Annex D: Informative Reference Mapping

This annex identifies categories of external frameworks that address requirements similar to those in this guide. The mapping is non-normative and is intended to assist implementers in understanding where SEDI requirements align with, diverge from, or go beyond existing frameworks.

The selection of specific standards is delegated to conformance profiles (see Chapter 14). Conformance profiles SHOULD include detailed mappings to the specific standards they adopt. See the Introduction for the current list of candidate technologies under consideration for profiles.

D.1 Identity Proofing Frameworks

SEDI Requirement

Framework Category

Notes

SEDI-IDP-01

Identity assurance level frameworks

Utah statute requires "generally accepted standard"; a conformance profile must specify which assurance level framework applies and at what level

SEDI-IDP-04

Evidence collection and validation standards

Four proofing objectives (existence, identity, binding, record) map to standard evidence requirements in established proofing frameworks

SEDI-SDI-06

Federation and assertion frameworks

Online presentation has parallels to federated assertions; offline presentation has no direct equivalent in most proofing frameworks

SEDI-SDI-17

Privacy requirements in proofing standards

SEDI's statutory anti-surveillance prohibition is more absolute than the privacy guidance in most identity frameworks

 

D.2 Digital Identity Wallet Architectures

SEDI Requirement

Architecture Category

Notes

SEDI-SDI-03

Unlinkability and pseudonym mechanisms

Various architectures address unlinkability through pseudonyms, batch issuance, or cryptographic blinding

SEDI-SDI-06

Proximity and remote presentation flows

Most wallet architectures define both proximity (offline) and remote (online) presentation modes

SEDI-SDI-07

Selective disclosure mechanisms

Attribute-level selective disclosure is a common requirement across digital credential architectures

SEDI-SDI-08

Predicate proof / zero-knowledge proof mechanisms

Not all credential formats natively support predicate proofs; this is a key differentiator when evaluating candidate technologies

SEDI-SDI-15

Open standards mandates

Most government wallet architectures mandate open standards, though specific standard bodies referenced vary

SEDI-WAL-04

Secure cryptographic device requirements

Wallet architectures vary in how they specify tamper resistance and secure element requirements

SEDI-WAL-06

Data portability and credential export

Portability requirements vary significantly across architectures

 

D.3 Credential Format Capabilities

Different credential formats offer different capability sets. A conformance profile must demonstrate that its chosen format satisfies all applicable SEDI requirements. Key capability dimensions to evaluate:

SEDI Requirement

Required Capability

Evaluation Question

SEDI-SDI-04

Issuer signature verification

Does the format support cryptographic proof of authenticity verifiable with only the issuer's public key?

SEDI-SDI-06 (offline)

Offline verification

Does the format support verification without network connectivity?

SEDI-SDI-07

Per-attribute selective disclosure

Does the format allow revealing individual attributes without exposing others, cryptographically enforced?

SEDI-SDI-08

Predicate proofs

Does the format support boolean assertions (e.g., "age >= 21") without revealing the underlying attribute?

SEDI-BOR-11

Contactless presentation

Does the format support presentation without requiring device handover?

SEDI-CRY-02

Holder-controlled key binding

Does the format bind the credential to a holder-generated asymmetric key pair?

SEDI-PRV-01

Unlinkable presentations

Does the format prevent cross-context correlation across presentations to different verifiers?

SEDI-INT-03

Wallet portability

Can credentials in this format be exported and imported across different compliant wallets?