Skip to content

End-to-End Payload Encryption for PII in CAMARA APIs #310

@drifterxy

Description

@drifterxy

Problem description
In a KYC-match flow involving Developer→ Aggregator → MNO, is there a recommended way to protect sensitive payload parameters (e.g., ID, name, address) so that the aggregator or other intermediaries cannot view them in clear text? Has there been any discussion on introducing a standard & compliant mechanism for payload encryption in the CAMARA spec?

Possible evolution
Can existing OIDC flows be extended to support end-to-end payload encryption while maintaining routing functionality?

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions