Authors:
Roberto De Prisco
1
;
Sergiy Shevchenko
1
;
2
and
Pompeo Faruolo
2
Affiliations:
1
Computer Science Department, University of Salerno, Salerno, Italy
;
2
eTuitus s.r.l., Fisciano (SA), Italy
Keyword(s):
OpenID Connect for Verifiable Credentials, DIDComm, Decentralized Identity, Secure Communication, Self-Sovereign Identity, Mediator Service.
Abstract:
In the evolving landscape of digital identity management, the secure and efficient handling of verifiable credentials is paramount. OpenID Connect for Verifiable Credentials (OIDC4VC) provides a foundational framework for such interactions, yet it lacks mechanisms for robust, secure communication post-credential issuance and verification. This paper addresses these limitations by proposing an enhancement to OIDC4VC, integrating DIDComm to facilitate encrypted, direct communication between entities. This enhancement introduces a novel approach by embedding an ”X-Mediation” header within the OIDC4VC response, containing the URL of a mediator service that is essential for the continued secure exchange of messages and credentials via DID-Comm. The proposed solution, while ensuring backward compatibility, aims to enhance the privacy, security, and user engagement in digital identity systems by allowing credential issuance and verification processes to be initiated through push notificatio
ns, thereby aligning OIDC4VC more closely with the decentralized ethos of self-sovereign identity.
(More)