Skip to content
This repository has been archived by the owner on Jan 25, 2019. It is now read-only.

Commit

Permalink
Updated Security/Privacy section based on input from Eric Korb.
Browse files Browse the repository at this point in the history
  • Loading branch information
msporny committed Mar 12, 2016
1 parent 82ea24c commit 523d463
Showing 1 changed file with 26 additions and 12 deletions.
38 changes: 26 additions & 12 deletions VCTF/charter/vcwg-draft.html
Original file line number Diff line number Diff line change
Expand Up @@ -215,23 +215,37 @@ <h3 id="definitions">Definitions</h3>

<h3 id="security">Security and Privacy Considerations</h3>

<p>Security is critical for verifiable claims.</p>
<p>
In general, the issuers of verifiable claims want to ensure that their
reputation is protected, the holders of verifiable claims want to
ensure their data is protected, and the inspectors of verifiable claims
want to be confident in their claims-based decisions. As a result,
both security and privacy are critical for verifiable claims.
</p>

<p>
From a security perspective it is important that verifiable claims are
protected from forgery and that interactions with verifiable claims are
protected from bad actors at all stages of the lifecycle.
</p>

<p>
From a privacy perspective it is important that information that is
intended to remain private is handled appropriately. Maintaining the
trust of a verifiable claims ecosystem is important. Verifiable
claims technology defined by this group should not disclose private
details of the participants' identity or other sensitive information
unless required for operational purposes, by legal or jurisdictional
rules, or when deliberately consented to (e.g. as part of a request
for information) by the holder of the information. The design of any
data model and format should guard against the unwanted leakage of
such data.
</p>

<p>The Working Group will work with the organizations
listed in the liaisons section of the charter to help ensure data model and
document security.</p>

<p>
Protection of the privacy of participants in a credentials ecosystem
is important to maintaining the trust that credential systems are
dependent upon to function. A credential format defined by this group
should not disclose private details of the participants' identity or
other sensitive information unless required for operational purposes,
by legal or jurisdictional rules, or when deliberately consented to
(e.g. as part of a request for information) by the owner of the
information. The design of any data model and format should guard against
the unwanted leakage of such data.
</p>

</div>
<div>
Expand Down

0 comments on commit 523d463

Please sign in to comment.