Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

2021-12-14 Aries Summit Session - General UX / Summit Wrap-up


Outcome & Work Items

RFC 496 - Transition to OOB and DID Exchange

  • To do: Chase wallet vendors, share findings, and update RFC Stephen Curran

How are we really going to do deep-links? From 2021-11-16 Session

Handling HTTP on mobile, since mobile OS's require an exemption to use HTTP. DIDComm over HTTPS results in double encryption.

Auto-approval of presentation requests

  • Can be risky, e.g. auto-presenting could lead to interaction-less login
  • One aspect: bulk approval (present series of proofs with one user action to approve)
  • Another aspect: policy approval (conditions by which an approval or other user action can be automated)
    • Care needed on: anti-patterns, security vs. convenience, following SSI principles, fiduciary responsibility when agents work on behalf of users
  • Outcomes:
    • Needs bulk presentation request (Present Proof) (mostly done)
    • Needs policy to recommend bulk actions
    • Policy approval is complex and needs more investigation

Machine-Readable Governance and UX

  • Introduces new types of user interactions
  • Has many types of governance: root of trust, identifying participants, etc.
  • Mike is working on test applications of Machine Readable Governance


UX of Invitations

  • Development of Machine Readable Governance
  • Development of language around trust
  • To Do: Need Proposed Initial Attempt as an Aries RFC - Sam Curren

Mobile Verifiers

  • Inversion of QR scanning flow where verifier scans holder's QR code
  • Other mechanisms other than QR Code (e.g.: BLE)
  • Todo: SU

Original Topics List

  • Mobile Infrastructure (2)
    • Mobile Verifiers
    • Device Recovery (Backup/Restore/Sync/Rotation to new keys)
    • Secure Element usage
    • SDK / Embedding Agents into existing Mobile Apps
  • Credential UX (3)
    • SVG Cred Display
    • Auto-approval of presentation requests (e.g.: trusted verifier, trusted preset, etc ...)
    • Credential Theming (e.g. Icon, Colors, Description)
    • Revocation implications for Mobile
    • Consequences of Machine Readable Governance on UX
  • Other User Experience (UX) (4)
    • UX of Invitations
    • Exposing errors / details to users & power users (404 and 503 like errors)
      • Unsupported DID Method
    • Glossary - naming conventions - how to hide technicalities in front of user
  • QR / Invitations (1)
    • How are we really going to do deep-links?
    • RFC 496 - Transition to OOB and DID Exchange
    • RFC 700 - sending out-of-band as query parameters and enable redirect back.
    • HTTP Mobile exemptions
  • Security
    • DID method specific
    • Immutability of schema and JSON-LD security issues
    • Biometrics/PIN unlock (overlap with UX)
  • Protocols
    • DIF Credential Manifest attachment (followup from Issue Credential v2 json-ld attachment in AIPv2).
    • DIDComm v2 (and related)
      • DIDComm v2
      • WACI