Great to be here. My name is Herbert Leithold. I'm director of the Secure Information Technology Center Austria. I see my slides now, which makes me feel better and in the next 20 minutes, I want to take you on a journey how Austria approaches the EUDI Wallet and and how we will get there.
Therefore, I will start with a little history taking you into the history of Austrian EID. Not because I'm old enough to love talking about the good old times, but if you see where we come from and where we ended up, you probably already will have a guess where we will go to on the EUDI Wallet. I will then briefly describe how the system looks like, the architecture, a few challenges, opportunities, success factors, and finally we'll conclude.
So, now back into the history. Austrian EID last month had its 20th anniversary. We started with various tokens, bank cards, health insurance cards, which were not successful as EID, just the mobile EID was successful. And you'll see later figures how we reached roughly 50% of the population that have active EIDs. We did a major relaunch in, well, we started a pilot in 21 and did a major relaunch in 23, where the new aspects were, on the one hand, enriching by attributes, and on the other hand, in particular, also following our mobile first strategy.
And in addition to that online EIDs, we have what is called E-Ausweise, which is the German word for EID, which I didn't translate here, which is for proximity situation, personal presence situation, presenting a mobile driving license, your ID card on the smartphone. And there we already reached more than 700,000 mobile driving licenses or more than 300,000 EIDs on the smartphone or age verification. What are the key concepts from the beginning? On the one hand, it's government-issued EIDs. Then it's a voluntary system.
I'll refer to that in the success factors, because if it is voluntary, just presenting it to the citizens and telling how great it is doesn't give you success yet. And it's free of charge, both for the citizen and for the relying parties, and therefore public sector and private sector relying parties. So the system was open for the private sector as well. I'll talk about that in the success factors as well. What are the core functions? From the beginning, identification.
Well, guess what? I mean, it's an EID. So identification with in-house persistent identifiers, and for privacy reasons, sector-specific identifiers. So the tax administration gets a different identifier than your bank or insurance company. Then from the beginning, a qualified signature free of charge, which now is a requirement under the wallet. Not just EID for citizens, but also for businesses through representation.
So I, as the director of ACID, can represent ACID by curing the central registers. Then in the major relaunch, the focus was on mobile devices, enriching by further attributes. I'll call them attestations in the new EIDAS world. And in particular, app-app, meaning same device use, so that the relying party is basically an app on your mobile phone. And in parallel, a little later, we launched the E-Ausweis app, which is the wallet for proximity situations. So if you go through that functions, you already have a quite good coverage of what the E-UDI wallet requires.
Online-offline situations, natural and legal persons, free qualified signatures, and attributes. What is the success so far?
Well, I won't go into the details, but what you see with the blue lines is the take-up of smart cards. Not too successful, I must confess. The red line then was the mobile EID, and the green line splits off as the relaunch, where on first use, the previous mobile EID gets converted to the new EID Austria. So that is why the red line drops and the green line increases, and we have 4 million active users in total, which is 50% of the population of 14. On the right-hand side, you see the use per relying party, and I just want to point to the green and the red bars.
The green bar means conventional, old-fashioned browser access from your desktop. And the red bar already is higher, which means app-to-app communication from the mobile. So we already have a supremacy of mobile use. So that is where we stand. Just a quick view on how the system looks like, so then I can later explain how we will define or develop the wallet out of that.
Well, the online authentication system is a central system. We use a remote HSM, where either a mobile device or other tokens, like a FIDO token or a smart card, triggers the heavy lifting in terms of the crypto operations. And an important aspect of the Austrian system is the attributes are curated freshly from the authentic sources, like the population register or other registers, through a system that is a register and system federation and access system, where you have a logical view on the various public registers on the federal level, regional level, or local level.
On the other hand, the proximity app has a back-end system for issuance, and their verifiable credentials or mobile documents, like the driving license, are loaded to the smartphone app and stored there. So that is the decentralized part. The proximity part is decentralized, the online part has central components. That is an architectural view that I won't get into.
I mean, there is a user, the user holds a token, the token in, let's say, 90%, 95% is the smartphone, with a secure enclave or a trusted execution environment, meaning smartphones the citizens currently have. Every modern smartphone has a hardware-backed key store. And on the back-end services, which is the trust service provider for qualified signatures or the EID system, there are HSMs that do the heavy lifting in terms of crypto operations.
And those devices are linked by a crypto link, basically meaning you generate a key on the hardware key store on your phone or on the FIDO token, and you register that on the HSM. The architecture of the decentralized app, and apologies for the German slide, but I won't get into the details.
Anyhow, you just see the core concept. Well, it's a proximity situation. We don't operate with smart cards or FIDO tokens. That requires a smartphone, of course. It has an app. The attributes are secured, again, by the secure enclave in Apple or trusted execution environments. And the smartphone stores the stuff. You need the online EID to authenticate yourself. So EID Austria is a prerequisite with the app-to-app communication with that app. And the access to the registers is through that register and system federation I mentioned with a logical view.
So there is a heterogeneous access to the registers. And a central system does the credential issuance like Christina and Torsten just explained for the decentralized systems. So that is where we stand. What are the plans?
Well, we already have a pretty good penetration of mobile EID plus a decentralized system. So with EUDI, it might be a bit insane to put a system in parallel if already 50% of the citizens use it. So the idea is to have a seamless migration of the existing systems to the EUDI wallet by end of 26. For the online use cases, the remote HSM solution will continue to be used to reach the lower high requirements that EIDAS gives us. We already have a pretty good coverage also of some of the protocols like the mobile driving license protocols.
Other need to be advanced like automatic connect or legacy SAML authentications towards verifiable credentials and what is defined in the architecture reference framework. But the main idea is take what we have and have a seamless migration into the future. What are my views to the success factors?
Well, the timeline is pretty challenging. So reusing what exists already can help us not just on the national level but also on the European level. Like the once only technical system that is established under the single digital gateway regulation. Where you have directory services of competent authorities, meaning credential issuers. Where there are semantic repositories of the various attributes and so forth.
Next, you have seen on the slide that we already in Austria have more users on the mobile apps as relying parties than conventional browser access. So for 26, we need to think mobile first. That needs to run and work to be successful because browser accesses might disappear over time. The EUDI wallet is voluntary for the citizen. So it's not just the existence that gets you take up. Both the citizens and the relying parties need to see a benefit in it. So it requires services.
And with the higher degree of or with the direct access of the wallet to the relying party, it needs a high degree of harmonization and interoperability. I mean that thing needs to work because otherwise it would fail. Which means also the protocols Torsten and Christina just talked about need to be tested and adhered to. And while EIDA's origins from e-government, that is let's say a low frequency use. I mean in Austria on average you have 1.7 qualified contacts per year with government services, much less cross-border services.
It is private sector services that might get you the frequency and we benefit as government benefit from it because that gives you a steep learning curve by the users as well. Well, what are the hurdles? One might be identity matching. The wallet is supposed to be used also with a social network and so forth where privacy and pseudonyms are important. On the other hand, in e-government or in KYC services you need unique identification. In EIDA's one, we had a sort of unique identifier for that.
That, however, with the wallet is gone. The mandatory persistent identifier is no longer part of the system. And on the right-hand side you see the cross-border uses we currently have where 80% are recurring users. Which means that rely on that unique identifier that go to an identity matching process. Meaning knowing that the Herbert Lighthoard is a very Herbert Lighthoard that is in the system once and then use the unique identifier. So that for KYC processes without persistent identifiers can become a challenge. Next challenge, one of my favorites, wallet certification.
It is beyond doubt that some sort of harmonized common security baselines are important. However, if you look at the Cybersecurity Act, how long it took to get the first certification schemas harmonized. I'm just picking one. EUCC converting an existing standard to a harmonized scheme took us seven years. That doesn't match with the deployment end of next year. So Austria welcomes pretty much that there is a route through national certification.
Still, establishing a national scheme, even if tailored to your system that you know, 26 is pretty challenging. So to also allow for a few questions, I come to my conclusions. In Austria, we already have some history and experience with online identification and proximity. We have a pretty good user base. So the road towards the EUDI wallet, even though the protocols change and some elements and functionality change, is basically use what we have and convert it as an engineering task with the same user experience that the user already has.
Because that also is a success factor that just for using the wallet or an electronic identity cross-border, the known user experience shouldn't change. And as mentioned with certification, for instance, we are confident that we can manage to deploy by end of 26.
Still, it remains challenging. So thank you for your attention. It was great being here. Thank you very much for furthering our discussion on identity wallets. There were a couple of questions about business cases. I'm not going to ask them now because we've got a whole stream on business cases. I think it's on Friday that Martin Kueppinger is heading, so make sure that you go to that session. I just wanted to ask you quickly, though, is you said you're kind of reusing a lot and that's great and that's helping speed up things.
But to what do you ascribe the fact that there's a high adoption in the first place in Austria? I mean, are Austrians just kind of, do they just get digital identity?
Well, I mean, if you look at that one slide that is no longer on the screen that started somewhere in 29 towards 25 now, it was a painful experience. So the expectation was higher, but then it was basically the services. The first popular petition that you could file electronically did tenfold the activation and the use. Access to your pension records did increase. And then you said, saw a pretty steep increase. And some of you might remember there was a pandemic and lockdowns in terms of services are not too helpful.
And that increase, however, in Austria was mainly the access to the electronic health system to get your vaccination certificate electronically, for instance, because that requires remotely access. So basically you have just a great use case, really. Exactly.
OK, thank you very much once again.