 | Credential Presentation | OpenID4VP 1.0 verifier and holder |
| CS-03 | Remote Qualified Signing with Wallet Units | Document Signing with a QTSP over the CSC API |
| CS-04 | Individual Wallet Unit Attestation (WUA) Lifecycle | Wallet Provider: TS3 WUA issuance and revocation |
| CS-07 | Credential Presentation and Issuance via the Digital Credentials API | Presentation over the DC API |
| CS-10 | Attestation Revocation Mechanism | IETF Token Status List |
| CS-12 | SCA Attestations for Payment Transactions (TS12 Profile) | TS12 SCA attestations and the payment extensions |
Extensions
The following extensions are available in the Organisation Wallet Suite:
| Extension | Purpose |
|---|---|
| Age Verification | Check the age of a user with PID, Passport or Photo ID |
| Know Your Customer (KYC) | Verify the identity of a customer with PID, Passport or Photo ID |
| Passwordless Login | OpenID Connect provider for login with an EUDI Wallet |
| Document Signing | Sign PDF documents with a Qualified Electronic Signature from the wallet |
| PID Credential Issuance | Issue PID credentials |
| Photo ID Credential Issuance | Issue Photo ID credentials |
| Payment Credential Issuance (TS12) | Issue SCA attestations for a payment account, card or user |
| Payment Authorisation (for Banks) (TS12) | Authorise payments initiated at the bank of the payer |
| Payment Authorisation (for Merchants) (TS12) | Authorise payments at a merchant or a PISP |
| Account Information Access (TS12) | Consented access to payment account information |
| Recurring Payment Mandate (TS12) | Consent for recurring or merchant-initiated payments |
| Risk-based Authentication (TS12) | Step-up SCA for login and sensitive actions |
| OpenID Conformance | Set up the organisation for the OpenID Foundation conformance test plans (HAIP 1.0) |
OpenID Foundation conformance (HAIP 1.0)
The Organisation Wallet Suite is tested against the OpenID Foundation conformance suite with the High Assurance Interoperability Profile (HAIP) 1.0 certification test plans: OpenID4VCI 1.0 Final + HAIP 1.0 Final and OpenID4VP 1.0 Final + HAIP 1.0 Final. The test plans below are published by the OpenID Foundation conformance suite, and each link opens the public test results.
As a software provider, we keep the Organisation Wallet Suite certification ready: all certification profiles that the software supports pass.
| Role | Certification profile | Test results |
|---|---|---|
| Issuer | OID4VCI 1.0 + HAIP 1.0, SD-JWT VC, wallet-initiated | View results |
| Issuer | OID4VCI 1.0 + HAIP 1.0, mdoc, wallet-initiated | View results |
| Issuer | OID4VCI 1.0 + HAIP 1.0, SD-JWT VC, issuer-initiated | View results |
| Issuer | OID4VCI 1.0 + HAIP 1.0, mdoc, issuer-initiated | View results |
| Verifier | OID4VP 1.0 + HAIP 1.0, SD-JWT VC, direct_post.jwt | View results |
| Verifier | OID4VP 1.0 + HAIP 1.0, mdoc, direct_post.jwt | View results |
| Holder | OID4VCI 1.0 + HAIP 1.0, SD-JWT VC, wallet-initiated | View results |
| Holder | OID4VCI 1.0 + HAIP 1.0, mdoc, wallet-initiated | View results |
| Holder | OID4VCI 1.0 + HAIP 1.0, SD-JWT VC, issuer-initiated, offer by value | View results |
| Holder | OID4VCI 1.0 + HAIP 1.0, SD-JWT VC, issuer-initiated, offer by reference | View results |
| Holder | OID4VCI 1.0 + HAIP 1.0, mdoc, issuer-initiated, offer by value | View results |
| Holder | OID4VCI 1.0 + HAIP 1.0, mdoc, issuer-initiated, offer by reference | View results |
| Holder | OID4VP 1.0 + HAIP 1.0, SD-JWT VC, direct_post.jwt | View results (PID query) |
| Holder | OID4VP 1.0 + HAIP 1.0, mdoc, direct_post.jwt | View results (mDL query, Photo ID query) |
EU Digital Identity Wallet Consortium (EWC) Specifications
The following EWC RFCs are supported by iGrant.io Organisation Wallet.
| Category | RFC |
|---|---|
| PID Issuance | EWC RFC003: Issue Person Identification Data (PID) - v1.1 |
| Legal PID Issuance | EWC RFC005: Issue Legal Person Identification Data (LPID) - v1.0 |
| Wallet Unit Attestation (Individual) | EWC RFC004: Individual Wallet Unit Attestation - v1.0 |
| Wallet Unit Attestation (Organisation) | EWC RFC006: Organisational Wallet Unit Attestation (Work-In-Progress) |
| Payment Authenticator | EWC RFC007: Payment Authenticator - v1.0 |
| Payment Data Confirmation | EWC RFC008: Payment Data Confirmation - v1.0 |