Skip to content

First pass at HAIP HPKE section - #362

Merged
brentzundel merged 10 commits into
mainfrom
haip-hpke
Sep 24, 2026
Merged

brentzundel merged 10 commits into
mainfrom
haip-hpke

Conversation

@Sakurann

@Sakurann Sakurann commented Mar 9, 2026 •

Copy link
Copy Markdown
Collaborator

resolves #356
resolves #357
builds up on #361 (#361 needs to be merged first)

@Sakurann Sakurann changed the title Haip hpke First pass at HAIP HPKE section Mar 9, 2026
@Sakurann
Sakurann requested review from GarethCOliver, awoie, bc-pi, c2bo, hlozi, jogu, selfissued, tlodderstedt and tplooker and removed request for jogu March 9, 2026 16:07
Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md Outdated
Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md Outdated

### Response Encryption using HPKE with JWE

Response encryption MUST be performed as specified in [@!OIDF.OID4VP, section 8.3.1]. The JWE `alg` (algorithm) header parameter (see [@!RFC7516, section 4.1.1]) value `HPKE-0` (as defined in [@I-D.ietf-jose-hpke-encrypt]). The JWE `enc` (encryption algorithm) header parameter (see [@!RFC7516, section 4.1.2]) value `A128GCM` (as defined in [@!RFC7518, section 5.3]) MUST be supported by Verifiers and Wallets.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

need to omit enc.

Co-authored-by: Kristina <52878547+Sakurann@users.noreply.github.com>

@GarethCOliver GarethCOliver left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm with the suggested change.

Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md Outdated
Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md Outdated
Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md Outdated
Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md Outdated
@Sakurann
Sakurann marked this pull request as ready for review April 27, 2026 20:23
Co-authored-by: Kristina <52878547+Sakurann@users.noreply.github.com>
Co-authored-by: Jan Vereecken <ciao@janvereecken.com>
@Sakurann
Sakurann requested a review from javereec April 27, 2026 20:30
Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md Outdated
Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md Outdated

### Response Encryption using HPKE with JWE

Response encryption MUST be performed as specified in [@!OIDF.OID4VP, section 8.3.1] using JOSE HPKE integrated encryption. The JWE `alg` (algorithm) header parameter (see [@!RFC7516, section 4.1.1]) value `HPKE-0` (as defined in [@I-D.ietf-jose-hpke-encrypt]) MUST be supported by Wallets and Verifiers. `psk_id` (pre-shared key id) header parameter MUST NOT be present. The JWE `enc` (encryption algorithm) header parameter (see [@!RFC7516, section 4.1.2]) MUST NOT be present.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

psk_id (pre-shared key id) header parameter MUST NOT be present

The JWE enc (encryption algorithm) header parameter (see [@!RFC7516, section 4.1.2]) MUST NOT be present.

It would probably be helpful to clarify where/when they must not be present.

Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md Outdated
@fkj

fkj commented Jul 24, 2026

Copy link
Copy Markdown
Member

I think this needs to be rebased before merging, and also we should probably check that section number references are still accurate.

@bc-pi bc-pi left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤷

@brentzundel

Copy link
Copy Markdown
Collaborator

discussed in WG: @c2bo will review

@brentzundel

brentzundel commented Sep 10, 2026 •

Copy link
Copy Markdown
Collaborator

Discussed today. Still need more review.
@Sakurann will you address the current set of comments and update the PR?
@bhjelm will review

@brentzundel
brentzundel requested a review from bhjelm September 10, 2026 16:15
Sakurann and others added 2 commits September 16, 2026 21:19
Co-authored-by: Frederik Krogsdal Jacobsen <fkj@users.noreply.github.com>
Co-authored-by: Kristina <52878547+Sakurann@users.noreply.github.com>
@Sakurann
Sakurann requested a review from fkj September 16, 2026 19:23

### Response Encryption using ECDH-ES with JWE

Response encryption MUST be performed as specified in [@!OIDF.OID4VP, section 8.3]. The JWE `alg` (algorithm) header parameter (see [@!RFC7516, section 4.1.1]) value `ECDH-ES` (as defined in [@!RFC7518, section 4.6]), with key agreement utilizing keys on the `P-256` curve (see [@!RFC7518, section 6.2.1.1]) MUST be supported. The JWE `enc` (encryption algorithm) header parameter (see [@!RFC7516, section 4.1.2]) values `A128GCM` and `A256GCM` (as defined in [@!RFC7518, section 5.3]) MUST be supported by Verifiers. Wallets MUST support `A128GCM` or `A256GCM` or both. If the Wallet supports both, it SHOULD use `A256GCM` for the JWE `enc`. Verifiers MUST list both `A128GCM` and `A256GCM` in `encrypted_response_enc_values_supported` in their client metadata.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We are pointing to OpenID4VP 1.0, so these links will currently be broken. I guess that is fine and we don't have to change the link 1.1 editor's draft, but will create broken references for the time being.

Comment thread 1.1/openid4vc-high-assurance-interoperability-profile-1_1.md
@brentzundel

Copy link
Copy Markdown
Collaborator

Discussed today. @c2bo will raise an issue to track the reference to VP 1.1

Co-authored-by: Christian Bormann <chris.bormann@gmx.de>
@brentzundel

Copy link
Copy Markdown
Collaborator

@bhjelm this has been updated and is now ready for your review

@brentzundel

Copy link
Copy Markdown
Collaborator

Discussed today. @bhjelm will review. Looks ready to merge after.

@bhjelm

bhjelm commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

Discussed today. @bhjelm will review. Looks ready to merge after.

PR approved.

@brentzundel
brentzundel merged commit cf7207c into main Sep 24, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Profiling JOSE-HPKE for HAIP 1.1 Who HPKE is mandatory / optional for in HAIP 1.1

8 participants