|||

IT-Wallet Technical Documentation - Editor's Copy

Quick search

Table of Contents

  • 1. Introduction
  • 2. Brand Identity
  • 3. Architecture Overview
  • 4. Onboarding System
  • 5. User Experience Design
  • 6. The Infrastructure of Trust
  • 7. Registry Infrastructure
  • 8. Entity Onboarding
  • 9. X.509 Certificate Management Operations
  • 10. Entities
  • 11. Digital Credential Management
  • 12. Digital Credential Flows
    • 12.1. Digital Credential Issuance
      • 12.1.1. Credential Issuance High-Level Flows
      • 12.1.2. Credential Issuance Low-Level Flows
      • 12.1.3. eID Substantial Authentication with MRTD Verification for PID Issuance
    • 12.2. Digital Credential Presentation
  • 13. Endpoints
  • 14. Cryptographic Algorithms
  • 15. Security and Privacy Considerations
  • 16. General Log Retention Policies
  • 17. Defined Terms and References
  • 18. How to contribute
  • 19. Open Source Releases
  • 20. Appendix

12.1. Digital Credential IssuanceΒΆ

This section describes the PID and (Q)EAAs issuance flow with a high level of security.

Credential Issuance Table of Contents

  • 12.1.1. Credential Issuance High-Level Flows
    • 12.1.1.1. High-Level PID flow
    • 12.1.1.2. High-Level (Q)EAA flow
  • 12.1.2. Credential Issuance Low-Level Flows
    • 12.1.2.1. Low-Level Issuance Flow
    • 12.1.2.2. Refresh Token Flow
      • 12.1.2.2.1. Security Considerations
    • 12.1.2.3. Re-Issuance Flow
      • 12.1.2.3.1. Re-Issuance Flow: Security Considerations
  • 12.1.3. eID Substantial Authentication with MRTD Verification for PID Issuance
    • 12.1.3.1. Design Principles
    • 12.1.3.2. System Architecture
    • 12.1.3.3. High-Level Flow
    • 12.1.3.4. Session Management
    • 12.1.3.5. Low-Level Flow
      • 12.1.3.5.1. Phase 1: OAuth Authorization Request
      • 12.1.3.5.2. Phase 2: Primary Authentication
      • 12.1.3.5.3. Phase 3: MRTD PoP Validation Flow
      • 12.1.3.5.4. Phase 4: OAuth Authorization Response
    • 12.1.3.6. Error Management
      • 12.1.3.6.1. MRTD PoP Response Errors
      • 12.1.3.6.2. MRTD PoP Validation Response Errors
      • 12.1.3.6.3. HTTP Status Code Mapping
    • 12.1.3.7. Security Considerations
      • 12.1.3.7.1. Secure Session Management
      • 12.1.3.7.2. Cryptographic Challenge Generation
      • 12.1.3.7.3. Nonce Lifecycle Management
      • 12.1.3.7.4. Security Controls
    • 12.1.3.8. Implementation Considerations
<12. Digital Credential Flows
12.1.1. Credential Issuance High-Level Flows>
Last updated on 21/10/2025. Created using Sphinx 7.4.5.