Wallet Attestation
A wallet attestation is a signed data object, issued by a Wallet Provider, that describes the components of a Wallet Unit so a PID Provider or Attestation Provider can check them before issuing a credential. The ARF calls this a Wallet Unit Attestation (WUA).
The ARF defines two concrete types. A Wallet Instance Attestation (WIA) attests the integrity and authenticity of the Wallet Instance, the app on the User's device, and names the Wallet Solution, its version and its certification. A Key Attestation (KA) attests the certification and properties of a WSCA/WSCD or keystore, and lists public keys whose private keys were generated in and are stored by it.
During issuance the Wallet Unit sends a WIA, and for a device-bound credential also a KA, to the PID Provider or Attestation Provider, which binds the new credential to one of the attested keys. To protect privacy, the Wallet Unit presents WIAs and KAs only to PID Providers and Attestation Providers, never to Relying Parties, and presents each KA only once.
A WIA is valid for less than 24 hours, so it reflects a recent integrity check of the Wallet Instance. Both types carry a revocation reference: when a Wallet Instance, WSCA/WSCD or keystore is compromised, the Wallet Provider revokes it, and PID Providers must then revoke the PIDs issued to that Wallet Unit.
A Relying Party gets its assurance indirectly: it verifies that the presented credential is device-bound, and trusts the certified Wallet Unit that holds the key.
Read the full explanation
This page gives the short definition. Our explainer shows what it means in practice: who is involved, how it works and what changes for your organisation.
Wallet Unit Attestation explainedDoes a Relying Party check the wallet attestation?
No. Under the ARF, a Wallet Unit presents its Wallet Instance Attestation and Key Attestation only to PID Providers and Attestation Providers, because they have a valid business reason to know these properties and Relying Parties do not. A Relying Party verifies the credential and its device binding instead, and trusts the certified Wallet Unit that holds the key.