Skip to main content

FIT-DS-10 — Authentication data stored properly

Any secret/confidential data related to the authentication of the user SHALL NOT leave the device. The wallet instance SHALL implement mechanisms to ensure no confidential authentication data can be transferred outside the app storage. Account recovery MAY transfer authentication data but SHALL ensure confidentiality and integrity.

PropertyValue
Section5.2.10 Authentication data stored properly
Ownerplatform

Mapped Controls

ControlTitle
SID-AUTH-01FIDO2/WebAuthn Passwordless Authentication
SID-CRYPTO-02PRF Extension Key Derivation

Source: Nordic EUDIW Certification System – Wallet Instance FitCEM PP Appendix