17 minute read

Main

  • EIDAS - Regulation with linked TOC
  • Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC

    (2) This Regulation seeks to enhance trust in electronic transactions in the internal market by providing a common foundation for secure electronic interaction between citizens, businesses and public authorities, thereby increasing the effectiveness of public and private online services, electronic business and electronic commerce in the Union.

    (3) Directive 1999/93/EC of the European Parliament and of the Council (3), dealt with electronic signatures without delivering a comprehensive cross-border and cross-sector framework for secure, trustworthy and easy-to-use electronic transactions. This Regulation enhances and expands the acquis of that Directive.

    (11) This Regulation should be applied in full compliance with the principles relating to the protection of personal data provided for in Directive 95/46/EC of the European Parliament and of the Council (7). In this respect, having regard to the principle of mutual recognition established by this Regulation, authentication for an online service should concern processing of only those identification data that are adequate, relevant and not excessive to grant access to that service online. Furthermore, requirements under Directive 95/46/EC concerning confidentiality and security of processing should be respected by trust service providers and supervisory bodies.

    (12) One of the objectives of this Regulation is to remove existing barriers to the cross-border use of electronic identification means used in the Member States to authenticate, for at least public services. This Regulation does not aim to intervene with regard to electronic identity management systems and related infrastructures established in Member States. The aim of this Regulation is to ensure that for access to cross-border online services offered by Member States, secure electronic identification and authentication is possible.

    (14) Some conditions need to be set out in this Regulation with regard to which electronic identification means have to be recognised and how the electronic identification schemes should be notified. Those conditions should help Member States to build the necessary trust in each other’s electronic identification schemes and to mutually recognise electronic identification means falling under their notified schemes. The principle of mutual recognition should apply if the notifying Member State’s electronic identification scheme meets the conditions of notification and the notification was published in the Official Journal of the European Union. However, the principle of mutual recognition should only relate to authentication for an online service. The access to those online services and their final delivery to the applicant should be closely linked to the right to receive such services under the conditions set out in national legislation.

  • Trust Services and Electronic identification (eID)
    • ensures that people and businesses can use their own national electronic identification schemes (eIDs) to access public services in other EU eID are available.
    • creates an European internal market for eTS - namely electronic signatures, electronic seals, time stamp, electronic delivery service and website authentication - by ensuring that they will work across borders and have the same legal status as traditional paper based processes. Only by providing certainty on the legal validity of all these services, businesses and citizens will use the digital interactions as their natural way of interaction.

About

  • Global Identity Networks: How to Leverage Them for Business Benefit 2022-03-02 Kuppinger Cole

    The uptake of eIDAS (facilitating cross-border acceptance of eIDs) is low relative to the technical capacity of states; only 15 of the 27 Member States able to fulfil the regulation’s requirements of accepting the eIDs of other Member States for public services.

    The EU Commission did reflect on the effectiveness of the regulation in its Impact Assessment, and is developing a revision of it. There are multiple revision options being discussed, but thus far, the preferred option would establish a framework that provides citizens with optional use of a personal digital wallet

  • Analyst Chat #134: How Self-Sovereign Identities Will Influence Public Services 2022-07-25 KuppingerCole

    Europe is on a “Path to a Digital Decade”, which envisions 80% of EU citizens using a digital ID card by 2030. A part of that journey will be self-sovereign identities. Research Analyst Alejandro Leal joins Matthias to continue their discussion on the digital transformation in public services. Self-sovereign identities, the new eIDAS regulation, and the impact of both on how interactions between citizens and the state will change, are a controversial topic in the public discussion as well.

  • Digital Identity: Leveraging the SSI Concept to Build Trust 2022-01-20 ENISA

    This report explores the potential of self-sovereign identity (SSI) technologies to ensure secure electronic identification and authentication to access cross-border online services offered by Member States under the eIDAS Regulation. It critically assesses the current literature and reports on the current technological landscape of SSI and existing eID solutions, as well as the standards, communities, and pilot projects that are presently developing in support of these solutions.

  • eIDAS and Self-Sovereign Identity 2021-03-11 (Video Dingle Group

    Why then is eIDAS v1 not seen as a success? There are many reasons; from parts of the regulation that focused or constrained its use into the public sphere only, to the lack of total coverage across all of the EU. Likely the key missing piece was that the cultural climate was not yet ripe and the state of digital identity was really not ready. Too many technical problems were yet to be solved. Without these elements the realized state of eIDAS should not be unexpected. All this said, eIDAS v1 laid very important groundwork and created an environment to gather important learnings to allow eIDAS v2 to realize the hoped for levels of success and adoption.

eIDAS Bridge

  • About SSI eIDAS Bridge 2022-02-22

    By sharing Verifiable Credentials, users can prove claims about themselves, but how can the credentials verifier trust them, if the only thing it knows about the issuer is its DID? This is indeed the goal of this project and where the eIDAS regulation can help. eIDAS stands for electronic identification and trust services for electronic transactions in the internal market. It ensures legal validity of electronic documents and cross border trust services, such as electronic signatures and seals. To make eIDAS available as a trust framework in the SSI ecosystem, the European Commission developed under this project, the eIDAS bridge.

  • Time for the eIDAS bridge​ 2022-02-18 ValidatedID

    The main goal of this new program was to provide an implementation of eIDAS bridge and to proof the interoperability between different provider implementations. Validated ID was selected to participate in part of the Call 1 of infrastructure. The results of this project are available as open source. If you are interested in digging into the code, you can find it all in the following repositories: our open source version implementation and the SSI eIDAS Bridge interoperability performed with SICPA.

  • Legal compliance and the involvement of governments 2021-02-06 SSI Ambassador

    It’s currently possible to be eIDAS compliant with SSI, leveraging one out of five scenarios described in the SSI eIDAS legal report by Dr. Ignacio Alamillo Domingo. Especially interesting is the SSI eIDAS bridge, which adds legal value to verified credentials with the use of electronic certificates and electronic seals. However, it’s also possible to derive national eIDs notified in eIDAS, which are eIDAS linked by issuing a verifiable credential with a qualified certificate according to the technical specification.

  • Introducing the SSI eIDAS Legal Report 2020-05-01 Ignacio Alamillo, SSIMeetup

    The European Commission developed the SSI (Self-Sovereign Identity) eIDAS bridge, an ISA2 funded initiative, to promote eIDAS as a trust framework for the SSI ecosystem. It assists a VC (Verifiable Credential) issuer in the signing process, and helps the verifier to automate the identification of the organization behind the issuer’s DID (Decentralized Identifier)

eIDAS 2.0

  • eIDAS 2.0. Moving Closer - European Digital Identity Wallet (EDIW) and Pilot Implementation 2023-06-07 Utimaco

    Large-Scale Pilots
    Before its implementation in the Member States, the European Digital Identity Wallet will be assessed in four large-scale initiatives. These projects aim to evaluate digital identity wallets in real-world scenarios covering numerous sectors. There will be participation from more than 250 private companies and government agencies from 25 Member States as well as Norway, Iceland, and Ukraine.

    The four pilot projects that commenced on 1st April 2023 are as follows:

    1. Potential
      • Piloting the use of EUDI wallets for the authorization of payments for products and services by the wallet user/ holder. This includes accessing a digital public service (for example, when trailing to another Member State, a requirement for proof of identity or a necessity to obtain medical prescriptions) and opening bank accounts.
      • Use of the EUDI wallet will also include the necessary requirement for signing contracts online, where a secure digital signature is provided.
    2. NOBID
      • The NOBID Consortium is developing a large-scale pilot to prepare, implement and test the EU Digital Identity Wallet. This will involve several banks for the authorization of payments for products and services. They aim to address the issuance of wallets, means of payment by financial institutions and acceptance of retail payments.
    3. DC4EU (Digital Credentials for Europe)
      • The pilot of the wallet across the education sector (by securing education credentials) and the Social Security domain. This will be achieved by deploying and accessing European interoperable digital service infrastructures, including integration, by applying the eIDAS cross-border framework.
    4. EUWC (EU Digital Identity Wallet Consortium)
      • Storing and presenting Digital Travel essentials within the wallet, enabling cross-border movement within Europe. Further scope to include business digital identity wallets as well as storage of payment credentials to authorize account-to-account based transactions.
  • eIDAS 2.0 - Introduction to The European Digital Identity Wallet & The Evolution of Self-Sovereign Identity 2022-08-18

    Until now, the eIDAS regulation has only focused on online identification. However, the new proposal – eIDAS 2.0 – aims to extend identity to the world of physical services which can be accessed from anywhere around the globe.

  • EIDAS 2.0 Turns To Self-Sovereign Identification To Bring Users Ownership And Control 2022-07-05 Forbes

    The new proposal will pivot on some of the more key issues that held back the original framework. For example, instead of enforcing a single, rigid ID that openly reveals everything about an individual indefinitely, the eIDAS 2.0 structure can now potentially employ a flexible, self-sovereign identity (SSI) that puts control of all identifying information entirely into the hands of the end-users they pertain to, in both public and private partnership frameworks.

  • Avast’s views on the proposed amendments to the eIDAS 2.0 regulation 2022-06-17 Avast

    In this article, we will take you through what we regard as the most important amendments and their implications for EU digital identity wallet providers as well as the overall eIDAS 2.0 ecosystem—and most importantly for European citizens. This article builds on our previous analysis of the proposed eIDAS 2.0 regulation and the European Digital Identity Architecture and Reference Framework.

  • eIDAS 2.0: How Europe can define the digital identity blueprint for the world 2022-02-24 Avast

    Avast supports the directions of the European Commission with this initiative and the motivators and principles behind it. As an organization that provides safety, privacy and convenience for millions and or people in Europe and around the world, we see great importance of a global interoperable digital smart agent service which is consistent with EC requirements. Further, we recognize the necessity of close public-private sector collaboration in the detailed definition of requirements and in the commercial operation of a partner-led network in Europe and beyond.

  • Drafting of the eIDAS 2.0 report with amendment tracking 2022-05-31 Vedran L. Head of Office at European Parliament

    on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity

EU Digital Identity Framework

EU Digital Identity Wallet

  • Two in three Europeans intend to use the EU’s Digital Identity Wallet 2022-06-08 NFCW

    “The results of the survey certainly underline the need for this pioneering European initiative aiming at offering the most convenient user experience (UX) at the highest level of security,” the company adds

  • Self-Sovereign Digital Identity Wallets for Citizens 2022-06-06 TAGES

    During the 2-days workshop, several panels were realized with the great interest of the participants physically and online. The information on Horizon Europe, EU Health, Digital Europe, Creative Europe, Digital Single Market, Citizens, Equality, Rights, and Values Programme were shared by the experts and also the representatives of the organizations that have project experience within the scope of these EU programs shared the achievements, outputs, challenges, lessons learned and cooperation processes with EU member states in the projects they implemented.

  • Is the EU Digital Identity Wallet an implementation of Self-Sovereign Identity? 2022-04-29 Innopay

    The intention of the European Commission is to allow – or even force – acceptance in a wide range of sectors in the public and private domain and thereby ensure that identities are as wisely usable as possible (interoperability). The principle of consent will also be met, as it is already fulfilled with current eID solutions notified under eIDAS and other EU regulations, such as GDPR and PSD2. One of the explicit requirements of the proposal is selective disclosure, in line with GDPR’s rules on data minimalisation.

  • [Video] Where do we stand on Self-Sovereign Identity? 2022-02-15 EBSI

    On December 14th, Joao Rodrigues, Head of sector (Digital) Building Blocks at @European Commission participated in an #ebcTALKS of the European Blockchain Convention about “Where do we stand on Self-Sovereign Identity”?

    In 2021 the European Commission announced the European digital identity wallet. This article explains the basic concepts, highlights the significance of this development and provides an overview of the status quo.

  • EU digital wallet: the race is on for pilot funding, tech supremacy, hearts and minds2022-04 Biometric Update

    eIDAS 2.0 is fast approaching. By September 2023, European Union citizens will have the right to download and populate a digital identity wallet on a smart device. In less than 18 months, Europeans may no longer need physical credentials to travel, work and live anywhere else in the bloc. But are they ready?

  • Working together to create an eIDAS wallet 2021-08-23 Jolocom

    Jolocom is currently working on the project “ONCE – Online einfach anmelden” (simply register online – ONCE) alongside a number of prestigious partners, with the aim to bring the digital identity of any citizen onto their smartphone.

    The project is part of the competitive innovation programme “Showcase Secure Digital Identities” (SSDI) funded by Germany’s Federal Ministry for Economic Affairs and Energy (BMWi) and one of four projects that qualified for the implementation phase.

  • EU decision on Identity Wallet: Starting signal for a seamless digital future 2021-07-25

    Last week, the EU Commission published a draft for the so-called digital identity wallet “EUid”. According to it, within 12 months of the law coming into force, every EU state must provide its citizens with a digital wallet.

  • What does the EU Wallet mean for self-sovereign identity? 2021-07-06 Fintechtalents.com

    While the EU wallet may not align entirely with every principle of self-sovereign identity, it is certainly a massive leap in that direction.

Background

  • EU Blockchain Observatory and Forum Report - Blockchain and Identity 2019-05-15

    Section 19: Decentralised identity and the European regulatory landscape

    • EIDAS: A PAN-EUROPEAN NATIONAL IDENTITY STANDARD

    Perhaps the most important regulation dealing with identity in the EU is eIDAS, an EU regulation and a set of standards for electronic identification and trust services for electronic transactions in the European Single Market. This regulation will have a deep impact on the decentralised identity framework, above all as it pertains to government-issued/recognised identity credentials, and so is worth a closer look.

  • EIDAS SUPPORTED SELF-SOVEREIGN IDENTITY 2019-05
    1. The DID / SSI approach to identity and Verifiable claims
    2. The eIDAS Regulation
    3. The need for verified identities
    4. Linking the DID with the identity provided by eIDAS
    5. Applying eIDAS to the Verifiable Claims lifecycle

    The purpose of this document is to stimulate the discussion on how identity management solutions based on the Decentralised Identity / Self-Sovereign Identity (SSI) paradigms can benefit from the trust framework created by the eIDAS Regulation.

  • Aligning SSI with European Union identity legislation (aka eIDAS Regulation) 2019-02-09 rwot8-barcelona

    Although electronic identification under eIDAS Regulation is today clearly aligned with SAML-based infraestructures (see Opinion No. 2/2016 of the Cooperation Network on version 1.1 of the eIDAS Technical specifications, available at https://ec.europa.eu/cefdigital/wiki/pages/viewpage.action?pageId=37750723 and eIDAS eID Profile, available https://ec.europa.eu/cefdigital/wiki/display/CEFDIGITAL/eIDAS+Profile), nothing in the eIDAS or its implementing acts should prevent the usage of a SSI system as an electronic identification means.

    Thus, the second use case considers a DID as an eIDAS compliant electronic identification means, enabling - at least - transactions with Public Sector authorities and Public Administrations and, if so decided by the DID creator, also with private sector entities.

  • EU BLOCKCHAIN OBSERVATORY AND FORUM Report - e-Identity 2018-11-07 e-Identity, Brussels

    eIDAS: Key Principles for Identity

    • Cooperation between Member States
    • Reciprocity relying on defined levels of assurance
    • Mandatory cross-border mutual recognition of identifiers
    • Sovereignty of Member states to use or introduce means for eID at their national level
    • Full autonomy to the private sector
    • Interoperability framework
    • Member States can use different means of identification, but with the same functionality
    • The problem is not the technology, but the legal framework, the distribution of liability, and the question to know whether what is enforceable in country A is also enforceable in country B (for instance in the court).
  • [Video] eIDAS and Self-Sovereign Identity 2018-09-23 Fabrizio Leoni, MyData 2018

    MyData 2018 Conference - Track: Interoperability

  • go.eIDAS-Initiative launched across Europe and beyond 2018-09-27

    Europe is awaiting a major milestone for trustworthy electronic identification: The cross-border recognition of notified electronic identification systems (eID) will start on 29th of September 2018 across Europe. Against this background, leading European associations, projects and expert organisations in the sector of eID and trust joined forces to launch the non-profit go.eIDAS-Initiative today, which aims at supporting the widespread adoption of eID and trust services according to the eIDAS-Regulation (EU) No 910/2014.

  • eIDAS as guideline for the development of a pan European eID framework in FutureID 2014

    Abstract: This paper addresses the Regulation on Electronic transactions in the internal market: electronic identification and trust services (eIDAS) and analyses this regulatory framework in relation to the pan European eID infrastructure being developed in the FutureID project. The aim of this paper is to identify if eIDAS sets forward any legal requirements that need to be implemented in the FutureID infrastructure. Even though the focus of this paper is on the development of the FutureID infrastructure, the description of eIDAS and the analysis of its main requirements for technical developers are in general relevant to the development of online identification and authentication schemes.