## NL Wallet App Simulator
- Execute each cell with Crtl+Enter
- Two cells will ask for an input. Make sure the respective QR (init, DCC) is visible on scree next to this browser window


Install libraries if you run this notebook for the first time

In [1]:
!pip install pyjwt cryptography protobuf pycryptodome ecdsa


Collecting pyjwt
  Downloading PyJWT-2.3.0-py3-none-any.whl (16 kB)
Collecting cryptography
  Downloading cryptography-36.0.1-cp36-abi3-manylinux_2_24_x86_64.whl (3.6 MB)
[K     |████████████████████████████████| 3.6 MB 23.9 MB/s 
Collecting pycryptodome
  Downloading pycryptodome-3.14.1-cp35-abi3-manylinux2010_x86_64.whl (2.0 MB)
[K     |████████████████████████████████| 2.0 MB 40.7 MB/s 
[?25hCollecting ecdsa
  Downloading ecdsa-0.17.0-py2.py3-none-any.whl (119 kB)
[K     |████████████████████████████████| 119 kB 75.0 MB/s 
Installing collected packages: pyjwt, pycryptodome, ecdsa, cryptography
Successfully installed cryptography-36.0.1 ecdsa-0.17.0 pycryptodome-3.14.1 pyjwt-2.3.0


### Ingest an invitation

Identify yourself at an airline (e.g. https://pinggg.mywire.org/static-v2) to obtain an invitation for validation. 

Grab the invitation string from url to wallet and paste in input-box. <br>
Or alternative: Open QR-code in Google-lens and "copy text" to capture the invitation string.

In [19]:
import requests
import json
import jwt
import base64

invite = input('Paste Invitation string contents here: ')

base64_message = invite
base64_bytes = base64_message.encode('ascii')
message_bytes = base64.b64decode(base64_bytes)
qr_code = message_bytes.decode('ascii')

qr_code_data =  json.loads(qr_code)
print(f"QR-Code data: {json.dumps(qr_code_data, indent=4)}")

token_info = jwt.decode(qr_code_data['token'], options={"verify_signature":False})
print(f"Invitation-token: {token_info}")


Paste Invitation string contents here: eyJwcm90b2NvbCI6IkRDQ1ZBTElEQVRJT04iLCJwcm90b2NvbFZlcnNpb24iOiIxLjQuMCIsInNlcnZpY2VJZGVudGl0eSI6Imh0dHBzOi8vcGluZ2dnLm15d2lyZS5vcmcvd2FsbGV0L2lkZW50aXR5L3YyIiwicHJpdmFjeVVybCI6Imh0dHBzOi8vc29tZS5pbnN0aXR1dGlvbi92YWxpZGF0aW9uL3ByaXZhY3kiLCJ0b2tlbiI6ImV5SmhiR2NpT2lKRlV6STFOaUlzSW5SNWNDSTZJa3BYVkNJc0ltdHBaQ0k2SWtGd1RYaHlZMGxJTURkVFZWWlRURVo0ZGs1cVVISjJNRTg1ZEVoUVdqaDZkRmszTURkQlIxRTJVM2NpZlEuZXlKcGMzTWlPaUpvZEhSd2N6b3ZMM0JwYm1kblp5NXRlWGRwY21VdWIzSm5MM2RoYkd4bGRDOXBaR1Z1ZEdsMGVTOTJNaUlzSW5OMVlpSTZJakl4TVdNeVlUa3pMVGcyWXpBdE5EZzVaQzFoWlRkakxUTTVZakZqTkdWa05qazJNQ0lzSW1saGRDSTZNVFkwTmpnME16STVOU3dpWlhod0lqb3hOalEyT0RRMk9EazFmUS52XzFpM3dCdnl3R1RHZEcwWUNBVE9YUVFUcVlybGluRkEyZHB3elhaOEVleDlkdmZFZFRYVGxEaEd0eUU5NFR2TW1LTkRvVTJRYTRVdjVsTVd4bGtZQSIsImNvbnNlbnQiOiJQbGVhc2UgY29uZmlybSB0byBzdGFydCB0aGUgRENDIEV4Y2hhbmdlIGZsb3cuIElmIHlvdSBub3QgY29uZmlybSwgdGhlIGZsb3cgaXMgYWJvcnRlZC4iLCJzdWJqZWN0IjoiMjExYzJhOTMtODZjMC00ODlkLWFlN2MtMzliMWM0ZWQ2OTYwIiwic2VydmljZVByb

### Init QR code handling by wallet app
The wallet app processes the invitation:


1.   The wallet gets airline identity document to learn airline endpoints and validation service location
2.   The wallet determines location of validation service ((from airline identity document)). A choice is presented in case multiple validation services are offered.

In [20]:
import ecdsa
import base64
from Crypto.Hash import SHA256
from ecdsa.curves import NIST256p

# Load the airline identity document 
serviceIdentity = requests.get( qr_code_data['serviceIdentity'] ).json()

# Get the information from the identity document. Identity contents
## services, i.e. airline endpoint to get validation access token and to return confirmation token, and (list of) providers that offer validation
## verification methods, public keys to validate signatures or for use in encryption 

validationlist=[];
for service in serviceIdentity['service']:
    
    # This should not always be 'ValidationService-1' but the current service
    # depending on rules and requirements
    if service['id'].find('#ValidationService')>0: 
        validationlist.append(service);
        validation_service_id = service['id']        
        print(f"Validation ServiceID {validation_service_id}") 
#print(validationlist)
if len(validationlist) == 1:
  choice = 0
else:
  choice = int(input('Please enter number of service you have chosen (1,2,3): ').strip())  # This picks up the validation service
  choice=choice-1
#Make record of validation service endpoint for future use
validation_service_id=validationlist[choice]['id']
validation_service_endpoint = validationlist[choice]['serviceEndpoint'] 
print(validation_service_endpoint) 

Validation ServiceID https://pinggg.mywire.org/wallet/identity/v2#ValidationService-1
https://pinggg.mywire.org/wallet/validation-stub/v2


#Wallet gets the validation access token
which packs travel data and some instructions for type of validation that is expected. 
- The endpoint to get access token is determined from the airline identity document
- The request is authenticated with invitation-token (so links back to booking and passenger)

Under EU-DCC-validation protocol (but not implemented by us)
- The wallet advises its one-time identity, not sure why??
- The airline hands back validation access token and a nonce (nonce, why??)

In [21]:
import ecdsa
import base64
from Crypto.Hash import SHA256
from ecdsa.curves import NIST256p

#create one-time wallet identity(key-pair) to sign the DCC on upload
userkey = ecdsa.SigningKey.generate(curve=NIST256p,hashfunc=SHA256.new) 

# App selects the AccessTokenService in Airline Identity document and requests for Validation Access token. 

for service in serviceIdentity['service']:
    if service['id'].endswith('#AccessTokenService-1'):
        response = requests.post( service['serviceEndpoint'], 
                    headers={'Authorization': f'Bearer {qr_code_data["token"]}', #initR-token goes here
                             'Content-Type':'application/json', 
                             'X-Version' : '1.0'},
                    json = {"pubKey": userkey.get_verifying_key().to_pem().decode(), 
                                    #advise pub key to validation service for inspection of signature on DCC
                            "service":validation_service_id}
                                     #advise chosen validation service
        )
        # print ("Undecoded Response", response.status_code, response.text, '\n\n')
        
        # This is the access token for the validation service
        validator_token = response.text 
        validation_nonce = response.headers['x-nonce']
        
        token_info = jwt.decode(validator_token, options={"verify_signature":False})
        print(f"Validator_Access_Token: {json.dumps(token_info, indent=4)}")




Validator_Access_Token: {
    "iss": "https://pinggg.mywire.org/wallet/identity/v2",
    "sub": "211c2a93-86c0-489d-ae7c-39b1c4ed6960",
    "aud": "https://pinggg.mywire.org/wallet/validation-stub/v2/validate",
    "t": 2,
    "v": "1.0",
    "vc": {
        "lang": "en-en",
        "coa": "NL",
        "cod": "BE",
        "poa": "AMS",
        "pod": "BRU",
        "roa": "NL",
        "rod": "BE",
        "type": [
            "r",
            "v",
            "t"
        ],
        "category": [
            "Standard"
        ],
        "validationClock": "2022-03-09T16:28:51.697Z",
        "validFrom": "2022-03-10T16:28:15.601Z",
        "validTo": "2022-03-10T17:28:15.601Z"
    },
    "jti": "dcfb9233-a679-4e53-84b6-7e89a3ebeff3",
    "iat": 1646843331,
    "exp": 1646846931
}


# Submit the health certificate
You can enter the health certificate data into an input field. 

Source for DCC: https://eu-dcc-validation.web.app/

Open the QR-code with Google lens (right click option in Chrome) and "copy text" to obtain health sertificate in string format 

Make sure that the name and date-of-birth match the data in the validation access token from above. 

##The wallet app now executes the following steps: 
- choose a random password (32 bytes)
- AES-encrypt the DCC with the password from above and the nonce that was obtained together with the access token 
- encrypt the password with the validation service's public key 
- sign the encrypted AES-encrypted data with the userkey that has been submitted to get the access token
- send JSON data to the validation service:
   - kid of validation server's public key that was used to encrypt password
   - encrypted dcc data
   - signature of encrypted dcc data
   - PKI encrypted password for dcc
   - constants: encScheme = RSAOAEPWithSHA256AESCBC, sigAlg = SHA256withECDSA
   - header: Access token that was previously obtained
- decode the response and print it
  - Private part of result is feedback on evaluation of individual busness rules
  - Public part of result is confirmaion token, which can be made availabe to airline if passenger wishes to do so



In [26]:
#hcert = input('Please paste your HCert: ').strip()  # Option 1: Enter the HC1:-String into the input field
#assert hcert.startswith('HC1:')

from base64 import b64decode
from random import randint
from Crypto.Cipher import PKCS1_OAEP
from Crypto.PublicKey import RSA
from Crypto.Cipher import AES
from Crypto.Util.Padding import pad
from ecdsa.util import sigencode_der

# Use real random numbers for production instead!
#password = bytearray([randint(0,255) for i in range(32)])

#validation_identity = requests.get(validation_service_endpoint+'/identity').json()

#for verificationMethod in validation_identity['verificationMethod']:
#    if verificationMethod['id'].endswith('ValidationServiceEncKey-1'):
#        validation_service_publickey =  verificationMethod['publicKeyJwk']
#        print("Selected Public Key:", validation_service_publickey )

#validatorkey = RSA.import_key(f'-----BEGIN CERTIFICATE-----\n{validation_service_publickey["x5c"]}\n-----END CERTIFICATE-----')
#aesCipher = AES.new(password, AES.MODE_CBC,iv=b64decode(validation_nonce))

#cipher = PKCS1_OAEP.new(validatorkey,hashAlgo=SHA256)
#cryptKey = cipher.encrypt(password)
#ciphertext= aesCipher.encrypt(pad(bytes(hcert,'utf-8'),AES.block_size))
#signature = userkey.sign(ciphertext,hashfunc=SHA256.new,sigencode=sigencode_der)

#######   initialize  ###### 
headers = {'content-type': 'application/json', "Authorization":"Bearer " + validator_token ,}
body = {
  "pubKey": "aaabbb",
  "alg": "RSA",
  "Nonce" : "argle"
}
txt=token_info['aud']
url = txt.rsplit("/validate")[0]+"/initialize"
response = requests.post(url, data=json.dumps(body), headers=headers)
print ("Undecoded Response", response.status_code, response.text, '\n\n')


####### validate   ######
headers = {'content-type': 'application/json', "Authorization":"Bearer " + validator_token }

#body = {"kid":validation_service_publickey["kid"],
#        "dcc":base64.b64encode(ciphertext).decode(),
#        "sig":base64.b64encode(signature).decode(),
#        "encKey":base64.b64encode(cryptKey).decode(),
#        "encScheme":"RSAOAEPWithSHA256AESCBC", 
#        "sigAlg":"SHA256withECDSA"}
body= {

}

response = requests.post(token_info['aud'], data=json.dumps(body), headers=headers)
print ("Undecoded Response", response.status_code, response.text, '\n\n')


if response.ok:
  validate_result = jwt.decode(response.content, options={"verify_signature":False})  # weak knees, no sign check
  print(f'Validate result message: {json.dumps(validate_result, indent=4)}')
#print(f'stub, stub, stub here comes the confirmation token ')

https://pinggg.mywire.org/wallet/validation-stub/v2/validate
https://pinggg.mywire.org/wallet/validation-stub/v2/initialize
Undecoded Response 200  


Undecoded Response 200 eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IkFwTXhyY0lIMDdTVVZTTEZ4dk5qUHJ2ME85dEhQWjh6dFk3MDdBR1E2U3cifQ.eyJpc3MiOiJodHBzOi8vc2VydmljZXByb3ZpZGVyIiwiY2F0ZWdvcnkiOiJbU3RhbmRhcmRdIiwic3ViIjoiMjExYzJhOTMtODZjMC00ODlkLWFlN2MtMzliMWM0ZWQ2OTYwIiwicmVzdWx0IjoiT0siLCJyZXN1bHRzIjoiW10iLCJjb25maXJtYXRpb24iOiJleUpoYkdjaU9pSkZVekkxTmlJc0luUjVjQ0k2SWtwWFZDSXNJbXRwWkNJNklrRndUWGh5WTBsSU1EZFRWVlpUVEVaNGRrNXFVSEoyTUU4NWRFaFFXamg2ZEZrM01EZEJSMUUyVTNjaWZRLmV5SnFkR2tpT2lJeU5XUmtOVGN4TUMxbU1EQmtMVFF6WmpZdE9XRTBNaTB3T0RaaU1EUmlNV1F6T0dFaUxDSnpkV0lpT2lJeU1URmpNbUU1TXkwNE5tTXdMVFE0T1dRdFlXVTNZeTB6T1dJeFl6UmxaRFk1TmpBaUxDSmpZWFJsWjI5eWVTSTZJbE4wWVc1a1lYSmtJaXdpY21WemRXeDBJam9pVDBzaUxDSndiMlFpT2lKQ1VsVWlMQ0p3YjJFaU9pSkJUVk1pTENKMllXeHBaRVp5YjIwaU9pSXlNREl5TFRBekxURXdWREUyT2pJNE9qRTFMall3TVZvaUxDSjJZV3hwWkZSdklqb2lNakF5TWkwd015MHhNRlF4Tnp

#completion, push confirmation
Wallet offers to push confirmation to airline, as final step. Under consent.

On "yes", wallet identifies endpoint from airline identity document and POSTs the confirmation token under authentication with invitation token. In final message traeler is advised to go back to airline site

In [27]:
ahum = input('Enter yes to push token to arline: ').strip()
  # App selects the ConfirmationService in Airline Identity document and posts the confirmation token.
for service in serviceIdentity['service']:
    if service['id'].endswith('#ConfirmationService-1'):
      response = requests.post( service['serviceEndpoint'],
                               headers={'Authorization': f'Bearer {qr_code_data["token"]}', #initR-token goes here
                               'Content-Type':'application/json', 'X-Version' : '1.0'},
                               json = {"confirmation": validate_result["confirmation"]})
print ("Undecoded Response", response.status_code, response.text, '\n\n')
        
print('Please navigate back to airline website')

Enter yes to push token to arline: 
Undecoded Response 200  


Please navigate back to airline website
