The systems used OpenID’s credential issuance and presentation protocols, which define how a credential enters a wallet and how the holder shares it with a verifier. They also followed the High Assurance Interoperability Profile, a common set of security and interoperability requirements. Security checks tied credentials to the holder’s cryptographic key and used one-time challenges to prevent replay of a previous presentation. The second phase used trusted lists to check credential issuers and wallet attestations to verify the wallet requesting a credential. Electronic seals supported checks on the issuing institution and whether the academic information had been altered.
Source: mobileidworld.com