Great, yeah. We thought about presenting our book, How to Onboard the EUDIW Ecosystem for Dummies, but I think instead of reading, we would more like to explain it in person to you.
Yeah, my name is Mirko, this is Konrad, we are from the Federal Agency of Breakthrough Innovation. Yes, and yeah, today we are talking about how you can become a part of the ecosystem, because we know, we have the law that every citizen needs the EUDI wallet, but it would also be cool when some companies are able to interact with the system, just having a wallet where you cannot really use it is not quite very efficient. And for this... The clicker is not working. Maybe now try it again.
Ah, okay. And instead of presenting long slides and so on, we tried a bit to make a presentation, a stage for you. So I will be the registrar that is offering the service, and then we have Konrad, that is a company. What's your name of the company? It's a good question. Dominic in the previous talk talked about health insurance, so maybe I'm a representative of a health insurance provider, and I want to join the ecosystem, and we will explain and try to figure out how this could work in the future. And what's the first question that comes in your mind when you're hearing about this?
I mean, I'm here at the conference, we talked and heard a lot about European Identity Wallet, it's, I think, a great tool, a lot of interesting features. I'm a health insurance provider, I have use cases, but how can I use this?
I mean, I really want to implement this, use it, because it offers value for me. What can I do? How can I approach this? So maybe to clarify why you should, because there is a lot of stuff out there, a lot of solutions where there's not real demand. And to break it down, there are two main reasons.
Of course, from the business side, optimization. You're cutting cost, or time, which will also cut cost, so your use cases, your processes will be more efficient. Because it's very difficult to explain your manager to say, well, we are wasting money or throwing it out of the window. Another part, of course, is regulation, because EIDAS is demanding it by you. It is getting a lot of, yeah, types of companies that have to be compliant for this, but a more stronger reason for you or for most companies should be because there's a benefit that is for the whole things. I buy this.
I mean, having good flows for my customers is really important, and I get the value. And also compliance.
I mean, I'm in a regulated industry. There's this really crucial privacy, security, and so on. But how can I really join?
I mean, how can I interact with this EID wallet? So basically, what is needed? What is needed?
Well, it's an app, of course, but with this app, you can do multiple things. We heard a lot by Christina Thorsen yesterday, some features, but let's reintroduce it. So first of all, attestations. We have the pit for authentication to identify yourself, but also driver licenses, degrees, anything you can imagine.
And here, there's no limit. So for a health insurance case, you can insert any kind of attestation. Another interesting part of this is for transaction authorization, like not only QES, but also giving consent. When I'm going to a doctor, I maybe want to give consent that they could share my data for research and so on. And this is quite possible right now, very easy with this app. So I don't need to sign any papers and so on. And of course, let's imagine your health insurance company has an online portal where you want to log in.
Then you could use also your wallet for pseudonym login instead of using Google login and so on. So also use it as a single sign device to log in. Sounds great, isn't it? I just choose my provider. I have my use case and then my customers are happy. Is it this way or do I need something more?
No, that's quite good. But of course, do you know where do you go? No. And the slide says you need to register. This sounds really bureaucratic. I need to do some paperwork and print it out or get a license for it. We don't know yet, but first of all, let's see where to go. So here the regulation says you have to go to the member states where your company is based. Where are you based? I'm based in Germany.
Oh, that's great. So then you go to Germany. Anyone from Great Britain here? Okay.
Yeah, sorry guys, but Brexit means you cannot participate. Maybe we should have told you this before. Yeah. So for EU member states, it's quite easy. You go to the member states where your company is registered. For all other of the world, we honestly don't know yet. Regulation has no concept for this, but since you're in Germany, congratulations. What's the next part? Now you know where to go. How does registration work? Tell me more. How to register? Yeah. So you're talking about you're afraid of paper? Yeah.
Oh, definitely. That's really good because here EIDA says there has to be a digital way for you, a fast and cheap one. So of course, in the first place, you are a business, but normally this is also for natural persons possible.
We say, okay, here we have to do a know-your-customer process because people need to know with whom they are acting. You could say that you are a company from the health sector, but who knows? So here we have a know-your-customer business and to not have an individual approach in Germany, we would have multiple existing authentic sources that are based on existing registers. So here we would have commercial register, company register, or even international approaches like the LAI. So here there will be multiple approaches.
And then during the onboarding service, you could select in which you are based and then choose from this. And this should be done hopefully in a few minutes. That sounds really cool and much better than the processes today. Tell me more about it. So it's not only about the registration because we want to increase privacy. So here EIDA says you have to declare the intended use. And the current situation is like, okay, we have a very long privacy policy. Everyone is reading, of course.
I'm not asking who is reading all then because there's at least one in this whole crowd all the time that raises his hands. But the main point is, let's be honest, nobody is reading this because we all just want to onboard. We don't have time to read it and we just want to use this. And here we want to make sure this register, since we know there has to be one to identify the wallet-relying party we are interacting with, to make sure the transparency, like what do I say I want to request from you and what I'm actually requesting.
So the idea is here that you make publicly available what data you want to request. So what kind of data do you think you need? My health insurance membership card, maybe e-prescription in the healthcare sector is interesting. But we have, of course, a lot of health services that are really important, where we really want to provide value to our customers. And I mean, I buy this argument. That's interesting. So it's about transparency and about knowing who is interacting with the wallet and the wallet is in the hand of the users. Do I get it right? Exactly.
So this registrar is not the next centralized server that knows who is talking to whom. It's just a basic registrar where you have to publish your information, like we have with PKIs, where you are publishing the information and then this information is publicly visible for at least 10 years also to civil society. So there will be no pre-check to really check like, are you allowed to request specific health data or maybe the PIDs? But since this is publicly available and we have identified you first, we are able to check it also later.
And when we saw a violation, since we did the know your customer process in the first pass, we could charge you. So you could abuse the trust we give you, but GDPR has strict rules and we will charge you. I'd better stick to the rules. But what is really important for me is because we have tough competition in the health insurance provider sector. So and how can I basically, my branding, that's really important. Is there a way to how my organization is visible to the users when they interact with the wallet? So how do you deal with this topic? Exactly.
So maybe in the future, an AI agent will do everything for us. But for the meantime, we know we are looking at images and logos. So here issuers and verifiers will be able to customize their brandings that are visible to the users. Because most of the time we are looking at the logo, we know, okay, this is our bank and so on. So we are interacting with the right endpoint. That sounds good. But I mean, identification, intended use, branding, multiple steps.
I mean, is there not a simple solution how to get the onboarding to this, that I can interact with the wallet ecosystem? Yes, because here we're saying this will be the ecosystem portal. So all the services where you have to go to the registrar, or even when somebody is complaining. So because there's a part where a citizen can say here, I have questions for you regarding this intended use, everything will be bundled for you at one portal. So we have easy access to all the data.
And of course, the good part is if you don't like our UI, because Germany is not very an expert and very good UI, unfortunately, you could also integrate it in existing systems via an API. So it's also interesting for intermediaries that are offering verifier or issuer as a service. So who are these intermediaries? They're expert, I can source and partner with them that they help me to comply to the steps or what they're doing?
Yeah, this is possible because the IDA says here that for small, for every kind of company, for example, even especially for small and medium enterprises that don't have the technical capabilities, but they are liable for things they're doing, they can go to a provider that is dealing with all the different protocols and so on. And yeah, acting as a kind of proxy to reduce all the heavy lifting so they can interact the way IDA wants them to do so. Really interesting. This sounds a really good, flexible digital concept.
But I mean, we have all this intended users and we have transparency and we know what is going on in the ecosystem. So can we also use maybe this data to make decisions? What do you think? So it's a good part as we know, the IDA says we have to register it. It has to be an API and so on. So civil society could look it up. But from a business perspective, it has more value because here I can see how is the ecosystem building up. I can see on the one hand which issuers are there, what credentials are issued.
So it's really see, okay, who is issuing medical data and so on, which hospitals are also providing this data. And also on the other side, who has registered specific intended uses, like who is consuming specific data. So it will be some kind of registrar where you can see what is offered in the market and what is demanded in the market. Because the alternative would be we have to crawl the whole internet, scan every endpoint to look like what is registered. And with this approach, you will get an exact overview over what is offered.
And we also can see, hopefully, a growing number of reliant parties interacting with this because you now see when you're on board, you know where you get the information and don't have to search around. That's really interesting because I think that's not only helpful for the users to know where he or she can use the wallet.
I mean, I can just monitor my competitors if they are already joined the ecosystem. That's interesting information for us, but maybe also for the critical public, as you said. And if we move on, now we are done with our little role play. So this is basically how we see the ecosystem. We see a need for orchestration, for this management portal to really provide a digital user-friendly and flexible process to onboard different multiple public-private issuers, verifiers, organizations to the ecosystem.
And with that, we are more than open to your questions and also for feedback, as this is basically an idea and concept we still try to further develop to really streamline and improve how we create the oily wallet ecosystem here in Germany. Thank you so much. Thanks. Thank you for your entertaining performance. Are there any?
Oh, yeah, we have questions. I will walk around. Thank you. You said that you would register relying parties, and if they are using the data in an incorrect way, according to what they said they would do, you would charge them. You would charge them. So as a business, that sounds like a liability. If I register with you and I don't honor that agreement, then I'm charged. How do you respond to people who would not want to join the ecosystem because of that risk?
Well, the point is the IDAS is forcing these participants to register this data. The registrar is not assigning, like, are you authorized to request this data? So it's more like a self-declaration, because when there has to be a ministry that is checking every type of credential, is your company authorized to request a driver license and so on? So the main idea here is to say you have to make publish the intended use. So why are you requesting, for example, the pit?
And you're saying here, I'm requesting the pit because I'm selling alcohol, and I have to make sure that only people older than 18 or 16, when it's beer, are able to get the alcohol stuff. But there's no pre-check before, because we would know it will never scale. We had this in Germany with our EID card, and it never scaled over the years. So here we say this is self-declaration, but you have the risk when you are abusing this feature, since we have done the know-your-customer process before, we can easily charge you. And this is a requirement by the EODI wallet.
So if you want to participate, you have to do this. And the wallet will also check every time if you are over-asking, and will print a warrant to you. The wallet ecosystem is extremely disconnected, so to say, especially from the perspective of the end user. If something goes wrong, it will be pretty hard, I guess, for an end user to figure out where it is going wrong. Is it on the issuer side? Is it on the verifier side that maybe my wallet is something wrong? Is the registry a place where we can actually provide some capabilities to help the user?
I think the most simple thing would be, and I think this is already in the legislation or in the ideas, to have an endpoint registered or something where you could go ask for help. But I could imagine this to be more elaborate, to provide actual suggestions to the end user that can actually be visualized in the wallet, for example, on how to get some help and how to resolve some of the challenges that the user might be facing using the ecosystem. So do you have any ideas around that? I think you're pointing out a really important aspect.
I mean, we have some kind of a decentralized ecosystem with multiple entities and components. And there needs to be, from an operation perspective, also some kind of alignment and also information towards the users. And that's also the reason why we have foreseen this role as an orchestrator, because it's not only about providing some components and deploying them. You really need to align with the different people to also aggregate information, provide processes. And this cannot be done by one entity. That's a collective challenge, so to say.
And yeah, to be brief, I think we are just at the beginning to really realizing what does it mean to deploy and roll out an ecosystem. And especially these points are really critical. Would also love to follow up to get more of your thoughts and ideas on this. You just mentioned that the wallet will check every request and prevent over-asking. That was my main worry, so you seem to have solved it. But for how many data attributes will it do that? For all of them. And how many? The main idea is here, it is right now standardized in Etsy, because we are just having the intended use as a string.
And for this, there's no easy way for machine processability. So the main approach here that we have is schema. For every credential we are defining right now, it's either mDoc, scjot, and so on.
So here, since you are still issuing schema-based credential, it's just a matching of two sets. And to look like, okay, you have registered to ask for the birth date. Is it there? If you have registered for the pre-name, it is there. So here we can do the automated check, so we don't also need no external services where privacy information is getting leaked or so. And we skipped it there. All this proposal is already in the German blueprint. So here we have this open consultation process. You will find also online recordings in English and OpenCode where you can consume it.
And also when you think like, maybe I have a question for this, or maybe there's even an error or some kind of improvement, you can easily give us feedback via OpenCode. It's a GitLab instance. You have to register, but there's no fee.
And yeah, anyone from the world can give us feedback and we much appreciate this. We've got three, no, two more minutes. So is there any further?
Okay, then we have two questions. I'd like to know how the ADAS2 solved one of the main problem on the version one, that is the different master key on the different member status. So a social number in one state and so on. So the ADAS1 was only focusing on the trusted list approach.
We say, okay, we have PKIs, we can identify the mechanisms. But here when dealing with credentials, especially with intended use, like when we are sharing, especially personal data, how can we control that this is not abused? Because we see already out there that specific companies are abusing this because there's no automatic way to validate or to check this. And there were really good improvements, because they said like every member state is defining their own way how to onboard or how to do the customer process because we have different registries in different member states.
So Germany can do a way, the Netherlands can do another way because they have us. But the good part is that we have in the end standardized certificates. So all the EODI wallets just have to comply to this standard and don't have to adopt and implement all the different approaches how the onboarding worked in the different member states.
You know, I'd like to criticize many subjects from you, but first of all, great presentation and it clarified many of my questions from your open code. But after this, the question you just mentioned that in any country we have to register. And you mentioned in your presentation that you plan such a dashboard, who offers what and who was registered for what.
Do you plan a consolidation of this dashboard with the other member states so that we have something like a meta dashboard on the EU level, a bit similar like the trust list, like the list of the lists for the trust services, so that the user can check this also for trust services and relying parties which are not registered in Germany? I think it makes a lot of sense to talk to other member states and this idea with the portal and also the dashboard is basically an attempt to really just share the idea, let's get and talk about it.
So, I mean, as natural we can focus here on Germany and we really see the need and I think we explained how we foresee this. But having a conversation on some kind of meta dashboard or maybe that other member states also say, well, that's a good approach, we want to use it. Maybe there are sources synergies and providing this dashboard and this onboarding portal. So that's definitely, we are more than open and curious and we definitely should talk as always in Europe.
Okay, I'm putting up my head as a moderator, putting on my head as a project lead. Since the portal itself is an API, any party could also use that data to set up an overarching dashboard, for example. This is an open data approach, so we do not all have exclusive access to that. We would like to share that with anyone. Based on the APIs, people can build stuff on top of it. You could also use it as a researcher, if you want to figure out what's going on in the ecosystem. Or a civil society organization, for example, that is, or privacy activists. Back to you.
Yeah, thank you very much for a great presentation.