EU Digital Identity Wallet

From MgmtWiki
Jump to: navigation, search

Definition

The European Union has legislated that all people registered in any of the member states should have access to a no cost Government Approved Wallet that can be used throughout any state in the union.

Context

https://ec.europa.eu/digital-building-blocks/sites/display/EUDIGITALIDENTITYWALLET/FAQ/?pk_source=linkedin&pk_medium=social_media_organic&pk_campaign=EUDIW_FAQ_WalletUsage1_22NOV2024

  1. POTENTIAL is addressing six use cases - SIM eRegistration, Account Opening, eDriving License, eGov Services, eSignature, ePrescription. The website contains short statements on objectives and visions for each use case. The consortium unites 148 participants from 19 EU member states and Ukraine. (WARNING the web site has so little regard for security that is not supporting encryption!)
  2. The NOBID consortium is looking into Wallet issuing, payment means issuance and payment acceptance.

European Commission: Material for the call to provide "Support to the implementation of the European Digital Framework" https://lnkd.in/esZ8bpgU

The Architecture and Reference Framework (ARF) is a set of requirements, recommendations, and specifications for the EU Digital Identity Wallet (EUDIW). It was developed by the eIDAS expert group and provides a summary description of the EUDI Wallet concept, including its objectives, roles of the actors of the ecosystem, functional and non-functional requirements, and potential building blocks. The ARF is non-mandatory and does not imply any formal agreement regarding its content or the legislative proposal.

The European Digital Identity Wallet Toolbox Process is a set of common standards, technical specifications, and guidelines that aim to ensure a high level of trust in digital transactions in Europe. The first version of a common EU Toolbox to implement the EU Digital Identity Wallet was published by the Commission on 10 February 2023. This document, developed by Member States in close collaboration with the Commission, can serve as the technical backbone of all future EU Digital Identity Wallets, ensuring their safety, interoperability, and user-friendliness. The Toolbox is non-binding until the legislative proposal on the EU Digital Identity Wallet has been adopted by the co-legislators.[1]

The High Level Requirements in Annex 2 make it clear that the EUDIW is targeted to on-line access, although it does address proximity wallet connectivity AFTER SOME CONNECTION IS ESTABLISHED. From then on it is wallet-wallet interchanges with OID4VP or Mobile Driver's License(mDL).

Architecture and Reference Framework

2025-02 A new version of the EU Architecture and Reference Framework has been released. In this ARF v1.6.0, relevant text from the Discussion Paper for Topic A (Privacy risks and mitigations) was included in Section 7.4.3.5. Similarly, relevant text from Discussion Paper for Topic B (Re-issuance and batch issuance of PIDs and attestations) was included in Sections 6.6.2.7. and 6.6.5.2. The High-Level Requirements introduced in these Discussion Papers were included in Annex 2, mainly in Topic 10/23 and Topic 7. This document contains links to all the annexes.

https://github.com/eu-digital-identity-wallet/eudi-doc-architecture-and-reference-framework/tree/main/docs/discussion-topics

Problems

there is a lot of really nasty stuff in the ARF. Like the following, which requires that all users of any EUDIW must be registered with some government to receive messages. SO - You will be tracked by Big Brother. (Watch the series "The Final Enemy" to see this roll out in the UK.)

EWTM-U8: As a User of a EUDI Wallet, I want to get an out-of-band indication (e.g. push message or e-mail message) if the certification status and thus the linked EUDI Wallet Trust Mark status of the EUDI Wallet Solution I use is revoked.

DIIP

The Normative References section links to the versions of specifications that DIIP-compliant implementations must support.

This document is not a specification but a profile. It outlines existing specifications required for implementations to interoperate with each other. It also clarifies mandatory features for the options mentioned in the referenced specifications.

The main objective of this profile is to allow for easy adoption and use the minimum amount of functionality for a working Digital Credential ecosystem.

Reference

  1. EU Digital Identity Wallet Toolbox Process https://digital-strategy.ec.europa.eu/en/policies/eudi-wallet-toolbox