Conformance and Profiles
Conformance to this implementation guide is assessed at two levels:
- Base conformance: Compliance with the requirements in Parts 1-8 and the Annexes of this guide. Base conformance is mandatory for all SEDI ecosystem participants.
- Profile conformance: Compliance with a specific conformance profile that binds technology choices to the profile hooks identified throughout this guide. Profile conformance is necessary for interoperability.
A system that satisfies all base requirements but does not implement a specific profile is "base-conformant but not interoperable." A system that implements a specific profile is "profile-conformant" and is interoperable with other systems implementing the same profile.
Conformance Levels
Three actor-specific conformance types reflect the distinct roles in the SEDI ecosystem:
Issuer Conformance (for the Department/Program): - All SEDI-SDI, SEDI-IDP, SEDI-PRG, SEDI-APP requirements - All applicable SEDI-CRY, SEDI-PRV, SEDI-INT requirements - SEDI-ENF requirements - For the complete per-requirement list, see Section 4.2 and Annex E
Wallet Conformance (for digital wallet providers): - All SEDI-WAL requirements - All applicable SEDI-CRY, SEDI-PRV, SEDI-INT requirements - Applicable SEDI-LOY and SEDI-PRC requirements - For the complete per-requirement list, see Section 4.4 and Annex E
Verifier/RP Conformance (for verifiers and relying parties): - All SEDI-VER requirements (for verifiers) or SEDI-RPY requirements (for relying parties) - All applicable SEDI-CRY, SEDI-INT requirements - Applicable SEDI-LOY and SEDI-PRC requirements - For verifiers, see Section 4.5 and Annex E. For relying parties, see Section 4.6
Profile Structure and Registration
A conformance profile is a supplementary document that binds specific technologies to the profile hooks identified in this guide. A profile SHALL contain:
- Profile identifier and version (e.g., SEDI-PROFILE-[NAME]-1.0)
- Normative references to specific standards and versions
- Profile hook resolution: For each profile hook in this guide, the specific technology choice, the relevant standard/specification section, and a justification for how it satisfies the base requirement
- Mapping to evaluation criteria: How the profile's technology choices satisfy each evaluation criterion in the base requirements
- Additional profile-specific requirements (clearly marked as profile-specific, not base)
- Test vectors or reference implementations where applicable
Profile Approval
Profiles are approved by the Department through the rulemaking process under Utah Code § 63A-20-202(3)(a), subject to the 45-day public comment period under Utah Code § 63A-20-202(3)(b)(i) and the response requirement under Utah Code § 63A-20-202(3)(b)(ii).
Multiple profiles MAY coexist. The Department SHALL NOT limit the ecosystem to a single profile, consistent with the technology neutrality principle and the open standards requirement (Utah Code § 63A-20-301(2)(e)).
Evaluation Methodology
Evaluation of conformance SHOULD follow this methodology:
- Document review: Verify that the implementation's design documents address each applicable requirement.
- Architecture analysis: Verify that the system architecture satisfies structural requirements (particularly anti-surveillance and data minimization).
- Functional testing: Verify that the system performs each required capability (selective disclosure, predicate proofs, offline presentation, etc.).
- Security assessment: Verify that security properties (tamper resistance, key protection, encryption) meet requirements.
- Interoperability testing: Verify that implementations of the same profile can interoperate (e.g., wallet A can present to verifier B).
- Privacy analysis: Verify that privacy properties (unlinkability, anti-surveillance, data minimization) hold under realistic usage scenarios.
Certification Process Guidance
This guide does not establish a certification program. It provides the requirements and evaluation criteria that a certification body (e.g., Kantara Initiative, a state-designated body, or the Department itself) could use to develop a formal certification program.
A certification program SHOULD: - Define specific pass/fail criteria for each evaluation criterion - Establish testing procedures and test suites - Define certification validity periods and renewal requirements - Address ongoing compliance monitoring - Establish a process for handling non-compliance findings
Severability
Utah Code § 63A-20-901 provides that if any provision of Utah Code Title 63A, Chapter- 20 is held invalid by a court, the remainder of the chapter continues in effect. The provisions are severable. This means that invalidation of any single requirement in this guide does not affect the enforceability of the remaining requirements.