FEP-ef61: Portable Objects

I guess you are specifically talking about the did:key method, which the FEP uses in its examples. But the FEP supports other DID methods too, and many methods supports rotating signing keys (verificationMethod) without changing the identity.

With those DID methods, the secret used to rotate the signing keys can (and is strongly recommended to) be different from the signing keys. Even if you choose to let the signing key in the custody of the gateway, you will hold the primary secret in your own device and only delegate the capability to sign the portable objects to the gateway’s signing key. If the gateway becomes malicious, you will simply revoke the old gateway’s key using your own secret.

3 Likes