w3c/websec

Hardware Token usage consistency (by KM)

Opened this issue · 1 comments

Section 3.2: Financial Transaction Signature, with User Consent
Text: That last step requires the user to use some credentials, distributed by the bank, usually stored in a secure container, such as a hardware based token (USB token or proximity token).

Section 3.2.1: French ecosystem
Text: Without the capability to rely upon Secure Elements in the browser, banks currently face a major issue in being able to replace the existing identity scheme delegation which provides a strong authentication and signature credential

Comment: Reference to hardware based token should also include at least one example of internal hardware device such as TEE, SE, or UICC. Or alternatively, make consistent use of terms so these terms do not have to be substantiated by examples.

Virginie: maybe we can make a reference to the Audkenni.is / Valimo deployment in Iceland leveraging UICC ?