Abstract
A self-contained, single-file digital identity credential that can be generated, stored, and verified entirely offline — integrating hybrid classical and post-quantum signing (ECDSA P-256 combined with ML-DSA-65, FIPS 204), AES-256-GCM payload encryption under Argon2id-derived keys, SHA-256 self-integrity verification, an embedded offline verification engine, a crypto-agile suite registry with backward-compatible hybrid receipts, and a deterministic modular build — all in a single HTML file requiring no server, no account, no network, and no installed software at any stage. Release artefacts (generator and documentation) are independently timestamped on public blockchains (Bitcoin, Ethereum) via a blockchain timestamping service — an issuer-performed, per-release, online operation entirely separate from the credential's own offline-first operation.
Creative Commons License

This work is licensed under a Creative Commons Attribution 4.0 License.
Recommended Citation
Benaudis, Michael, "Post-Quantum Ready, Offline-Verifiable Digital Identity Credential: Hybrid ECDSA P-256 and ML-DSA-65 Signing with Embedded Offline Verification Engine, Crypto-Agile Suite Registry, and Deterministic Build in a Self-Contained Single-File Document", Technical Disclosure Commons, ()
https://www.tdcommons.org/dpubs_series/11121