So, welcome everybody. The topic today, I wanted to start off with simple physical world examples. If I give any of you this, you have no doubt, you know what it is, and you will trust it immediately. You are not experts on passports, on passport recognition, but you will accept it. If you're in a hotel, you will accept this. At a border, they will accept it. They will have a little closer look at it, but they will accept it.
So, one of the questions is, when can we do the same with a digital version, but in a safer way? The other one, as an example, is the driver's license. This is a European driver's license, I'm Dutch, but it is made according to international standards that we've all agreed on.
Now, in the next couple of years, we'll have an EUDI wallet, and we will have the mobile driver's license in there. But, I wonder when I can go to the US and I rent a car, and I guess I'll still have to take this one out to rent a car.
So, what we're going to talk about today is how can we actually really get to a digital version that is more privacy-preserving and easy to use. So, without further ado, we have a perfect panel to discuss this. From right to left, Laurent Loeb from SIGPA. He is also Work Package Lead for the EUDI Wallet Consortium, piloting a lot with the DTC, and he'll talk about that later. Cor de Jonge from the Dutch Ministry of Justice and Security, but he's here especially as the chair of the ICAO PKD Working Group. Lofi Jordaan from the American Association of Motor Vehicle Administrators.
I practiced that one, Lofi. He's Mr.
MDL, can I say that? And last but not least, Sergis Nolle from Unix, and they are a secure identity provider. He'll be talking about some exciting projects they've done.
So, this seems like a daunting task, right? Because it took a while before we could all have a passport. That's only been for maybe 100 years or so since we had a passport.
Actually, we had standards that were even shorter. I'm looking at Cor, yes, that's even shorter, like 50, 60 years. And we could use that to travel across a border, and it was trusted and was standardized.
So, this can seem like a daunting task before we can have that in a digital version. So, I'm an optimist.
So, my first question to all four, what is the big highlight of the last year or time there that you've experienced and you see happening that really gets us towards this global ideal end state? I'll just start with Laurent, to my right. Can you hear me?
Yes, okay. So, yes, as you know, we have this large-scale pilot in Europe, and one of them called EWC. We are testing out the future European wallet, and especially in travel and payments. And what we give to the EU Commission is a feedback on the whole journey, user journey.
So, it means from booking to boarding, to boarding crossing, and then to hotel booking, museums. We have ferries as well.
So, we have really the whole chain, and this is where we want to use those and to show actually that this is feasible at large scale. So, that's a little bit our task at the moment. And what are you seeing happening that will probably solve some problems towards global adoption?
Yes, I think currently what is missing is really digital credentials that are issued by governments. Like they are currently, we have a lot of silos, identity provider, but it's still the question of trust, of global trust across use case, across jurisdictions. It's still an issue, let's say. And what we have here actually with the passport is really a global standard and a global trust, which has been worked out for many, many years to actually arrive to the states of trust that we have today.
And so, we'll have to go probably to the same way with the digital part. Yes, and it's a topic all around.
So, a lot of people, a lot of organizations and countries are working towards this. And one to have a great overview of this is Korte Jonge, because he's the chair of the ICAO. And ICAO is the International Civil Aviation Organization. And they have been given the responsibility to deal with standards in travel documents.
So, that's why ICAO is responsible here. And CORE is the chair of the ICAO PKD Working Group.
So, what highlights can you see new steps moving towards a digital version of our identity documents that we can really use across an international border? I would say it started with travel documents, as you said. But to say it more or less blunt, it's now going all over the place. Due to COVID, that is my lesson learned. We had suddenly the urge of exchanging health certificates. And there was not really, at least in the mind of a lot of people, a standardized institute who can do so.
So, all of a sudden, health certificates were also placed in the public key directory of ICAO. And so, it's involving a lot. There are a lot of initiatives, as my neighbor said. There are also all kinds of different business needs to identify not only people, but also goods, if it comes to air travel and that kind of things.
And also, barcodes are a phenomenon right now. So, it doesn't really matter what type of token you are using. You want to identify and to authorize whatever that is related to that token. And if it comes to that, then at least I see as a big challenge a worldwide interoperability.
Because, as we see, a lot of initiatives in Europe, two countries, bilateral, in a formal way, they all do the best of things they can do. But, as you said earlier, the European wallet, how nice would it be that you can use it in America, Australia, wherever you are in Asia. And we have to put effort in that to become that normalization of whatever tokens there are. Yeah.
And Lofi, you have seen a lot of developments with the MDL, a growing use of it. What is the highlight? What are you really happy about? What we've seen that we are very excited about over the last year is the emergence of regional trust lists. The trust model envisioned by the ISO standard for a driver's license, MDL, envisioned regional trust lists because we don't have, like ICAO, one worldwide governing body for driver licenses.
So, you have to fall back on something else and the solution was to define a trust list structure with the vision of having regional trust lists so that each region remains sovereign. And that we align the rules for getting into the regional trust lists so that region A can take certificates from the trust list in region B and put it into their own trust list so that the local relying parties in region A only has one trust point, which is their local trust list, which then, in theory, would include keys from all over the world.
And so, we've seen in North America, my organization has created, stood up a trust list. We call it a VyCal provider in the ISO language.
So, we've created the trust list. Australia is standing up their own trust list for issuers issuing authorities in Australia and New Zealand. And we've heard that there's movement from DigiMove in Europe to also investigate standing up a trust list along the same lines.
So, we're very excited about that because we need that to make reality coming from Europe, presenting your driver's license in US and having accepted. So, it's a very good and promising start.
It is, and it's crossing continents, you're just saying. Again, it may seem like a daunting task, but I know you're all in networks that also cross borders and cross continents.
So, this is really, you know, it's working towards that. The steps are being set. Yes. Wonderful news.
Now, then to go back to local. Sergej, explain, you've worked, built a digital identity system for Austria, but also for Liechtenstein. And I was really intrigued with the practicality of Liechtenstein's approach to the many commuters they have. It's a small country. And that's a perfect example of how you can start small.
Yeah, thank you. Maybe I'll explain it like in a real life scenario. You can issue an eIDLi, it's called eIDLi, from everywhere in the world. And then you have like a signed app where you have your credentials. And then you could theoretically open up an account.
So, if you're a German citizen living permanently in Austria, like in the region of Vorarlberg, and you are working in Liechtenstein, then you get Liechtenstein app. You can, via video ID, you can verify yourself. You can then get a certificate to cross the border. Then you're allowed to work there. And then you can return back to Austria. And if you're a permanent citizen in Austria, you can do your tax return with the digital ID from Liechtenstein on the Austrian tax return website.
So, that's what we implemented. It's not like ID wallet right now, but we are working on that.
And, yeah. The standards are? The standards, we try to follow everything that every of the participants said before, like MDL. Liechtenstein also has an MDL mobile driving license in this app. Yeah. And almost 60% of all Liechtenstein citizens use this app.
So, it's very exciting. And they are very, very eager to move on to ID wallet. And we are in discussions with them to transition the app to official. Yeah. It's really great first predecessor to EDI wallet. That's right. Especially because you can use your Liechtenstein digital identity to do your taxes in Germany. Yes. Which is unique. Yes. Yeah. Wonderful.
So, to go back to the ecosystems and how do we grow the adoption, because without that, we don't need to do anything. Again, back to Lofi, to the example of the MDL. Because I remember when it was only three states that had the MDL. And by now, I think half the states have the MDL. And it's growing.
And, of course, we had real ID issued this week. So, the need is also increasing. What is your experience? How do you grow the adoption? How do you get verifiers to join this? How do you make it simple for them? Because it can look like a complicated task. And they also have all their stakeholders. They have to get on board to join this.
So, how did you get this system to grow to be so big as it is right now in the U.S.? With difficulty. It's a challenge. Adoption consists of essentially mostly two sides. You have the holders. And you have the verifiers. You have issuers as well. We have found that we have many issuers lining up.
So, that's not the core challenge for us. I think the core challenge is the actual holders to convince them that this is a nice thing. It's not just a novel thing. You can actually use it. On the relying party's side, they mostly see the value. This is a solution that is more trustworthy than the physical equivalent.
Yet, they say, it makes sense to me financially if there's so many. That percentage of holders actually has it.
So, it's sort of a chicken and egg situation. What we're finding is that you need to identify your champion relying parties that see the value of this as a concept and are willing to invest in it knowing that they're not going to get an immediate return on investment. They are out there. There aren't many of them. We're trying to find as many as we can. But we find that that's one of the things we're trying to do to really help build the ecosystem. This is in the U.S. specifically.
When we broaden our scope a little bit because a driver's license is something that is used across international borders, we have found that it's very important to keep your technical solution simple and stable. The moment it's not simple and not stable, it becomes very much more difficult to get people on board than otherwise.
So, we think that's a very core requirement. Talking about adoption, what are the success use cases that drive the adoption? So far in the U.S., the big public use case we have is the federal government at airports. The Transportation Security Administration is one of these champion use cases that really saw the benefit that it can have for them and has invested quite a bit in the infrastructure to read it. You mentioned RealID. RealID has been around.
It's a set of requirements for issuers that they have to comply with so that their credentials is acceptable to the federal government for, among others, air travel. The final due date by which every state, all the credentials had to be compliant with the RealID requirements was yesterday. That included mobile driver licenses.
So, mobile driver licenses are also accepted by the federal government, and they also had to be compliant, yeah, with a small qualification, with the requirements for mobile driver licenses that the federal government has set. So, that's a very nice example of a big use case that we have that is really helping adoption along. And then there is an incentive because it's a faster way to go across the airport from A to B, right? It helps the facilitation. It helps the security process. Yeah.
Yes, and the value on the TSA side, on the Transportation Security Administration side, is that it's more trustworthy, so that's benefit to them, and it's a smooth user process, although I have to qualify that in that it does depend on the user experience in the wallet, which is outside the control of the relying party, the Transportation Security Agency. And so, that's something else that plays into this adoption thing, is keeping it simple, keeping the user experience in mind, because if it's a bad user experience, you will have low adoption.
Exactly, exactly. Yeah, Laurent?
Yeah, I think if we look at the, let's say, the criteria for the adoption, first of all, we talk about UX. UX is obviously one of the key elements, but beyond that, it's the frequency of usage.
So, typically, it's not one super use case where you will have incentive for people to use it. No, people need to be able to use that almost on a daily basis. If you have credentials that they use maybe once every three years, it's just yet another app, and they are going to forget it. It needs to be global, so they need to be able to use that, again, across jurisdiction when they are traveling. And that's the most difficult part. They need to be able to use that in the border control context and from the industry, and that's the most difficult. Public and private.
Yes, and that's the most difficult, because ICAO, for example, that you mentioned, their mandate is to provide security elements, like the passport, for the context of the border crossing, and not for the purpose of the industry. However, we know that there are national and supranational regulations requiring, and are those identity documents requiring a unique identifier and requiring all the industry to know your customer, AML, you name it, for the airlines industry, for the hotel industry. They are heavily relying on those ones, so they need to use that.
So, there's kind of a discrepancy between the mandate of ICAO and the real-life daily usage of those identity documents. And I think that's what we are testing right now. If we crack the code on this one, that's really, truly a game changer for the industry and for people.
So, because privacy needs to be preserved, you only should share the data that you need to share, which often means that private parties, if they look at my document like this, they get too much information, but they need to comply with the rules and regulations. So, it's really about compliance and balancing the privacy.
So, what is the ultimate solution there? Well, I would say it's an end.
So, we need it all. So, we have this concept of photo ID, and we might talk about it a little bit later. It's a final draft mode by ESO, and this credential is containing, let's say, the secure elements from a data group from the passport chip that can be used by border authorities. And the different attributes, one by one, signed, can be used by airlines and hotels and banks and so forth.
So, I think here we have, let's say, one concept that has the, let's say, the potential to tick all the green boxes. Yeah, this is promising to meet compliance and still privacy preserving, but it needs to be, if there is a standard, it needs to become adopted in regulation, of course, because otherwise it doesn't have a status. If you want to comply with regulation, it has to be adopted in regulation. And best be issued by countries and authorities like it is today for the passports.
So, somebody with great experience at a global level. Cor, yeah, it seems a big, steep hill to climb sometimes, but you've seen a lot of progress over the years, and you are aware of this bit of, you know, the problem between what do you give the private parties and what do you give the public parties.
How, to give us an idea, you chair this ICAO PKD, all the countries, all the politics comes at your table. How do you move forward? How do you find the common ground? Finding common ground, in my opinion, is connecting to each other, as you said already, because you're right, if it comes to the strict things ICAO has to do and what they have to do, it's the travel congenium and travelers, but that's not really true, because it's always connected to each other.
So, for that reason, we do a lot of things in a triangle. It's not only ICAO, it's also IATA, it's also the representatives of the airports, and it's not only travelers, it's also goods at the moment, and as a sideline, as I said, health certificates and all kinds of barcode stuff.
So, it is not as narrow as the assignments should be and is, and I think, for me, that's a good reason, because that's the way to move forward. That's the way to do things, as said before, not only for travelers, but also for goods.
In goods, we see different types.
Normally, on a container, there's a sheet and a barcode on it, and it identifies what's in it, but as I have learned, there are also precious goods, and precious goods have their own chip, they have their own track and trace, and also that needs to be interoperable, and if something leaves an airport in the United States and comes over to somewhere in Switzerland, then it would be nice that the Swiss know what's in it, and they have to read it, and they have to identify it, and they have to know what do we have to do, does it need special protection or not, because sometimes you want to have some goods that need special protection, and that moves the world forward.
I've seen it with my head on as chair of the ICAO-PKD also with the member states, because being a part of ICAO-PKD is not mandatory. You can do it or you don't do it.
For now, we have 104 member states, but we cover, if it comes to that, more than 95% of the digital documents. So you can see it from the way we still have 60 countries to go, because in general there are 164, 165 countries issuing documents with a chip in it, but the current part of ICAO-PKD covers already 95%, and countries like Vanuatu or Fiji or something like that, maybe they're never going to issue an e-pass because it's not feasible for them. It's too expensive, they have too low number of travellers and that kind of stuff. So you need to see things in context and then move forward.
That's what I would have to add. Thanks. And then again from the global level, I would like to go to the local level, because CORE is doing this at a global level with everybody around the table, but Sergej, you had to work with governments, with one government, and as a provider you have to, of course, you're providing a service that complies and expedites the local rules and regulations. How did you experience that? And how did the, again, what I really like, this practical use that Liechtenstein added to their app, how did that come about?
There was a lot of convincing to do and a lot of talking, that's why we waited four years to come here, and we made a conscious decision to base the software, the SDK, and our design system on all possible standards that will be mandatory at some point, like IKL, MDL, and we know from experience what you said, that it has to be something that you use every day, or something that you don't have to learn every time when you open it up.
It also has to be something that is understandable between borders, so we have decided to base our software, the app, on an approach of activities, so you have a roadside check, so you have a roadside check, not like I grab my documents, and then you open the app and choose roadside check, and then you have documents that you can add to the QR code that you show to the police, So the police has a specific application? A reader? A verifier? A verifier, and they only get the data sets that you have decided to give over to the police. You consent?
Yeah, and then you consent to that, and then you give two documents with one QR code, it's very simple. So users, there has to be a benefit to switch to digital from this grabbing out of your pocket, and that's the main focus that we will focus on from the user experience perspective, because that's a very important thing as well.
Adoption and use cases that are actually used, and that again is the big driver, we have lots of discussions like what will be the use case for the EODI wallet, could you quickly explain, because there's one use case that is really very practical, which is with Benidorm, I believe. Could you briefly explain what that use case does with sharing passport data, because I don't know if you all know, if you've been to Spain, but there is a new regulation in Spain, you have to share more data, which is cumbersome, prone to make mistakes if you do it manually, and it's also not very customer friendly.
Yeah, so I think especially in hotels, and again with this new regulation in Spain, it's very cumbersome for hotel at-the-counter people, they have to gather not only all the passport attributes, but also your phone number, home address, your email address, and then if you have two kids, they need to register everything, so it's like 10 minutes per guest, and if you're arriving at 11 o'clock after a 10-hour flight, it's the least thing that we want to do.
So how this translates in real time for customers, so it means when they arrive, they are going to be shown a QR code like this, and by scanning it, they will be able to share just in one go all their data that they have stored from the passport, and maybe also self-attested attributes like again email and phone number, so there is an obvious advantage for the user experience, but also in data quality, because this is from a relying party, for them it's really a benefit, they are on a daily basis struggling with all manual errors, getting into their systems that they have to deal with it, and also it's resources that they have to put at the desk that cannot be used for something else, so it's really a pain for the relying party, and this is what we are experimenting with, I think it's a must-go for all this industry, but then we can multiply that in other market verticals.
And to be clear, it's with the EUDI wallet? Yes, absolutely. So we have a few minutes to go, and we have enough to discuss, but maybe I want to open up to questions, and hello to our online viewers, I'm sorry I didn't welcome you, but wonderful that you are joining, and maybe we have some online, any questions in the room?
So we talked a lot about the PID-like documents and the driver's license documents, but if we want to do all the things that you guys just described, get yourself into a hotel, engage in all kinds of leisure activity, and we want to have global interop for that, we don't just have to make sure that the transport protocols work, but we also have to make sure that the actual semantical values of the credentials are being understood globally, that strikes me as a daunting task, so I was wondering if you have any insights on how we can expedite that, because I think some of the standards that you have actually worked on have taken some time to sort of come together, how can we do that more quickly, so that we can actually more quickly service our users?
Great question, who would like to take it? Maybe, that's what I just explained on the photo ID, it's the name of the credential, and this is where it's an attempt to harmonize all the data structure, and it's an ISO standard, it's in final draft mode, and we expect this to be released still this year, and then to be adopted and pushed by ICAO, that would be, let's say, the goal, but it's still a long way to go, because again, we have to go through all the different steps until we get to that point.
To add to that, and to the question, in my mind, you have a protocol, and you have a standard for the data that you're exchanging, the standard exists, otherwise you won't know what to read, you won't know what to ask for, so you have to ask in terms of a standard, and that standard defines the values.
Yes, you have a driver's license, and you have a travel document, and they may not define your name in exactly the same way, yet I don't see that as a challenge, because you know that the driver's license defines it this way, the passport defines it this way, if I ask for the driver's license, this is what I ask for, and if I get it back, I know exactly what it means, and if it's passport information that I get back, I know exactly what it means, so I don't really see a challenge there, because the standards will define exactly the semantic meaning of the data. Yes, more questions.
Regarding the usage of the driver's license, are there any legal basis for it?
For the international driver's permit, there are two conventions, one is the Geneva Convention, and the other one is the Vienna Convention, and I've been looking for any plans for converting such an international driver's license based on these two conventions in MDLL format, and also let's say between Japan and Germany, there's the special treaty of the German driver's license can be used in Japan, and the Japanese driver's license can be used in Germany, but with translation, and I'm also curious of what's your thoughts about actual work on the legal basis of these international conventions?
I can't speak for Germany. As far as the conventions on drug traffic are concerned, there is work to amend them to recognize mobile driver licenses, and so that is in process, and that is the vision. Unfortunately, the group responsible used to be called WP1. They're a subset of UNECE. They're called the Global Forum for Road Safety or Road Traffic, Road Safety, I think.
They move not very fast, to put it politely, and when they do change the convention, it takes five years, I think, before it takes effect, so it's not going to happen overnight, but there is work going on to make exactly that happen. Thank you.
Yes, another question here up front. Yeah, sorry. It's good to do some exercise. A comment and a question. A comment a bit towards Laurent. You were asking for that uniform digital identity issued by governments. Good news. That exists. It's inside your passport and your identity card. It's the uniform digital identity in the chip. Use it for TTCs or whatever. So I think that's a great foundation, also thanks to ICAO, and there may be a question towards ICAO and the PKD list. There are quite a few countries still that don't share their country signing certificate. I simply don't understand why.
Do you? Same here. So the message we did in the last regional seminar in Qatar three weeks ago, if you don't share your certificates, why do you issue an e-passport? So the message is getting stronger, something more unpolite, so to speak, but countries are moving, not as fast as we want, but they are moving and we are collecting more and more. And if you're looking at the content of the public key directory right now, it's about 400 plus certificates. So we're growing fast, but we're not there. And it keeps us busy and it is keeping our attention because you're very right.
If you don't share your certificates, some countries declare them state secret. Public key.
Yeah, yeah. But it's all about understanding for us bringing the knowledge, what is public and why. Please share them.
Actually, all the other questions on the online thingy were from him, so... Yeah, and maybe...
No, he disclosed himself, so... Maybe just to comment, just comment on your points.
I think, yeah, you're right. I mean, the physical part are used today in almost everywhere now with the online registrations. But it's still, I mean, for everyone that has done that process, it's very cumbersome, to be quite honest. We have to scan the MRZ, explain that to your grandmother that has to take that, then scan with a tap and go. You need to download the app.
I mean, honestly, it's a nightmare. So, and on top, it will be just one app that maybe you use for one travel. And then you have to do it again for the next application for your bank and then for your telecom operator, and then, et cetera.
So, I think that's why we... But use it to avoid your wallet and do that once. If you want, you can come to our booth. We have a competition on who can do it fastest.
Yesterday, somebody did it in 8.2 seconds. Complete verification into the wallet. 8.2 seconds. The slower ones were 25 seconds. But ask the average Joe. Ask the average Joe. I don't want to have a super competitor. We want to have everyone's grandmother that is able to do that in less than five minutes or ten minutes.
So, we end up with a race that everybody can join. You can win a fake identity. You get your identity of choice. That's always useful, a fake identity, yes. I want to thank this panel because it was super informative. I enjoyed it very much. Give them a warm round of applause.