Skip to content

Commit

Permalink
Merge pull request #18 from Yubico/introduction-review-sander
Browse files Browse the repository at this point in the history
Note that for online scenarios, ARKG gives assurance of same-hardware binding
  • Loading branch information
emlun authored May 13, 2024
2 parents d9697e9 + 50d9beb commit 4a57119
Showing 1 changed file with 6 additions and 1 deletion.
7 changes: 6 additions & 1 deletion draft-bradleylundberg-cfrg-arkg.md
Original file line number Diff line number Diff line change
Expand Up @@ -145,8 +145,13 @@ Some motivating use cases of ARKG include:
which is set to use single-use asymmetric keys to prevent colluding verifiers from using public keys as correlation handles.
Each digital identity credential would thus be issued with a single-use proof-of-possession key,
used only once to present the credential to a verifier.
ARKG enables offline usage scenarios by allowing pre-generation of public keys for single-use credentials
ARKG empowers both online and offline usage scenarios:
for offline scenarios, ARKG enables pre-generation of public keys for single-use credentials
without needing to access the hardware security device that holds the private keys.
For online scenarios, ARKG gives the credential issuer assurance
that all derived private keys are bound to the same secure hardware element.
In both cases, application performance may be improved
since public keys can be generated in a general-purpose execution environment instead of a secure enclave.

- __Enhanced forward secrecy__:
The use of ARKG can facilitate forward secrecy in certain contexts.
Expand Down

0 comments on commit 4a57119

Please sign in to comment.