GDC26 meeting report published: Wallet Security Assurance — ST/PP and Convergence

Dear Cyber Security and IKP colleagues,

The GDC 2026 breakout in Geneva on 3 September 2026 (15:00–15:50) is now on the BGIN website as a meeting report, with the session slides. The record is written under the Chatham House Rule for floor interventions: information may be used; other participants are not identified. The programme speaker is Julien Bringer (BGIN Cyber Security).

The 50-minute session asked how the identity and blockchain rooms can get from vendor-specific security targets to a common, evaluate-able protection profile for crypto wallets—without forking Common Criteria, FIDO, GlobalPlatform, or EUDI schemes, and without a process that only large vendors can complete. It built on the Security Target & Protection Profile (ST/PP) workstream.

Read and cite

What the room actually used

  • There is no common protection profile for crypto wallets today. Certification means a vendor-specific security target; a chip or component certificate does not evaluate the integrated seed, update, isolation, and consent path.
  • Reuse existing building blocks (Common Criteria, CSPN, SSCD/QSCD, GlobalPlatform TEE, FIDO, FIPS/PCI, EUDI/EUCC drafts). Do not fork those schemes; write only the wallet/DLT gap, including PQC agility as an objective from the start.
  • One profile will not cover all ToEs. Candidate families are non-custodial, custodial, and MPC/threshold, with tiered assurance. Distinctions the room used include hardware entropy present versus entropy used, and QSCD/WSCD versus WSCA/activation software.
  • A copy-paste of heavy Common Criteria practice will not be followed by small wallet startups. Practical reuse of certified secure components, with minimal crypto-wallet deltas, is the adoption path. ISO/IEC JTC 1/SC 27 has no crypto-wallet PP today; CEN/TC 224 / EUCC identity-wallet work is adjacent rather than sufficient.

Continue at Block 15

Please bring comments, corrections, proposed use cases, and a view on whether to draft retail or custodial profiles first into this thread. The named continuation is BGIN Block 15 (15–16 October 2026, Washington, D.C.; hybrid), including Cyber: Security Target & Protection Profile (ST/PP) on 16 October, 15:40–17:10.

Anyone can participate on Discourse. No membership application is required.

Shin’ichiro Matsuo
BGIN Co-Chair