How Does Europe Build Trusted Digital Identity?

57 views
•
August 22, 2022
by
RSAC Cybersecurity
YouTube video player
How Does Europe Build Trusted Digital Identity?

TL;DR

Europe’s proposed identity ecosystem gives every citizen access to a digital identity and wallet that must work across member states, while leaving use voluntary. Its issuer, holder, and verifier model aims to combine interoperability, security, privacy, user control, and usability, with self-sovereign identity and decentralized blockchain infrastructure presented as attractive options rather than mandatory technologies.

Transcript

Yeah. Ladies and gentlemen, welcome to the session Europe Get Its Identity Back. And, um, you know, what do we want to express, uh, with this statement? Um, what we want is, uh, we want to discuss about SSI, Self-Sovereign Identity ecosystems for European identities. And, uh, look at the picture. Here you see the architecture or one possible archit... Read More

Key Insights

  • Self-sovereign identity uses three principal roles: an authorized issuer creates a signed verifiable credential, a holder stores and controls it, and a verifier checks it when the holder presents selected identity information to an application.
  • Verifiable credentials can represent identity cards, driver licenses, certificates, or classifications. Their issuer signatures allow other parties to check them, while secure transfer into the holder’s wallet supports controlled use across applications.
  • The holder independently decides which identity data to disclose from a secure wallet. This user-centric arrangement is intended to increase privacy because an application receives information selected by the user instead of obtaining it directly from the issuer.
  • A decentralized blockchain infrastructure can act as a security layer between issuers, holders, and verifiers. It stores cryptographic and issuer metadata in a tamper-proof manner, enabling applications to verify presented credentials without directly contacting the issuing organization.
  • The European identity scheme is technology agnostic rather than dependent on one self-sovereign identity or blockchain implementation. SSI principles offer privacy and user sovereignty, but governments are still researching variants and may adapt existing national identity ecosystems.
  • The revised eIDAS framework requires every European Union member state to issue a digital identity and recognize identities issued by other member states. Citizens are not required to use their digital identity, even though one must be available to them.
  • Interoperability and security require a uniform set of standards across the European ecosystem. National authorities can govern how identity is presented, while regulated wallet interfaces and trust requirements provide a shared foundation for cross-border recognition.
  • Digital identity is central to cybersecurity because authentication and authorization increasingly protect hybrid IT operations, cloud access, and relationships involving supply-chain partners. A trusted European identity ecosystem can therefore serve as a foundation for broader cybersecurity infrastructure.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: What is self-sovereign identity in the European identity ecosystem?

Self-sovereign identity is a user-centric model in which authorized issuers create signed verifiable credentials, holders keep those credentials in secure wallets, and verifiers check credentials presented to applications. The holder independently decides which identity information to disclose. The model aims to support privacy, trustworthiness, and secure digital services without requiring a direct connection between each application and the original issuer.

Q: How do verifiable credentials work in a secure identity wallet?

An authorized organization issues and signs a verifiable credential, which can represent an identity card, driver license, certificate, or classification. The credential is securely transferred to the holder’s wallet. When an application needs proof, the holder selects the relevant identity information and presents it. The application then uses cryptographic information from the identity infrastructure to verify the credential rather than contacting the issuer directly.

Q: What role does blockchain play in self-sovereign identity?

A decentralized blockchain network can provide a trust and security layer connecting issuers, holders, and verifiers. The infrastructure stores cryptographic information and issuer metadata in a tamper-proof manner. Applications can use that information to verify credentials presented by users. Blockchain is described as one attractive technical approach, but the European framework does not require every national identity system or wallet to use a specific SSI blockchain implementation.

Q: What changes does the revised eIDAS framework introduce?

The revised eIDAS framework is intended to ensure that every European Union member state issues a digital identity and recognizes identities issued by other member states. Under the earlier approach described by the panel, issuance was voluntary for member states, which also limited obligatory recognition. Citizens may still choose not to use their digital identity, but a recognized identity must be available to them.

Q: Why are common standards needed for European digital identities?

Common standards are needed so digital identities and wallets can work securely across national borders. They establish how interoperability is achieved, how wallet interfaces are called, and how a wallet can be recognized as trusted. National governments may retain authority over how identities are presented, but shared technical and security requirements allow credentials from one member state to be recognized within another member state.

Q: Is the European digital identity wallet required to use blockchain?

The European digital identity wallet is not necessarily an SSI blockchain wallet. It can be software that holds identity information in a specified form or links to a trusted identity source. The proposed European scheme is described as technology agnostic. SSI and blockchain approaches are being researched and tested, while governments may continue developing existing national systems that comply with common interoperability, security, privacy, and trust requirements.

Q: How does the European identity ecosystem protect user privacy?

The ecosystem protects privacy by making the holder an active participant in disclosure decisions. A user can choose which identity data to send from a secure wallet to an application, rather than allowing unrestricted access to all available information. Signed credentials and cryptographic verification provide trust, while the absence of a required direct connection between the application and issuer can further support user control over data sharing.

Q: Why is digital identity important for cybersecurity?

Digital identity is important because authentication and authorization determine who can access systems and what they are permitted to do. The panel connects this role to hybrid IT operations, cloud services, and trust relationships involving supply-chain partners. By creating interoperable and trusted identities, the European ecosystem can provide a security foundation for digital services while also addressing privacy, user control, and cross-border recognition.

Summary & Key Takeaways

  • A self-sovereign identity architecture separates issuers, holders, and verifiers. Authorized organizations issue signed verifiable credentials, such as identity cards, driver licenses, certificates, or classifications. Holders receive them in secure wallets and independently choose which identity information to provide to an application, without requiring a direct application-to-issuer connection.

  • A decentralized blockchain network can provide a trust and security layer among participants. It stores cryptographic and issuer metadata in a tamper-proof manner, allowing applications to verify credentials. However, the proposed European identity framework remains technology agnostic, and governments may retain existing national identity systems while researching self-sovereign identity approaches.

  • The revised eIDAS framework is intended to make digital identity issuance and cross-border recognition obligatory for European Union member states, while individual use remains voluntary. Common standards will address interoperability and security, national governance will shape identity presentation, and regulated wallet interfaces will support privacy, user choice, usability, and trusted services.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚