Skip to main content

Organisation Wallet Suite Features

The Organisation Wallet Suite from iGrant.io is specifically designed for enterprises, offering support for OpenID for Verifiable Credentials (OpenID4VC - OpenID4VCI and OpenID4VP), the EUDI Wallet technical specifications TS3 and TS12, and the WE BUILD conformance specifications, as detailed below.

OpenID for Verifiable Credentials (OpenID4VC - OpenID4VCI and OpenID4VP)​

Summary of key features and protocols

CategorySupported Options
Formats Supported
  • IETF SD-JWT VC (dc+sd-jwt), with selective disclosure as per SD-JWT (RFC 9901), including nested objects and array elements
  • ISO/IEC 18013-5 mdoc (mso_mdoc), for example mDL, PID and Photo ID
  • W3C VC (JWT, jwt_vc_json), presented with OpenID4VP (Draft 18)
Issuance ProtocolsOpenID4VCI 1.0 with HAIP 1.0

EWC RFC001: Issue Verifiable Credential - v2.0
Issuance Features
  • Pre-authorised code flow with transaction code (tx_code), and authorisation code flow with Pushed Authorisation Requests (PAR) and PKCE
  • Issuer-initiated issuance (credential offer by value or by reference) and wallet-initiated issuance
  • Credential offer reuse per credential definition: one credential offer can start several issuances
  • Interactive Authorisation Request (IAR), including OpenID4VP presentation during issuance
  • Sender-constrained tokens with DPoP (RFC 9449) and wallet authentication with OAuth 2.0 Attestation-Based Client Authentication
  • Proof types jwt and attestation, with key attestation requirements set per credential definition and per proof type
  • Batch issuance, deferred issuance, nonce endpoint and notification endpoint
  • Credential refresh (re-issuance with a refresh token)
  • Encrypted credential requests and responses
  • Dynamic credential request (the issuer requests a presentation before it issues)
  • External authorisation servers: user authentication at an external OpenID Connect provider, set per credential definition
Key ManagementsCryptographic key formats supported are: X.509, JWK, Decentralised Identifier (DID) did:key

The key storage can be:
  • iGrant.io secure storage vault
  • Bring your HSMs via Hashicorp Vault
  • Use a Qualified Trust Service Provider (QTSP) through the Cloud Signature Consortium (CSC) API v1.0.4.0 or v2.2.0.0
Presentation ProtocolsOpenID4VP 1.0 with HAIP 1.0, OpenID4VP (Draft 18)

ISO/IEC 18013-7 Annex C and the W3C Digital Credentials API (see DC API overview)

EWC RFC002: Present Verifiable Credentials - v1.0
Presentation Features
  • Digital Credentials Query Language (DCQL), including credential sets, claim sets and trusted authorities (aki, etsi_tl)
  • Transaction data, including the TS12 payment, e-mandate, account access and login and risk types, and qualified electronic signature data
  • Response modes direct_post, direct_post.jwt, dc_api and dc_api.jwt
  • Client identifier prefixes x509_san_dns, x509_hash, decentralized_identifier (did:key), verifier_attestation and redirect_uri
  • Signed request objects, passed by value or by reference (request_uri, including request_uri_method=post)
Signing AlgorithmsECDSA (secp256r1/P-256) with SHA-256 (ES256)
Revocation ManagementIETF Token Status List:
  • Status List Token in JWT format for SD-JWT VC, and in CWT format for mdoc as per ISO/IEC 18013-5, served from the same status list URL (the format is selected with the HTTP Accept header)
  • A status list signing key per credential configuration; for mdoc, a revocation list signer certificate as per ISO/IEC 18013-5 Table B.9
Trust ManagementsX.509 certificate chains, EU Trusted Lists as per ETSI TS 119 612 (XML), Lists of Trusted Entities as per ETSI TS 119 602 (JSON and XML), and trust anchors configured per organisation. See Trust in the Wallet Ecosystem
Wallet Provider
  • Wallet Unit Attestation (WUA) as per TS3: Wallet Unit Attestation, with a Wallet Instance Attestation (WIA) and a wallet-provider-signed key attestation
  • Wallet unit management and statistics
  • Revocation of WUAs and key attestations through the Token Status List
Holder (Organisation Wallet)
  • Receive and store credentials over OpenID4VCI 1.0, including deferred and batch issuance, DPoP and credential refresh (see Receive and Store Credential)
  • Present credentials over OpenID4VP 1.0 (see Receive and Present Credential)
  • Holder keys in a separate holder key store, apart from the issuer and verifier signing keys
  • Organisational identity with Legal Person Identification Data (LPID)
Payments (TS12)Strong Customer Authentication (SCA) attestations as per TS12: Electronic payments, SCA implementation with the wallet: payment card, payment account, payment service user (issued without user claims, as the rulebook defines), and Strong User Authentication (SUA) user and IBAN credentials. SCA transaction data is validated at presentation. See the payment extensions below.

EUDI Wallet technical specifications​

The Organisation Wallet Suite implements the following EUDI Wallet technical specifications:

SpecificationOrganisation Wallet Suite feature
TS3: Wallet Unit AttestationWallet Provider: WUA with WIA and key attestation; issuers can require key attestation with a specified assurance level
TS12: Electronic payments, SCA implementation with the walletSCA attestations, SCA transaction data and the payment extensions

WE BUILD conformance specifications​

The Organisation Wallet Suite is built against the WE BUILD conformance specifications, which iGrant.io helps to write (see WE BUILD Consortium). The WE BUILD Conformance Overview of the WE BUILD Interoperability Test Bed lists the Organisation Wallet Suite (wallet, issuer and verifier) with full conformance to the base protocols CS-01 and CS-02.

SpecificationTitleOrganisation Wallet Suite feature
CS-01Credential IssuanceOpenID4VCI 1.0 issuer and holder
CS-02Credential PresentationOpenID4VP 1.0 verifier and holder
CS-03Remote Qualified Signing with Wallet UnitsDocument Signing with a QTSP over the CSC API
CS-04Individual Wallet Unit Attestation (WUA) LifecycleWallet Provider: TS3 WUA issuance and revocation
CS-07Credential Presentation and Issuance via the Digital Credentials APIPresentation over the DC API
CS-10Attestation Revocation MechanismIETF Token Status List
CS-12SCA Attestations for Payment Transactions (TS12 Profile)TS12 SCA attestations and the payment extensions

Extensions​

The following extensions are available in the Organisation Wallet Suite:

ExtensionPurpose
Age VerificationCheck the age of a user with PID, Passport or Photo ID
Know Your Customer (KYC)Verify the identity of a customer with PID, Passport or Photo ID
Passwordless LoginOpenID Connect provider for login with an EUDI Wallet
Document SigningSign PDF documents with a Qualified Electronic Signature from the wallet
PID Credential IssuanceIssue PID credentials
Photo ID Credential IssuanceIssue Photo ID credentials
Payment Credential Issuance (TS12)Issue SCA attestations for a payment account, card or user
Payment Authorisation (for Banks) (TS12)Authorise payments initiated at the bank of the payer
Payment Authorisation (for Merchants) (TS12)Authorise payments at a merchant or a PISP
Account Information Access (TS12)Consented access to payment account information
Recurring Payment Mandate (TS12)Consent for recurring or merchant-initiated payments
Risk-based Authentication (TS12)Step-up SCA for login and sensitive actions
OpenID ConformanceSet up the organisation for the OpenID Foundation conformance test plans (HAIP 1.0)

OpenID Foundation conformance (HAIP 1.0)​

The Organisation Wallet Suite is tested against the OpenID Foundation conformance suite with the High Assurance Interoperability Profile (HAIP) 1.0 certification test plans: OpenID4VCI 1.0 Final + HAIP 1.0 Final and OpenID4VP 1.0 Final + HAIP 1.0 Final. The test plans below are published by the OpenID Foundation conformance suite, and each link opens the public test results.

As a software provider, we keep the Organisation Wallet Suite certification ready: all certification profiles that the software supports pass.

RoleCertification profileTest results
IssuerOID4VCI 1.0 + HAIP 1.0, SD-JWT VC, wallet-initiatedView results
IssuerOID4VCI 1.0 + HAIP 1.0, mdoc, wallet-initiatedView results
IssuerOID4VCI 1.0 + HAIP 1.0, SD-JWT VC, issuer-initiatedView results
IssuerOID4VCI 1.0 + HAIP 1.0, mdoc, issuer-initiatedView results
VerifierOID4VP 1.0 + HAIP 1.0, SD-JWT VC, direct_post.jwtView results
VerifierOID4VP 1.0 + HAIP 1.0, mdoc, direct_post.jwtView results
HolderOID4VCI 1.0 + HAIP 1.0, SD-JWT VC, wallet-initiatedView results
HolderOID4VCI 1.0 + HAIP 1.0, mdoc, wallet-initiatedView results
HolderOID4VCI 1.0 + HAIP 1.0, SD-JWT VC, issuer-initiated, offer by valueView results
HolderOID4VCI 1.0 + HAIP 1.0, SD-JWT VC, issuer-initiated, offer by referenceView results
HolderOID4VCI 1.0 + HAIP 1.0, mdoc, issuer-initiated, offer by valueView results
HolderOID4VCI 1.0 + HAIP 1.0, mdoc, issuer-initiated, offer by referenceView results
HolderOID4VP 1.0 + HAIP 1.0, SD-JWT VC, direct_post.jwtView results (PID query)
HolderOID4VP 1.0 + HAIP 1.0, mdoc, direct_post.jwtView results (mDL query, Photo ID query)

EU Digital Identity Wallet Consortium (EWC) Specifications​

The following EWC RFCs are supported by iGrant.io Organisation Wallet.

CategoryRFC
PID IssuanceEWC RFC003: Issue Person Identification Data (PID) - v1.1
Legal PID IssuanceEWC RFC005: Issue Legal Person Identification Data (LPID) - v1.0
Wallet Unit Attestation (Individual)EWC RFC004: Individual Wallet Unit Attestation - v1.0
Wallet Unit Attestation (Organisation)EWC RFC006: Organisational Wallet Unit Attestation (Work-In-Progress)
Payment AuthenticatorEWC RFC007: Payment Authenticator - v1.0
Payment Data ConfirmationEWC RFC008: Payment Data Confirmation - v1.0