Skip to main content

SID-KEY-01 — WSCA WebSocket Key Signing Delegation

PropertyValue
Statusverified
Ownerplatform
Categorytechnical
CSF Functionprotect
GroupKey Management Controls

Description

Wallet Secure Cryptographic Application: signing operations delegated to frontend via authenticated WebSocket. Backend requests signing; frontend executes with local keys in the encrypted keystore. Keys never transmitted to backend.

Components

  • Wallet Frontend
  • Wallet Backend (Go)
  • WSCA / HSM

Source References

Audit Findings

FindingSeverityStatus
EN-P-2 — WSCD/WSCA via FIDO sign extensioncriticalin progress
EN-P-5 — Partial user authentication and session controlshighin progress
EN-P-6 — Partial key management and credential operationsmediumin progress