Shibboleth Developer's Meeting, June 7, 2013
...
https://spaces.internet2.edu/display/scalepriv/Scalable+Privacy
RE the RSA key matching issue, Chad requested a feature of vt-crypt a while back that provided keypair verification.
AFAICT use of PublicKeyUtils.isKeyPair(PublicKey, PrivateKey) would have avoided the BC/Santuario runtime exception issue.