Skip to content

timestamp fo the batch issued credentials #592

@Sakurann

Description

@Sakurann

there was an issue raised regarding traceability concerns in batch issuance that all tokens are generated with the same timestamp, making them traceable. If the issuer generates a new timestamp for each attestation, during batch issuance, the issuance of 10/30/50 attestations often falls within the same second, or at most, spans two seconds.

Suggestion would be to add a privacy considerations section like the following (it is also in the sd-jwt rfc):

"claims carrying time information, like iat, exp, and nbf, MUST either be randomized within a time period considered appropriate (e.g., randomize iat within the last 24 hours and calculate exp accordingly) or rounded (e.g., rounded down to the beginning of the day)."

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions