You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: blueprint/01-executive-summary.md
+14-16Lines changed: 14 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -15,7 +15,7 @@ WE BUILD operates within the emerging EUDI and EBW ecosystem, but it is not the
15
15
16
16
In the final EUDI ecosystem, every EU citizen will receive an EUDI Wallet at Level of Assurance (LoA) High.
17
17
18
-
WE BUILD focuses in particular on the EBW - designed for economic operators to manage mandates, exchange trusted business documents such as electronic invoices, and receive legally valid notifications. Some EBW functions, such as onboarding and data portability, will operate at Level of Assurance (LoA) Substantial.
18
+
WE BUILD focuses in particular on the EBW, designed for economic operators to manage mandates, exchange trusted business documents such as electronic invoices, and receive legally valid notifications. Some EBW functions, such as onboarding and data portability, will operate at LoA Substantial.
19
19
20
20
### Bridging ARF Gaps through Specifications and Testing
21
21
@@ -27,38 +27,36 @@ To address these gaps, WE BUILD defines project-specific implementation rules th
27
27
28
28
In the final ecosystem, wallets and services must undergo formal certification by national supervisory bodies.
29
29
30
-
WE BUILD operates in a pilot setting but builds functional, interoperable software that is as close to production-ready as possible. Where relevant, later sections refer back to this pilot framework rather than repeating these distinctions.
31
-
32
30
| WE BUILD does not | WE BUILD does |
33
31
|---------------|----------------|
34
-
| certify EUDI wallets | provide WE BUILD wallets that pass the ITB |
35
-
| rely on eIDAS-eID | provide WE BUILD-eID, with fictitious but realistic identities |
36
-
| create eIDAS-qualified e-signatures | define WE BUILD-qualification of e-signatures, focusing on realistic technical interoperability |
37
-
| use real MS registries |involve real public sector bodies where possible, and otherwise simulate them, always with fictitious registries|
32
+
| certify EUDI wallets | provide WE BUILD wallets that pass ITB testing|
33
+
| rely on eIDAS-eID | provide WE BUILDeID with fictitious but realistic identities |
34
+
| create eIDAS-qualified e-signatures | define WE BUILDqualification of e-signatures focused on technical interoperability |
35
+
| use real MS registries |use real public sector bodies where possible, otherwise simulate them using fictitious |
38
36
| use the EC List of Trusted Lists (LoTL) | provide a WE BUILD LoTL |
39
-
| use the MS Trusted lists (TL) | provide WE BUILD TLs, with feedback from real supervisory bodies if available |
37
+
| use the MS Trusted lists (TL) | provide WE BUILD TLs with input from supervisory bodies where available |
40
38
| reach production-level legal liability | operate within the WE BUILD agreement and trust framework, not within eIDAS |
41
-
| deal with national policy-making |let the WP5 MS Forum indicate where alignment with national policy-making is advisable|
42
-
| deal with universal definitions |assess how far WE BUILD semantics can go within the available timeframe |
39
+
| deal with national policy-making |use the WP5 MS Forum to indicate alignment with national policy-making |
40
+
| deal with universal definitions |define WE BUILD semantics within the available timeframe |
43
41
| issue EUDIW-RP access certificates | issue WE BUILD RP access certificates |
44
-
| issue eIDAS-QEAA | define WE BUILD-QEAA, focusing on realistic technical interoperability |
42
+
| issue eIDAS-QEAA | define WE BUILDQEAA focused on technical interoperability |
45
43
46
44
## Work Package 4 (WP4) - General Capabilities
47
-
WP4 provides the shared technical capabilities that enable the WE BUILD use cases. Our technical groups - Architecture, Semantics, Wallet Providers, PID & EBWOID Providers, Qualified Trust Service Providers (QTSP), Trust Registry Infrastructure, and Test Infrastructure exist solely to provide the engine that powers the use cases.
45
+
The technical groups in WP4 - Architecture, Semantics, Wallet Providers, PID & EBWOID Providers, Qualified Trust Service Provider (QTSP), Trust Registry Infrastructure, and Test Infrastructure - provide the technical capabilities that support the use cases.
48
46
49
47
WP2 and WP3 use cases are expected to use the capabilities provided by WP4 rather than developing parallel technical solutions.
50
48
51
49
To ensure interoperability across participants, WE BUILD uses three levels of documentation:
52
50
53
-
1. This **Architecture & Integration Blueprint (D4.1)**– the high-level architecture and system overview.
54
-
2.[**Architectural Decision Records (ADR)**](https://github.com/webuild-consortium/wp4-architecture/tree/main/adr)explain major architecture decisions and the reasoning behind them.
55
-
3.[**WE BUILD Conformance Specifications (WBCS)**](https://github.com/webuild-consortium/wp4-architecture/tree/main/conformance-specs)define the detailed technical requirements that implementations must follow.
51
+
1. This **Architecture & Integration Blueprint (D4.1)**- the high-level architecture and system overview.
52
+
2.[**Architectural Decision Records (ADR)**](https://github.com/webuild-consortium/wp4-architecture/tree/main/adr)- explains major architecture decisions and the reasoning behind them.
53
+
3.[**WE BUILD Conformance Specifications (WBCS)**](https://github.com/webuild-consortium/wp4-architecture/tree/main/conformance-specs)– defines the detailed technical requirements that implementations must follow.
56
54
57
55
The governance process behind ADRs and WBCS, including how decisions are proposed and adopted, is described in Chapter 7.
58
56
59
57
The Interoperability Testbed (ITB) is a first step toward understanding conformity assessment requirements. In a controlled consortium environment, regulatory and technical specifications are translated into executable interoperability scenarios.
60
58
61
-
## How to get Started
59
+
## Getting Started
62
60
The Blueprint is the starting point for understanding how WE BUILD works.
63
61
64
62
- Technical teams should begin with the WBCS to implement their interfaces.
Copy file name to clipboardExpand all lines: blueprint/02-regulatory-alignment.md
+14-14Lines changed: 14 additions & 14 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ The WE BUILD architecture aligns with two key regulatory instruments: [Regulatio
6
6
7
7
WE BUILD aligns with the legal and technical framework for EUDI wallets. Users can authenticate and present identity and attribute information while retaining control over what data is shared through selective disclosure and explicit consent.
8
8
9
-
The amended eIDAS Regulation is supported by several implementing acts defining the technical and governance framework for the EUDI ecosystem, most importantly:
9
+
The amended eIDAS Regulation is supported by several implementing acts defining the technical and governance framework for the EUDI Wallet ecosystem, most importantly:
10
10
11
11
**Core Wallet Architecture and Technical framework**
12
12
-[2024/2979 – Integrity and core functionalities](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402979)
@@ -30,23 +30,23 @@ The amended eIDAS Regulation is supported by several implementing acts defining
30
30
-[2025/1570 – Notification of certified or cancelled QSCDs](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202501570)
31
31
-[2025/1572 – QTSP initiation, notification and verification](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202501572)
32
32
33
-
### Standardization and Technical Specifications
33
+
### Standardisation and Technical Specifications
34
34
The European Commission, together with the European Digital Identity Cooperation Group, has published:
35
35
36
-
- The [ARF](https://eudi.dev/latest/architecture-and-reference-framework-main/)specify main functionalities, roles and responsibilities, architecture and design principles, attestation formats and protocols, trust model, certification, and risk management of the EUDI Wallet ecosystem.
37
-
- The [Technical Specifications](https://github.com/eu-digital-identity-wallet/eudi-doc-standards-and-technical-specifications/tree/main/docs/technical-specifications)specifies more technical details of selected topics derived from the ARF. The technical specifications describe various topics such as Relying Party registrations, zero-knowledge proofs, attestation rulebooks, schemas and catalogues.
36
+
- The [ARF](https://eudi.dev/latest/architecture-and-reference-framework-main/)specifies main functionalities, roles and responsibilities, architecture and design principles, attestation formats and protocols, trust model, certification, and risk management of the EUDI Wallet ecosystem.
37
+
- The [Technical Specifications](https://github.com/eu-digital-identity-wallet/eudi-doc-standards-and-technical-specifications/tree/main/docs/technical-specifications)specify more technical details of selected topics derived from the ARF. The technical specifications describe various topics such as Relying Party registration, zero-knowledge proofs, attestation rulebooks, schemas and catalogues.
38
38
39
-
Furthermore, there are several standardization organizations that contribute with standards for the EUDIW ecosystem.
39
+
Furthermore, there are several standardisation organisations that contribute with standards for the EUDIW ecosystem.
40
40
41
-
-**ETSI ESI:**[ETSI ESI](https://www.etsi.org/committee/esi) is a European Standardization Organization (ESO) that creates technical standards and European Norms for electronic identity and signatures supporting the eIDAS regulation. ETSI ESI has published approximately 80 standards for QTSP conformity assessment, protocols and formats for digital signatures, as well as protocols and formats for the EUDI Wallet. ETSI ESI has also got the standardization request [STF 705](https://portal.etsi.org/STFs/ToR/ToR705_EUDIW-Stan-project_with_Annexes.docx) from the EU Commission to create and/or update several standards for the EUDI Wallet ecosystem.
42
-
-**CEN TC224:**[CEN Technical Committee 224 (TC224)](https://standards.cencenelec.eu/ords/f?p=205:7:::::FSP_ORG_ID:6205&cs=1F02AD409B602B96990A87E2638AAA212) is an ESO that has published several standards related to identification and devices with secure elements. More specifically, CEN TC224 WG17 are standardizing Common Criteria protection profiles of QSCD/WSCA, CEN TC224 WG18 are writing standards related to biometric solutions, whilst CEN TC224 WG20 are creating standards related to EUDI Wallet on-boarding and access control.
43
-
-**ISO/IEC:** ISO is an international standardization organization and International Electrotechnical Commission (IEC) develops international standards for electronic technologies. The international standardization activities related to digital identities are performed within [ISO/IEC Joint Technical Committee (JTC) 1](https://www.iso.org/committee/45020.html) "Information Security". More specifically, several ISO/IEC standards are applicable to Common Criteria certification, conformity assessment and evaluation of the EUDI Wallet solutions. Furthermore, ISO/IEC has standardized the mobile driving license (ISO mDL) in ISO 18013-5, which is a PID format for the EUDI Wallet.
44
-
-**IETF:** The Internet Engineering Task Force (IETF) create technical standards that comprise the internet protocol suites. More specifically, [IETF PKIX](https://datatracker.ietf.org/wg/pkix/about/) covers secure data exchanges and formats in the area of electronic signatures, PKI and trust services. Most notably, IETF has published standards for PKIX X.509 certificate and CRL profiles, OCSP, TLS and SD-JWT, which are relevant for the EUDI Wallet ecosystem. Furthermore, some of the IETF standards are used as basis by ETSI ESI, which have created European profiles of Qualified Certificates, AdES signature formats, SD-JWT VC, etc.
45
-
-**OpenID Foundation:** The [OpenID Foundation](https://openid.net/foundation/) is an industrial standardization organization that develops open standards for identity, federation and security. The following OpenID standards are relevant for the EUDIW technical architecture: OpenID Connect Core (OIDC), OpenID For Verifiable Credential Issuance (OID4VCI), OpenID For Verifiable Presentations (OID4VP), and OpenID High Assurance Interoperability Profile (HAIP). OID4VP, OID4VCI and HAIP are used as the foundation for the ETSI TS 119 472 standardization of EUDI Wallet protocols.
46
-
-**W3C:** The [World Wide Web Consortium (W3C)](https://www.w3.org/) is an international standardization organization. The following W3C standards are relevant to the EUDI Wallet technical architecture: W3C Verifiable Credentials Data Model, W3C Web Authentication (WebAuthn), and W3C Digital Credentials API. More specifically, the W3C Verifiable Credentials Data Model is referenced as basis for an ETSI TS 119 472 EAA profile.
47
-
-**Cloud Signature Consortium (CSC):** The [Cloud Signature Consortium (CSC)](https://cloudsignatureconsortium.org/) is an international standardization organization focusing on compliant digital signature creation in the cloud. The CSC specification "CSC API v2 - Architectures and protocols for remote signature applications" is referenced by the EUDI Wallet architecture and is used as basis for the ETSI TS 119 432 standard.
41
+
-**ETSI ESI:**[ETSI ESI](https://www.etsi.org/committee/esi) is a European Standardisation Organisation (ESO) that creates technical standards and European Norms for electronic identity and signatures supporting the eIDAS regulation. ETSI ESI has published approximately 80 standards for QTSP conformity assessment, protocols and formats for digital signatures, as well as protocols and formats for the EUDI Wallet. ETSI ESI has received the standardisation request [STF 705](https://portal.etsi.org/STFs/ToR/ToR705_EUDIW-Stan-project_with_Annexes.docx) from the EU Commission to create and/or update several standards for the EUDI Wallet ecosystem.
42
+
-**CEN TC224:**[CEN Technical Committee 224 (TC224)](https://standards.cencenelec.eu/ords/f?p=205:7:::::FSP_ORG_ID:6205&cs=1F02AD409B602B96990A87E2638AAA212) is an ESO that has published several standards related to identification and devices with secure elements. More specifically, CEN TC224 WG17 are standardizing Common Criteria protection profiles of QSCD/WSCA, CEN TC224 WG18 develop standards related to biometric solutions, whilst CEN TC224 WG20 are creating standards related to EUDI Wallet onboarding and access control.
43
+
-**ISO/IEC:** ISO is an international standardisation organisation and the International Electrotechnical Commission (IEC) develops international standards for electronic technologies. The international standardisation activities related to digital identities are performed within [ISO/IEC Joint Technical Committee (JTC) 1](https://www.iso.org/committee/45020.html) "Information Security". More specifically, several ISO/IEC standards are applicable to Common Criteria certification, conformity assessment and evaluation of the EUDI Wallet solutions. Furthermore, ISO/IEC has standardised the mobile driving license (ISO mDL) in ISO 18013-5, which is a PID format for the EUDI Wallet.
44
+
-**IETF:** The Internet Engineering Task Force (IETF) creates technical standards that comprise the internet protocol suites. More specifically, [IETF PKIX](https://datatracker.ietf.org/wg/pkix/about/) covers secure data exchanges and formats in the area of electronic signatures, PKI and trust services. Most notably, IETF has published standards for PKIX X.509 certificate and CRL profiles, OCSP, TLS and SD-JWT, which are relevant for the EUDI Wallet ecosystem. Furthermore, some of the IETF standards are used as basis by ETSI ESI, which have created European profiles of Qualified Certificates, AdES signature formats, SD-JWT VC, etc.
45
+
-**OpenID Foundation:** The [OpenID Foundation](https://openid.net/foundation/) is an industrial standardisation organisation that develops open standards for identity, federation and security. The following OpenID standards are relevant for the EUDIW technical architecture: OpenID Connect Core (OIDC), OpenID For Verifiable Credential Issuance (OID4VCI), OpenID For Verifiable Presentations (OID4VP), and OpenID High Assurance Interoperability Profile (HAIP). OID4VP, OID4VCI and HAIP are used as the foundation for the ETSI TS 119 472 standardisation of EUDI Wallet protocols.
46
+
-**W3C:** The [World Wide Web Consortium (W3C)](https://www.w3.org/) is an international standardisation organisation. The following W3C standards are relevant to the EUDI Wallet technical architecture: W3C Verifiable Credentials Data Model, W3C Web Authentication (WebAuthn), and W3C Digital Credentials API. More specifically, the W3C Verifiable Credentials Data Model is referenced as basis for an ETSI TS 119 472 EAA profile.
47
+
-**Cloud Signature Consortium (CSC):** The [Cloud Signature Consortium (CSC)](https://cloudsignatureconsortium.org/) is an international standardisation organisation focusing on compliant digital signature creation in the cloud. The CSC specification "CSC API v2 - Architectures and protocols for remote signature applications" is referenced by the EUDI Wallet architecture and is used as basis for the ETSI TS 119 432 standard.
48
48
49
-
In addition to the aforementioned standardization organizations, the [European Cybersecurity Agency (ENISA)](https://www.enisa.europa.eu/) is developing the [EUDI Wallet Certification Scheme](https://certification.enisa.europa.eu/browse-topic/eudi-wallet_en), which will be published as an implementing regulation under the Cybersecurity Act. The purpose of the EUDI Wallet Certification Scheme is to harmonize the national certifications of the EU Member States' EUDI Wallets.
49
+
In addition to the aforementioned standardisation organisations, the [European Cybersecurity Agency (ENISA)](https://www.enisa.europa.eu/) is developing the [EUDI Wallet Certification Scheme](https://certification.enisa.europa.eu/browse-topic/eudi-wallet_en), which will be published as an implementing regulation under the Cybersecurity Act. The purpose of the EUDI Wallet Certification Scheme is to harmonise the national certifications of the EU Member States' EUDI Wallets.
50
50
51
51
## The EBW Framework
52
52
@@ -62,7 +62,7 @@ The proposal also introduces a European Digital Directory maintained by the Comm
62
62
63
63
The regulation supports role-based access so that multiple authorised users can operate a wallet. It also enables secure data exchange between EBWs, EUDI Wallets and relying parties, while allowing additional functionalities provided that core features remain unaffected.
64
64
65
-
From a technical perspective, the framework promotes the use of common protocols for sharing attestations. It requires secure onboarding using eID with a Level of Assurance (LoA) of at least Substantial and mandates interoperability, secure communication interfaces, and mechanisms for validation and revocation. Further requirements will be defined in implementing acts.
65
+
From a technical perspective, the framework promotes the use of common protocols for sharing attestations. It requires secure onboarding using eID with a LoA of at least Substantial and mandates interoperability, secure communication interfaces, and mechanisms for validation and revocation. Further requirements will be defined in implementing acts.
66
66
67
67
Within WE BUILD, the proposed EBW framework is treated as a primary regulatory and architectural reference for business-focused identity and data exchange scenarios. Use case design and pilot activities align with the EBW model’s legal structure, interoperability requirements and trust-service framework, while taking forthcoming implementing acts into account.
0 commit comments