Skip to main content

Holder Binding

A credential with holder binding is tied to a cryptographic key the holder controls, so only the rightful holder can present it. A copied or stolen credential is useless, because the copy cannot produce a signature with that key. Key Binding is the mechanism SD-JWT and SD-JWT VC define for this.

The binding is set up at issuance. The wallet generates a key pair in secure hardware and sends the public key to the issuer, which puts it in the cnf (confirmation) claim of the credential it signs. From then on the credential names exactly one key.

At presentation the verifier supplies a fresh nonce and its own identifier. The wallet signs a Key Binding JWT (KB-JWT) over both, plus a hash of the disclosures it presents, and the verifier checks that signature against the key in the cnf claim. The nonce stops replay, the audience stops a verifier forwarding the presentation, and the hash stops claims being added or removed.

The binding is only as strong as where the private key lives. In the EUDI Wallet it never leaves a WSCD, such as the phone's secure element or a remote HSM, and a Key Attestation tells the issuer which WSCD holds it. A wallet attestation like this is shown only to the issuer. The binding is what the verifier checks. An mdoc reaches the same property under the name device binding, with a device signature over the session transcript.

What holder binding does not prove is who is holding the phone. It shows control of a key, not the identity of a person, which is why the wallet also authenticates the user before the key can be used. An SD-JWT VC without a cnf claim is a bearer credential that anyone holding it can present.

Read the full explanation

This page gives the short definition. Our explainer shows what it means in practice: who is involved, how it works and what changes for your organisation.

Holder binding explained

What is the difference between Key Binding and Holder Binding?

They are the same property at two levels. Holder binding is the general idea that a credential is tied to a key its holder controls. Key Binding is the concrete SD-JWT mechanism: the holder's public key sits in the cnf claim, and at presentation the wallet signs a Key Binding JWT over the verifier's nonce and audience. For mdoc, ISO/IEC 18013-5 calls the same property device binding.

Back to the glossary