Skip to content

Latest commit

 

History

History
24 lines (19 loc) · 2.63 KB

File metadata and controls

24 lines (19 loc) · 2.63 KB

Task 2: Trust Framework

This task defines the conceptual trust framework for the WP4 Trust Infrastructure, providing the models, policies and criteria used to evaluate and manage trust in the digital Wallet ecosystem.

Folder contents

  • README.md – High‑level overview of the trust framework and its role in WP4
  • authentication-authorization-policy-framework.md – Distinction between authentication and authorization, additive/subtractive policy principles, and federated trust mark use cases
  • credential-catalog-and-issuer-constraints.md – Overview and index for credential catalogues and Trusted List extensions for issuer constraints
  • credential-catalogue.md – Catalogue of attributes and catalogue of attestation schemes (ARF Section 5.5, CIR 2025/1569)
  • entities-involved.md – Description of the entities participating in trust evaluation, the trust registry and trust infrastructure (aligned with the EUDIW ARF)
  • trusted-list-registration-trust-evaluation-matrix.md – Requirements matrix for trusted lists, participant registration and trust evaluation derived from EUDI Wallet ARF Annex 2
  • trust-infrastructure-schema.md – Structural schema of the trust infrastructure, including registries, entities and relationships
  • eudi-wallet-trust-and-entitlement-discovery.md – Policy discovery and trust verification from wallet (holder) perspective: WRPRC/WRPAC discovery, Trusted List validation, Registry lookup, entitlement and attribute validation (ARF RPRC_21, RPA_*)
  • rp-intermediary-openid4vp-technical-report.md – Non-normative technical report on Relying Party intermediaries in remote OpenID4VP flows: verifier_info, WRPAC/WRPRC exposure, intermediary detection, and examples (ARF Topic 52, ETSI TS 119 472-2)
  • issue-mdl-pub-eaa-discovery.md – Issue note on mDL, EAA publication and discovery in relation to the trust framework
  • etsi-identifier-handling.md – Handling of ETSI identifiers and their mapping into the trust infrastructure

Scope of Task 2

  • Trust model and policies – Define trust hierarchy, roles, trust anchors, trust chains and categories of policies (identity, security, operational, legal).
  • Evaluation and management – Specify trust metrics, indicators, scoring, validation, establishment, maintenance, revocation and monitoring.
  • Data and interfaces – Describe the data model and architectural components (trust registry, engine, policies, APIs) that are later realized in Tasks 3, 4 and 5.
  • Standards alignment – Align the framework with ETSI trusted list specifications and X.509 PKI standards used across the rest of WP4.