Chapter 3 · 2/5
Selective disclosure
Each field of a credential is sealed separately; the person opens only the field asked for, the rest stays closed.
6 min
The previous page reached a conclusion: a person should show only what is needed. That creates a puzzle. A digital credential is valuable because of the issuer's signature, and a signature protects the whole document; change one letter and it breaks. So how do you hide part of a signed credential and keep the signature valid?
The answer is called selective disclosureShowing only the requested fields of a credential and keeping the rest hidden.. Let us start with an analogy and then look at how it really works.
An analogy: envelopes and a sealed list
Imagine a university gives you a degree, not as one sheet of paper but as a set of small envelopes. Each envelope holds one fact: your name, your field of study, your year of graduation, your grade average. The university stamps each envelope with a seal unique to it, writes the list of seals on a single page and signs that page.
When an employer asks only for your field and year, you hand over the signed list and just those two envelopes. The employer opens them, checks that what is inside matches the seals, and sees that the list was signed by the university. The envelope with your grade average stays with you; the employer sees a seal on the list but cannot tell what is inside.
How it actually works
The envelopes are small data packets; the seals are fingerprints:
- For each field the issuer generates a random value called a salt. The field and its salt are turned into a hashA short fingerprint of data: change the data and the fingerprint changes; you cannot get the data back from it.. The result is a salted hashA hash mixed with a random value, so the same data gives a different hash every time..
- The issuer puts only these hashes into the credential, not the fields themselves, and signs the list of hashes.
- The readable versions of the fields (salt, field name, value) come to the wallet as separate small packets.
- When presenting, the wallet sends only the requested packets. The verifier computes each packet's hash itself and compares it with the signed list.
Why the salt? Fields like a date of birth have a limited set of possible values. Without a salt, someone could hash every possible date and find the one that matches. A random salt makes that impossible: to anyone who has not seen the field, its hash is a meaningless number.
Can someone copy it and use it?
No. When the credential is issued it is bound to a device keyA private key created inside the phone that never leaves it; it ties the credential to that device. on the person's phone. At every presentation the wallet signs, with that key, a one-time number sent by the verifier (a nonceA random number used once; it stops an old answer from being replayed.). The verifier is then sure of two things: the credential is genuine, and the person presenting it is its holder. A captured old presentation is useless anywhere else.
Where it stops
Selective disclosure protects the content of hidden fields. But a field you show is still a value: a verifier could ask for the date of birth instead of "over 18". And if the same copy of a credential is shown in two places, both presentations carry the same signature and hashes. The next two pages deal with those limits: zero-knowledge proofs and unlinkability.
Summary
- The issuer seals each field separately (a salted hash) and signs only the list of seals.
- The person sends only the requested fields; the verifier checks them against the signed seals.
- Hidden fields cannot be guessed, and because each presentation is signed with the person's device key it cannot be replayed.
Go deeper
Technical details and binding rules: