You are viewing an old version of this page. View the current version.
Compare with Current
View Page History
« Previous
Version 2
Next »
SD-JWT
- JWT for Selective Disclosure. https://www.ietf.org/archive/id/draft-fett-oauth-selective-disclosure-jwt-02.html
- Flow:
- Issuer passes two objects to the holder:
- SD-JWT (signed JWT, contains CLAIMs, HASHES OF VALUES, and a signature)
- SD-JWT-SVC (Salt Value Container, contains CLAIMs, SALTS, and JSON-Encoded VALUES)
- Holder
- creates SD-JWT-R (unsigned subset of the SD-JWT-SVC) i.e. holder can see the values of the claims that are released.
- passes SD-JWT and SD-JWT-R to the verifier
- Verifier
- Uses salts to verify hashes
- Can then trust the SD-JWT
- Extensions allow for "holder binding" to eliminate replay attacks.
- Pros:
- User sees values that are passed on
- User is in charge of the selection of claims
- Cons:
- Breaks existing JWT flows
ELM-V3