IOXIO Tags™
MetadataSigning

IOXIO Tags™️ signatures

Technical details about the signatures used with IOXIO Tags™

The signed codes start with an identifier to designate that they are an IOXIO Tags™ code, including a version number. Right now the header used is the characters IT1:.

Encoded signed data §

Following the header there is the signed data, encoded in Base45, used commonly in e.g. the EU COVID passports and other standards where QR codes need to be used to represent arbitrary binary data.

The data is signed with COSE (CBOR Object Signing and Encryption), effectively a version of the JOSE system but for CBOR, and CBOR itself is a more efficiently packed binary friendly format similar to JSON.

By parsing the COSE signature without verifying it, you should be able to get the JWKS kid and alg from the COSE header, as well as the payload. You can use the iss from the payload to fetch the product-passport.json, which points to the jwks.json. Once you load that file, you can use the other properties to determine the correct key to verify the signature with.

Check out the verify_code function in our demo application for a full example.

Payload §

Once the COSE data is parsed, you will get the properties of the code, so the iss, product, and id, from it.

The data is signed with COSE (CBOR Object Signing and Encryption), effectively a version of the JOSE system but for CBOR, and CBOR itself is a more efficiently packed binary friendly format similar to JSON.

Parsing process §

  1. Scan the QR code
  2. Verify the header - that the first 4 characters match exactly IT1:
  3. Remove the header from the code
  4. Base45 decode the code
  5. Parse the alg and kid from the COSE header, as well as the COSE payload without verifying the signature
  6. Fetch https://{payload.iss}/.well-known/product-passport.json metadata
  7. Fetch the JWKS keys from {jwks_url} in the product-passport.json
  8. Verify the COSE signature matches the key provided via JWKS
  9. Fetch https://{payload.iss}/.well-known/product-passport/{payload.product}.json for product metadata
  10. Fetch https://{product_dataspace}.well-known/dataspace/dataspace-configuration.json
  11. Proceed to do what you wish with the supported_dataproducts from the {payload.product}.json, including e.g. fetching the data products via the product_gateway_url from the dataspace-configuration.json

Check out our Sandbox's dataspace-configuration.json to see what configuration is available for IOXIO dataspaces.

Example signed code §

The line feeds are added to make it easier to see what the code is like, but are not a part of the code. Having extra linefeeds breaks the code.

Printed into a QR code one might look something like this:

example of a signed IOXIO Tag QR code

Check out the make_cose_code function in our demo application for a full example.

You can check out our IOXIO Tag™ generator and as well as IOXIO Tag™ scanner, and their source code to see how these work in practice.

On this page