The EUDI Wallet is accelerating a shift in how digital identity is presented and verified: cryptographic proof replaces data sharing, consent becomes explicit, and verification becomes reusable across borders and services. The challenge for most organisations is not whether wallets matter, but how to make them work reliably in production — across channels, devices, jurisdictions, assurance levels, and evolving trust requirements.
Jonathan Care, Lead Analyst at KuppingerCole Analysts, will outline how organisations can operationalise the EUDI Wallet, highlighting practical considerations around cryptographic proofs, selective disclosure, and the need for trust frameworks that are ready for a post‑quantum future. Joining him are Michael Jones and Simon Rodway, who will expand on how wallet interactions can be smoothly integrated into existing enterprise identity, compliance, and fraud‑management environments, helping organisations navigate the shift from centralised to decentralised identity models. They are complemented by Bryant Nielson and Derrick Sturisky, whose work at the Quantum Core Institute brings additional depth on preparing identity infrastructures for quantum‑resilient security, ensuring long‑term robustness in an evolving threat landscape.
Good morning, good afternoon, good evening, wherever you are, and thank you for joining us on the Road to EIC. Today we have From Mandate to Market Share. Many thanks to our sponsors, Ditto, you can see them at ditto.id, and with me today I have Derrick L.
Sturisky, I have Dr. Michael B.
Jones, and from Ditto I have Simon Rodnard. Gentlemen, we'd like to introduce ourselves.
Derrick, please go first. Thank you. Good morning, good afternoon, and good evening, a real pleasure to be here, and Jonathan, thank you to you and your colleagues for this opportunity to spend some time with you this morning. My name is Derrick Sturisky, I'm originally from South Africa, you may pick up a slight accent, but I've been in the U.S.
for the past 30 years, I'm based in Atlanta, I've been a management consultant most of my career, I spent time at PwC and Accenture, I was with Decatur Pharmaceuticals, I was also with the Quantum Startup, and I'm now a university professor and an independent consultant. A real pleasure to be with you. Thank you.
Michael, would you go ahead and introduce yourself?
Sure, I'm Mike Jones, I have been working on building the Internet's missing identity layer since 2005 with others, I have produced a number of standards that have gotten used, including OpenID Connect and the JSON Web Token, I've worked on WebAuthn, FIDO2, WebCrypto, a number of other things, I worked on a system that didn't get used in the end called Information Cards with Kim Cameron that nonetheless was a digital wallet with identities that you control, but that was 20 years ago, but you know some good ideas do come back, so I'm looking forward to talking with you. Excellent, thank you.
And last but not least, Simon from Ditto, welcome. Welcome everybody, so just a quick note, fraud is no longer just a financial crime problem, I think we all accept that, it's becoming an identity infrastructure problem, and Michael will be able to talk at length I'm sure about that in a moment.
In the UK, fraud represented 45% of all crime recorded last year up to September, that's up from 41% the year before, it's still a huge number, but that means almost half of recorded crime is now exploiting trust, identity, and digital interactions. I'm Simon Rodway, Global Head of Solution Consulting here at Ditto, and really my role sits in that intersection between product, technology, sales, and customer engagements.
I work with our clients and partners to understand their identity, authentication, and fraud challenges, and help to translate that into something that is practical, it's a solution that a design that works both commercially and practically for their outcomes. Thank you. Well thank you all, and well I think the first thing, but building on from that, is where we are with implementation.
I think the regulations exist, and the question for me is whether reality is actually keeping up, and I'd like to get into where member states generally are with EUDI wallet rollout versus what the press releases say, and what's causing the delays when they exist. Beyond Europe, other regions are moving on their own wallet initiatives, and so it's worth asking whether we're heading towards a connected global ecosystem or a patchwork of incompatible systems.
And so I guess the first question, since I've got a panel of experts here, which country do you think is furthest ahead in actual deployment, not just policy, and what's made the difference? Derek, you'd like to go first.
Yes, I would. Jonathan, thank you. Let me give a slightly different perspective on the answer. Here in the US, just about everybody uses Apple wallet. There is no government mandated or government backed digital wallet like there is in the EU. The core difference, of course, is the Apple wallet relies on hardware trust within a proprietary ecosystem within the Apple ecosystem, and the EUDI wallet relies on legal and cryptographic trust within the regulated public framework. So there are core differences between Apple wallet and the EUDI wallet, of course.
The Apple wallet is, as any of you who've used it before, best for simple, secure, everyday use if you have Apple devices. If you don't have an Apple device, then of course it's a little harder to use. The security of the Apple wallet is impressive.
I mean, most of the people that I know, myself included, of course, use the Apple wallet here. It's got hardware level security, very impressive, isolates encrypted credentials in the hardware itself. It's tamper resistant. Biometric authentication, everybody uses their face ID to authenticate. That is stored on the device, similar to the EUDI, of course. It's not backed up to the cloud. Apple cannot track where you buy, what you buy, any of your transactions. Purchase history is not used for advertising, which is maybe a surprise.
And again, it relies on Apple's proprietary ecosystem. So here in the States, most people with Apple devices use the Apple wallet. The EUDI wallet, of course, is a little different. It's governed by the RDS 2.0 regulation. It's a legally binding EUI framework.
It uses, as a security professional, I'm very impressed with the security architecture. It uses advanced cryptographic encryption with safeguards preventing secrets from being exported outside of the wallet. It supports zero knowledge proof, which I don't believe Apple does, which is a fascinating concept where you could verify facts, such as your age or account balance, without actually sharing your age or your account balance. The wallet's got selective disclosure.
Again, as a security professional, this is very important, which ensures that the minimum required data is shared at any given point in time. Right. So it sounds like score one for the corporate state is Apple, and driven, obviously, by a desire to sustain and grow profit share.
Simon, what's your view? I think if we're going to look specifically at EUDI, EID, and the technology that the European Union are driving, we can look at, obviously, certain countries, Germany, France, Italy, have launched wallets. They've got their own wallet technology out there. The adoption is relatively low. It's relatively unused.
However, if you look at national ID schemes or identity services, just take Spain. I'm currently in Barcelona at the moment, and here in Spain, they've launched their MNDNI application, and it's the highest downloaded application on the app store in Spain at the moment. There are millions of downloads for that app for identity already. They're already starting to make significant progress in the identity space, and we're starting to see across Europe, because of EUDI and the adoption requirements for this year and next year, we're starting to see progress. Would I call it significant progress?
I think there's certain improvements that can be made, but we're certainly seeing the take-up of wallets and tokenization and the security around it making great progress. And certainly, countries like Spain, even the Netherlands and Finland, who've had national ID schemes for quite a while, are also making good progress and inroads. I think that's probably the key from a European perspective, but then you start to look at other countries. India is a good example. They're making huge progress in identity schemes, and India is ahead on scale and document wallet adoption globally.
I mean, the adoption factors that they've got are phenomenal numbers. So we are seeing an EU-style selective disclosure policy prevention identity architecture being rolled out across India, and certainly I expect other countries, Canada possibly being one, to start to take similar programs and start to adopt in similar ways.
I mean, we could go around the countries of the world. They've all, everything, everybody has got a desire to try and improve identity. And in reality, from a Ditto perspective, we see this more as a trust problem, and we've got very much government-led initiatives that are trying to solve this. Dare I say it, the UK, from where I'm actually from, have probably made the poorest attempt at trying to solve this with recent endeavors. But I think we'll definitely see a more cohesive joined-up-and-together process evolving over the next two years.
I, yes, before I left the UK to move to semi-acclined, I discovered, or I opined to some senior civil servants that their digital identity attempts were never going to work. So far, I have not been proved wrong. It's interesting, and we do see, as you're saying, we've seen, obviously, Estonia has, you know, for a long time made a digital citizenship and digital government possible.
Actually, I've seen Ukraine, despite the things that they're going on, have this capability. I guess, Michael, if I could turn to you. The timeline that we see for things like EIDAS 2.0, is it realistic? Or are we going to have a conversation in 2027, all four of us, about why it slipped?
Well, the timeline, I mean, certainly, I have many friends working in the different EDI wallet initiatives in Italy, in the Netherlands, in Germany, in Finland. And, you know, they're watching with dismay as new implementing acts come out that are different than the previous ones, that contain specs that the previous ones didn't. And there's legal mandates to do things that weren't anticipated.
You know, any development manager will tell you that if you throw requirements into a project at the last minute, the results will not necessarily be what you want. So, yeah, I think in 2027 at AIC, there'll be lots of interesting retrospectives and potentially horror stories about what worked and what didn't, and why. I'm going to take a standards perspective on the question of, will we have globally interoperable digital wallet infrastructure? Because I work on standards. I've worked on some of the standards used in this case.
And as one of my fellow panelists said, it all becomes to be about trust. The European regulations require that relying parties or verifiers have EU-issued qualified certificates to prove that they're eligible to receive the EU personal identity documents, the PIDs. And if you don't have that, you can't receive one.
But, you know, I had a conversation two years ago at AIC with some of the European regulators about this. So, you know, let's imagine that the EU wallets wildly succeed. And I wish them that. All of a sudden, you'll have people in Portugal that have gotten used to using their digital identities in Spain, in Germany, in Estonia, and Finland. And they will imagine that they can use it in other places, like the UK and Canada and Singapore and Botswana. And it just is not allowed. And I asked, you know, how are you going to solve that?
And at the time, the answer was, well, we could set up PKI trust bridges. Well, the world is littered with the corpses of attempts at PKI trust bridges. There's other ways of establishing trust, but they've not been incorporated.
So, you know, I think the EU answer is going to be some of it's going to work by the end of the year. Will it work in Canada? No. It's not even a design goal for it to work in Canada. And that's very, it's very interesting. And as you say, I think, even though I, you know, I tell people I left the UK fleeing persecution, but it actually to avoid being compared with Botswana. But anyway, the turning to the standards, and there are many of them, ISO MDL, W3C variable credentials, SDJWT. And they're not just technical footnotes.
These are, you know, significant bodies of work with real consequences for whether wallets from different economies will ever talk to each other. Mike, you just made a very valid point about, you know, the, yeah, it's a very dismal future, if you say, well, yes, we'll have trust bridges between them, whether PKI or other. And so I got a genuine question, whether standards bodies are converging, or whether we'll see competitive interest keeping this debate a lifelong it needs to be.
And if you're operating, and you're an organization operating across multiple jurisdictions, like Derek, you mentioned Apple earlier, who, as you say, have led with innovation, and waited for the legislation and standards catch up, whereas in Europe, we lead with legislation and wait for the innovation to catch up. And it's not abstract. And obviously, people are trying to make procurement decisions. And obviously, you know, your, and these can be your clients, and Derek, and your client, Simon, I imagine. And they are, you know, these are the affecting their procurement decisions.
And I guess, honestly, and without any, without any side humor at all, are we going to get to a single dominant credential format? Or are we just building new interoperability problems? And I don't think it's anyone here, but who has got the power to force convergence, or do rely on market forces, and dominant players to just sort it out, they to lead, lead from the front end and go, okay, that's where we're going.
And Simon, have you got a view? It's a very interesting question. It's one that is quite a difficult question to give a direct answer to, but let me give it a try. One of the things that we've definitely seen, and we've, if you look back over history, and especially within IT, we've endeavored at every point in the milestone markers of technology to establish a standard on which we build. We have endeavored to set out a framework on which we stand. And if you go back to the very beginning of life, in terms of IT, we set out a network protocol, and we built that in layers.
And we said, we stand on this next layer, we stand on this layer, level four, level seven, et cetera, et cetera. We end up with TCP IP, then we end up with protocols on top of that, to actually stand on the shoulders of the giants that we've gone before us. We bring that into the identity world, and I think if you consider that carefully, we've done the same here. We've came up with a particular protocol around which we can manage identity, and we've built a W3C standard for it. We've set that out, and we've said, right, here we go.
And then we've discovered that that falls apart because it's got problems, it's got security problems. So we establish a new standard. We're now up to OpenID for VC, so the Verifiable Credentials standard, which has got a W3C backing. Will that be the silver bullet that solves everything? Absolutely not, because what will happen is things will evolve, and it will grow. Anything that stands still in this world becomes obsolete very, very quickly. And I think anything that is written down in that regard, we need to be cognizant of.
What I would say, though, is with these standards, they're relevant, and their relevance will live long. As we know with the network protocols that we use today, TCP IP is going to live long. And we know for certain standards that we can stand on them with a level of assurance. I think with OpenID for VC, it's got the framework, the backbone for what will form a solid standard for us to work with for the next forthcoming five to ten years, would be my guess.
And the challenge that we as technologists need to also be cognizant of is we design things from a point of knowledge, knowing what we know. There's a lot within this identity and trust program that we still don't know. And we see that. We've got in the press in the last few weeks, we've got AI engines that are now finding flaws and weaknesses in security systems that have been there for 20 years. And yet we didn't know about it. And now there are systems out there that can find those problems. Do we think from an identity perspective, we're not going to face that problem? Of course we're not.
But what we can do is we can prepare for that. We can design with that in mind. And this is where things like identity systems that require us to store PII, personally identifiable information, we should abandon them as quick as possible. Because anything that requires store, in my view, becomes a risk. Because that's a harvest now and decrypt later. That's a repository for the fraudsters and the criminals to go and collect today and have some great fun and make lots of money out of it. Your and mine expense in the months to come.
And I know Derek can speak at great lengths to that in terms of post-quantum cryptography. But I guess my view, just to be brief, as brief as I possibly can, many of the underlying processes that remain rooted in the movement and replication of sensitive personal data across multiple systems, operational teams and third-party providers, each additional touchpoint within an identity ecosystem that these standards require. So what Michael was referring to as trust layers with certificate exchanges, etc.
Each one of those elements that require us to pass things on become another vulnerability point in the ecosystem. We've got to stop and think about how do we design these systems so we don't have to do that. We don't have to share that data. And if there can be a standard that basically establishes a recognised verifiable credential that can be universally understood, then we're at the framework point of establishing trust. I think you're right. I had horror when I was invited to speak, actually give evidence at the House of Lords in the UK, the age identity.
Which is pretty much, you summed up my response actually. Ideas like, you know, we'll take snapshots of people's faces and store them in a database. And don't worry, our big blue system integrator told us it will be okay. Which is nice to hear.
But Derek, I mean, as Simon said, you obviously got a view on this. I'm very interested to hear what that is. Thank you.
Yes, I can only answer this from the security perspective. And I'll attempt to do so.
Look, Europe is building the most ambitious digital identity infrastructure in history. And as somebody who spent their entire career in security, my professional instinct when I see technological ambition like this is, especially at this scale and at this speed, December is the deadline, theoretically is the deadline, is cautious optimism. You're right, we may be having some retroactive conversations in 2027 at ERC. And by the way, I'd welcome anybody on this call. I will be at ERC this year in 26. I look forward to hopefully meeting many of you.
But yes, so cautious optimism from the security perspective. The wallet will carry the verified identity of up to 450 million citizens, national ID, health insurance information, professional qualifications on the consumer smartphone.
Now, I will say that the wallet is built on the architecture and reference framework, which is I've looked at it in detail. It's a serious, robust, credible framework. Credible engineering went into that framework.
However, the framework and the 450 million live wallets lie across 27 member state implementations, thousands of participants in the ecosystem. And I think this is something we don't really talk about enough, who the participants in the ecosystem are. Not just the citizen, of course, it's not just the government, of course, but there's a whole host of other participants.
As was alluded to earlier about Simon, the post-quantum cryptographic transition, something I'm a security guy, but I'm specifically a quantum security guy, is something that is to me an impending catastrophic problem, catastrophic risk for the wallet and for all cryptography. And of course, there's the political deadline we deal with, as mentioned, December of this year. But I do want to, again, from an optimistic perspective, emphasize the digital sovereignty means that the user is the one who holds the master key.
This is not like an individual citizen's all the information is stored in the cloud somewhere. Theoretically, at least, the user holds the master key. The price of this freedom is the responsibility of managing the key, managing your own device, much like you and I manage our physical wallets. We've got to be responsible for our physical wallets. We can't leave our physical wallet in a coffee shop, for example. So there is a responsibility that comes with this freedom and this flexibility, of course.
The wallet has rich functionality, significant utility, but there are important security and privacy questions which need to be asked and answered. And Jonathan, if you'd like, I can go into some of the main threats, but perhaps let me pause there for a moment.
I think, yes, I would, but let's move that further down the conversation. I want to give Mike the opportunity to speak. Absolutely. Sure.
I mean, I agree that the post-quantum cryptography is going to be an event. We just don't know when. I submitted a presentation with the somewhat cheeky title, The Post-Quantum Apocalypse Is Already With Us, and I'll talk about what actions people need to take today or start planning for today and why. I'm going to return to a question from 10 minutes ago, taking the standards approach again. The question was asked, are we going to have a single credential format standard, or is it going to be different ones in different places? And I will say I know some things about this space, too.
I was an editor on the W3C Verifiable Credentials Standard. I worked on the SDJOT standard. I did not work on the ISO MDOC, but I'm quite familiar with it. There are certainly use cases where regulatory and commercial authorities already mandate a particular format.
So, if you get a Mebles driver's license in the United States, it is an MDOC. And the European PIDs are mandated to be in MDOC and other formats. The digital passports are going to be in MDOC format.
So, for high validation or for high assurance, government issued identities, I think MDOCs have already won. You know, how that plays out over time, we will see, but you won't go wrong by implementing and accepting the MDOC format. I think it's clunky. I think it's not how I would have done it, but sometimes there's a standard that wins is not the most elegant one, which is fine. I think W3C Verifiable Credentials have a self-inflicted wound, which is JSON-LD, that developers get wrong demonstrably all the time.
And so, it's not actually going to be interoperable, even though there's people who are adherents of that for kind of philosophical reasons. I think the W3C Verifiable Credential standard in most application uses is not going to win.
Now, SDJOT tries to be a JSON-based format that will or does enable selective disclosure, just like MDOCs do, but a little simpler. I mean, engineering-wise, I like it better, but it's not clear. Having multiple formats is going to help interoperability long-term, so we'll see how that shakes out. It's also the case that there's multiple credential transport formats, and that that battle is not won. ISO produced some both for in-person and for online presentation that are different than the OpenID for VP and OpenID for VC that I worked on.
And, you know, different jurisdictions and different use cases are using those. So, I think it is the case that a lot of stuff will shake out, I think it is the case that a lot of stuff will shake out in the marketplace in the coming years, and that future is not yet written. To the much earlier point about, quote, everybody's using the Apple Wallet, well, if you have an iPhone and you're using one of the use cases that it supports, yes, then some people are doing that, but, you know, I have a Google phone, I use the Google Wallet, but mostly just for payment.
It's not an identity system right now, or it's not generally used for identity credentials. I know that Apple has rolled out a derived credential for the passport for proof of age. That's a kind of innovation. Is it all standards-based? Will people accept it?
I think, you know, it's a market question. It depends.
So, you know, we have a patchwork of stuff. We're at the first 1% at best of the ecosystems rolling out for digital identity wallets and uses of them online.
So, we'll see what happens. Well, thank you. And I think you allow me to segue on to my next question. Is it real? Is there a real business case, or are we, as so often happens in cybersecurity, you know, just complying? Is it just compliance of driving this? You mentioned a good point that, as you say, Apple has defined what you can do in the Apple way.
And, as you say, when their wallet first came out, it was a payment extension to iTunes. And now you say it's identity, it can read NFC documents and so on.
Well, we do see, I think, in covering a cold that most organizations are approaching wallets as a regulatory obligation. A smaller number are seeing genuine commercial levels. Reduce onboarding friction, every bank tells me they like. Reduce data portability plays, which, again, for me, as obviously in a foreign – living in a foreign country, I appreciate from a healthcare point of view.
And, of course, better customer trust. It's easier to trust a customer the more you know about them, but you don't want to, as they slurp all their data at the outset, because that's invasive, intrusive, and so on. I think the gap between these two camps are interesting, regulatory versus genuine commercial upsides. And there's the relying party problem.
So, even if wallets are well-designed – and, Derek, I liked your description earlier when you were saying, actually, there's this large, complex edifice, and we're all staring at it in wonder and wondering which brick is going to fall first. But if wallets are well-designed, they only work if organizations accepting credentials have actually integrated them. And I see that side of the market moving slowly.
So, here's my challenge to the panel today. Can anyone point to a wallet deployment that delivered actual business value, not just compliance?
And, if so, tell me what makes it work. What's the use case that gets ordinary consumers like me, like my 85-year-old mother in South Wales, to install and use a wallet? Who wants to take that? Derek? My perspective, my personal perspective, is don't underestimate technology's adoption, independent of the regulatory environment. Look at any young person, teenager, early 20s, they live on their phones, on their devices, and that's just almost a cultural phenomenon, that they don't want to deal with paper, old-fashioned, old-school documentation.
So, I wouldn't underestimate that it will be extremely – now, it may take a while, and the regulations can encourage it, to use a pretty benign term along the way, but I wouldn't rule against, I wouldn't bet against widespread adoption over the course of the next three to five to ten years of something like the wallet, for two key reasons. One is a frictionless – you mentioned, Jonathan, you mentioned onboarding. You open up a bank account relative to my home country of South Africa, where I grew up.
I mean, you can open a bank account sitting on safari in the middle of the bush on your phone, through remote biometric authentication and other authentication methods, so that's – although that is the – one of the weak links in the wallet is the onboarding, and that's where there's typically more friction, as opposed to just using it for day-to-day transactions. But I wouldn't bet against widespread adoption in the future. Like all of – I teach a class to undergrads, like all of technology, like going back to the typewriter.
My first computer was a Sinclair ZX80, someone you may remember back in the day, and Jonathan, you too, and then we moved on to the 81, and it's just a progression of technological advancement. I give a talk on Moore's Law and the – just the rate of change of technology and technology advancement, it is unstoppable. It is absolutely unstoppable, and as I say, once we can address the frictionless imperative and also provide the security assurance that what we're doing is secure, then I think, yes, widespread adoption is ultimately a foregone conclusion. Good to know.
Simon, what's your view? I think it will depend on how we define wallet. If we look at implementations of – let's call them wallet-like solutions. So Singapore has got MyInfo, which is a wallet app that has significant usage across Singapore. India with their DigiLocker. We've got Nordics and Bank ID. Bank ID has been around for quite a while. When they switched from SIM to eSIM, it became a wallet in nature. It operates like a wallet. It behaves like a wallet. It's a full identity scheme, and they have returned huge financial value in terms of their applications.
And if you look at MyInfo, the Singapore SingPass MyInfo, they saw with that implementation an 80 percent reduction in transaction time. So they're seeing significant benefit to the end consumer by using the app, using the wallet, and seeing financial benefits. But if you expand the concept of a wallet and you think about what we mentioned earlier about young people of today spend a disproportionate amount of time on their device, and they use that for everything. That's been under no delusion. That means I'm a young person because I spend the same amount of time on my phone, and I use this.
I don't take my wallet. I take this, and everywhere I go, I use this to pay. Fantastic. More importantly, all of my loyalty schemes, so my favorite coffee shop, my favorite airline, whatever that might be, I have within my wallet a token that authenticates me to them so I can actually take the benefits of that particular scheme. That actually gives me significant benefits as a frictionless, easy-to-use solution. But equally, I know they're speaking to a fairly well-known coffee retail store in terms of their wallet use.
They get significant information from that in terms of customer loyalty, customer products that people buy, cross-sells, up-sells, and benefits so that they can make sure that they can maintain their customer portfolio. Now, if we look into the future of where this could go in terms of wallets, et cetera, then this starts to open up some very lucrative financial opportunities, especially if you think about loyalty. What about the use case where one, let's say one coffee store wants to entice somebody from another coffee store?
If you've got interoperability, if you've got a verified credential that says, I'm a loyal member of coffee store S and I want to go to coffee store C, coffee store C can say, well, if you can show to me that you are a loyal member of coffee store S, we'll give you a free coffee. Okay, today I could rock up with a plastic card. That doesn't mean I go there at all. It's got no information about it, but my token I could use to say, I buy coffee at coffee store S once a week. And therefore, coffee store C might say, hey, come and try our coffee instead.
That then starts to build an ecosystem where you can actually build value and you can build some very interesting yet to be kind of realized use cases. Interesting.
I mean, so there's a couple of questions actually that I, and thank you for those of you putting questions into the questions tab. I'm going to draw on a couple of those because it actually leads on to one of my interests is what happens to those who left behind. Mark has asked us, the underlying premise of the EUD and I relied on a smart device.
You said, yeah, Android phone, Apple phone. What are the options for the lowest denominators? So someone who just has a good old fashioned flip phone or someone just plain can't afford a device or service capable of supporting EUDI. Maybe they have a very basic 10 Euro device from the local bodega. What do we think about that? How do we deal with those who could get left behind? Who wants to take that one? Because that's the hot potato. I'll let you all volunteer there.
Derek, Michael, have any thoughts? So one of my clients is the Cirrus Foundation that's produced a cloud-based wallet that actually was one of the winners of the German wallet competition. And it's exactly cloud-based so that there's a set of the population that doesn't have to have a smart device to carry their data around.
Instead, it can be encrypted in the cloud and yet still meet all the mandates and speak all the protocols. So that's certainly one of the options. It goes by the name WW wallet. And some of you have probably heard of that. I think that plays into a good area. The ability to actually execute EUDI over a browser through a secured controlled process does mean that you need an online device. Because you can't store that web-based proposition locally really.
I mean, there are options. We know this is local storage within a browser and stuff, but it's not secure. There's no way of securing that token and making it safe. And so having an online option does mean that there are options. But let's be under no delusion here. This technology is designed to work in a particular way to make it secure. If you don't have the technology, the device that can operate that, then you are going to be disenfranchised. There's no two ways about it. But what the EU are doing is they're not getting rid of the existing authentication systems.
They're not getting rid of what they're doing is they're introducing a more secure and a safer way in terms of the terminology to engage and interact. If you can't do that, don't want to do that, you want to remain using your old passports and go through that process, you can still do that. You're not going to be left behind because of it. You're just going to have the way that you currently engage today will be the way you engage tomorrow.
Now, in my honest opinion, I think that'll probably mean over time you will, there will be a disenfranchisement. But I think that's just going to be the way things go.
Simon, if I could just follow up to both you and Mike on that one. I take the optimistic view that the hardware manufacturers, because I'll quote Moore's law again, the price of computing basically halves approximately every two years. I think the hardware manufacturers are going to then start as hopefully hardware prices go down. I understand functionality goes up, our phones and Androids are still relatively expensive.
But again, I've seen in South Africa, I've seen very, very relatively low cost mobile devices that you can do the remote biometric authentication on. The hardware manufacturers I think will understand that there is a market for ease of use, for security and for low cost. And that might encourage emerging devices to fulfill that market need. But I'm very pleased that you're right. So this is a supplement to current identity procedures. It's not replacing them, certainly not overnight.
We did some work actually, to be honest, Derek, with an organization some time ago, who were actually producing a device at $35 for the device that was capable of meeting the EUDI token security capabilities. And hopefully with ease of use, because one of the issues is cost, the other is fluency.
I mean, these devices were full screen touch capable. I mean, so I'm really glad we're touching this because we appear to have touched a nerve in the questions. And so James, thank you for this. You pointed out that WW wallet deals with those who are financially incapable. And we said, there are people for whom 35 bucks is a big deal.
You know, frankly, in my younger days, I was one of them. You know, but it's not just that that is caused people that left behind. I talk about my mother, bless her. And by the way, now as a Twitter account, so all the rest of the internet get to experience what I was like, what it's like for me as a teenager in terrorizing. But anyway, what about the other leave behinds? People who don't have the skill, cognitively, people who don't have the dexterity, and, you know, arthritis in old age, at certain conditions of birth? How do we help them?
Is that something that you you see the requirement or sorry? Yeah, it is a significant challenge, don't get me wrong, and it should be addressed. No question about it. I can't speak for the EU, of course, but I would imagine that they don't want to leave anybody behind financially or otherwise. I do think that technology in general, the big technology players, the tech giants have made reasonable, you could argue, but have made reasonable efforts at accommodation. And I think technology advancement has helped to a certain extent.
Translation, for example, is nowadays instantaneous back in our day, guys on the panel, we had little books to do our translation when we were touring Europe. So there are I think technology can help technology can certainly help to make it easier. But I do think that there will be real challenges, real cases that need to be studied. I think it needs a combination of regulators, academics, the healthcare industry, and the broader community to address those and to proactively address them sooner rather than later.
And I think if you take that, if we specifically look at EUDI, that actual framework, it's a technical framework, there's the reference architecture that goes through all of the technical details. But if you look at the actual writ that goes with EUDI, it's been written so that wallets must be accessible to people with disabilities on an equal basis. That's actually in the legislation. It's in the actual definition of operation. The European Accessibility Act is noted as part of a requirement within the EUDI.
That means you can't assume someone can hold a phone steady, you can't assume the text size, you can't assume that there's a touch gesture requirement. So whenever you're building your wallet and the operation of the wallet and the UI that goes with it, you have to factor in a user-friendly, disability-friendly interaction. And certainly from what I've seen and what we see with the clients that we're engaging with, most of the wallets are kept as simple as possible. If it's a matter of exchanging a token, then it's simply saying yes or no. Do you want to share this data with this person?
Yes or no. And you can say that verbally, visually, gesture controls, there's lots of different options. There's even for people who are physically disabled, arthritic, etc. There are ways that that can actually operate.
Now, in addition to that, they also do build into the requirements they operate on behalf of. So for your grandmother who can't use, let's be realistic, do we really want to put them, put people in that situation through the strain and stress? I remember this with my father, trying to get him to do tax returns, etc. It was so stressful for him. So what did we do?
We said, no, dad, you don't need to do that. We'll get somebody to do it for you. And we make things simple. So there has to be, we have to look at this not just in terms of the technology that's going to help, but the process around it that also needs to be in place. And any identity system, like I said at the very, very beginning, if it's not based on trust, and that's not just trust in terms of the ecosystem, it's trust in terms of the service itself, then it's not a service that's actually meeting its goal.
So that means being able to do on behalf of where I can say I trust somebody to work for me with my best interest at heart, and then still manage the liability for that properly, then we have a solution that can work and can service both the physical and the physically disabled. Thank you.
Michael, as one of the people responsible for the designing of these things, I'm really interested in what you have to say. And then before we go, there's another question I want to get to. So what are your thoughts?
You know, there's a lot of barriers to use by different parties. And I worked at Microsoft for a number of years. And one of the interesting facts there was there were requirements when shipping a product to address disability challenges of many kinds, visual, cognitive, what have you. And that wasn't put in place primarily for regulatory reasons. It was put in place for selfish commercial reasons, that if your product is usable by people with visual disabilities or with other kinds of disabilities, hearing disabilities, you have a larger market.
And yes, there is a cost to doing accessibility work. But there's a benefit. So it's my hope that just as in the commercial space, commercial space, people will see the advantages of inclusion. I think that may be the case with the wallet initiatives. I know there's also in different places legislative mandates to make products accessible. But hopefully this will be done not begrudgingly, but because it helps everyone to be able to use the product. Thank you. Thank you. I couldn't help but smile when I went to my doctor and said, oh, you've got a bit of arthritis in your fingers.
Do you use a keyboard much? I'm like, well, only since age 10. So moving on from that, and thank you, that was actually really enlightening from all of you. I have a question from Alberto.
Thank you, Alberto, for this. And this is our last question before we wrap up, I think. So very quickly, regarding the international dimension, countries outside the EU, do you have any views as well about the business wallet? So instead of identifying consumers and citizens, we're now identifying businesses. Is Europe a primer with it? Or are there interesting experiences out there to be considered for wallets enabling secure, fully digital B2B and B2A visual interactions? I think if I can, Simon, would you like to lead on that one, please? Sure. So I think actually, is Europe a primer?
In my personal view, I would probably say yes. I think what they're doing in terms of EUDI, EUDI for the consumer has got a roadmap, we know that. But the actual primary, the most significant piece in that roadmap actually comes in 2027, when the business side of the wallet actually comes into effect. That's when value and the whole ecosystem will actually start to take off, in my view. We're going to start to see the adoption of EUDI as a standard, because businesses are going to be mandated to operate under it.
And whilst the wallet is intended to store and manage digital identities and electronic attestations and attributes, the whole business element will actually start to play a bigger part. I think what they've done is they've laid out a standard. I think the timeframe, as is always, those people that have worked around the European Union and legislation will know this, that more often than not, what happens is they lay something down.
And yes, let's just say timescales move out a little bit, but they ultimately do land. And what we actually see is we see what they built actually come to fruition. We saw this with CEPA some years ago. In my view, we'll see the same here with EUDI and businesses.
Now, having said that, at the same time, there are lots of countries around the world that are looking at this and saying, actually, that bit is the most interesting part, and they're already starting to look at programs they can put together to actually expedite that. Will they overtake? Maybe. But I would still say stick with the European model, stick with the way that that's driving, and I think, actually, you'll drive towards success. Okay. Thank you very much.
Derek, very quickly, do you have a view you can share with Alberto? You know, thank you. Great question. Fascinating, fascinating discussion, and I agree with you, Simon. My thinking's not that clear on the business application, but I will say this. It has got enormous potential. If consumers adopt it, the logical extension will be businesses adopt it, government adopts it, so that, again, from a cybersecurity perspective, from a privacy perspective, you've got more assurance that the transaction that you're entering into with another consumer or with a business is secure, is protected.
Absolutely. I see enormous potential for businesses to also get involved, and it is the logical extension. Okay.
Mike, if I can get 30 seconds from you on this. Sure.
You know, as far as wallets and businesses, I was going to make an observation earlier per the coffee wallet example. Our mobile phones are full of applications that store credentials for a specific purpose.
You know, I have a Delta Airlines application that stores my frequent flyer information and my itineraries, but, you know, it won't even work with a different airline. And, you know, I have a coffee application that only works with that. Are these wallets or not? They're kind of wallet-like, but it depends upon what you mean by the term. The trick with these standards-based wallets is they are credential purpose and credential format independent to some extent.
Again, we will see how this plays out in practice. Will my Delta Airlines application go away? I doubt it. Okay.
Well, we have run out of time. Thank you. First of all, thank you to the audience for joining us. Whether you listened live and you contributed with your comments and questions, we're extremely grateful if you're doing so. For our sponsor, Ditto, thank you again for enabling us to put this event on. And lastly, of course, thank you to the panel.
Derek, Simon, Michael, you've been absolutely awesome. I've really enjoyed this.
Obviously, this is the road to EIC, so join us at EIC in the Berlin Conference Center 19th to 22nd of May. For Covering a Cold, I've been Jonathan Kerr. Thank you all very much indeed. Thanks very much. Thank you. Thank you.
See All Locations
See All Locations