eudi-doc-architecture-and-reference-framework icon indicating copy to clipboard operation
eudi-doc-architecture-and-reference-framework copied to clipboard

Verification of Revocation status shall be mandatory and validity period shall be shorter than 24h

Open GSMA-EIG opened this issue 7 months ago • 0 comments

Annex 2 §A.2.3.7(VCR_14) & A.2.3.38 (WIRevocation_18): the verification of the revocation status of a PID or an attestation shall be mandatory (SHOULD is used in the requirements) at least in a LoA high scenario and based on a revocation check with a shorter validity period than 24h, ideally less than 1min.

Annex §A.2.3.38: WIRevocation_09, WIRevocation_10 &WIRevocation_11 mentions that the WIA shall be revoked if the validity is higher than 24h. 24h is a too long period to ensure an appropriate level of user protection. There are state- of- the- art solutions to provide real-time revocation.

GSMA-EIG avatar Jul 04 '24 09:07 GSMA-EIG