eudi-doc-architecture-and-reference-framework
eudi-doc-architecture-and-reference-framework copied to clipboard
Verification of Revocation status shall be mandatory and validity period shall be shorter than 24h
Annex 2 §A.2.3.7(VCR_14) & A.2.3.38 (WIRevocation_18): the verification of the revocation status of a PID or an attestation shall be mandatory (SHOULD is used in the requirements) at least in a LoA high scenario and based on a revocation check with a shorter validity period than 24h, ideally less than 1min.
Annex §A.2.3.38: WIRevocation_09, WIRevocation_10 &WIRevocation_11 mentions that the WIA shall be revoked if the validity is higher than 24h. 24h is a too long period to ensure an appropriate level of user protection. There are state- of- the- art solutions to provide real-time revocation.