In the previous post I described issuance and presentation protocols for a kind of third-party credential that is made available at once to all the browser instances controlled by a user, which I refer to as the user's sync fabric, instead of being issued to one instance and then replicated to other instances upon request by relying parties. The credential comprises a passkey and a certificate, uses the public key of the passkey as the public key in the certificate, and uses an AES key stored in the user.id parameter of the passkey to encrypt the certificate.
Then in this LinkedIn post I referred to the third-party credential as being the result of "fusing" a passkey with a public key certificate.
Here I'm going to formally define the term passkey-fused credential (PFC) to refer to that kind of third-party credential, restate the issuance and presentation protocols of the previous post with reference to that definition, and provide four examples of use cases where PFCs can be used.
Continue reading "Passkey-fused credentials: definition, protocols and use cases"