Welcome to the KuppingerCole Analysts chat. I'm your host. My name is Matthias Reinwarth. I'm an advisor and analyst with KuppingerCole Analysts. My guest today is and we are on our road to the EIC, which will be held in May in Berlin. For that reason, I have invited Martin Kuppinger, Principal Analyst and one of the founders of KuppingerCole.
Hi, Martin. Good to have you.
Hi, Matthias. Pleasure being here. Great to have you. And we want to highlight a topic that will be central stage at EIC. We want to talk about decentralized identity, EUDI wallets. So this new type of trust that we hopefully can soon build applications and services and business processes on. And the headline that we have for that track at EIC says, at least parts thereof, say digital identity you can trust. So this is some kind of change, a shift. So when we say this digital identity, this decentralized identity, this state issued identity, at least parts of them will be state issued.
They are trustworthy. We can trust them. What does that mean? What are the minimum properties of such an identity that have to be true for users, for businesses and regulators? And what has changed recently so that we really can say and dare to say that digital identity is something we can trust? Yeah. If we can trust. I think that's the interesting question here. And I think that depends a bit on a very individual perspective. Because it is a system that is built to be decentralized. So I hold my verifiable credentials, my attributes basically, in my wallet.
I decide about when I use them, to whom I issue them, for which purpose, et cetera. So I in general have control about it. I have a verified identity. And from that perspective, it is something which is under my control. What we need to be a bit clear about is that there are certain scenarios where governments potentially can collect certain, let's say, metadata about usage. Like when you look at aspects around revocation or status of services, which are managed centrally. And also that depends on the implementations of the individual member state.
And some are more on the, we have the central elements, some are less on that side. But it's not a hundred percent perfect. What is very clear is what you do as a holder with a verifier, with a relying party, that's yours, that's invisible for the government. What potentially could be visible is that you interact with a certain party, with a relying party. That is something which is not a hundred percent sort of excluded, also not cryptographically, where we need to be aware of.
On the other hand, I think it's a huge step forward compared to any central ID scheme where one party, be it a government, be it Apple, be it Facebook, be it your employer, whoever issues it, Microsoft, whatever else, knows basically or potentially can know exactly with whom you are interacting in significantly more depth. But it is a challenge we must not underestimate. And it is something that is to be kept in mind, I think, in the entire communication and education or dissemination about this concept, as well as in where will it potentially win or where could it lose. Right.
So, we need to look at the actual implementation to really understand what is possible and what not. And that might be nation-state dependent. I think that's the main story behind that. But overall, the framework itself could allow for a quite decent privacy-preserving way of issuing identities.
And that, in the end, is part of what we define as privacy. Definitely far better than most of or probably virtually everything that is available at scale and widely accepted. It's better than everything else we have.
So, I think we can also look at it from the perspective of, is it a step forward? And then the clear answer is yes, it is a step forward, it's a big step forward. If it is used. Right. Right. And if we insert a short explanation part, maybe there are terms that we use that are not common to everybody or fully, fully embraced.
So, if we say decentralized identity, we say verifiable credentials, a digital wallet, how does that play together? It starts with somebody issuing an identity for you. And that is where trust starts. That's the anchor. I think that the main aspect is, first, this structure, which is very frequently quoted of issuer, holder, and verifier.
So, an issuer issues something, verifiable credentials, that someone holds. So, the issuer could be someone who does an identity verification. It could be your employer. It could be yourself. It could be a bank, an insurance company, whoever that goes to the holder. The holder, in that concept, puts it into the wallet. But the main element first would be the holder and hands it over to a verifier in the course of a transaction.
And it might be the information about, yes, I'm a marketer, or it might be some additional information like whatever, information about financials or whatever else is needed, other information that is relevant. There's also this EU DI business wallet, so DI for digital identity, where an organization has certain proofs about sort of legal state and legal aspects of the organization that can be provided within a transaction and then business processes.
And there, right, we need to be very clear that sensitivity for privacy or for privacy is significantly lower than it is from an individual perspective. Right, so we will have the experts on site at EIC, which know much more about the details about the implementation part, and there will be interesting discussions. And that gives us room to talk about the real interesting additional aspects, apart from technologies. We now are getting closer to having this EU digital identity wallet in our pockets, in our mobile phones.
From an analyst perspective, under what condition will such a digital identity wallet, or many there are, become a real success beyond the mandatory compliance use cases? And what needs to be the case for that?
Yeah, and I think we need to differentiate between three levels of scenarios. The one is where someone only can use that wallet. The second is where the relying party is obliged to support that concept. But where it's not exclusive. And the third one is where no application exists at all. So the first scenario that might be an interaction with your government, if you want to do it online, which probably for a longer time still will leave the option to say, hey, I just want to walk to the office and do it in traditional manual paper-based manner.
But overall, I think there will be some pressure, there will be some advantage of that as well. So that interactions with your government are faster. The point we must not underestimate is, this is a rare occasion. So that happens for the individual on average, maybe two times a year or so. If you count elections, maybe three times on average, but it's a very low number. Because whatever your passport is valid for five years, 10 years, your physical ID card, your driver's license, they all have a validity of a couple of years. For a lot of things, you don't need a strong proof.
And then that leaves you with a relatively limited number of these interactions. If you add a tax scheme to that, then it's at least once a year, depending on how often you need to report. But at the end of the day, it's limited. So a broad acceptance and sort of moving to a state where someone is used to use this UDI wallet basically on a daily basis or multiple times a day, where it's a sort of a standard means that requires more. And this is where I would say the obligations come in.
So that a series of businesses must or obliged to support it when electronic identification authentication is required, which would be financial services, which would be utilities like energy, telcos, and a couple of others. There, clearly, the first step is we will end up a bit in a clash with certain existing schemes. So in Germany, we have our health ID, health card. We already have a scheme and such a transition is a very long term thing, if it happens at all. And clearly, there's an extremely high sensitivity for segregation as well, especially when it comes to health.
The other thing is that all of these services already have established schemes. And the obligation is not to say, replace everything you have, rip and replace, and just do UDI wallet. But the obligation is to also support it. And I think it's very clear, these businesses will basically decide on based on acceptance and cost. So if it's too costly to maintain other schemes in a regulatory compliant manner, over time, they will move, try to move their customer base to the UDI wallet. But that will be a longer term thing. And only from a cost perspective.
And then there's the other side, which is acceptance. Acceptance is low if they see, okay, 90% still use our traditional scheme. And we may even have a churn rate that people move to someone else when the other schemes are accepted, which potentially can happen. Then you end up with a situation where, yes, it's supported, but no one uses it. And I think it's even more extreme when you look at the very large online platforms and gatekeepers, the ones that are impacted or that are in the scope of the Digital Markets Act, like large networks, et cetera.
Again, if the user chooses the wallet login, they are obliged to support it. But how likely is it that you shift for your large online retailer in a minute from the proven passkey-based login to using the UDI wallet? We will need to wait and see. But I think this is something we just need to keep in mind.
Right, so we are looking at a continuum between where you use it once or twice a year and you don't know how it works and you forget where it is. Maybe the app has uninstalled itself from the phone because of lack of memory. And that would be the one side. And this is really what needs to be prevented now that we are rolling out this overall infrastructure. On the other hand, I think there is a lot of opportunity. Also for organizations, for businesses, for using that actually. So there is added value beyond the compliance part.
You've mentioned those interactions that you have to use the UDI wallet. As you said, limited use cases, two or three a year. That would be my worst case scenario. Then the ones where it's possible to do it. So there needs to be some additional added value. And then those who could use it for their own business processes. I think this is where the fun is, where the actual business opportunity is. And that is where I would say there's a huge mistake made by the EU and the ones pushing it. So also various governments not focusing on the potential of UDI wallet.
So it is something where the focus is really on these limited use cases. And sometimes you may get the impression there's belief because someone must use it. Someone will use it. Instead of really explaining and enabling a much broader usage. I think we see to a certain extent this UDI business wallet where there's a much stronger focus on how can you simplify business processes that require AML and KYC, so anti-money laundering, or KYB in this case, know your business use cases. And at the end of the day, the money, the success is in the business process.
So the relying parties will be interested when they can save money. At the end of the day, it's about money. And whether they will massively save money with just the onboarding process, maybe yes, because video identifiers, for instance, are which anyway is slowly disappearing. But if you have any identity verification, you need to run yourself. Then it's a cost issue. If you can rely on one that is already existing and which is in the wallet of the customer, then you save money. So that's to a certain extent, it is something which helps you.
And clearly, if you can rely on certain information for signing schemes, this is more established, all helpful. But the real fun starts, so to speak, for a business when we go deeper into the business process. I talked about this at EIC 2024 already, so two years ago, when I looked at how could an application for a loan at a bank look like in a process where you have really many verifiable credentials? And this is, I think, one of the important things we need to think much broader than there's a wallet that holds basically a verified identity of yours and the ability to sign.
We need to look and I think the term wallet is not very well chosen because when you look at a broad use cases, there's much more in that than you would have in your wallet. It would be a lot of stuff you have somewhere in your rack, in folders, information you may need when you apply for a bank loan. You need to provide information about your salary statements, about your family status, about your possession of real estate and all that stuff. If all that would be a verifiable credential, then you could automate basically the entire loan process nowadays.
And that would then mean that the banks can save hundreds of millions per year, maybe more. And then we are talking about real money. There are so many examples that have been discussed around business. Some of them are, to be fair, reflected in the large scale pilots of you, but some of them also got sort of oversimplified. So the original intention to look at this loan process moved to opening a bank account, which is boring, honestly. So I think the EU massively missed that there's a need for demonstrating the real value at the end of the day for both parties.
And I think it's also super important going back to our first point to explain why someone can trust and why this is better. That is a communication issue. And I also don't see much happening there. So that is, I think, because the potential is huge. And if we do it right, and by the way, that would also require a much more evolved concept. I talked about this earlier. So having it on just one device can't be the long term solution. We need some sort of a roaming verifiable credentials where you can hold it on all of your device and decide where it is.
Because your bank loan, you probably don't, at least if it's a larger loan, let's say for buying a house, you won't hold on the wallet. And by the way, this is also one of the business potentials. With verifiable credentials, with all the stuff we have aside that nowadays technology, we also can get rid of a lot of intermediaries in that.
So you would imagine you buy a house and you don't have to go to the notary and you don't have to sign that stack of paper nowadays to your bank for that loan because it's all automated based on verifiable credentials based on other types of technologies we have, even contracting, etc. That would be good and it would massively reduce costs in this process. It would remove unnecessary intermediaries. There would be a business process.
I think we need to think beyond the sort of the basic use cases, identification, authentication, and really start from a business process because then it becomes interesting to every relying party. And then the relying parties will push for using this decentralized identity scheme. They will just over their established schemes because it's more relevant, much cheaper, delivering a better business value. This is where the success will come from. Right.
And that was also the final thought that I want to bring in our discussion is it's really, we have seen the pilots or not because they were not that visible, but we know when this will happen. And I think what is really important is a critical mass to be there and to be ready to use these wallets and the verifiable credentials on day one of the availability to actually prove the value and to be prepared for that.
So if somebody, an enterprise, a company really wants to prepare either being obliged or just using the infrastructure for better business processes, what would be actionable steps to prepare for that? I think the first thing they should already have started because the wallets will be available by the end of this year. The obligation period ends end of 2027.
So, and that is two or three years after the Implementation Act. So basically the start has been almost or already more than one year ago.
So yes, the clock is ticking and these things take a bit of time. I think the first thing is understand the potential and potentially also the limitations, understand this as something that is an additional scheme to what you had so far for identification, authentication, signing, and think about how this can be used to improve your processes to reduce cost, so there's cost reduction because you can replace costly other individual approaches in this area by sort of a standard decentralized identity that could be the one advantage. Keep in mind, will your users have it accepted?
Is there a risk of a churn rate increasing? And then start thinking about how can you optimize the processes behind it?
So, because this is really where the value is, business process cost, business process optimization, that is the topic where we move from an IT issue to a business issue and this is really then where the attractiveness comes from and that is something which takes time, which needs to be analyzed, which requires to dig into the process to work with the business people who own the processes. So this is where we leave the, so to speak, the identity real, but where we also as identity can provide real business value, but it's not something which will just happen automatically.
I think we need to be clear about that. It requires activity and it needs to be well thought out and everyone needs to do a proper job in implementing and delivering the UDI wallets. We will have a lot of Germany, so I think after one year period, other implementations, the side of the sort of the government issued one will be supported in other countries. It will vary and some implementation details will vary, but the fundamental aspects are the same for everywhere. It is something we have, it is a scheme that is very powerful, that is much better than what we had before.
It's probably not perfect, but okay, perfection is a very ambitious target and we can make a lot of value out of that and hopefully also evolution of this concept does not stop with the idea, okay, it's sufficient if someone has one wallet on one smartphone, but reflects the broader digital reality of people. Right. So we are building infrastructure or infrastructure is built for us. The question is how can we leverage that infrastructure for our purposes?
The right place to go is of course EIC because there will be expert practitioners, but also the standard bodies will be around to support through their knowledge and through communication, maybe the most important part at EIC is talking during the breaks and having a coffee together with those who do. If you have experience, share that, go there and tell how you are doing it. It's not just giving away your knowledge, it's sharing and creating acceptance for this, I think this is a good starting point, but don't wait for EIC.
Of course, go to EIC, but don't wait. Start as Martin, as you said yesterday to prepare for using this powerful infrastructure for these business processes that you just mentioned, where it makes sense, where you have savings, where you have new opportunities of creating new, more stringent business processes. And maybe two things here. The one is EIC, there will be a lot of experts with very different perspectives on that, which is, I believe, super important for this. So it's not a bubble with all believing in the same thing.
So it will be clearly more controversial, which is, I believe, important for the evolution of this entire UDI wireless thing. And the other thing, just to mention that, clearly also our advisory team is very eager on supporting you in identifying the potential and the right place to implement EUDI Wallet into your business scheme. Absolutely. I can just confirm that because, of course, we are working both together with and in the advisory team. So if there are any questions, if there are detailed questions, just leave it in the comments and we will get back to you.
And if there are bigger challenges that you want to solve, maybe we can kickstart some ideas together with you. Thank you, Martin, for being my guest today. Looking forward to talking about that topic with the experts at EIC. And until then, thank you very much for being my guest today and looking forward to having you soon again. Welcome.