Thank you, everyone. It's day three, 3 p.m. Probably a lot of you, I hope, like nobody's sleeping at least for the next three minutes at least. It's going to be interesting.
So today, I have prepared a presentation for introductory course. So I assume you would have six or seven EUDI wallets kind of thing today. So I'll go with very, very simple and very realistic of what I have experienced and what you will experience in two years as well. So Hopae is my second company. My first company, I built the COVID vaccination for South Korean government, which was used by 43 million users during COVID-19. So we were one of the few having digital credentials. And people, when COVID was about to be okay, people went to foreign countries.
And one day, I got a call from airport from Guam. The officer said, all the people coming from Korea are presenting this mobile credential. This is my real credential. I need to get past with this. And they had no clue what this is. So this is, I believe, it's going to be the exact same when 2026, 2027, you will face. Europe is on another chapter of having digital IDs.
By 2026, there's a mandatory acceptance to EIDAS 2.0. So what you can expect is at the bank, people will come to you in the office, not many, but some will come to you and ask for, oh, this is my ID from Australia. I want to open a bank account with this. Then you need to accept it. And at that point, you'll get a call as a IAM leader, as a digital identity specialist, your team will get a call from people that, oh, someone came with this. Can we process opening bank account, giving the loan account with this? So you must be ready for, there are two things that you need to be ready.
The first one is you have an option. This is optional. You either embed wallet feature in your existing app. So this is an introductory course, so I'm not talking to all the wallet providers who are out there, but this is for more like a chief security officers and compliance officers. And the second one is you need to accept digital ID and be able to verify them, become a relying party.
So, there are a lot of jargons, like new technical standards coming out every month, every two weeks, it's super hard to follow. And what actually it will do with your business, there will be some values. I think not a lot of people are like, we are talking about what kind of values actually this regulation can bring to us. For example, having a wallet feature within the existing app. For example, in airlines, you can import user's passport or visa on ticket purchase and have no one on the counter at the airport.
And also, you can also replace some eligibility check for destination countries, which is causing tons of money to airlines right now. This is a picture from EU blog.
So, when applying for a bank loan, before it was tons of paper, tons of time. After, it will be very paperless and instant.
So, how to build a EUDI compliant wallet? I've talked to a lot of people during this conference, and I've noticed many people wanted to get some keywords or concepts they can bring back to their office, do some research.
So, here are some keywords. The first one is, you definitely want to take a look at architecture reference framework from EIDAS 2.0. Some diagrams are over there. Check where you need to focus on, where you're lying at.
And also, another keyword is, you will expect a lot of open source modules. All the wallets and wallet SDKs are being built on top of open source right now.
So, you'll be able to play with them. You'll be able to implement with them in a very, very easy way. And another keyword is, there's an open wallet foundation under Lynx Foundation.
So, open wallet foundation has a bunch of SDKs that can cover all the wallet ecosystem. So, you can go and try. There are a lot of developer communities actively out there as well.
So, today I want to focus more on the secure EODI compliant wallet. So, there are some requirements for key management as well. There are three main things. Embedded secure element, secure element or eSIMs, or external device, which is smart cards and remote backend cloud HSM.
So, to build a secure EODI compliant wallet, it's not just the app or it's not about just having this data management or networking. It's also about crypto key management to ensure you can provide your customers of high level of assurance wallet.
So, for people who might not be familiar with the concept of high level of assurance, if it's just not using the compartmentalized key management, software key management is not enough. You need to have some sort of hardware that provides the high LOA and to also be EODI compliant wallet feature.
So, I made some tables. So, there are embedded secure elements, eSIMs, external secure devices like smart cards, like German ID, and remote HSM cloud APIs.
So, there are some criteria for you to check. This is not applicable for everyone because everyone has different kind of user base.
So, what I would suggest is take this as a reference, do your evaluation on your side, and I hope this can be a good guide. So, the first one is level of assurance. Secure element, definitely a lot of secure element by definition is like certified, and most of them are LOA high. And the only part that level of assurance can be a bit low can be remote HSM, cloud HSM. Which cloud-based HSM you use, which vendor you use, you need to think about and know well what kind of security types, security standards they meet. And for security part, I believe all four options are very valid.
And for offline access, if you have your user base based on offline access, then cloud HSM might not be your option. And for user experience-wise, secure element, it's just seamless integrated within the device, eSIM also. But what secure device, the smart cards or external device that you need to plug in to your phone or plug in to your computer might not be the best UX your customer would expect. I think we have all experienced it from a lot of bringing your own keys for MFAs.
So, also inclusivity-wise, I think this is a bit controversial of coverage on secure element, but it's getting better. It's widely, it's been available for certain premium models in hardware devices like Google, Samsung, Apple, but now it's getting very common and I have some slides behind to talk about it.
So, how about pricings? So, in order to have this wallet feature, definitely pricing matters. I have another table for evaluate could help you think about the pricings.
So, the first one is integration cost. So, definitely having a smart device forcing or requiring your user to come up with a smart device to your employees is going to cost a lot. If you can have access to secure element or remote HSM, there's no initial cost, but it'll get costly as you grow. Is there a hardware cost?
Also, for a smart device, it's very high. And certifications, you'll have to spend some money to get certified for all those four options out there. And for scaling out and maintenance, if your user has secure element, there's no maintenance cost. It's embedded to the device. For others, for example, like HSM cloud API, you need to have someone to keep an eye on if your cloud HSM crypto signing API is not going down or going up, it's not working, and also ECM is going to be very complex. Depends on what carrier or device your user has.
And for overall cost profile, I would suggest secure element is so far the best option for having the wallet feature within the app. So, the one question here is secure element, are they widely available? I know for sure it's not covering 100% of your user's device.
So, from recent research, 60% of smartphones will include secure elements. So, it makes 40% or maybe up to 50, 60% of your users will need to have another method for having this secure part.
So, I would highly suggest to come up, try with a lot of options, make the best options of combinations. And also, it's being a trend that all these hardware vendors are including the secure element part in their hardware devices. Samsung recently also announced that they will include all the electronic secure elements in their not just premium brand, but also for the older devices they have.
So, yeah, what happens, what will happen when this is built right? People, to sum up, people will carry their credentials, IDs. They might want to put the credentials into your app, into your employee app, into your customer app, and they will want to use it for KYC process that you might want to provide.
And also, it's going to change how we deal with the business. Not just banks, airlines, it's going to be every day in our life, in our digital identity fabric, it's going to be there. And I suggest you can have, you need to prepare ahead. Yep.
So, that's it for the presentation today. Thank you very much.
So, although it was a bumpy start, we have three minutes left, which leaves room for questions. Who wants to build a secure EODI wallet and wants to ask the experts some questions?
Hi, thanks for the presentation. I really like your table with the different aspects. I wanted to pick up on the point about the low cost or supposed low cost of the embedded secure element, particularly on Apple. There were a couple of announcements they made last year, one opening up the security of the EODI wallet, and one opening up the security of the EODI wallet. And I wondered if you had any insights on the costs and commercials of that. Thank you.
Yeah, it's a great question. So, Apple, you can access secure element through a secure enclave.
So, it's been not direct access to the secure element, but you'll be able to have enough feature for providing wallet feature using the secure enclave. So, as of now, a lot of vendors who provide wallet SDK, they use secure enclave. I'm not sure if it's going to be, we haven't, there's no set standard of secure enclave is good enough for high LOA or not. But for Apple, you can, I think you can use secure enclave and still consider as a high LOA with low cost.
Okay, thank you very much. Any other questions, final chance?
Three, two, one. Thank you very much, Ace. Thank you very much for that introductory, but for me, really inspiring presentation. Thank you. Thank you.