Register did:huuid DID Method — Health Identity Resolver#722
Conversation
🤖 AI Preliminary Specification ReviewThis is an advisory, automated review of the DID Method specification(s) referenced in this pull request, checked against the registration checklist. It does not replace review by the registry editors.
|
| Item | Level | Status | Notes | |
|---|---|---|---|---|
| ✅ | M1. Specification is reachable and is a DID Method specification | MUST | pass | |
| ✅ | M2. DID Method Syntax is defined | MUST | pass | |
| ✅ | M3. CRUD operations are defined | MUST | pass | |
| ✅ | M4. Security Considerations section present and substantive | MUST | pass | |
| ✅ | M5. Privacy Considerations section present and substantive | MUST | pass | |
| ✅ | M6. Method name is indicative and non-generic | MUST | pass | |
| ✅ | M7. No unreasonable legal, security, moral, or privacy harms | MUST | pass | |
| ✅ | M8. Human-readable description of the addition | MUST | pass | |
| ✅ | S1. contactEmail present | OPTIONAL | pass | |
| ✅ | S2. verifiableDataRegistry present | OPTIONAL | pass | |
| ✅ | S3. Intellectual-property posture is clear | SHOULD | pass |
swcurran
left a comment
There was a problem hiding this comment.
The submission meets the minimum requirements for inclusion in the registry.
The DID Method is a central registry of DIDs. It is likely that the same functionality could be achieved with existing DID Methods -- even a did:web server with a database of DIDs.
There is mention of a history of DIDs via an "audit log", but no mention of how that is accessed.
ottomorac
left a comment
There was a problem hiding this comment.
The entry meets the minimum requirements. Approved.
|
Thank you for the review and approval. On the did:web comparison: did:web requires a stable domain and web hosting per DID, making it unsuitable for patient identity in low-resource clinical environments where individual facilities may not have persistent web infrastructure. did:huuid is designed specifically for health-domain constraints:
These are health-specific protocol requirements that would require significant additional specification work to achieve with did:web. On audit log access: The audit log is accessed by the Root Authority (currently HUUID Protocol Working Group, transitioning to the national health authority upon formal adoption) via internal service role only. It is not a public endpoint by design — exposing audit records publicly would create a privacy violation for patients. Access model:
We have added a dedicated Audit Log Access section to the specification at https://7evenbillion.github.io/huuid-did-method Thank you again for the thorough review. |
|
One more question following your response on did:web. In the spec, there are references to the "huuid.health" DNS domain in the DID operations. Is that intended to representative of a root for a did:huuid (like how "example.com" is used in other specs) or a literal endpoint for the DID Method? |
|
Thank you for the follow-up question. To answer directly: "huuid.health" in the current To answer your specific question about the DID did:huuid:gh: — Ghana (Africa) These country codes are not references to the The specification will be updated to clearly |
----- DID METHOD REGISTRATION FORM: DELETE EVERYTHING ABOVE THIS LINE ------
DID Method Registration
As a DID method registrant, I have ensured that my DID method registration complies with the following statements:
contactEmailaddress [OPTIONAL].verifiableDataRegistryentry [OPTIONAL].