KeyBindingJws

@Serializable
data class KeyBindingJws(val issuedAt: Instant? = null, val audience: String, val challenge: String, val sdHash: ByteArray, val transactionDataHashes: List<@Serializable(with = ByteArrayBase64UrlSerializer::class) ByteArray>? = null, val transactionDataHashesAlgorithmString: String? = null)(source)

Key Binding JWT for SD-JWT, per RFC 9901.

Constructors

Link copied to clipboard
constructor(issuedAt: Instant? = null, audience: String, challenge: String, sdHash: ByteArray, transactionDataHashes: List<@Serializable(with = ByteArrayBase64UrlSerializer::class) ByteArray>? = null, transactionDataHashesAlgorithmString: String? = null)

Properties

Link copied to clipboard
@SerialName(value = "aud")
val audience: String

RFC 9901: REQUIRED. The value MUST be a single string that identifies the intended receiver of the Key Binding JWT. How the value is represented is up to the protocol used and is out of scope for this specification.

Link copied to clipboard
@SerialName(value = "nonce")
val challenge: String

RFC 9901: REQUIRED. Ensures the freshness of the signature or its binding to the given transaction. The value type of this claim MUST be a string. How this value is obtained is up to the protocol used and is out of scope for this specification.

Link copied to clipboard
@SerialName(value = "iat")
@Serializable(with = InstantLongSerializer::class)
val issuedAt: Instant?

RFC 9901: REQUIRED. The value of this claim MUST be the time at which the Key Binding JWT was issued using the syntax defined in RFC7519.

Link copied to clipboard
@SerialName(value = "sd_hash")
@Serializable(with = ByteArrayBase64UrlSerializer::class)
val sdHash: ByteArray

RFC 9901: REQUIRED. The base64url-encoded hash value over the Issuer-signed JWT and the selected Disclosures. The hash value in the sd_hash claim binds the KB-JWT to the specific SD-JWT. The sd_hash value MUST be computed over the US-ASCII bytes of the encoded SD-JWT, i.e., the Issuer-signed JWT, a tilde character, and zero or more Disclosures selected for presentation to the Verifier, each followed by a tilde character: <Issuer-signed JWT>~<Disclosure 1>~<Disclosure 2>~...~<Disclosure N>~ The bytes of the digest MUST then be base64url encoded.

Link copied to clipboard
@SerialName(value = "transaction_data_hashes")
val transactionDataHashes: List<@Serializable(with = ByteArrayBase64UrlSerializer::class) ByteArray>?

OID4VP: Array of hashes, where each hash is calculated using a hash function over the strings received in the transaction_data request parameter (see SignatureRequestParameters). Each hash value ensures the integrity of, and maps to, the respective transaction data object.

Link copied to clipboard
@Transient
val transactionDataHashesAlgorithm: Digest
Link copied to clipboard
@SerialName(value = "transaction_data_hashes_alg")
val transactionDataHashesAlgorithmString: String?

OID4VP: REQUIRED when this parameter was present in the transaction_data request parameter. String representing the hash algorithm identifier used to calculate hashes in transactionDataHashes response parameter.

Functions

Link copied to clipboard
open operator override fun equals(other: Any?): Boolean
Link copied to clipboard
open override fun hashCode(): Int