.NET / SQL / Enterprise Engineering
The Patefacere Machine Passport: Credential Classes, Selective Disclosure, Status, Replacement, and Contextual Presentation
Report summary
The digital identity landscape of 2026 is defined by an absolute architectural separation between the ontological, civic meaning of identity and the mathematical proofs that facilitate its operational execution. Within this paradigm, the sovereign state of Eviulon defines the civic semantics, legal
Key topics
- .NET / SQL / Enterprise Engineering
- .NET
- SQL
- Enterprise Engineering
- AI
- Agentic Web
- Runtime
- Privacy
- Semantic Systems
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
The digital identity landscape of 2026 is defined by an absolute architectural separation between the ontological, civic meaning of identity and the mathematical proofs that facilitate its operational execution. Within this paradigm, the sovereign state of Eviulon defines the civic semantics, legal weight, and inherent standing of citizenship. Conversely, Patefacere operates as the machine-level orchestration layer under delegated authority, managing credential issuance, verifiable presentation workflows, privacy-preserving status signaling, and key replacement mechanisms. The machine passport is fundamentally an infrastructure of verifiable claims, not a universal trust badge. The presence of a valid cryptographic credential does not inherently prove a subject's current authority to execute every possible action. External recognition of these credentials remains entirely separate from internal Eviulon validity, requiring independent bilateral treaties, cross-border trust frameworks, and dynamic policy enforcement. Following the publication of the W3C Verifiable Credentials Data Model (VCDM) v2.0 as an official Recommendation on May 20, 20251, the ecosystem shifted strictly toward a privacy-first, three-party architecture (Issuer, Holder, Verifier). By leveraging advanced cryptosuites such as BBS (bbs-2023)3 for unlinkable zero-knowledge proofs, Selective Disclosure JWTs (SD-JWT)4, and the Bitstring Status List v1.06 for herd-privacy revocation, the Patefacere ecosystem achieves exhaustive compliance, security, and data minimization.
What a Machine Passport Proves
A machine passport proves exclusively that a specific, mathematically verifiable cryptographic authority (the Issuer) attested to a bounded set of claims regarding a specific cryptographic subject (the Holder) at an exact point in time8. Furthermore, it proves that the Holder currently possesses the private key mathematically bound to that credential (holder binding). Through the integration of the W3C Bitstring Status List, the passport proves that the Issuer has not explicitly flagged the credential’s cryptographic index as revoked, suspended, or otherwise invalidated as of the status list's most recently cached update8. Ultimately, the machine passport proves mathematical possession, the temporal validity of the digital signature, semantic conformity to a defined JSON Schema10, and resistance to tampering. It validates that the data presented to the verifier has not been altered since the moment of issuance, utilizing robust cryptographic suites like EdDSA or ECDSA11.
What a Machine Passport Can Never Prove by Itself
A machine passport can never prove the philosophical or physiological reality of human citizenship, ongoing intent, or absolute universal authority. The passport is merely a mathematical container for assertions; it is not the ontological truth of Eviulon citizenship itself. A digital signature cannot prove that the human presenting the passport is acting of their own free will and not under duress. Furthermore, a valid credential does not prove current, contextual authority for every action within an enterprise or civic system. A user may hold a mathematically valid institutional role credential, but their authority to execute a specific financial transaction may have been suspended by an off-chain operational policy engine that has not yet reflected its state in the asynchronous 16KB status bitstring9. Finally, the passport cannot prove that an external, foreign verifier will recognize the internal validity of the Eviulon claim, as external trust frameworks evaluate issuer DIDs and schemas based on independent sovereign policies.
Passport Replacement Without Identity Erasure
Historically, digital identity systems have erroneously conflated the identifier (the cryptographic key) with the identity (the human subject). In such fragile architectures, the loss of a hardware key results in the erasure or complete reset of the identity. Patefacere circumvents this catastrophic failure through the integration of Key Event Receipt Infrastructure (KERI) principles12 and the deployment of did:webvh (Trust DID Web with Verifiable History). The did:webvh specification relies on a Self-Certifying Identifier (SCID) that is mathematically derived from the genesis event of the DID log13. When a holder loses their machine passport device, they execute a passport replacement without identity erasure by appending a new key rotation event to their decentralized did.jsonl log file, utilizing a pre-rotated recovery key established at the wallet's inception12. This appended log entry updates the cryptographic state of the DID Document, invalidating the lost or compromised key while perfectly preserving the SCID15. Verifiers interacting with the system traverse the did.jsonl history to mathematically verify the authorized chain of custody from the genesis key to the new recovery key13. Because the SCID remains immutable, all Verifiable Credentials previously issued and bound to that SCID remain structurally and legally valid; the subject simply generates subsequent Verifiable Presentations using the newly authorized key16.
A Complete Passport Architecture
The Patefacere architecture fundamentally decouples credential issuance from presentation, operating via a multi-format Verifiable Credential Data Registry (VDR). At the foundational identifier layer, the architecture relies on did:webvh, migrating away from standard did:web to ensure robust verifiable history without requiring a centralized, energy-intensive distributed ledger14. For credential payload formatting, the architecture supports W3C VCDM 2.0 utilizing multiple token encapsulations to accommodate diverse operational environments:
1. SD-JWT / JWT: Standard JSON Web Tokens utilizing salted hashes (SD-JWT) allow for selective disclosure in standard HTTP APIs5. While highly interoperable, SD-JWT disclosures remain somewhat traceable if multiple colluding verifiers compare the presentation salts.
2. BBS Cryptosuite (bbs-2023): To achieve true unlinkability and prevent verifier collusion, the architecture deploys the BBS pairing-based signature scheme3. The issuer signs the base credential, and the holder dynamically generates a derived proof containing only the requested subset of claims. The derived proof contains zero identifying cryptographic salts, masking the presentation entirely18.
3. SD-CWT / CBOR: For constrained IoT devices, drone telemetry, and hardware root-of-trust runtime environments, CBOR Web Tokens (CWT) are deployed. CBOR offers a concise binary object representation that drastically reduces payload size by representing integers, floats, and byte strings as raw bytes rather than text19. SD-CWT applies selective disclosure capabilities to these binary tokens4, ideal for low-bandwidth constrained networks.
4. ISO/IEC 18013-5 mdoc: For offline interactions—such as highway patrol stops or border gates—the architecture leverages the mdoc format over BLE, NFC, or QR codes. The mdoc structure allows for device engagement and offline cryptographic verification combined with locally cached Bitstring Status Lists.
Revocation and status management are handled universally via the W3C Bitstring Status List v1.08. Patefacere entirely rejects real-time OCSP-style "phone home" architectures, which inherently leak holder tracking data to the issuer. Instead, issuers publish a GZIP-compressed bitstring mapping over a Multibase encoding6. The default bitstring length is 131,072 bits (16KB uncompressed), providing a sufficient mathematical herd size to guarantee group privacy6. When processed via run-length compression, sparse revocation lists shrink to a few hundred bytes, seamlessly distributed via global CDNs for rapid verifier caching6.
Credential Classes
The following matrix strictly defines the 24 exhaustive credential classes operated under the Patefacere ecosystem. Each class mandates strict policies regarding issuance authority, selective disclosure thresholds, status mechanics, and external boundary recognition.
| Class | Issuer | Subject | Authority Source | Claims | Sensitive Fields | Selective-Disclosure Requirements | Validity | Status | Replacement | Revocation | Correction | External-Recognition Boundary |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1\. Citizenship Standing | Eviulon State Auth. | Citizen SCID | Eviulon Constitution | Civic standing, Date of Naturalization, Civic ID | True Name, Civic ID | Must use BBS derived proofs to hide True Name unless legally mandated. | 10 Years | Bitstring | Pre-rotated key recovery via did.jsonl. | Permanent via civic denaturalization. | Reissuance via formal Judicial Order. | Recognized strictly via bilateral state treaty. |
| 2\. Institutional Role | Eviulon Agency | Employee SCID | Agency Charter | Agency Name, Role Title, Clearance Level, Dept | Clearance Level, Employee ID | Disclose only Role Title for physical access; hide clearance level. | 1 Year | Bitstring | Automated HR trigger upon role change. | Immediate upon termination via status bit flip. | HR API automated issuance. | Unrecognized outside internal Eviulon agency systems. |
| 3\. Delegated Authority | Corporate Entity | Officer SCID | Board Resolution | Signing Limit, Corporate ID, Power of Attorney | Signing Limit | Hide transaction limits during basic auth; reveal only for wire execution. | 90 Days | Bitstring | Board resolution reissue and new signature. | Immediate upon emergency board vote. | Resolution amendment. | Accepted by participating commercial financial institutions. |
| 4\. Professional Qual. | Guild / University | Graduate SCID | Academic Accreditation | Degree Type, Major, Issue Date, GPA, Disciplinary | GPA, Disciplinary Record | Present Degree and Major (SD-JWT) without revealing GPA or history. | Lifetime | Bitstring | Lost credential recovery via university portal. | Only for proven academic fraud. | Transcript update and re-issuance. | Widely accepted by external, global employers. |
| 5\. Runtime Assurance | Patefacere Root | Software Daemon | Hardware TPM / Secure Enclave | Boot State, Kernel Hash, Geolocation | Geolocation of server node | Minimal disclosure via SD-CWT4 to save bandwidth. | 24 Hours | Bitstring | Daily automated rotation via cron jobs. | If TPM integrity checks fail. | N/A (Automated rotation replaces bad state). | Unrecognized beyond closed Patefacere networks. |
| 6\. Software Provenance | DevSecOps Pipeline | Binary Image | CI/CD Policy | Commit Hash, CVE Status, Build Date, Source IPs | Source Code IP paths | Reveal CVE Status for deployment; hide internal paths from public. | 30 Days | Bitstring | Re-compile, sign, and issue new CBOR token. | If zero-day vulnerability is discovered. | Patch application and reissue. | Accepted by compliant downstream orchestrators. |
| 7\. Insurance Capacity | Financial Underwriter | Policyholder SCID | Actuarial Contract | Coverage Limit, Policy Type, Risk Score | Medical/Financial Risk Score | Prove "Coverage \> X" using ZKP range predicates; never reveal score. | 1 Year | Bitstring | Annual policy renewal and premium payment. | Non-payment or identified insurance fraud. | Endorsement reissue. | Accepted by cross-border medical and trade bodies. |
| 8\. Civic-service Status | Eviulon Civic Board | Volunteer SCID | Service Mandate | Service Hours, Deployment Zone, Address | Home Address, Next of Kin | Reveal Hours for transit passes; hide Home Address. | 1 Year | Bitstring | End of deployment triggers new status credential. | Disciplinary action or AWOL status. | Manual HR correction and reissue. | Civic points valid only internally within Eviulon. |
| 9\. Recovery Authority | Patefacere Trust | Recovery Agent | User Mandate | Recovery Limit, Target SCID, Biometric Hash | Agent Biometric Hash | Reveal limits; hide biometric hash during initial handshake. | 30 Days | Bitstring | User revokes agent and replaces via did.jsonl. | Immediate user action via wallet interface. | New mandate issuance. | Eviulon jurisdiction only. |
| 10\. Appeal Entitlement | Judicial System | Appellant SCID | Court Order | Case Number, Filing Deadline, Crime History | Subject's criminal history | Reveal Deadline for extensions; hide Case Number for travel. | 60 Days | Bitstring | Court extension issuance. | Case officially closed or dismissed. | Judicial clerk amendment. | Recognized by cross-border judicial bodies. |
| 11\. Biometric Binding | Authorized Kiosk | Hardware Enclave | NIST SP 800-63-422 | Face Template, Liveness Score, Kiosk ID | Raw Biometric Template | Disclose Liveness Score boolean; never transmit raw template. | 5 Years | Bitstring | Kiosk re-enrollment required. | Device compromise or kiosk tampering detection. | Physical re-enrollment. | Limited to compliant FIDO/WebAuthn domains. |
| 12\. Travel Authorization | Border Authority | Traveler SCID | Treaty Framework | Entry Port, Visa Type, Expiry, Passport Num | Passport Number, Nationality | Prove valid visa class without transmitting Nationality. | 6 Months | Bitstring | Visa renewal and fee payment. | Overstay violation or criminal activity. | Embassy correction. | Strictly governed by ICAO and bilateral treaties. |
| 13\. Financial KYC | Banking Consortium | Customer SCID | AMLA Rulebook22 | AML Cleared, Risk Tier, Tx History | Transaction History | Zero-Knowledge KYC Attestation (SD-JWT)22; hide exact history. | 2 Years | Bitstring | Periodic compliance review. | Sanctions list match (e.g., OFAC). | Dispute resolution with bank. | Highly interoperable across global FATF domains. |
| 14\. Medical Prescription | Healthcare Provider | Patient SCID | Medical License | Drug Name, Dosage, Refills, Diagnosis Code | Diagnosis Code | Reveal Drug Name to pharmacy; hide Diagnosis Code completely. | 30 Days | Bitstring | New prescription from authorized provider. | Pharmacy fulfillment reduces refill status bit. | Doctor reissue. | Subject to strict cross-border narcotics laws. |
| 15\. Real Estate Title | Land Registry | Owner SCID | Property Law | Parcel ID, Liens, Ownership Share, Mortgage | Mortgage Balance | Disclose Ownership for HOA; hide Mortgage Balance. | Lifetime | Bitstring | Title transfer requires complete replacement. | Fraud discovery or eminent domain. | Court-ordered correction. | Recognized exclusively within Eviulon sovereignty. |
| 16\. Vehicle Registration | Transit Authority | Vehicle SCID | Transport Law | VIN, Emission Class, Owner Address | Owner's Home Address | Prove Emission Class for city toll entry; hide Owner. | 1 Year | Bitstring | Annual emissions and safety test. | Total loss of vehicle or severe moving violation. | Mechanic certified update. | Generally recognized for cross-border transit. |
| 17\. Tax Payer Standing | Eviulon Tax Auth. | Citizen SCID | Tax Code | Tax ID, Compliance Status, Income Bracket | Income Bracket | Prove Compliance Status boolean without revealing Income Bracket. | 1 Year | Bitstring | Annual tax filing and assessment. | Tax evasion conviction or gross negligence. | Audit correction and fee payment. | Subject to OECD and FATCA reporting. |
| 18\. First Responder | Emergency Services | Medic/Fire SCID | Municipal Law | Responder Type, Skill Set, Home Address | Home Address, Salary | Disclose Skill Set for disaster scene access via BBS derived proof. | 2 Years | Bitstring | Re-certification of medical/tactical skills. | Gross negligence or criminal charge. | Training update reissue. | Recognized in mutual-aid cross-border zones. |
| 19\. Import/Export License | Customs Board | Merchant SCID | Trade Tariff | Goods Class, Quota Remaining, Origin | Supply Chain Origin | Disclose Quota to port; hide Origin to protect trade secrets. | 1 Year | Bitstring | Quota reset at fiscal year start. | Smuggling violation or tariff evasion. | Manifest correction by broker. | Recognized by WTO participating states. |
| 20\. Academic Transcript | University Registrar | Student SCID | Academic Senate | Course List, Grades, Honors, Disciplinary | Disciplinary Actions | Reveal specific Course Grade for job app; hide remaining history. | Lifetime | Bitstring | Never (Immutable record of past achievement). | Massive academic fraud or degree mill discovery. | Grade appeal tribunal. | Universally accepted via higher-ed standards. |
| 21\. Legal Representation | Bar Association | Attorney SCID | Supreme Court | Bar Number, Status, Malpractice Claims | Malpractice Claims | Prove Active Status to court portal; hide Claims from general public. | 1 Year | Bitstring | Annual dues paid and CLE credits logged. | Disbarment for ethical violations. | Court petition and board review. | Recognized based on jurisdictional reciprocity. |
| 22\. Drone Operator | Aviation Authority | Pilot SCID | Airspace Regs | UAV Class, Max Altitude, Medical History | Pilot Medical History | Reveal UAV Class to ATC; hide Medical History. | 3 Years | Bitstring | Flight test and medical renewal. | Severe airspace violation or reckless endangerment. | Medical clearance review. | Interoperable with standard ICAO unmanned protocols. |
| 23\. Refugee Asylum | Int. NGO / State | Asylum SCID | Geneva Convention | Asylum Status, Issue Date, Persecution Origin | Origin Country Persecution | Reveal Status for aid; completely hide Origin for subject safety. | 5 Years | Bitstring | Naturalization into permanent standing. | Fraudulent claim discovery. | Tribunal review. | High external boundary recognition required. |
| 24\. Voting Entitlement | Election Comm. | Voter SCID | Civic Constitution | District Code, Eligibility, Vote Cast History | Vote Cast History | Prove Eligibility to voting machine; never reveal actual Vote Cast. | 4 Years | Bitstring | Redistricting requires new credential class. | Felony conviction (jurisdiction dependent). | Address update via DMV. | Strictly internal to Eviulon democratic process. |
48 Presentation Scenarios
The Patefacere infrastructure operates across varying degrees of network connectivity, hardware constraints, and trust boundaries. The following presentation scenarios dictate the optimal format (OpenID4VP, ISO mdoc, BLE, etc.) and cryptographic technique.
| ID | Scenario Context | Verifier Entity | Required Credential Class(es) | Crypto Format | Network Context | Selective Disclosure Strategy | Expected Outcome |
|---|---|---|---|---|---|---|---|
| 1 | Automated Border Gate | Border Control | Travel Auth, Biometric | ISO mdoc / BBS | Offline BLE | Disclose entry validity, ZKP of liveness | Gate opens physically |
| 2 | Alcohol Purchase | Retail POS | Citizenship Standing | SD-JWT5 | Offline NFC | Disclose age\_over\_18 boolean only | Sale approved |
| 3 | Employment Onboarding | Corporate HR | Professional Qual, Tax | OID4VP23 | Online REST | Present full degree, Tax compliance boolean | Candidate Hired |
| 4 | Remote Server Access | Cloud Gateway | Institutional Role | SD-CWT4 | Online TLS | Reveal Clearance Level via CBOR | SSH Access granted |
| 5 | Hospital Admission | Medical Admin | Medical Rx, Insurance | BBS18 | Online API | Reveal Policy Type, hide Risk Score | Admitted to ward |
| 6 | Traffic Stop | Highway Patrol | Vehicle Reg, Driver | ISO mdoc | Offline QR | Reveal VIN and Owner Name | Citation/Clear |
| 7 | Corporate Wire Transfer | Banking API | Delegated Authority | SD-JWT | Online REST | Reveal Signing Limit \> Transfer Amount | Wire successfully sent |
| 8 | Restricted Airspace Entry | ATC System | Drone Operator | SD-CWT4 | Online Telemetry | Reveal Max Altitude to tower | Flight cleared |
| 9 | Pharmaceutical Dispensing | Pharmacy POS | Medical Prescription | BBS | Online API | Reveal Drug Name and Dosage | Medication dispensed |
| 10 | Court e-Filing | e-Filing Portal | Legal Representation | SD-JWT | Online REST | Reveal Bar Status and Number | Filing accepted |
| 11 | Zero-Trust Boot Sequence | Hypervisor | Runtime Assurance | SD-CWT4 | Offline Boot | Reveal Boot State and Kernel Hash | OS securely boots |
| 12 | Mortgage Application | Loan Officer | Real Estate Title, Tax | OID4VP23 | Online REST | Reveal Property Liens and Tax standing | Loan conditionally approved |
| 13 | Civic Voting | Ballot Machine | Voting Entitlement | BBS3 | Offline NFC | Reveal District Code, Anonymous Binding | Ballot issued |
| 14 | Software Deployment | Kubernetes Admin | Software Provenance | SD-CWT | Online API | Reveal CVE Status and Build Date | Pod deployed to cluster |
| 15 | Disaster Zone Access | Military Checkpoint | First Responder | BBS | Offline QR | Reveal Skill Set (e.g., EMT-P) | Zone entry granted |
| 16 | Cross-border Trade | Customs Agent | Import/Export License | SD-JWT | Online REST | Reveal Quota Remaining | Cargo cleared port |
| 17 | Wallet Key Recovery | Patefacere Root | Recovery Authority | BBS | Online API | ZKP of Agent Biometric Hash | DID Document key rotated |
| 18 | Judicial Appeal | Court Clerk | Appeal Entitlement | SD-JWT | Online REST | Reveal Case Deadline | Appeal officially logged |
| 19 | Refugee Aid Distribution | NGO Agent | Refugee Asylum | BBS24 | Offline BLE | ZKP of Asylum Status | Aid rations granted |
| 20 | Academic Transfer | University | Academic Transcript | OID4VP | Online REST | Reveal only relevant Course Grades | Transfer credits approved |
| 21 | Anonymous Polling | Eviulon Census | Citizenship Standing | BBS18 | Online API | ZKP of Citizenship, hide True Name | Poll counted anonymously |
| 22 | Hazardous Materials | Transport Auth | Vehicle Reg, First Resp | SD-JWT | Online REST | Reveal Emission Class, Driver Skill Set | Transport authorized |
| 23 | Financial Audit | External Auditor | Financial KYC | BBS | Online API | Reveal Risk Tier | Audit securely logged |
| 24 | Fleet Vehicle Checkout | Corporate Depot | Delegated Auth | SD-CWT4 | Offline NFC | Reveal Corporate ID via binary token | Engine started |
| 25 | Emergency Surgery | Trauma Surgeon | Insurance Capacity | BBS | Offline QR | Reveal Coverage Limit | Surgery greenlit |
| 26 | VIP Club Entry | Private Venue | Citizenship Standing | SD-JWT | Offline BLE | ZKP of Age \> 21 | Entry granted |
| 27 | Domain Name Purchase | Registrar | Financial KYC | OID4VP23 | Online REST | ZKP AML Cleared | Domain provisioned |
| 28 | Diplomatic Immunity | Foreign Police | Institutional Role | ISO mdoc | Offline NFC | Reveal Role Title (Diplomat) | Subject released |
| 29 | Tax Audit | Revenue Service | Tax Payer Standing | SD-JWT | Online REST | Reveal Compliance Status | Audit conditionally cleared |
| 30 | Casino Cashout | Casino Cashier | Financial KYC | BBS18 | Online API | Reveal AML Cleared | Cash disbursed |
| 31 | Specialized Tool Rental | Hardware Store | Professional Qual | SD-JWT | Online REST | Reveal Degree Type (e.g., HVAC) | Tool rented |
| 32 | Industrial Control Sys | SCADA Network | Runtime Assurance | SD-CWT4 | Offline LAN | Reveal Kernel Hash | PLC updated |
| 33 | CI/CD Pipeline Merge | Git Server | Software Provenance | SD-JWT | Online REST | Reveal Build Date and CVE Status | Pull Request merged |
| 34 | High-Value Art Auction | Auction House | Financial KYC | BBS | Online API | Reveal Risk Tier to auctioneer | Bid accepted |
| 35 | City Congestion Zone | Toll Camera | Vehicle Registration | SD-CWT | Online Telemetry | Reveal Emission Class (EV vs Gas) | Toll assessed appropriately |
| 36 | Secure Facility Access | Smart Door | Institutional Role | BBS | Offline NFC | Reveal Clearance Level | Door opens |
| 37 | Anonymous Forum | Civic Web | Citizenship Standing | BBS | Online API | ZKP of Standing, Anonymous Binding | Post allowed on forum |
| 38 | Commercial Fishing | Coast Guard | Import/Export License | ISO mdoc | Offline QR | Reveal Fishing Quota | Inspected and passed |
| 39 | Gun Purchase Background | Firearms Dealer | Appeal Entitlement | SD-JWT | Online REST | Reveal No Active Felony Cases | Sale approved |
| 40 | Organ Donation Status | EMT | Biometric Binding | ISO mdoc | Offline BLE | ZKP of Identity \-\> Organ Status | Organs retrieved for transplant |
| 41 | E-Sports Tournament | Organizer | Citizenship Standing | OID4VP25 | Online REST | Reveal Nationality for region lock | Registration confirmed |
| 42 | Public Transit Pass | Metro Gate | Civic-service Status | SD-CWT4 | Offline NFC | Reveal Service Hours | Fare automatically waived |
| 43 | Subpoena Response | Legal Discovery | Delegated Authority | BBS | Online API | Reveal Power of Attorney | Documents legally released |
| 44 | Wildlife Park Entry | Ranger | Drone Operator | SD-JWT5 | Offline QR | Reveal UAV Class | Flight mapped by park |
| 45 | Eviction Defense | Tenant Court | Real Estate Title | BBS | Online REST | Reveal Ownership Share | Eviction stay granted |
| 46 | Blood Donation | Blood Bank | Medical Prescription | SD-JWT | Online API | Reveal Drug Name (for blood screening) | Donation accepted |
| 47 | Blockchain Node Join | Consortium | Software Provenance | SD-CWT | Online P2P | Reveal Commit Hash of node software | Node successfully joined |
| 48 | Consular Protection | Embassy Staff | Travel Authorization | ISO mdoc | Offline NFC | Reveal Passport Number to staff | Protection procedures initiated |
32 Status and Replacement Scenarios
Relying exclusively on short-lived credentials introduces unacceptable network latency and operational overhead. Patefacere balances lifespan with robust status mechanisms, utilizing the W3C Bitstring Status List v1.06 for privacy-preserving status checks, complemented by did:webvh DID logging for cryptographic key replacements13.
| ID | Trigger Event | Affected Component | Mechanism Utilized | Resolution Workflow | Privacy Implication |
|---|---|---|---|---|---|
| 1 | Mobile Device Stolen | Holder Key | did:webvh log15 | Recovery key appends did.jsonl, updates DID Document | Identity preserved; no tracking leaked |
| 2 | Employment Terminated | Institutional Role | Bitstring Status | Issuer flips bit to 1 (Revoked) in status array | Verifier sees revocation via offline CDN cache |
| 3 | Temporary Security Audit | Delegated Authority | Bitstring Status | Issuer flips bit to 1 (Suspended) | Suspended status is reversible without reissue |
| 4 | Routine Credential Expiry | All VCs | VCDM validUntil | Holder requests new issuance from provider | Temporal unlinkability via fresh signatures |
| 5 | Issuer Key Compromise | Issuer DID | did:webvh rotation | Issuer rotates key in public did.jsonl | All previously issued VCs remain cryptographically secure |
| 6 | Degree Revoked (Fraud) | Academic Transcript | Bitstring Status | University flips bit to 1 | Group privacy (16KB list) hides targeted subject6 |
| 7 | Visa Overstay | Travel Auth | Bitstring Status | Border Auth flips bit to 1 | Revocation aggressively pushed to global CDNs |
| 8 | Name Change (Marriage) | Citizenship Standing | VCDM Issuance | Holder proves old SCID, gets new VC | Old VC remains structurally valid but goes unused |
| 9 | Status List CDN Outage | Verifier Cache | Bitstring Caching | Verifier relies on local, slightly stale cache | Slight risk of false-negative revocation |
| 10 | Hardware TPM Failure | Runtime Assurance | OCSP / Bitstring | Immediate bit flip / key rotation triggered | Device quarantined at network edge |
| 11 | Zero-Day CVE Discovered | Software Provenance | Bitstring Status | DevSecOps suspends all related VCs globally | Broad suspension protects critical infrastructure |
| 12 | Insurance Policy Lapsed | Insurance Capacity | Bitstring Status | Underwriter flips bit to 1 | Holder privacy maintained at point of care |
| 13 | Civic Deployment Ends | Civic-service Status | Bitstring Status | Board flips bit to 1 upon demobilization | Graceful offboarding from civic systems |
| 14 | Recovery Agent Revoked | Recovery Authority | Bitstring Status | User flips bit to 1 on agent's VC | Agent loses recovery rights instantly |
| 15 | Court Deadline Extended | Appeal Entitlement | VCDM Update | New VC issued with extended date | Old VC ignored by verifier logic |
| 16 | AML Sanctions Match | Financial KYC | Bitstring Status | Bank flips bit to 1 | Global network notified via highly compressible status list |
| 17 | Prescription Refilled | Medical Prescription | Bitstring Message | Pharmacy updates status message index9 | Status dynamically indicates 0 refills left |
| 18 | Mortgage Paid Off | Real Estate Title | Bitstring Status | Registry issues new VC, revokes old VC | Old lien data permanently revoked and cleared |
| 19 | Vehicle Emissions Fail | Vehicle Registration | Bitstring Status | Transit Auth flips bit to 1 | Toll cameras automatically deny entry |
| 20 | Tax Fraud Conviction | Tax Payer Standing | Bitstring Status | Tax Auth flips bit to 1 | Financial institutions deny future loans |
| 21 | Medic Cert Expires | First Responder | VCDM Expiry | VC expires natively without bit flip | Requires full physical re-certification |
| 22 | Import Quota Reached | Import/Export License | Bitstring Status | Customs flips bit to 1 | Subsequent cargo held at port of entry |
| 23 | Bar Disbarment | Legal Representation | Bitstring Status | Bar Assoc flips bit to 1 | e-Filing portal immediately rejects digital signature |
| 24 | Drone Crash (Negligence) | Drone Operator | Bitstring Status | Aviation Auth suspends VC during inquiry | Pilot grounded pending federal investigation |
| 25 | Asylum Claim Fraud | Refugee Asylum | Bitstring Status | Tribunal flips bit to 1 | Interpol notified via offline backchannels |
| 26 | Felony Conviction | Voting Entitlement | Bitstring Status | Election Comm suspends VC | Anonymous ballot access mathematically denied |
| 27 | Wallet Firmware Update | Holder Environment | did:webvh update | Hardware attestation key rotated in log | Transparent to standard verifiers |
| 28 | Offline Revocation Sync | Verifier Cache | ISO mdoc profile | Verifier downloads delta list over secured channel | Enables highly secure offline policing |
| 29 | Issuer Bankruptcy | Corporate Entity | did:webvh | Liquidator updates DID log to deactivate entity | All delegated VCs rendered invalid instantly |
| 30 | Biometric Kiosk Hack | Biometric Binding | Bitstring Status | All kiosk VCs suspended en masse | Herd privacy completely protects mass revocation |
| 31 | Status Message Update | Academic Transcript | Bitstring Message | University updates bitstring to 'Honors' state9 | Highly compressible delta pushed to CDNs |
| 32 | Accidental Revocation | Institutional Role | Bitstring Status | Issuer flips bit back to 0 | Instant reinstatement via decentralized CDN |
A Privacy-Threat Model (30 Threats)
Digital identity implementations frequently expand the attack surface by centralizing honeypots or exposing tracking vectors. Patefacere’s threat model identifies and mitigates correlation, cryptographic, and operational threats.
| ID | Threat Vector | Description | Countermeasure / Mitigation Strategy | Residual Risk |
|---|---|---|---|---|
| 1 | Issuer Tracking | Issuer monitors real-time verification requests to track citizens. | Verifier caches Bitstring Status List via CDN rather than pinging issuer directly6. | Low (Cache timing attacks) |
| 2 | Verifier Collusion | Verifiers cross-reference presented VCs to profile users. | BBS Unlinkable Derived Proofs ensure mathematical presentation uniqueness3. | Low |
| 3 | Replay Attacks | Attacker captures and re-uses a Verifiable Presentation. | Challenge-response Nonce required in OID4VP payloads23. | None (If Nonce validated) |
| 4 | Correlation via Schema | Niche, highly specific schemas fingerprint the user uniquely. | Standardized Patefacere generalized JSON schemas18. | Low |
| 5 | Status List Isolation | Single VC per status list eliminates group/herd privacy entirely. | Mandate 131,072 bit minimum status list length6. | Low |
| 6 | Device Fingerprinting | Bluetooth/NFC hardware stack identifies the physical holder. | OS-level MAC randomization and BLE ephemeral pairing. | Medium (Baseband limits) |
| 7 | Key Extraction | Malware steals software private key from memory. | Keys locked in Hardware Enclaves / Secure Enclaves. | Medium (Zero-day exploits) |
| 8 | Biometric Template Theft | Verifier steals raw biometric face/fingerprint template. | Biometric Binding Class only reveals Liveness/Match boolean. | Low |
| 9 | DID Document Tracking | DID resolution leaks holder IP address to resolvers. | did:webvh resolved via Tor or decentralized web caches16. | Low |
| 10 | Metadata Correlation | VC issuance timestamp links directly to user behavior. | Batch issuance with fuzzed timestamps across populations. | Low |
| 11 | Side-Channel Attack | Timing attack on BBS pairing proof generation execution. | Mandatory constant-time cryptographic libraries. | Low |
| 12 | Over-disclosure | User accidentally shows full VC due to confusing interface. | SD-JWT and BBS selective disclosure UI anti-patterns blocked5. | Medium (User error) |
| 13 | Eavesdropping (BLE) | Attacker intercepts mdoc offline transfer in public space. | Ephemeral session encryption via ISO 18013-5 standard. | Low |
| 14 | Quantum Decryption | Quantum computer easily breaks ECDSA/EdDSA signatures. | Mandatory transition to NIST PQC signatures (Cryptographic Agility)11. | High (Long-term) |
| 15 | Token Size DoS | Massive VPs crash Verifier parser and exhaust memory. | SD-CWT and compressed bitstrings limit payload size4. | Low |
| 16 | Issuer DID Hijacking | Attacker alters standard did:web document via DNS hack. | did:webvh cryptographic log strictly prevents tampering14. | Low |
| 17 | Forced Disclosure | Police/Cartel compel unlocking of wallet via violence. | Plausible deniability features and Duress PINs wiping UI. | Medium |
| 18 | Revocation List DoS | Attacker floods CDN with status checks to drain funds. | Bitstring List GZIP compression (few hundred bytes)6. | Low |
| 19 | Phishing for VPs | Fake verifier requests highly sensitive VP from user. | Domain-bound verification and decentralized Trust Registries. | Medium |
| 20 | SCID Linkability | User uses same SCID for all contexts, allowing tracking. | Automatic Pairwise DIDs for contextual separation. | Low |
| 21 | Clock Skew Denial | Verifier rejects valid VP due to minor server time skew. | Tolerant validation windows engineered in JWT/CWT specs. | Low |
| 22 | Inference Attacks | Inferring data precisely from missing SD-JWT payload fields. | Dummy salts and decoy claims inserted into SD-JWT4. | Low |
| 23 | Downgrade Attacks | Attacker forcing legacy, weak cryptosuites during handshake. | Strict cryptographic agility policies and format deprecation11. | Low |
| 24 | Hardware Supply Chain | TPM backdoored by original equipment manufacturer. | Open-source firmware and reproducible builds where possible. | Medium |
| 25 | Network Partition | Verifier cannot check revocation due to internet outage. | Grace period policies defined for offline caching tolerance. | Medium |
| 26 | Semantic Misinterpretation | Verifier misreads claim meaning, leading to false rejection. | Strict JSON Schema structural validation requirement10. | Low |
| 27 | Authorization Creep | VP used for unintended downstream purpose by verifier. | Audience binding (aud) embedded in presentation signature27. | Low |
| 28 | Offline Replay | Stolen mdoc presented to offline verifier system. | Device authentication (mDL reader mathematically checks device key). | Low |
| 29 | Cloud Wallet Breach | Custodial wallet provider hacked, losing all user keys. | Strict self-sovereign edge-agent architecture mandate. | Low |
| 30 | Sybil via Deepfakes | Advanced AI bypasses identity verification enrollment. | Advanced Liveness detection via Biometric Binding Class. | Medium |
Schemas
To ensure strict interoperability, the Patefacere ecosystem utilizes rigid JSON and JSON-LD schemas. These schemas dictate the structure of the passport envelope, the public status list, and the presentation workflows.
1. Passport-Envelope Schema
Operating under the W3C VCDM 2.0 framework, this schema defines the structural envelope for the Patefacere Machine Passport. It explicitly declares its type, references the JSON Schema for semantic validation10, and includes the credentialStatus pointer to the Bitstring Status List18.
JSON { "@context": \[ "https://www.w3.org/ns/credentials/v2", "https://patefacere.eviulon.gov/ns/v1" \], "id": "urn:uuid:313801ba-24b7-11ee-be02-ff560265cf9b", "type": \["VerifiableCredential", "PatefacerePassport"\], "issuer": "did:webvh:eviulon.gov", "validFrom": "2026-08-09T00:00:00Z", "validUntil": "2036-08-09T00:00:00Z", "credentialSchema": { "id": "https://patefacere.eviulon.gov/schemas/passport.json", "type": "JsonSchema" }, "credentialStatus": { "id": "https://patefacere.eviulon.gov/status/3\#list", "type": "BitstringStatusListEntry", "statusPurpose": "revocation", "statusListIndex": "42069", "statusListCredential": "https://patefacere.eviulon.gov/credentials/status/3" }, "credentialSubject": { "id": "did:webvh:citizen.example", "citizenshipStanding": "ACTIVE" } }
2. Public Passport-Status Schema
This public schema exposes absolutely no private passport body information. It leverages highly compressible GZIP and Multibase encoding to represent the cryptographic revocation status of at least 131,072 credentials in a few hundred bytes6. This ensures herd privacy and rapid CDN distribution.
JSON { "@context": \[ "https://www.w3.org/ns/credentials/v2", "https://www.w3.org/ns/credentials/status/v2" \], "id": "https://patefacere.eviulon.gov/credentials/status/3", "type": \["VerifiableCredential", "BitstringStatusListCredential"\], "issuer": "did:webvh:eviulon.gov", "validFrom": "2026-08-09T00:00:00Z", "credentialSubject": { "id": "https://patefacere.eviulon.gov/status/3\#list", "type": "BitstringStatusList", "statusPurpose": "revocation", "encodedList": "uH4sIAAAAAAAAA-3BMQEAAADCoPVPbQwfoAAAAAAAAAAAAAAAAAAAAIC3AYbSVKsAQAAA" } }
3. Presentation-Request Schema
Utilizing the Presentation Exchange (PE) specification over the OID4VP protocol23, this schema demonstrates how a verifier requests specific bounded claims from a holder. It explicitly includes a nonce to prevent presentation replay attacks.
JSON { "client\_id": "did:webvh:verifier.example", "response\_type": "vp\_token", "presentation\_definition": { "id": "vp\_req\_1", "input\_descriptors": \[ { "id": "citizenship\_proof", "constraints": { "fields": \[ { "path": \["$.type"\], "filter": { "type": "array", "contains": { "const": "PatefacerePassport" } } }, { "path": \["$.credentialSubject.citizenshipStanding"\], "filter": { "type": "string" } } \] } } \] }, "nonce": "9f7b1e4a2c3d5f6g" }
4. Presentation-Result Schema
This final schema demonstrates a Verifiable Presentation (VP) utilizing a DataIntegrityProof. It specifically showcases the bbs-2023 cryptosuite for generating derived, unlinkable presentations3. The outer proof acts as the holder binding, confirming the presenter owns the key, while the inner proof represents the issuer's derived BBS signature.
JSON { "@context": \[ "https://www.w3.org/ns/credentials/v2" \], "type": "VerifiablePresentation", "holder": "did:webvh:citizen.example", "verifiableCredential": \[ { "@context": \[ "https://www.w3.org/ns/credentials/v2", "https://patefacere.eviulon.gov/ns/v1" \], "type": \["VerifiableCredential", "PatefacerePassport"\], "issuer": "did:webvh:eviulon.gov", "credentialSubject": { "citizenshipStanding": "ACTIVE" }, "proof": { "type": "DataIntegrityProof", "cryptosuite": "bbs-2023", "created": "2026-08-09T21:14:54Z", "verificationMethod": "did:webvh:eviulon.gov\#key-1", "proofPurpose": "assertionMethod", "proofValue": "u0x...\[Derived\_BBS\_Proof\]..." } } \], "proof": { "type": "DataIntegrityProof", "cryptosuite": "eddsa-rdfc-2022", "created": "2026-08-09T21:14:54Z", "verificationMethod": "did:webvh:citizen.example\#key-1", "proofPurpose": "authentication", "challenge": "9f7b1e4a2c3d5f6g", "domain": "verifier.example" } }
Standards Maturity and Interoperability Matrix
The success of the Patefacere ecosystem hinges on strict alignment with global standards, ensuring interoperability without compromising sovereign security.
| Standard Specification | Governing Organization | Maturity Status (Aug 2026\) | Role in Patefacere Ecosystem |
|---|---|---|---|
| VCDM 2.0 | W3C | Recommendation1 | Foundational data model for all machine passports. |
| Bitstring Status List 1.0 | W3C | Recommendation6 | High-performance, privacy-preserving credential revocation. |
| did:tdw / did:webvh | DIF / CCG | Draft / Adopted14 | Provides the SCID identifier and cryptographic history log. |
| BBS Cryptosuite (bbs-2023) | W3C | Candidate Rec.18 | Facilitates unlinkable ZKPs and advanced selective disclosure proofs. |
| SD-JWT / SD-JWT VC | IETF OAuth | RFC / Draft5 | Standardized universal JWT-based selective disclosure mechanism. |
| SD-CWT | IETF SPICE | Draft4 | CBOR binary token minimization for IoT/Runtime environments. |
| OpenID4VP / OID4VCI | OIDF | Final / Draft23 | HTTP-based issuance and presentation orchestration workflows. |
| ISO/IEC 18013-5 mdoc | ISO | International Standard | Offline, BLE/NFC presentation primarily for border contexts. |
| KERI / ACDC | ToIP | Specification12 | Cryptographic key pre-rotation and authentic chained data logic. |
| JSON Schema | IETF | Standard10 | Provides structural syntactic validation for credential bodies. |
Forty FAQs
| Q\# | Question | Expert Answer | Architectural Context |
|---|---|---|---|
| 1 | Is Patefacere a citizenship registry? | No. Eviulon holds the philosophical and civic truth; Patefacere is merely the mechanical operator of credentials. | Strict separation of sovereign authority and technical execution. |
| 2 | Does a valid VC mean I can automatically enter Eviulon? | No. A valid VC simply proves a prior attestation; Border Control policy ultimately dictates access at runtime. | Cryptographic Validity \!= Operational Authority. |
| 3 | How does Patefacere handle real-time revocation? | Through W3C Bitstring Status Lists8, utilizing GZIP compressed bitstrings distributed over CDNs. | Network optimization and privacy preservation. |
| 4 | Can an issuer track where I use my passport? | No. Revocation checks hit a decoupled CDN cache, and BBS/SD-JWT formats prevent cryptographic tracking correlation. | Anti-surveillance architecture. |
| 5 | What exactly is did:webvh? | A DID method combining did:web domain simplicity with a verifiable cryptographic history log (did.jsonl)15. | Decentralized identifier management. |
| 6 | Does Patefacere use a global blockchain? | No. KERI and did:webvh achieve local cryptographic history without global ledgers16. | Maximizing scalability and reducing cost. |
| 7 | What is BBS? | A pairing-based signature scheme (bbs-2023) allowing selective disclosure and mathematically perfect unlinkability3. | Advanced cryptosuite agility. |
| 8 | How is SD-JWT different from BBS? | SD-JWT uses salted hashes; it remains somewhat traceable if colluding verifiers compare salts5. BBS is truly unlinkable. | Implementation tradeoffs and backward compatibility. |
| 9 | How does offline presentation work without internet? | Using ISO/IEC 18013-5 mdoc standards over localized BLE/NFC, cross-referenced with cached status lists. | Remote border and transit scenarios. |
| 10 | What happens if my hardware key is permanently lost? | The SCID is preserved; the subject appends a pre-rotated recovery key to the did.jsonl log to regain control14. | Identity recovery and continuity. |
| 11 | Is a credential a universal trust badge? | No. It is a strictly bounded claim. Verifiers must decide independently if they trust the issuer's policies. | Nuanced ecosystem trust models. |
| 12 | How large is a standard Bitstring Status List? | A minimum of 131,072 bits (16KB uncompressed), compressing to merely hundreds of bytes via GZIP9. | Extreme network efficiency. |
| 13 | What is holder binding? | A cryptographic proof demonstrating that the presenter physically owns the private key linked to the VC's subject identifier. | Anti-fraud and anti-theft mitigation. |
| 14 | How is replay prevented during a digital handshake? | The verifier provides a cryptographic nonce that the holder must sign during the live presentation generation23. | Presentation session security. |
| 15 | What is CWT and why use it? | CBOR Web Token. It uses binary encoding for constrained devices, drastically reducing payload size4. | IoT and SCADA network integration. |
| 16 | Why implement SD-CWT? | It applies selective disclosure capabilities to binary CWTs for high-efficiency, privacy-preserving environments4. | Severe bandwidth limitations. |
| 17 | What significant changes does VCDM 2.0 introduce? | Strict separation of data integrity proofs, multi-credential presentation logic, and vastly enhanced privacy mechanisms1. | W3C Standard evolution and refinement. |
| 18 | Can a potential employer see my overall GPA? | Not if you utilize selective disclosure to only reveal your degree title and graduation date. | Enforcing data minimization. |
| 19 | Who legally governs Patefacere's JSON schemas? | Eviulon legally delegates schema governance to Patefacere's specialized cryptographic steering committee. | Data standardization and governance. |
| 20 | Can a foreign issuer operate smoothly on Patefacere? | Yes. External recognition is technically separated from internal Eviulon validity, allowing broad interoperability. | Cross-border utility. |
| 21 | What mathematically happens if a credential expires? | The validUntil field dictates structural invalidity; the wallet requires a new issuance from the authority. | Temporal lifecycle management. |
| 22 | Can a suspended credential be reactivated easily? | Yes. Bitstring Status Lists support completely reversible "suspension" bits alongside permanent revocation bits9. | Administrative grace periods. |
| 23 | Does Patefacere centralize my biometric data? | No. Biometrics are securely held in local hardware enclaves; VCs only attest to liveness or abstract match scores. | Strict data sovereignty. |
| 24 | What is audience binding (aud)? | The VP is cryptographically bound to the specific verifier's domain (aud), preventing the verifier from reusing it elsewhere. | Preventing authorization creep. |
| 25 | Is OID4VP absolutely required for all presentations? | It is the primary HTTP-based presentation protocol, though raw BLE/NFC workflows are used for offline edge cases. | Transport layer flexibility. |
| 26 | What if the Verifier's CDN revocation cache is stale? | The Verifier may accept the risk of a false-negative, or demand a real-time, synchronous HTTP fetch. | Enterprise risk management. |
| 27 | Can I hold credentials from multiple sovereign nations? | Yes. The digital wallet acts as an agnostic cryptographic container for global, interoperable claims. | Maximizing cross-border utility. |
| 28 | What prevents verifiers from hoarding citizen data? | SD-JWT and BBS ensure the verifier technically receives only the absolute minimum required data points22. | Zero-Knowledge KYC. |
| 29 | Are JSON Schemas themselves cryptographically secured? | Yes, schemas can be referenced via verifiable credentials to mathematically prevent tampering or swapping18. | Deep forgery defense. |
| 30 | What exactly is a Self-Certifying Identifier (SCID)? | An identifier mathematically derived from its initial key state, independent of vulnerable DNS or Ledgers. | Achieving true decentralization. |
| 31 | What is the definition of a ZKP? | Zero-Knowledge Proof. Proving a mathematical statement (e.g., Age \> 18\) without revealing the underlying exact data (Birthdate). | Ultimate privacy preservation. |
| 32 | What is the regulatory eIDAS 2.0 alignment? | VCDM 2.0 and OID4VP are strictly aligned with European digital identity wallet compliance mandates1. | Global regulatory compliance. |
| 33 | How are status lists safely indexed? | Each VC receives a random statusListIndex at issuance to prevent sequential enumeration attacks. | Guaranteeing herd privacy. |
| 34 | Can I use a hardware token like a YubiKey? | Yes, Patefacere supports TPMs, YubiKeys, and secure enclaves for maximum private key storage security. | Endpoint key security. |
| 35 | What is KERI architecture? | Key Event Receipt Infrastructure. It enables verifiable chronological key histories without ledgers12. | Advanced key management. |
| 36 | Why not use OCSP for all revocation scenarios? | OCSP natively leaks holder activity metadata to the issuer. Bitstrings prevent this correlation entirely. | Defense-in-depth privacy architecture. |
| 37 | How does Patefacere handle future quantum threats? | Cryptographic agility11 allows transitioning to NIST PQC algorithms by simply updating the payload header. | Systemic future-proofing. |
| 38 | Can Patefacere rewrite my civic Eviulon record? | No. It only orchestrates the VCs; the core civic record belongs exclusively to Eviulon authorities. | Separation of powers. |
| 39 | Does a credential strictly require internet to verify? | No. Cryptographic signatures can be mathematically verified offline against previously cached public keys. | Systemic resilience. |
| 40 | Can an AI agent or daemon hold a passport? | Yes, utilizing specifically the Runtime Assurance and Delegated Authority credential classes. | Extending machine identity. |
Twenty-Five Direct Answers
| ID | Direct Architectural Imperative | Expert Rationale |
|---|---|---|
| 1 | A passport is definitively not citizenship. | Citizenship is a deep civic right; a passport is merely a cryptographic transmission vehicle. |
| 2 | A passport is not a universal trust badge. | Trust is highly contextual. A valid passport does not blindly grant access to restricted networks. |
| 3 | A credential proves only a bounded claim. | It asserts specific, narrow fields (e.g., Degree Type) for a specific timeframe, nothing more. |
| 4 | A valid credential does not prove current authority. | Off-chain policies or offline cache delays may override the credential's strict mathematical validity. |
| 5 | External recognition is separate from Eviulon validity. | Foreign sovereign states decide their own trust roots regardless of Eviulon's mathematical proofs. |
| 6 | Do not publish private credentials on public APIs. | Doing so violates data minimization principles and exposes correlation-rich identifiers to scraping. |
| 7 | Use Bitstring Status Lists exclusively over OCSP. | OCSP enables issuer surveillance; Bitstrings provide robust mathematical herd privacy. |
| 8 | Rely on did:webvh for maximum portability. | Ledger-less verifiable histories prevent identity lock-in and enable smooth, secure key rotation. |
| 9 | Enforce Selective Disclosure strictly across all APIs. | Never transmit a full credential payload when a subset of claims fully satisfies the verifier's request. |
| 10 | Implement Audience Binding on all VPs. | Prevents a malicious or compromised verifier from replaying your presentation to an unintended third party. |
| 11 | Utilize Nonce Binding for replay protection. | Ensures the presentation was dynamically generated live for the specific, current interaction. |
| 12 | Rotate issuer keys periodically and systematically. | Limits the catastrophic blast radius of a potential, albeit unlikely, private key compromise. |
| 13 | Use offline caching for operational resilience. | Border control and critical infrastructure systems must survive total internet partitions. |
| 14 | Distinguish explicitly between Suspension and Revocation. | Suspension is a reversible state (e.g., during an audit); Revocation is permanent (e.g., proven fraud). |
| 15 | Align strictly with W3C VCDM 2.0. | It is the uncontested global standard for verifiable data interoperability as of mid-2025. |
| 16 | Use SD-CWT for constrained IoT devices. | CBOR binary compression is absolutely required for constrained bandwidth and low-power processing environments. |
| 17 | Shield biometrics permanently in enclaves. | Never transmit raw templates; transmit only ZKP match scores or hardware liveness attestations. |
| 18 | Assume Verifier collusion as a baseline threat. | Use bbs-2023 derived proofs to prevent verifiers from tracking users across domains via salt comparison. |
| 19 | Standardize JSON Schemas rigorously. | Strict syntactic conformity prevents parser-level exploits and semantic misunderstandings across borders. |
| 20 | Issue pairwise DIDs when necessary for privacy. | Using a single SCID everywhere enables tracking; use contextual DIDs to enforce domain separation. |
| 21 | Prepare architecture for Post-Quantum Cryptography. | Maintain cryptographic agility in the passport envelope to swap legacy signature algorithms immediately. |
| 22 | Do not conflate the identifier with the identity. | Losing a hardware key should invoke recovery protocols, not erase the human's fundamental civic standing. |
| 23 | Treat status lists as critical infrastructure. | Deploy them via highly distributed CDNs to ensure global high availability and sub-millisecond latency. |
| 24 | Decouple issuance from presentation entirely. | Issuers should not mathematically know when, where, or to whom a holder presents a credential. |
| 25 | Minimize payload size relentlessly. | Use multibase encoding and GZIP for status lists to easily accommodate degraded mobile networks. |
70-Term Glossary
| Term | Technical Definition | Specification Reference |
|---|---|---|
| ACDC | Authentic Chained Data Container; cryptographically verifiable data securely linked to KERI logs. | ToIP12 |
| Audience Binding | Cryptographically binding a Verifiable Presentation to a specific verifier's identity (aud). | OID4VP |
| Base45 | Encoding algorithm used for QR codes, often utilized in health or optical credentials. | W3C Barcodes30 |
| BBS | A pairing-based signature scheme allowing selective disclosure and unlinkability. | W3C3 |
| bbs-2023 | The specific W3C cryptosuite utilizing BBS signatures for VCDM Data Integrity. | W3C32 |
| Bitstring | An array of bits used to represent the binary status (0/1) of credentials efficiently. | W3C9 |
| BitstringStatusList | The W3C standard for highly compressed, privacy-preserving credential revocation. | W3C6 |
| CBOR | Concise Binary Object Representation; a data format designed for extremely small code size. | RFC 894919 |
| COSE | CBOR Object Signing and Encryption; the binary, constrained equivalent of JOSE. | RFC 905220 |
| Credential Class | A strictly defined schema and policy set for a specific type of Verifiable Credential. | Patefacere Arch |
| CWT | CBOR Web Token; a highly compact means of representing claims in a constrained environment. | RFC 83924 |
| Data Integrity Proof | W3C mechanism securing VC authenticity using advanced cryptographic proofs. | W3C VCDM 2.0 |
| Deco | A privacy-preserving oracle architecture (conceptual related term in ZK domains). | Web3 / ZKP |
| Derived Proof | A proof dynamically generated by the holder from a base proof, revealing only selective claims. | W3C BBS18 |
| DID | Decentralized Identifier; a globally unique, highly available, and cryptographically verifiable identifier. | W3C DID Core |
| DID Document | A document describing the public keys and service endpoints logically associated with a DID. | W3C DID Core |
| did.jsonl | The JSON Lines log file containing the verifiable cryptographic history of a did:webvh DID. | DIF15 |
| did:tdw | Trust DID Web; the precursor developmental name to did:webvh. | DIF13 |
| did:web | A common DID method rooted in the traditional Domain Name System (DNS). | W3C CCG |
| did:webvh | DID Web with Verifiable History; provides SCIDs and ledger-less cryptographic key logs. | DIF16 |
| ECDSA | Elliptic Curve Digital Signature Algorithm. | Cryptography |
| EdDSA | Edwards-curve Digital Signature Algorithm. | Cryptography |
| Eviulon | The sovereign/civic entity exclusively defining the semantic truth of citizenship. | Patefacere Arch |
| GZIP | A file format and software application used for high-ratio data compression (used in Bitstrings). | RFC 19526 |
| Holder | The entity possessing a Verifiable Credential and generating Verifiable Presentations. | W3C VCDM 2.08 |
| Holder Binding | Proof that the entity presenting the VC currently possesses the key linked to the VC's subject. | OID4VP |
| Issuer | The trusted entity asserting claims and cryptographically signing the Verifiable Credential. | W3C VCDM 2.08 |
| JSON-LD | JSON for Linking Data; a method of encoding Linked Data semantics using JSON. | W3C |
| JWE | JSON Web Encryption; encrypts token content for strict confidentiality. | RFC 7516 |
| JWS | JSON Web Signature; represents digitally signed content using standard JSON data structures. | RFC 75155 |
| JWT | JSON Web Token; a compact, URL-safe means of representing claims across networks. | RFC 75195 |
| KERI | Key Event Receipt Infrastructure; provides key pre-rotation and self-certifying identifiers. | ToIP12 |
| Key Pre-rotation | Committing to a future cryptographic key before the current key is compromised or lost. | KERI12 |
| mdoc | Mobile Document; an ISO standard format for digital documents like mobile driver's licenses. | ISO/IEC 18013-5 |
| Multibase | A protocol for disambiguating various base encodings (e.g., base58, base64url) in payloads. | IETF Draft6 |
| NFC | Near Field Communication; a protocol used for offline Verifiable Presentations at close range. | Hardware Standard |
| Nonce | A random number used exactly once in a cryptographic challenge to prevent replay attacks. | OID4VP |
| OCSP | Online Certificate Status Protocol; a legacy method for checking revocation that leaks privacy. | RFC 6960 |
| OID4VCI | OpenID for Verifiable Credential Issuance; standardizes how wallets request VCs. | OIDF25 |
| OID4VP | OpenID for Verifiable Presentations; standardizes how verifiers request VPs. | OIDF23 |
| Pairwise DID | A unique DID generated strictly for a specific relationship to prevent cross-domain correlation. | W3C DID Core |
| Patefacere | The architectural operator strictly executing machine passport workflows. | Patefacere Arch |
| Presentation Exchange | A standard allowing verifiers to request specific formats and narrow claims from holders. | DIF |
| Privacy-First | Architectural design methodology heavily prioritizing data minimization and unlinkability. | Security |
| Run-length Compression | Data compression replacing sequences of identical data with a single value and count (used in Bitstrings). | Computer Science |
| SCID | Self-Certifying Identifier; an identifier inextricably bound to its cryptographic genesis event. | did:webvh \[cite: 15\] |
| SD-CWT | Selective Disclosure CBOR Web Token; applies complex data minimization to binary CWTs. | IETF SPICE4 |
| SD-JWT | Selective Disclosure JSON Web Token; uses salted hashes to hide claims from verifiers. | IETF OAuth5 |
| SD-JWT VC | A Verifiable Credential officially formatted as an SD-JWT. | IETF23 |
| Selective Disclosure | The technical ability to reveal only a specific subset of claims from a larger credential. | W3C VCDM 2.0 |
| StatusListIndex | The specific integer position corresponding to a VC's status inside a Bitstring. | W3C28 |
| StatusPurpose | Defines whether a Bitstring is used for revocation, temporary suspension, or status messaging. | W3C28 |
| Subject | The entity about which claims are specifically made in a Verifiable Credential. | W3C VCDM 2.0 |
| Suspension | A fully reversible state rendering a VC temporarily invalid. | W3C9 |
| TPM | Trusted Platform Module; a specialized hardware chip on an endpoint for secure crypto operations. | Hardware |
| Trust Registry | A cryptographic registry allowing verifiers to confirm if an issuer is legally authorized. | ToIP |
| Unlinkability | The mathematical property preventing a verifier from correlating multiple presentations to the same holder. | Privacy |
| VCDM 2.0 | Verifiable Credentials Data Model version 2.0. | W3C1 |
| VDR | Verifiable Data Registry; the decentralized system where DIDs and Schemas are anchored. | W3C VCDM |
| Verifiable Credential | A tamper-evident, cryptographically verifiable set of structured claims made by an issuer. | W3C VCDM 2.08 |
| Verifiable Presentation | Data derived dynamically from one or more VCs, proving possession to a verifier. | W3C VCDM 2.08 |
| Verifier | The entity requesting, parsing, and validating a Verifiable Presentation. | W3C VCDM 2.08 |
| ZKP | Zero-Knowledge Proof; proving a mathematical statement without revealing the underlying exact data. | Cryptography |
| AML | Anti-Money Laundering; compliance policies strictly bound into Financial KYC VCs. | FATF22 |
| FATF | Financial Action Task Force; international body setting core KYC standards. | AML22 |
| eIDAS 2.0 | EU regulation dictating stringent identity wallet compliance standards. | EU Law1 |
| SHAKE-256 | An extendable-output function heavily used in the bbs-2023 cryptosuite. | NIST3 |
| BLS12-381 | A pairing-friendly elliptic curve used predominantly for BBS signatures. | Cryptography31 |
| JSON Schema | A vocabulary that allows for the structural annotation and validation of JSON documents. | IETF10 |
| Salted Hash | Appending random decoy data to a claim before hashing it to prevent dictionary attacks (used in SD-JWT). | Cryptography5 |
Primary-Source Bibliography
1. World Wide Web Consortium (W3C). Verifiable Credentials Data Model v2.0. W3C Recommendation, May 20, 2025\.1
2. World Wide Web Consortium (W3C). Bitstring Status List v1.0. W3C Recommendation, May 15, 2025\.6
3. World Wide Web Consortium (W3C). Data Integrity BBS Cryptosuites v1.0 (bbs-2023). Candidate Recommendation, 2023–2026.3
4. Internet Engineering Task Force (IETF). Selective Disclosure JSON Web Token (SD-JWT). RFC 9901 / Draft, 2025–2026.5
5. Internet Engineering Task Force (IETF SPICE WG). Selective Disclosure CBOR Web Tokens (SD-CWT). Draft, June 2026\.4
6. Decentralized Identity Foundation (DIF). Trust DID Web (did:tdw / did:webvh) v0.3–0.5. 2024–2026.13
7. OpenID Foundation (OIDF). OpenID for Verifiable Presentations 1.0.23
8. Trust Over IP Foundation (ToIP). Key Event Receipt Infrastructure (KERI) & ACDC.12
9. International Organization for Standardization (ISO). ISO/IEC 18013-5: Personal identification — ISO-compliant driving licence.
10. Financial Action Task Force (FATF). Digital Identity Guidance & AMLA Single Rulebook.22
Works cited
1. W3C Verifiable Credentials 2.0: The New Standard Reshaping Enterprise Digital Identity, https://vidos.id/blog/w3c-verifiable-credentials-2-0-the-new-standard-reshaping-enterprise-digital-identity
2. Verifiable Credential Evidence Provenance | Knogin Developers | Argus Command Center, https://knogin.com/en/developers/verifiable-credential-evidence
3. BBS Cryptosuite v2023 \- W3C, https://www.w3.org/TR/2023/WD-vc-di-bbs-20231104/
4. SPICE SD-CWT \- IETF, https://www.ietf.org/archive/id/draft-ietf-spice-sd-cwt-04.html
5. RFC 9901: Selective Disclosure for JSON Web Tokens, https://www.rfc-editor.org/rfc/rfc9901.html
6. Bitstring Status List v1.0 \- W3C, https://www.w3.org/TR/vc-bitstring-status-list/
7. Bitstring Status List v1.0 publication history | Standards \- W3C, https://www.w3.org/standards/history/vc-bitstring-status-list/
8. Verifiable Credentials Overview v1.0 \- W3C on GitHub, https://w3c.github.io/vc-overview/
9. Bitstring Status List v1.0 \- W3C, https://www.w3.org/TR/2024/WD-vc-bitstring-status-list-20240204/
10. Verifiable Credentials Data Model v2.1 \- W3C on GitHub, https://w3c.github.io/vc-data-model/
11. Verifiable Credential Data Integrity 1.0 \- W3C, https://www.w3.org/TR/vc-data-integrity/
12. Working Groups \- Trust Over IP, https://trustoverip.org/get-involved/working-groups/
13. Trust DID Web \- The did:tdw DID Method \- Version 0.3 \- Decentralized Identity Foundation, https://identity.foundation/didwebvh/v0.3/
14. Trust DID Web \- The did:tdw DID Method \- Version 0.4 \- Decentralized Identity Foundation, https://identity.foundation/didwebvh/v0.4/
15. The did:webvh DID Method \-- did:web \+ Verifiable History \- Version 0.5, https://identity.foundation/didwebvh/v0.5/
16. Overview \- did:webvh DID Method Information \-- "did:web \+ Verifiable History", https://didwebvh.info/latest/overview/
17. Verifiable Credential Standardization \- Grotto Networking, https://www.grotto-networking.com/VerifiableCredentials.html
18. Verifiable Credentials Overview v1.1 \- W3C, https://www.w3.org/TR/vc-overview-1.1/
19. FIDO Device Onboard Specification 1.1, https://fidoalliance.org/specs/FDO/FIDO-Device-Onboard-PS-v1.1-20220419/FIDO-Device-Onboard-PS-v1.1-20220419.html
20. CBOR Decoder Online | Decode CBOR to JSON \- Ajit Singh, https://singhajit.com/tools/cbor-decoder/
21. Credential Status | Vidos, https://vidos.id/docs/explanations/standards/w3c/verifiable-credentials/credential-status/
22. Identity Verification Solutions 2026: A Scope-Honest Buyer's Guide | Verifyo, https://verifyo.com/insights/identity-verification-solutions-2026-buyers-guide
23. OpenID for Verifiable Presentations 1.0, https://openid.net/specs/openid-4-verifiable-presentations-1\_0.html
24. Data Integrity BBS Interoperability Report 1.0 \- W3C on GitHub, https://w3c.github.io/vc-di-bbs-test-suite/
25. Technology Stack \- swiyu technical documentation, https://swiyu-admin-ch.github.io/technology-stack/
26. vc-bitstring-status-list/EXPLAINER.md at main \- GitHub, https://github.com/w3c/vc-bitstring-status-list/blob/main/EXPLAINER.md
27. Messaging Layer Security Credentials using Selective Disclosure JSON and CBOR Web Tokens \- GitHub Pages, https://rohanmahy.github.io/mls-sd-cwt-credential/draft-mahy-mls-sd-cwt-credential.html
28. Bitstring Status List Vocabulary \- W3C, https://www.w3.org/ns/credentials/status
29. draft-ietf-spice-sd-cwt-08 \- Selective Disclosure CBOR Web Tokens (SD-CWT), https://datatracker.ietf.org/doc/draft-ietf-spice-sd-cwt/
30. Verifiable Credential Barcodes v0.7 \- W3C, https://www.w3.org/community/reports/credentials/CG-FINAL-vc-barcodes-20260320/
31. BBS Cryptosuite v2023 \- W3C, https://www.w3.org/community/reports/credentials/CG-FINAL-vc-di-bbs-20230405/
32. Data Integrity BBS Cryptosuites v1.0 \- W3C, https://www.w3.org/TR/vc-di-bbs/
33. Token Status List (TSL) \- IETF, https://www.ietf.org/archive/id/draft-ietf-oauth-status-list-12.html
34. Verifiable Credentials for Identity Assurance in the Digital Society: An Overview and Trends in Standards Development, https://www.boj.or.jp/en/research/wps\_rev/rev\_2026/data/rev26e06.pdf