Skip to content

Assurance

EUDI-grade engineering beneath a global runtime: machine-checked proofs, explicit threat models, native assurance, and profile-specific conformance.

Conformance & standards

Standards are executable contracts.

One row per standard or profile, with its exact version, the wallet's implementation role, the suite that exercised it, the result, the date, and the artifact. External certification has not been performed for any row — planned rows claim nothing.

Filter by status:
13/13 rows
OpenID for Verifiable Presentations (OpenID4VP)1.0 · role: WalletTested

Signed request objects, DCQL query parsing, type-aware credential selection (meta.vct_values / meta.doctype_value), data-minimised consent, KB-JWT holder binding for SD-JWT VC, and an ISO 18013-5 mdoc DeviceResponse vp_token whose device authentication is signed over the OpenID4VP SessionTranscript — direct_post form response with DCQL-keyed vp_token + echoed state, all exercised, including a full presentation over a live TCP relying-party endpoint and an mdoc presentation verified by an independent party from wire data.

Format:
SD-JWT VC (dc+sd-jwt)
Suite:
In-repo: state-machine, wire-format and live-TCP E2E suites (cargo test)
Executed:
2026-07-23
Commit:
3d19993

Evidence: crates/oid4vp/ · crates/wallet-core/tests/e2e_mdoc_flow.rs · crates/shell-io/tests/e2e_live_presentation.rs

Notes & limitations Both direct_post and encrypted direct_post.jwt are implemented and tested end-to-end for SD-JWT and mdoc. Nonces are strict opaque URL-safe strings; mdoc status is checked fail-closed; and x509_san_dns client IDs are bound to the leaf certificate SAN. The OIDF conformance suite has not yet been run (see row below).

OpenID for Verifiable Credential Issuance (OpenID4VCI)1.0 · role: WalletTested

Pre-authorized and authorization-code (PAR + PKCE S256) machines; in-core issuer-trust decision; Wallet Unit Attestation key gate; device-signed proof-of-possession; c_nonce replay rejection; credential stored exactly as received over a live socket.

Format:
SD-JWT VC (dc+sd-jwt)
Suite:
In-repo: issuance state machine + live-TCP lifecycle E2E (cargo test)
Executed:
2026-07-23
Commit:
3d19993

Evidence: crates/oid4vci/ · crates/shell-io/tests/e2e_live_lifecycle.rs

Notes & limitations Official AusweisApp SDK 2.5.4 adapters and secret-free process-death recovery contracts are wired on iOS and Android. Production entitlement/device evidence and a successful live external PID round-trip remain pending; the reference issuer currently returns HTTP 500.

High Assurance Interoperability Profile (HAIP)1.0 · role: WalletPartial

HAIP-aligned guards are enforced in-core (signed request objects, grant-type allow-list, PKCE S256, sender-bound tokens, attested proof keys).

Commit:
3d19993

Evidence: crates/oid4vci/src/lib.rs · crates/oid4vp/src/lib.rs

Notes & limitations Encrypted direct_post.jwt and mdoc-over-OpenID4VP are implemented and tested. No official profile-level conformance run has been executed, so the overall HAIP claim remains partial.

SD-JWT-based Verifiable Credentials (SD-JWT VC)draft (dc+sd-jwt) · role: Wallet (holder) + verifier-side checks in testsTested

Parse/verify, selective disclosure with digest checking, KB-JWT issuance & verification, alg:none and malformed-input rejection; fuzz target sdjwt_parse.

Format:
dc+sd-jwt
Suite:
In-repo: crates/sdjwt tests + E2E presentation verification (cargo test)
Executed:
2026-07-19
Commit:
cb688a8

Evidence: crates/sdjwt/

Notes & limitations Test vectors are repo-generated; alignment against published external vectors is planned.

ISO/IEC 18013-5 (mdoc / mDL proximity)2021 · role: mdoc holder (Wallet)Tested

IssuerSigned/MSO build+verify, DeviceResponse assembly, SessionTranscript binding, reader authentication, session-encryption state machine; canonical-CBOR negative tests; fuzz targets mdoc_cbor and cose_cbor; Kani bounded proofs on the mdoc crate in CI.

Format:
mso_mdoc (CBOR/COSE)
Suite:
In-repo: crates/mdoc + crates/iso18013-5 suites (cargo test)
Executed:
2026-07-19
Commit:
cb688a8

Evidence: crates/mdoc/ · crates/iso18013-5/

Notes & limitations BLE/NFC transports are shell adapters not yet implemented on device. The mdoc-over-OpenID4VP handover (the OID4VPHandover SessionTranscript that device authentication signs over) is now wired and tested end-to-end — see crates/oid4vp/tests/mdoc_presentation.rs and crates/wallet-core/tests/e2e_mdoc_flow.rs.

OpenID Foundation Conformance Suite (OpenID4VP / OpenID4VCI / HAIP)self-certification program opened 2026-02-26 · role: WalletPlanned

Notes & limitations Not yet executed. The suite is the intended external interoperability bar. Self-certification scope, evidence retention, and renewal rules are documented in docs/certification-evidence/openid-self-certification.md; no result is claimed.

EUDI ARF requirement traceability (harmonized register)ARF v2.9.0 · PID Rulebook v1.7 (register snapshot 2026-07-17) · role: Wallet UnitPartial

180 of 684 harmonized requirements mapped to implementation symbols AND named tests; the remaining 504 are explicitly recorded as unassigned (provider-side backends, governance, and P2 credential types not built).

Suite:
tools/evidence/generate.sh (Tier 0)
Applicable / mapped:
180/684
Executed:
2026-07-19
Commit:
cb688a8

Evidence: traceability/requirements.csv · docs/certification-evidence/verification-report.md

Notes & limitations Mapping coverage, not conformance testing. Kept deliberately high-precision (no keyword inflation).

EUDI Functional Conformance Assessment Framework (FCAF)v0.0.7 (pinned) · role: Wallet UnitPlanned

Notes & limitations FCAF defines harmonized functional test cases; it is not itself an automated executable suite. A pinned FCAF run + report directory exists in the evidence set (docs/certification-evidence/fcaf-reports/, currently empty). No result is claimed.

PSD2 SCA & dynamic linking (Commission Delegated Regulation (EU) 2018/389)RTS Articles 4–5 · role: Wallet as SCA/authorization component (never payment execution)Tested

Article-by-article traceability: authentication-code generation & verification (Art. 4), forgery resistance, payer awareness of amount+payee (Art. 5(1)), dynamic linking to amount, payee name, payee IBAN and currency (Art. 5(1)(c)/5(3)), code integrity (Art. 5(2)), replay rejection, possession-factor requirement.

Suite:
crates/crypto-backend/tests/regulatory_sca.rs (cargo test, real aws-lc-rs crypto)
Executed:
2026-07-19
Commit:
cb688a8

Evidence: docs/certification-evidence/payment-sca.md

Notes & limitations TS12 wire envelope is approximated pending the published schema; transport confidentiality is the shell's TLS; SCA exemptions (Arts. 10–18) out of wallet scope.

eIDAS qualified electronic signatures (QES orchestration)Regulation (EU) 910/2014 as amended by (EU) 2024/1183 · role: Wallet as authorization/orchestration component (not a QSCD)Partial

The WYSIWYS authorization core is implemented and formally analysed (Lean QesModel; Tamarin qes.spthy: what_you_see_is_what_you_sign, no_document_substitution).

Commit:
cb688a8

Evidence: crates/qes/ · formal/tamarin/qes.spthy

Notes & limitations No QTSP integration yet: CSC API v2.0 alignment and a remote-QSCD flow against a qualified trust service are planned. No signature produced today is a qualified signature.

Token Status List (credential revocation/suspension)IETF draft · role: Wallet (relying on issuer-published lists)Tested

Signed status-list verification, bit-level status lookup, fail-closed policy for remote presentation (unresolvable status blocks presentation).

Suite:
crates/status tests + wallet-core e2e_status (cargo test)
Executed:
2026-07-19
Commit:
cb688a8

Evidence: crates/status/

Notes & limitations Fetch-and-refresh scheduling is a shell concern; core decides on verified lists only.

Wallet Unit Attestation (key attestation gate)EUDI TS (register snapshot 2026-07-17) · role: WalletTested

WUA JWT verification binding the device public key at the stated assurance level; issuance proof-of-possession is refused in-core when the key is not attested.

Suite:
crates/wua tests + issuance gate tests (cargo test)
Executed:
2026-07-19
Commit:
cb688a8

Evidence: crates/wua/

Notes & limitations Wallet-provider WUA issuance service is out of scope of this repository.

Wallet certification (CIR (EU) 2024/2981 + EUCC)2024 · role: Wallet solutionPlanned

Notes & limitations Certification is performed by an accredited CAB under the national scheme; this project maintains the evidence set (docs/certification-evidence/) but has not entered certification. No certification is claimed.