Yeah, good afternoon. I like the disruption as well and we are really pleased and honored to be able to run this project on behalf of the German government. The world we live in is digital, but the way we prove things about us, our identity, our achievements, entitlements, are not. So what we see today is that people are breaking the angles when presenting ID cards through video chats, taking pictures from those documents and sending them through instant messaging, right? That's the current situation and it's got a lot of challenges. First of all, it's painful. It's cumbersome, right?
No one really likes that and it's inefficient because in most cases the data need to be manually entered again and the cumbersome nature of the processes also causes drop-offs by the user. So convenience is bad and conversion is bad too. And what is sometimes not realized is that the security properties of the documents are made for physical presentation. And if you take a screenshot of your ID card or your driver's license, all those properties are going away, which opens the floor for all sorts of fraud. So we are in a pretty, pretty bad state. The solution is simple, right?
Use digital objects, use digital credentials. They are cryptographically protected and carry them with you. I would like to ask one question to the audience. Who of you uses the mobile phone for payments? Thank you very much. That means most of you already have a wallet on their phone, right? And you can put your boarding passes in that and tickets and all that sorts of things and it's very convenient. It's pre-installed on your phone, it's easy to handle, so let's just use them.
But wait, there are a couple of challenges. First of all, the functionality covers payments and I would say low assurance, low security credentials. What about high assurance credentials?
I mean, if we're talking about putting an ID or a passport in the wallet, that's a completely different game. Second, the technologies and the use cases supported by those wallets are determined by the wallet providers, typically the platform providers. Which leads us to the next point. Since we would like to use credentials for all sorts of use cases, for all sorts of credentials, the question is to what degree do we need to influence this upcoming part of our digital infrastructure? Or does that in any way treat, for example, Europeans' digital sovereignty? And here we are.
The European Digital Identity Wallet is the European Union's vision of how we can establish a kind of wallet that is non-discriminatory, meaning any provider of a credential can use it. Any relying party can use it to get access to data. And it is secure and it's interoperable, meaning it doesn't matter on which platform you're living, which wallet you use, you can use your credentials all over the place. So that's basically the vision.
And in the end, it doesn't matter what you're going to use going forward, a state-provided wallet or a government-provided wallet or something provided by a foundation or a big tech, it doesn't matter. They all have to comply to the same rules. And that's the key here. That's the key to sovereignty. We define the rules, anyone can play with us. The member states across the European Union have to provide their residents with a European Digital Identity Wallet by end of 26, which is quite ambitious. And the member states can choose which model they prefer.
They can do their own wallet, they can give that to an entity, or they can run an ecosystem. But all those solutions need to be certified and they need to be recognized to ensure they are secure enough, they are non-discriminatory, and they are interoperable. We both are representatives of the German EODI Wallet Project. It was started two years ago. It is run by the Federal Agency for Disruptive Innovation. On behalf of the Ministry of Interior, it is going to change the name in the course of the next days, or at least we will be assigned to a new ministry.
And the project is run as a very transparent process. So for those of you that have already been involved, I'm not telling you something new. We publish anything we do on open code. We are very open to contributions to what we do. And over time, the project also evolved into the rollout project for the German ecosystem and the government provided wallet. We've got a couple of partners or very important partners involved in that in a project. The Federal Office for Information Security, Bundesdruckerei, Fraunhofer ISEC and PwC.
And based on the preliminary or interim results that we have produced in the project, the German government decided on our strategy for the EODI Wallet ecosystem. And the German government decided to go with a hybrid or dual strategy, meaning Germany is building a government provided wallet. And we've got the product owner of that wallet on stage today. But Germany also decided it will establish the basis for having alternative wallet providers in the market.
And I just today talked to one of the prospect wallet providers and we are very excited about this opportunity to have more than one wallet in the ecosystem. And there are a couple of very important reasons why the German government decided that way. First of all, risk management. We need to make sure we're going to provide the wallet by end of 26.
Second, we want to have level playing field when talking to other wallet providers. That's why having our own wallet is a good starting point. We have seen that, for example, and we are inspired by the experience, for example, with the MDL rollout in the US, where the different states use different approaches. And we are very much in favor of what California has done there. And that also kind of inspired our decision. And the third bullet is also very important. The certification for the UDI wallet is going to be something pretty unique and new.
Because the UDI wallet is not just a chip on a smart card. It's going to be a pretty complex software system, which consists of hardware security modules, apps on the phone, back-end systems, and so on. This is really a complex thing and we need to get that right. And because we have the development of our own wallet and we are working closely with the BSI, which is the party in Germany that will, in the end, define the certification scheme, that's very useful for us.
So the government-provided wallet will be the blueprint, the reference model, basically, for all the wallets that are going to be recognized in Germany. But why are we open for alternatives?
Well, first of all, we believe that people should have a choice. Because trust is an individual decision. So whom I trust might differ from whom you trust or you trust, right? So that's why we think that having choice is good for trust, which will help us to achieve the goal of broad adoption of the concept of the UDI wallet across Germany. And second, competition is good for innovation. And we would like to have the best ecosystem that we can get with the best wallets, with the best user experience, the best functionality.
And we believe that having alternatives will help us achieving that goal. How do we achieve security and also sovereignty? When I'm talking about sovereignty, there are two different aspects to that.
First, the digital sovereignty of the users. But second, also, the digital sovereignty of Germany as a nation. So first of all, we are in control of the First of all, we are in control of the certification scheme and also who we recognize as a wallet provider. And we will make sure that the security requirements, the privacy requirements, the functional requirements, and so on, will be fulfilled by those wallet providers recognized in Germany.
And for those of you that are not familiar with the differentiation between those two terms, certification means it's all correct from a technical standpoint and so on. Recognition is more than a political decision to allow this wallet to get access, for example, to the EID data of German citizens and residents. So you can certify in one member state, but you need to be recognized in Germany to get access to the PID data. Looking onto the user perspective, so first of all, all the relying parties, and this is already buried in the regulation, need to be registered in the ecosystem.
And this enables the user, with the help of the EUDI wallet, to easily determine whom he or she is working with. So the relying party's identity is checked in a reliable manner, which means you know whom you're talking to, and it's not the dog you're talking to.
Second, all the relying parties need to register their intended use, and this intended use is published and can be reviewed, for example, by civil society activists. And if they believe there is some over-identification going on, they can make noise. And this is kind of the hygiene in the ecosystem. Users have full control about what they're going to do, right? They know whom they're sharing data with, they know what the intended use and purpose is, and they can decide whether they're going to share the data or not.
And clearly we use privacy-enhancing or privacy-preserving technologies to prevent linkability and foster data minimization. And last but not least, if something goes wrong, you have all the right as a user to complain about the other party. And this all in all, with those mechanisms, what we want to achieve is a level playing field. We want to empower users, right? It's not our goal to protect users. We want to empower users to make informed decisions with their wallet. And now you are most likely eager to learn what is this wallet all about, right? What are the functions?
And for that, I hand over to Christina. Thank you, Torsten. So these are the four key features that every single wallet has to provide. And as you can see, it's not just identification. It's definitely the important feature having this digital version of ID in your wallet, but it's also digital version of any other documents, right? There's sometimes code attestation of attributes, but basically digital driving license, e-prescription, digital residence certificate, and, you know, anything you can think of. And but also, it's about electronic signatures.
The regulation governing the wallet, EITS2, inherits the qualified electronic signature apart from EITS1, so that's legally binding signatures. And last but not least, for payments, we're looking at the authorization of the payment, right? So this is a really new feature that we don't really have right now where you can bind authorization of a specific transaction to an identification of the user. And let me illustrate how these four features bring convenience to the users by using an example of renting a car. So Mary is in a Dodge van. There's some delays.
She spontaneously wants to rent a car. She goes on a website, starts a booking process, and, uh-oh, she forgot her physical wallet at home. But luckily, she has an EUDI wallet on her smartphone which has her digital ID card, driving license, debit cards, among all other things.
And first, she's asked to identify herself by presenting a digital ID, which she successfully does. Then she proves her driving privileges using her digital driving license. That's the digital credentials, attestations part. And she can also use her wallet to sign the contract in a legally binding manner. And finally, she has to pay, and she can authorize the payment also using the wallet. And after she completes all the steps, the digital car key gets into her wallet, so on arrival, she just goes, picks up the car, and everything's very smooth. How did we get there?
Here's a roadmap for the German EUDI wallet project. Back in 2023, we started with the blueprint. So that's a document with architecture, the operation model, and we believe in learning by doing, so we ran the funky challenge, which is where we built the prototypes of these wallets to make sure that what we have been putting in blueprint actually works, right? And last year, we also started developing the government-provided wallet, and starting mid this year, there are three things that will be happening.
One is this wallet innovation lab, so that's for the relying parties on, you know, maybe some issuers who want to keep prototyping, right? And for the funky challenge, we use a prototype PID issuer, but we will have a production PID issuer, so that's part of ecosystem rollout, and what's important here is we're not looking just at the wallet, not just a native app sitting on your device, right?
When we say ecosystem, when we say the wallet, we mean not just the wallet, it includes the PID issuer and onboarding all other players in the ecosystem, so we will have the ecosystem rollout and the operations of the government-provided wallet. So two small announcements. Our team is growing, so we're actively hiring, and especially for my government-provided wallet team, we're hiring developers, so if you're interested, please let us know. And second, there's only so much we can do within our project, right?
So we need help rolling out these ecosystem portals, whatnot, so there will be a few tenders coming out, so please stay tuned, and everything will be open source by default. Not just architecture, but also for the wallet, the ambition is to make the code entirely open source, but in a way that you can just take it and run it, so ideally, we're doing our best, but ideally, you would not be dependent on some external licences, hopefully.
And as you all know, the value of the wallet increases with number of credentials people are willing to issue into the wallet, and the places that actually accept the wallet, right?
The more we have, the higher the value of the wallet, and to do all that, we also need the trust public underlying, so we need all the players, we're obviously more than happy to help, that's why we're having this ecosystem portal, but also, yes, please take the risk, please become an EIA issuer, become the relying party, and that's where we truly believe that EU is leading in this space, and it is a blueprint for globally, and mainly these four points, one is definitely attracting top talent, innovations, funding, we have people quitting big tech, moving all the way to Germany, loving Berlin, and then we have really a lot of requirements in terms of security, privacy, interoperability, so we're pushing it to, like, how do you make, how do you bring convenience to the user's hands while guaranteeing the highest level of security and privacy, and it is very challenging.
But also, if you can get it right, you will get a great product. And also, the scalability, we're looking at operating these products at the massive scale. It's actually 440 million citizens in the EU, which is a lot, but also interoperability, right? These wallets have to work within the entire EU first, right? Not just within Germany, but also throughout the EU, and once we achieve that, also globally, right?
Like, why can't I use my German wallet at the Japanese border or US border, right? So I think, like, we're really exploring the cutting edge of all these topics, and, yes, I think we're doing a great job. Thank you for attention. We are very reachable, so feel free to reach out if you have questions.