Open wfolkendt opened 4 months ago
Thank you for your input. We agree that the ARF should provide clearer guidance on the definition of a legal person and its implications for attestations and wallets used by legal entities. For example, it should clarify whether legal-person wallets must be controlled by natural persons and better address the delegation process—specifically, when to issue an attestation to a legal person versus authorizing a natural person to represent them.
However, we must stress that your suggestion for a legal-person wallet to function as a Holder (User), Relying Party, and EAA Provider is not aligned with the Regulation. Additionally, the development of the legal-person wallet concept is still in progress within the ARF, and further details will be addressed in future updates.
Description
As a legal person I want to have an EU Digital Identity Wallet (EUDIW) for legal entities which allows me to act as Holder, Relying Party and also EAA Provider in order to issue attestations to my employees (e.g. company ID, mandates, power of attorney) or EAAs which have an product/object as the subject (e.g. material composition, product carbon footprint) and need to be exchanged in supply chains or with authorities (e.g. tax authorities , notified bodies). As a legal person I have several internal IT systems that contain the authentic data (e.g. human resource databases or product data bases) and that integrate the EUDIW wallet core component (WCC) as a backend system. The EUDIW is used to sign EAAs and to transfer the EAAs to the holder wallets.
Problem Description: As a legal person with an EUDIW I need at least one designated “EAA-Provider”-public/private key pair managed by the EUDIW and a mechanism to enable unknown Relying Parties to get access to my public key and my legal PID (LPID) that attests my legal person identity.
Solution Description based on “EAA Provider-LPID Chaining” mechanism:
Significant benefit and advantage of “EAA Provider-LPID Chaining”:
User Story
User: legal person as User Goal: Enable millions of legal entities to become EAA provider simply by using their EUDIW Reason: In several organizational identity use cases of the Europeean Wallet Consortium (EWC) a power of attorney or employee mandate attestation is required. Within the travel use cases the “Hotel Check In” scenario requires
Acceptance Criteria
Priority
High:
Estimates
Has to be estimated by ARF expert group
Presentation that explains the mechanism developed within the European Wallet Consortium (EWC) and the IDunion publicly funded project from Germany: [##https://nextcloud.idunion.org/s/enZDRWaTMtXttWM] For additional questions please contact: werner.folkendt@de.bosch.com