Trust & Decentralization
Facebook X LinkedIn

Trust & Decentralization

Combined Session
Wednesday, May 10, 2023 12:00—13:00
Location: A 05-06

EU Wallet – eIDAS 2.0: The New European Identity Framework is a Gamechanger

The existing eIDAS governance framework for digital identity is fragmented for different regulated markets in different EU countries. Today identity provider solutions for finance, healthcare and other regulated markets follow central approaches for the management of identities and consent in high secure data center environments and using legacy standards (e.g. OIDC, central public key infrastructure).

eIDAS 2.0 creates a EU wide identity ecosystem with adapted new standards, new stakeholders and a focus on using mobile devices. The existing roadmap allows to anticipate three to five years (or more) transition. For banking, insurance, healthcare or the public sector it is time to adopt these standards in their digital transformation strategy.

Based on the Gematik requirements for a federated identity provider with central OIDC compliant resource and authorization server Comuny shifted relevant identity provider functions (data storage + token generation) on the mobile device.

The speakers will describe challenges and solutions for this regulated market. They also discuss the chance to combine existing central OIDC flows with mobile decentral, wallet based principles as a bridge into the new eIDAS 2.0 governance framework. The audience will get a clear understanding about requirements, opportunities and practice details to create the transition into eIDAS 2.0 identity ecosystem.

EU Wallet – eIDAS 2.0: The New European Identity Framework is a Gamechanger
Event Recording
EU Wallet – eIDAS 2.0: The New European Identity Framework is a Gamechanger
Click here to watch the recording of this session. Please note that this video is only available to event participants and subscribers. You'll need to log in to watch it.
EU Wallet – eIDAS 2.0: The New European Identity Framework is a Gamechanger
Presentation deck
EU Wallet – eIDAS 2.0: The New European Identity Framework is a Gamechanger
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Dr. Dominik Deimel
Dr. Dominik Deimel
comuny
As an entrepreneur and expert in digital change management, Dominik Deimel has many years of experience in accompanying change processes in companies and their transformation into digital...
Sven Schreyer
Sven Schreyer
PwC
Sven Schreyer is Director in the Cybersecurity & Privacy practice at PwC Germany and leads a team of experts in the area of Identity & Access Management (IAM) and IT Security. He has over...

How do You Know Who to Trust?

OpenID Connect Federation enables trust establishment at scale and is being deployed to do so in Europe.

A key question when granting access to resources is “Who do you trust?”.  It’s often important to know who the party is that you’re interacting with and whether they’ve agreed to the terms and conditions that apply when accessing a resource.

OpenID Connect enables identities of participants to be securely established but doesn’t answer the question of whether a participant is trusted to access a resource such as your personal data.  A complementary mechanism is needed to do that.  In small-scale and static deployments, it’s possible to keep a list of the trusted participants.  However, in large-scale and dynamic deployments, that doesn’t scale.

This presentation will describe how the OpenID Connect Federation protocol enables scalable trust establishment with dynamic policies.  It does so by employing trust hierarchies of authorities, each of which are independently administered.  Examples of authorities are federation operators, organizations, departments within organizations, and individual sites.

Two OpenID Connect Federations are deployed in Italy, enabling secure access to digital services operated by Italian public and private services with Italian digital identities.  This presentation will also describe why OpenID Connect Federation was selected for them and how it meets their needs.  OpenID Connect Federation is being used by the GAIN PoC.  A public deployment is also being planned in Sweden.

How do You Know Who to Trust?
Event Recording
How do You Know Who to Trust?
Click here to watch the recording of this session. Please note that this video is only available to event participants and subscribers. You'll need to log in to watch it.
How do You Know Who to Trust?
Presentation deck
How do You Know Who to Trust?
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Dr. Michael B. Jones
Dr. Michael B. Jones
OpenID Foundation
Michael B. Jones is on a quest to build the Internet’s missing identity layer. He is an editor of the OpenID Connect specifications, IETF OAuth specifications, including JSON Web Token (JWT)...
Giuseppe De Marco
Giuseppe De Marco
Dipartimento per la Trasformazione Digitale
Giuseppe is an expert in Digital Identities, Authentication and Authorization Infrastructures and trust ecosystems, with a solid background in software development, systems administration and...

Best and Worst Practices of Digital Wallets User Experience

Digital identity wallets are central components for Decentralized and Self-Sovereign Identity (SSI) approaches. They are the interface for users to manage their identities and gain access to services. Hence, the usability and user experience of these wallets is pivotal for the adoption of those popular and privacy friendly identity management concepts.  This talk will summarize research findings into naming some of the Best and Worst Practices to be considered in the further development of the user experience of Digital Wallets.

This talk would highlight multiple studies, publications, and projects that I have done on this topic.  However, if you would prefer another topic, I could propose another talk idea that would be related to other identity topics in either the Digital Wallets, mGov/eGov Services, or Trust Management.

Best and Worst Practices of Digital Wallets User Experience
Event Recording
Best and Worst Practices of Digital Wallets User Experience
Click here to watch the recording of this session. Please note that this video is only available to event participants and subscribers. You'll need to log in to watch it.
Best and Worst Practices of Digital Wallets User Experience
Presentation deck
Best and Worst Practices of Digital Wallets User Experience
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Rachelle Sellung
Rachelle Sellung
Fraunhofer IAO
Rachelle Sellung is a Senior Scientist Researcher in the Identity Management Competence Team at Fraunhofer IAO in Stuttgart, Germany. She conducts socio-economic and user experience research on a...
Subscribe for updates
Please provide your email address