WS_AP_SM_DeviceBinding_012a¶
Objective¶
Verify that the Wallet uses the nonce from the Nonce Endpoint of the Credential Issuer to include a nonce in the proof of Key Attestation, when the Wallet uses the jwt Proof Type.
References¶
- [CIR 2024/2979 amended] annex Ib
- [ETSI TS 119 472-3] section 4.6.1.2
- [HAIP] section 4.5.1
- [OpenID4VCI] section 7, 8.2, F.1
Profile applicability¶
Wallet uses the jwt proof type to convey a key attestation in Credential Requests.
EUDI-wallet relevancy¶
EUDI_specific | EUDI_required
Technology¶
Preconditions¶
- Wallet is set to 'default_configuration_1'
- Wallet started engagement with Credential Issuer.
- Wallet successfully obtained Credential Issuer Metadata, including the
nonce_endpointof the Credential Issuer. - Wallet successfully authenticated to the (Authorization Server of the) Credential Issuer.
- Wallet successfully obtained an Access Token from the Token Endpoint of the (Authorization Server of the) Credential Issuer.
- Wallet successfully obtained a value in
c_noncein the Nonce Response, by making a Nonce Request to the Nonce Endpoint of the Credential Issuer. - Wallet send a valid and trusted signed JWT as proof of Key Attestation, with the Credential Request.
- Wallet send a syntactically correct
noncein the proof of Key Attestation.
Test Scenario¶
- Verify the
noncevalue in the proof of Key Attestation.
Expected results¶
- The value of the
noncein the signed JWT that makes the proof of Key Attestation, is equal to the value of thec_nonceprovided in the Nonce Response from the Nonce Endpoint.