11# D - Embedded Disclosure Policies
22
3- Version 0.9 , updated 18 February 2025
3+ Version 1.0 , updated 24 February 2025
44
55## 1. Introduction
66
@@ -154,7 +154,8 @@ If an evaluation of the embedded disclosure policy results in "deny" and this re
154154generating an error that reveals the attestation's existence while denying presentation to the
155155Relying Party may leak information about the user. A Relying Party should
156156not be able to distinguish between a nonexistent attestation and an existing
157- attestation for which presentation is denied. It is noted that currently protocols
157+ attestation for which presentation is denied. Measures shall also be considered
158+ to prevent related timing attacks. It is noted that currently protocols
158159specified in the Implementing Acts do not consider such error response.
159160
160161
@@ -209,7 +210,7 @@ such a language.
209210
210211## 4 Additions and changes to the ARF
211212### 4.1 High-Level Requirements to be added to topic 43
212- The following High-Level Requirements will be added to Annex 2 of the ARF v1.11
213+ The following High-Level Requirements will be added to Annex 2 of the ARF
213214
214215#### REQUIREMENT 1
215216A Wallet Solution SHALL support the implementation of the 'Authorised relying parties only policy'
@@ -227,7 +228,7 @@ in attestation metadata in a way that is compatible with the issuance protocol
227228considered by the ARF.
228229
229230#### REQUIREMENT 4
230- When the presentation of an attestation is denied, the Wallet Unit SHALL behave
231+ When the presentation of an attestation is denied by the User , the Wallet Unit SHALL behave
231232towards the Relying Party as it would if the attestation did not exist.
232233
233234### 4.2 High-Level Requirements to be changed
0 commit comments