Skip to content

Commit 79fc54d

Browse files
committed
Switch to ASCII
1 parent 636e413 commit 79fc54d

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

draft-dijkhuis-cfrg-hdkeys.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ normative:
3131
- organization: National Institute of Standards and Technology (NIST)
3232
date: 2012-06
3333
ISO18013-5:
34-
title: "Personal identification ISO-compliant driving licence Part 5: Mobile driving licence (mDL) application"
34+
title: "Personal identification - ISO-compliant driving licence - Part 5: Mobile driving licence (mDL) application"
3535
target: https://www.iso.org/standard/69084.html
3636
seriesinfo:
3737
ISO/IEC: 18013-5:2021
@@ -536,15 +536,15 @@ The solution proposal discussed herein works in all four WSCD architectures that
536536
- P-256 EC-SDSA key pair generation
537537
- P-256 EC-SDSA signature creation
538538

539-
The other HDK operations can be performed in the WI running on any UD, including hostile ones with limited sandboxing capabilities, such as in a smartphones rich execution environment or in a personal computer web browser.
539+
The other HDK operations can be performed in the WI running on any UD, including hostile ones with limited sandboxing capabilities, such as in a smartphone's rich execution environment or in a personal computer web browser.
540540

541541
If the user enters the PIN in the WI instead of on the WSCD directly, the WI MUST process it directly after entering, the WI MUST keep the plaintext PIN confidential, and the WI MUST delete the PIN from memory as soon as the encrypted PIN or data derived from the PIN is passed over the SCI.
542542

543543
The rate-limiting of the PIN check MUST be managed within the WSCD or on securely managed SCI infrastructure. In particular, the rate-limiting MUST NOT be managed solely in local WI software since it is aassumed that attackers could modify this without detection.
544544

545545
## Trust evidence
546546

547-
Some issuers could require evidence from a solution provider of the security of the holders cryptographic device. This evidence is in the context of [EU2024-1183] divided into initial Wallet Trust Evidence and related Issuer Trust Evidence. Each is a protected document that contains a trust evidence public key associated with a private key that is protected in the secure cryptographic device. In HDK, these public keys are specified as follows.
547+
Some issuers could require evidence from a solution provider of the security of the holder's cryptographic device. This evidence is in the context of [EU2024-1183] divided into initial "Wallet Trust Evidence" and related "Issuer Trust Evidence". Each is a protected document that contains a trust evidence public key associated with a private key that is protected in the secure cryptographic device. In HDK, these public keys are specified as follows.
548548

549549
### Wallet Trust Evidence
550550

0 commit comments

Comments
 (0)