OpenID opens certification for digital ID issuance, verification protocols
Digital wallet providers, digital identity and credential issuers, verifiers and government agencies can now use test suites developed by the OpenID Foundation for self-certification to common digital identity and verifiable credentials specifications.
The Foundation opened self-certification conformance tests for OpenID for Verifiable Presentations (OpenID4VP)and OpenID for Verifiable Credential Issuance (OpenID4VCI) to give implementers a clear way to validate that they’ve followed the specifications correctly.
OpenID4VP and OpenID4VCI are used with the High Assurance Interoperability Profile (HAIP), and OpenID anticipated the launch of the conformance test suites near the end of last year, calling it “a defining moment for global digital identity systems worldwide.” While slightly delayed from the original release schedule, that moment has arrived.
“Until now, there has been no independent way for governments, regulators or ecosystem partners to verify that different implementations of OpenID for Verifiable Presentations and OpenID for Verifiable Credential Issuance would actually work together or meet the security requirements built into these specifications,” says OpenID Foundation Executive Director Gail Hodges.
The organization notes that implementers around the world have carried out extensive real-word interoperability testing for the protocols. During the last of these, in November, OpenID4VP 1.0+ HAIP 1.0 passed 98 percent of tests and OpenID4VCI 1.0+HAIP 1.0 passed 73 percent in one configuration and 82 percent in another.
The protocols are already implemented within the digital identity systems of more than 30 jurisdictions around the world, according to the announcement. Those include all EU member states, the UK, Switzerland, India, and California. Dozens more are considering joining them.
“We want to support all our app and wallet developers to implement these standards correctly on our platform,” says Google Android Auth Identity and Payments Lead Lee Campbell. “With the release of these conformance tests, we now have a proven mechanism to ensure security, interoperability, and consistency across the Android ecosystem.”
Validating implementations of OpenID4VCI for credential issuance and OpenID4VP for presentations and verification of credentials from wallets is therefore important and timely.
The Foundation is also engaged in active talks around conformance requirements and support programs for local implementers with organizations within the EU Digital Identity Wallet ecosystem.
"This is also a firm foundation from which individual jurisdictions can build and tailor their own conformance requirements to meet their specific needs,” Hodges adds. “We are calling on every implementer of OpenID4VP, OpenID4VCI and HAIP to self-certify now and be among the first publicly recognized for meeting this global standard."
"The OpenID4VC test suite fills a critical gap in the ecosystem,” comments Hopae Head of Research Lukas Han in the announcement. “As implementers, we've long needed a way to validate conformance against the spec rather than against each other's interpretations of it. This is what makes interoperability real instead of aspirational."
OIDF charges the same “modest” fees for submitting self-certification applications as for OpenID Connect certifications, and plans to call out early adopters over the first 14 days.