This paper describes a client-side system for creating Verifiable Presentations (VPs) entirely within a web browser, without server round-trips during presentation generation. The system employs two key derivation strategies: (A) a passkey-derived strategy using the WebAuthn PRF extension to derive deterministic cryptographic keys, and (B) a device-bound strategy using non-extractable Web Crypto API keys with OPAQUE session key-based wrapping. Both strategies produce pairwise per-service binding identifiers, preventing cross-service profile linkage. Novelty claims disclosed: (1) Browser-based offline VP generation using WebAuthn PRF, (2) Deterministic cross-device key recovery without central key escrow, (3) Pairwise service binding for privacy, (4) Selective disclosure within the VP payload, (5) Authenticator change detection via public key hash, and (6) OPAQUE session export keys as a device recovery mechanism.
Dmitry O. Prúdnikov (Thu,) studied this question.