Signature Validation
The Identity Profile Report JSON contains a proof object that can be used to verify the integrity of the data. To keep the JSON structure in human-readable form, we use a variation of JSON Web Signature (JWS) with detached payload format. This means that instead of carrying the JSON payload in the JWS, it can be attached to the payload as the proof.jws field value, while keeping the payload as it was signed.
Below is the proof object structure:
Verification process
Verifying the signature and data integrity can be achieved by the following:
Retain the
proof.jwsvalue from the Identity Profile Report.Change the
proof.jwsvalue to an empty string (““) in the Report JSON.Canonicalise the report according to RFC 8785.
Verify the signature against the key that’s obtained by resolving
proof.public_key_url.
Example code
Reference
JWS Detached Payload - https://tools.ietf.org/html/rfc7515#appendix-F
RFC 8785: JSON Canonicalization Scheme (JCS) - https://datatracker.ietf.org/doc/html/rfc8785
RFC 7517: JSON Web Key (JWK) - https://datatracker.ietf.org/doc/html/rfc7517
Got a question? Contact us here.