Skip to content

Commit e2e5cfe

Browse files
authored
Blueprint v1 last edits (#153)
1 parent be7849f commit e2e5cfe

4 files changed

Lines changed: 32 additions & 34 deletions

File tree

blueprint/01-executive-summary.md

Lines changed: 14 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ WE BUILD operates within the emerging EUDI and EBW ecosystem, but it is not the
1515

1616
In the final EUDI ecosystem, every EU citizen will receive an EUDI Wallet at Level of Assurance (LoA) High.
1717

18-
WE BUILD focuses in particular on the EBW - designed for economic operators to manage mandates, exchange trusted business documents such as electronic invoices, and receive legally valid notifications. Some EBW functions, such as onboarding and data portability, will operate at Level of Assurance (LoA) Substantial.
18+
WE BUILD focuses in particular on the EBW, designed for economic operators to manage mandates, exchange trusted business documents such as electronic invoices, and receive legally valid notifications. Some EBW functions, such as onboarding and data portability, will operate at LoA Substantial.
1919

2020
### Bridging ARF Gaps through Specifications and Testing
2121

@@ -27,38 +27,36 @@ To address these gaps, WE BUILD defines project-specific implementation rules th
2727

2828
In the final ecosystem, wallets and services must undergo formal certification by national supervisory bodies.
2929

30-
WE BUILD operates in a pilot setting but builds functional, interoperable software that is as close to production-ready as possible. Where relevant, later sections refer back to this pilot framework rather than repeating these distinctions.
31-
3230
| WE BUILD does not | WE BUILD does |
3331
|---------------|----------------|
34-
| certify EUDI wallets | provide WE BUILD wallets that pass the ITB |
35-
| rely on eIDAS-eID | provide WE BUILD-eID, with fictitious but realistic identities |
36-
| create eIDAS-qualified e-signatures | define WE BUILD-qualification of e-signatures, focusing on realistic technical interoperability |
37-
| use real MS registries | involve real public sector bodies where possible, and otherwise simulate them, always with fictitious registries |
32+
| certify EUDI wallets | provide WE BUILD wallets that pass ITB testing |
33+
| rely on eIDAS-eID | provide WE BUILD eID with fictitious but realistic identities |
34+
| create eIDAS-qualified e-signatures | define WE BUILD qualification of e-signatures focused on technical interoperability |
35+
| use real MS registries | use real public sector bodies where possible, otherwise simulate them using fictitious |
3836
| use the EC List of Trusted Lists (LoTL) | provide a WE BUILD LoTL |
39-
| use the MS Trusted lists (TL) | provide WE BUILD TLs, with feedback from real supervisory bodies if available |
37+
| use the MS Trusted lists (TL) | provide WE BUILD TLs with input from supervisory bodies where available |
4038
| reach production-level legal liability | operate within the WE BUILD agreement and trust framework, not within eIDAS |
41-
| deal with national policy-making | let the WP5 MS Forum indicate where alignment with national policy-making is advisable |
42-
| deal with universal definitions | assess how far WE BUILD semantics can go within the available timeframe |
39+
| deal with national policy-making | use the WP5 MS Forum to indicate alignment with national policy-making |
40+
| deal with universal definitions | define WE BUILD semantics within the available timeframe |
4341
| issue EUDIW-RP access certificates | issue WE BUILD RP access certificates |
44-
| issue eIDAS-QEAA | define WE BUILD-QEAA, focusing on realistic technical interoperability |
42+
| issue eIDAS-QEAA | define WE BUILD QEAA focused on technical interoperability |
4543

4644
## Work Package 4 (WP4) - General Capabilities
47-
WP4 provides the shared technical capabilities that enable the WE BUILD use cases. Our technical groups - Architecture, Semantics, Wallet Providers, PID & EBWOID Providers, Qualified Trust Service Providers (QTSP), Trust Registry Infrastructure, and Test Infrastructure exist solely to provide the engine that powers the use cases.
45+
The technical groups in WP4 - Architecture, Semantics, Wallet Providers, PID & EBWOID Providers, Qualified Trust Service Provider (QTSP), Trust Registry Infrastructure, and Test Infrastructure - provide the technical capabilities that support the use cases.
4846

4947
WP2 and WP3 use cases are expected to use the capabilities provided by WP4 rather than developing parallel technical solutions.
5048

5149
To ensure interoperability across participants, WE BUILD uses three levels of documentation:
5250

53-
1. This **Architecture & Integration Blueprint (D4.1)** the high-level architecture and system overview.
54-
2. [**Architectural Decision Records (ADR)**](https://github.com/webuild-consortium/wp4-architecture/tree/main/adr) explain major architecture decisions and the reasoning behind them.
55-
3. [**WE BUILD Conformance Specifications (WBCS)**](https://github.com/webuild-consortium/wp4-architecture/tree/main/conformance-specs) define the detailed technical requirements that implementations must follow.
51+
1. This **Architecture & Integration Blueprint (D4.1)** - the high-level architecture and system overview.
52+
2. [**Architectural Decision Records (ADR)**](https://github.com/webuild-consortium/wp4-architecture/tree/main/adr) - explains major architecture decisions and the reasoning behind them.
53+
3. [**WE BUILD Conformance Specifications (WBCS)**](https://github.com/webuild-consortium/wp4-architecture/tree/main/conformance-specs) – defines the detailed technical requirements that implementations must follow.
5654

5755
The governance process behind ADRs and WBCS, including how decisions are proposed and adopted, is described in Chapter 7.
5856

5957
The Interoperability Testbed (ITB) is a first step toward understanding conformity assessment requirements. In a controlled consortium environment, regulatory and technical specifications are translated into executable interoperability scenarios.
6058

61-
## How to get Started
59+
## Getting Started
6260
The Blueprint is the starting point for understanding how WE BUILD works.
6361

6462
- Technical teams should begin with the WBCS to implement their interfaces.

blueprint/02-regulatory-alignment.md

Lines changed: 14 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ The WE BUILD architecture aligns with two key regulatory instruments: [Regulatio
66

77
WE BUILD aligns with the legal and technical framework for EUDI wallets. Users can authenticate and present identity and attribute information while retaining control over what data is shared through selective disclosure and explicit consent.
88

9-
The amended eIDAS Regulation is supported by several implementing acts defining the technical and governance framework for the EUDI ecosystem, most importantly:
9+
The amended eIDAS Regulation is supported by several implementing acts defining the technical and governance framework for the EUDI Wallet ecosystem, most importantly:
1010

1111
**Core Wallet Architecture and Technical framework**
1212
- [2024/2979 – Integrity and core functionalities](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202402979)
@@ -30,23 +30,23 @@ The amended eIDAS Regulation is supported by several implementing acts defining
3030
- [2025/1570 – Notification of certified or cancelled QSCDs](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202501570)
3131
- [2025/1572 – QTSP initiation, notification and verification](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=OJ:L_202501572)
3232

33-
### Standardization and Technical Specifications
33+
### Standardisation and Technical Specifications
3434
The European Commission, together with the European Digital Identity Cooperation Group, has published:
3535

36-
- The [ARF](https://eudi.dev/latest/architecture-and-reference-framework-main/) specify main functionalities, roles and responsibilities, architecture and design principles, attestation formats and protocols, trust model, certification, and risk management of the EUDI Wallet ecosystem.
37-
- The [Technical Specifications](https://github.com/eu-digital-identity-wallet/eudi-doc-standards-and-technical-specifications/tree/main/docs/technical-specifications) specifies more technical details of selected topics derived from the ARF. The technical specifications describe various topics such as Relying Party registrations, zero-knowledge proofs, attestation rulebooks, schemas and catalogues.
36+
- The [ARF](https://eudi.dev/latest/architecture-and-reference-framework-main/) specifies main functionalities, roles and responsibilities, architecture and design principles, attestation formats and protocols, trust model, certification, and risk management of the EUDI Wallet ecosystem.
37+
- The [Technical Specifications](https://github.com/eu-digital-identity-wallet/eudi-doc-standards-and-technical-specifications/tree/main/docs/technical-specifications) specify more technical details of selected topics derived from the ARF. The technical specifications describe various topics such as Relying Party registration, zero-knowledge proofs, attestation rulebooks, schemas and catalogues.
3838

39-
Furthermore, there are several standardization organizations that contribute with standards for the EUDIW ecosystem.
39+
Furthermore, there are several standardisation organisations that contribute with standards for the EUDIW ecosystem.
4040

41-
- **ETSI ESI:** [ETSI ESI](https://www.etsi.org/committee/esi) is a European Standardization Organization (ESO) that creates technical standards and European Norms for electronic identity and signatures supporting the eIDAS regulation. ETSI ESI has published approximately 80 standards for QTSP conformity assessment, protocols and formats for digital signatures, as well as protocols and formats for the EUDI Wallet. ETSI ESI has also got the standardization request [STF 705](https://portal.etsi.org/STFs/ToR/ToR705_EUDIW-Stan-project_with_Annexes.docx) from the EU Commission to create and/or update several standards for the EUDI Wallet ecosystem.
42-
- **CEN TC224:** [CEN Technical Committee 224 (TC224)](https://standards.cencenelec.eu/ords/f?p=205:7:::::FSP_ORG_ID:6205&cs=1F02AD409B602B96990A87E2638AAA212) is an ESO that has published several standards related to identification and devices with secure elements. More specifically, CEN TC224 WG17 are standardizing Common Criteria protection profiles of QSCD/WSCA, CEN TC224 WG18 are writing standards related to biometric solutions, whilst CEN TC224 WG20 are creating standards related to EUDI Wallet on-boarding and access control.
43-
- **ISO/IEC:** ISO is an international standardization organization and International Electrotechnical Commission (IEC) develops international standards for electronic technologies. The international standardization activities related to digital identities are performed within [ISO/IEC Joint Technical Committee (JTC) 1](https://www.iso.org/committee/45020.html) "Information Security". More specifically, several ISO/IEC standards are applicable to Common Criteria certification, conformity assessment and evaluation of the EUDI Wallet solutions. Furthermore, ISO/IEC has standardized the mobile driving license (ISO mDL) in ISO 18013-5, which is a PID format for the EUDI Wallet.
44-
- **IETF:** The Internet Engineering Task Force (IETF) create technical standards that comprise the internet protocol suites. More specifically, [IETF PKIX](https://datatracker.ietf.org/wg/pkix/about/) covers secure data exchanges and formats in the area of electronic signatures, PKI and trust services. Most notably, IETF has published standards for PKIX X.509 certificate and CRL profiles, OCSP, TLS and SD-JWT, which are relevant for the EUDI Wallet ecosystem. Furthermore, some of the IETF standards are used as basis by ETSI ESI, which have created European profiles of Qualified Certificates, AdES signature formats, SD-JWT VC, etc.
45-
- **OpenID Foundation:** The [OpenID Foundation](https://openid.net/foundation/) is an industrial standardization organization that develops open standards for identity, federation and security. The following OpenID standards are relevant for the EUDIW technical architecture: OpenID Connect Core (OIDC), OpenID For Verifiable Credential Issuance (OID4VCI), OpenID For Verifiable Presentations (OID4VP), and OpenID High Assurance Interoperability Profile (HAIP). OID4VP, OID4VCI and HAIP are used as the foundation for the ETSI TS 119 472 standardization of EUDI Wallet protocols.
46-
- **W3C:** The [World Wide Web Consortium (W3C)](https://www.w3.org/) is an international standardization organization. The following W3C standards are relevant to the EUDI Wallet technical architecture: W3C Verifiable Credentials Data Model, W3C Web Authentication (WebAuthn), and W3C Digital Credentials API. More specifically, the W3C Verifiable Credentials Data Model is referenced as basis for an ETSI TS 119 472 EAA profile.
47-
- **Cloud Signature Consortium (CSC):** The [Cloud Signature Consortium (CSC)](https://cloudsignatureconsortium.org/) is an international standardization organization focusing on compliant digital signature creation in the cloud. The CSC specification "CSC API v2 - Architectures and protocols for remote signature applications" is referenced by the EUDI Wallet architecture and is used as basis for the ETSI TS 119 432 standard.
41+
- **ETSI ESI:** [ETSI ESI](https://www.etsi.org/committee/esi) is a European Standardisation Organisation (ESO) that creates technical standards and European Norms for electronic identity and signatures supporting the eIDAS regulation. ETSI ESI has published approximately 80 standards for QTSP conformity assessment, protocols and formats for digital signatures, as well as protocols and formats for the EUDI Wallet. ETSI ESI has received the standardisation request [STF 705](https://portal.etsi.org/STFs/ToR/ToR705_EUDIW-Stan-project_with_Annexes.docx) from the EU Commission to create and/or update several standards for the EUDI Wallet ecosystem.
42+
- **CEN TC224:** [CEN Technical Committee 224 (TC224)](https://standards.cencenelec.eu/ords/f?p=205:7:::::FSP_ORG_ID:6205&cs=1F02AD409B602B96990A87E2638AAA212) is an ESO that has published several standards related to identification and devices with secure elements. More specifically, CEN TC224 WG17 are standardizing Common Criteria protection profiles of QSCD/WSCA, CEN TC224 WG18 develop standards related to biometric solutions, whilst CEN TC224 WG20 are creating standards related to EUDI Wallet onboarding and access control.
43+
- **ISO/IEC:** ISO is an international standardisation organisation and the International Electrotechnical Commission (IEC) develops international standards for electronic technologies. The international standardisation activities related to digital identities are performed within [ISO/IEC Joint Technical Committee (JTC) 1](https://www.iso.org/committee/45020.html) "Information Security". More specifically, several ISO/IEC standards are applicable to Common Criteria certification, conformity assessment and evaluation of the EUDI Wallet solutions. Furthermore, ISO/IEC has standardised the mobile driving license (ISO mDL) in ISO 18013-5, which is a PID format for the EUDI Wallet.
44+
- **IETF:** The Internet Engineering Task Force (IETF) creates technical standards that comprise the internet protocol suites. More specifically, [IETF PKIX](https://datatracker.ietf.org/wg/pkix/about/) covers secure data exchanges and formats in the area of electronic signatures, PKI and trust services. Most notably, IETF has published standards for PKIX X.509 certificate and CRL profiles, OCSP, TLS and SD-JWT, which are relevant for the EUDI Wallet ecosystem. Furthermore, some of the IETF standards are used as basis by ETSI ESI, which have created European profiles of Qualified Certificates, AdES signature formats, SD-JWT VC, etc.
45+
- **OpenID Foundation:** The [OpenID Foundation](https://openid.net/foundation/) is an industrial standardisation organisation that develops open standards for identity, federation and security. The following OpenID standards are relevant for the EUDIW technical architecture: OpenID Connect Core (OIDC), OpenID For Verifiable Credential Issuance (OID4VCI), OpenID For Verifiable Presentations (OID4VP), and OpenID High Assurance Interoperability Profile (HAIP). OID4VP, OID4VCI and HAIP are used as the foundation for the ETSI TS 119 472 standardisation of EUDI Wallet protocols.
46+
- **W3C:** The [World Wide Web Consortium (W3C)](https://www.w3.org/) is an international standardisation organisation. The following W3C standards are relevant to the EUDI Wallet technical architecture: W3C Verifiable Credentials Data Model, W3C Web Authentication (WebAuthn), and W3C Digital Credentials API. More specifically, the W3C Verifiable Credentials Data Model is referenced as basis for an ETSI TS 119 472 EAA profile.
47+
- **Cloud Signature Consortium (CSC):** The [Cloud Signature Consortium (CSC)](https://cloudsignatureconsortium.org/) is an international standardisation organisation focusing on compliant digital signature creation in the cloud. The CSC specification "CSC API v2 - Architectures and protocols for remote signature applications" is referenced by the EUDI Wallet architecture and is used as basis for the ETSI TS 119 432 standard.
4848

49-
In addition to the aforementioned standardization organizations, the [European Cybersecurity Agency (ENISA)](https://www.enisa.europa.eu/) is developing the [EUDI Wallet Certification Scheme](https://certification.enisa.europa.eu/browse-topic/eudi-wallet_en), which will be published as an implementing regulation under the Cybersecurity Act. The purpose of the EUDI Wallet Certification Scheme is to harmonize the national certifications of the EU Member States' EUDI Wallets.
49+
In addition to the aforementioned standardisation organisations, the [European Cybersecurity Agency (ENISA)](https://www.enisa.europa.eu/) is developing the [EUDI Wallet Certification Scheme](https://certification.enisa.europa.eu/browse-topic/eudi-wallet_en), which will be published as an implementing regulation under the Cybersecurity Act. The purpose of the EUDI Wallet Certification Scheme is to harmonise the national certifications of the EU Member States' EUDI Wallets.
5050

5151
## The EBW Framework
5252

@@ -62,7 +62,7 @@ The proposal also introduces a European Digital Directory maintained by the Comm
6262

6363
The regulation supports role-based access so that multiple authorised users can operate a wallet. It also enables secure data exchange between EBWs, EUDI Wallets and relying parties, while allowing additional functionalities provided that core features remain unaffected.
6464

65-
From a technical perspective, the framework promotes the use of common protocols for sharing attestations. It requires secure onboarding using eID with a Level of Assurance (LoA) of at least Substantial and mandates interoperability, secure communication interfaces, and mechanisms for validation and revocation. Further requirements will be defined in implementing acts.
65+
From a technical perspective, the framework promotes the use of common protocols for sharing attestations. It requires secure onboarding using eID with a LoA of at least Substantial and mandates interoperability, secure communication interfaces, and mechanisms for validation and revocation. Further requirements will be defined in implementing acts.
6666

6767
Within WE BUILD, the proposed EBW framework is treated as a primary regulatory and architectural reference for business-focused identity and data exchange scenarios. Use case design and pilot activities align with the EBW model’s legal structure, interoperability requirements and trust-service framework, while taking forthcoming implementing acts into account.
6868

blueprint/03-architecture-overview.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ While the previous chapter describes the regulatory and architectural frameworks
55

66
- **Interoperability:** Wallet providers, issuers and verifiers interact across organisational and national boundaries.
77
- **Reusability:** The architecture builds on existing EU digital infrastructure and results from previous Large Scale Pilots.
8-
- **Security by design:**Security controls are integrated into the architecture from the start.
8+
- **Security by design:** Security controls are integrated into the architecture from the start.
99
- **Privacy by design:** Users retain control over personal and organisational data through selective disclosure and explicit consent.
1010

1111
## The Ecosystem at a Glance

0 commit comments

Comments
 (0)