You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/en/defined-terms.rst
+78-48Lines changed: 78 additions & 48 deletions
Original file line number
Diff line number
Diff line change
@@ -1,10 +1,22 @@
1
1
.. include:: ../common/common_definitions.rst
2
2
3
-
..
4
-
Defined Terms and Acronyms
5
-
==========================
6
-
The terms *User*, *Trust Service*, *Trust Model*, *Trusted List*, *Trust Framework*, *Attribute*, *Electronic Attestations of Attributes Provider* or *Trust Service Provider (TSP)*, *Person Identification Data (PID)*, *Revocation List*, *Qualified Electronic Attestations of Attributes Provider* or *Qualified Trust Service Provider (QTSP)*, *Electronic Attestation of Attributes (EAA)*, are defined in the `EIDAS-ARF`_.
7
-
Below is the description of acronyms and definitions which are useful for further insights into topics that complement the IT-Wallet System and the interacting components.
3
+
Normative References
4
+
====================
5
+
6
+
Below the normative references and respective acronyms included in these Technical Specifications:
7
+
8
+
[CAD]
9
+
10
+
Legislative Decree No. 82 of March 7, 2005, as amended, containing the 'Digital Administration Code'.
11
+
12
+
[REF_ACCESSIBILITY]
13
+
14
+
Accessibility Guidelines for IT Tools as per Article 11 of Law 4/2004.
15
+
Directive (EU) 2019/882 of the European Parliament and of the Council of 17 April 2019 on the accessibility requirements for products and services.
16
+
17
+
[GL_DESIGN]
18
+
19
+
Design Guidelines for websites and digital services provided by public administrations, pursuant to Article 53, paragraph 1-ter of Legislative Decree No. 82 of March 7, 2005, as amended.
8
20
9
21
.. _defined-terms:
10
22
@@ -13,12 +25,16 @@ Defined Terms and Acronyms
13
25
14
26
This section aligns the IT-Wallet System's terminology with the definitions provided in ARF 1.10 (see `ARF Annex 1 <https://github.com/eu-digital-identity-wallet/eudi-doc-architecture-and-reference-framework/blob/main/docs/annexes/annex-1/annex-1-definitions.md>`_). For each term, the IT-Wallet definition is compared and mapped to the ARF definition, with notes on any differences or clarifications.
15
27
28
+
The terms *User*, *Trust Service*, *Trust Model*, *Trusted List*, *Trust Framework*, *Attribute*, *Electronic Attestations of Attributes Provider* or *Trust Service Provider (TSP)*, *Person Identification Data (PID)*, *Revocation List*, *Qualified Electronic Attestations of Attributes Provider* or *Qualified Trust Service Provider (QTSP)*, *Electronic Attestation of Attributes (EAA)*, are defined in the `EIDAS-ARF`_.
29
+
30
+
Below is the description of acronyms and definitions which are useful for further insights into topics that complement the IT-Wallet System and the interacting components.
31
+
16
32
.. glossary::
17
33
:sorted:
18
34
19
35
**Accreditation Process**
20
36
Process performed by the National Accreditation Body to accredit CABs, resulting in an accreditation certificate.
21
-
Identical to ARF 1.10.
37
+
Not present in ARF 1.10; specific to IT-Wallet.
22
38
23
39
**Attributes**
24
40
**User Attribute**
@@ -36,38 +52,37 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
36
52
37
53
**Certification Process**
38
54
Process by Conformity Assessment Bodies to certify the Wallet Solution, including periodic technical assessments.
39
-
Aligned with ARF 1.10.
55
+
Not present in ARF 1.10; specific to IT-Wallet.
40
56
41
57
**Conformity Assessment Body (CAB)**
42
58
Accredited body competent to assess/certify Wallet Solutions or trust service providers.
43
59
Aligned with ARF 1.10.
44
60
45
61
**Credential Issuer**
46
62
**Issuer**
47
-
**Attestation Provider**
48
63
Organizational Entity providing Digital Credentials to Users (may be PID Provider or (Q)EAA Provider).
49
64
ARF 1.10 uses similar terms; IT-Wallet merges PID and (Q)EAA Providers under this term.
50
65
51
66
**Credential Status Assertion**
52
67
**Status Assertion**
53
68
Signed document proving a Digital Credential's current validity status.
54
-
Aligned with ARF 1.10.
69
+
Not present in ARF 1.10; specific to IT-Wallet.
55
70
56
71
**Critical Assets**
57
72
Assets (e.g., cryptographic keys) whose loss would seriously impact the Wallet Unit.
58
73
Aligned with ARF 1.10.
59
74
60
75
**Cryptographic Hardware Key Tag**
61
76
Unique identifier for Cryptographic Hardware Keys, used to access the private key in hardware.
62
-
Aligned with ARF 1.10.
77
+
Not present in ARF 1.10.
63
78
64
79
**Cryptographic Hardware Keys**
65
80
Key pair generated by the Wallet Instance, valid for its lifetime.
66
-
Aligned with ARF 1.10.
81
+
Not present in ARF 1.10.
67
82
68
83
**Device Integrity Service**
69
84
Service by device manufacturers to verify app integrity and secure key storage.
70
-
Aligned with ARF 1.10.
85
+
Not present in ARF 1.10.
71
86
72
87
**Digital Credential**
73
88
**Credential**
@@ -76,20 +91,19 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
76
91
77
92
**Federation Authority**
78
93
Public governance entity issuing guidelines, rules, and managing trust lists and participant status.
79
-
Aligned with ARF 1.10.
94
+
Not present in ARF 1.10.
80
95
81
96
**Holder**
82
97
Person or entity that receives, manages, and presents Digital Credentials via the Wallet Instance.
83
-
Aligned with ARF 1.10.
98
+
Not present in ARF 1.10; specific to IT-Wallet.
84
99
85
100
**Holder Key Binding**
86
-
**Cryptographic Binding**
87
101
Ability of the Holder to prove possession of the private key attested by a Trusted Third Party.
88
-
Aligned with ARF 1.10.
102
+
Not present in ARF 1.10.
89
103
90
104
**Identity and Access Management (IAM)**
91
105
Framework for managing digital identities and access to information.
92
-
Aligned with ARF 1.10.
106
+
Not present in ARF 1.10.
93
107
94
108
**IT-Wallet System**
95
109
Set of Technical Solutions implementing the Italian Digital Wallet System.
@@ -101,31 +115,31 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
101
115
102
116
**Key Attestation**
103
117
Attestation from device OEM about secure key storage in hardware-backed keystore.
104
-
Aligned with ARF 1.10.
118
+
Not present in ARF 1.10.
105
119
106
120
**Level of Assurance**
107
-
- Degree of confidence in identity vetting and credential presentation.
108
-
- Aligned with ARF 1.10.
121
+
Degree of confidence in identity vetting and credential presentation.
122
+
Not present in ARF 1.10.
109
123
110
124
**Metadata**
111
125
Digital artifact with information about an Organizational Entity (endpoints, public keys, etc.).
112
-
Aligned with ARF 1.10.
126
+
Not present in ARF 1.10.
113
127
114
128
**National Accreditation Bodies (NAB)**
115
129
Body performing accreditation under authority from a Member State.
116
130
Aligned with ARF 1.10.
117
131
118
132
**National Identity Provider**
119
-
Preexisting identity systems (e.g., SPID, CIE) notified to eIDAS.
120
-
Aligned with ARF 1.10.
133
+
Preexisting identity systems (e.g. CIE) notified to eIDAS.
134
+
Not present in ARF 1.10.
121
135
122
136
**Notification Process**
123
137
Process for transferring information to the EC and inclusion in the Trusted List.
124
138
Aligned with ARF 1.10.
125
139
126
140
**Organizational Entity**
127
141
Legal person (organization or public entity) recognized to operate a role in the IT-Wallet ecosystem.
128
-
Aligned with ARF 1.10.
142
+
Not present in ARF 1.10; specific to IT-Wallet.
129
143
130
144
**Personal Identification Data**
131
145
A set of data which allow to establish the identity of a natural or legal person, or of a natural person representing another natural or legal person, to be established.
@@ -137,7 +151,7 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
137
151
138
152
**Policy Language**
139
153
Formal language for defining security, privacy, and identity management policies.
140
-
Aligned with ARF 1.10.
154
+
Not present in ARF 1.10; specific to IT-Wallet.
141
155
142
156
**Primary Actors**
143
157
Entities implementing Technical Solutions for the IT-Wallet System.
@@ -155,24 +169,27 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
155
169
Digitally verifiable attestation in electronic form, substantiating possession of attributes.
156
170
Aligned with ARF 1.10.
157
171
158
-
**Public Electronic Attestation of Attributes (Pub-EAA)**
172
+
**Electronic Attestation of Attributes issued by or on behalf of a public sector body (Pub-EAA)**
173
+
**Public Electronic Attestation of Attributes**
159
174
Electronic Attestation of Attributes that contains Attributes deriving from a public Authentic Source.
160
175
Aligned with ARF 1.10.
161
176
162
177
**Electronic Attestation of Public Interest**
163
178
**Credential of Public Interest**
164
179
Electronic Attestation of Attributes that contains Attributes intended to certify the release, by the State or other public administrations, of authorizations, certifications, qualifications, identity and recognition documents, receipts of revenue, or to assume a fiduciary value and protection of public faith afterwards their issuance or the entries made on them and, in general, when they are considered security documents pursuant to Article 2, paragraph 10-bis, Law 13 July 1966, no. 559.
180
+
Not present in ARF 1.10; specific to IT-Wallet.
165
181
166
182
**Person Identification Data (PID)**
167
183
Electronic Attestation that allows the subject to whom the Personal Identification Data refers to be authenticated.
168
184
Aligned with ARF 1.10.
169
185
170
186
**Qualified Electronic Attestation of Attributes Provider**
171
-
Entity providing QEAAs.
187
+
Organizational Entity providing QEAAs.
172
188
Aligned with ARF 1.10.
173
189
174
190
**Electronic Attestation of Attributes Provider**
175
-
Entity providing EAAs.
191
+
**Electionic Attestation Provider**
192
+
Organizational Entity providing EAAs.
176
193
Aligned with ARF 1.10.
177
194
178
195
**Qualified Electronic Signature Provider**
@@ -194,11 +211,11 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
194
211
195
212
**Relying Party Solution**
196
213
Product (software/hardware/cloud) enabling Credential presentations in various contexts.
197
-
Aligned with ARF 1.10.
214
+
Not present in ARF 1.10; specific to IT-Wallet.
198
215
199
216
**Relying Party Backend**
200
217
Remote infrastructure with server-side components managed by a Relying Party Solution provider.
201
-
Aligned with ARF 1.10.
218
+
Not present in ARF 1.10; specific to IT-Wallet.
202
219
203
220
**Relying Party Instance**
204
221
**Verifier App**
@@ -211,47 +228,47 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
211
228
212
229
**Self-Sovereign Identity (SSI)**
213
230
Approach giving individuals control over their digital identity information.
214
-
Aligned with ARF 1.10.
231
+
Not present in ARF 1.10.
215
232
216
233
**Supervision Process**
217
234
Process by a Supervisory Body to review and ensure proper functioning of the Wallet Provider and others.
218
-
Aligned with ARF 1.10.
235
+
Not present in ARF 1.10; specific to IT-Wallet.
219
236
220
237
**Technical Solutions**
221
238
Hardware/software systems and services implemented by Wallet Solution Providers, PID Provider, etc.
222
-
Aligned with ARF 1.10.
239
+
Not present in ARF 1.10; specific to IT-Wallet.
223
240
224
241
**Technical Specifications**
225
242
Specifications providing technical architecture, implementation framework, and design requirements.
226
243
Aligned with ARF 1.10.
227
244
228
245
**Trust**
229
246
Confidence in the security, reliability, and integrity of entities and their actions.
230
-
Aligned with ARF 1.10.
247
+
Not present in ARF 1.10.
231
248
232
249
**Trust Attestation**
233
250
Electronic attestation of compliance with the regulatory framework, cryptographically verifiable.
234
-
Aligned with ARF 1.10.
251
+
Not present in ARF 1.10.
235
252
236
253
**Trust Evaluation**
237
254
Process of verifying trustworthiness of registered Organizational Entities.
238
-
Aligned with ARF 1.10.
255
+
Not present in ARF 1.10.
239
256
240
257
**Trust Framework**
241
258
Legally enforceable set of rules and agreements for a multi-party system.
242
-
Aligned with ARF 1.10.
259
+
Not present in ARF 1.10.
243
260
244
261
**Trust Layer**
245
262
Architectural component enabling participants to establish trust.
246
-
Aligned with ARF 1.10.
263
+
Not present in ARF 1.10.
247
264
248
265
**Trust Model**
249
266
Collection of rules ensuring legitimacy of components/entities in the IT-Wallet ecosystem.
250
-
Aligned with ARF 1.10.
267
+
Not present in ARF 1.10.
251
268
252
269
**Trust Relationship**
253
270
Reliable relationship between Organizational Entities after Trust Evaluation.
254
-
Aligned with ARF 1.10.
271
+
Not present in ARF 1.10.
255
272
256
273
**Access Certificate**
257
274
Certificate authenticating and validating the (Wallet-) Relying Party.
@@ -263,7 +280,7 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
263
280
264
281
**Certificate Signing Request (CSR)**
265
282
Request sent to a CA containing the public key and identifying information for a digital certificate.
266
-
Aligned with ARF 1.10.
283
+
Not present in ARF 1.10.
267
284
268
285
**Trusted List**
269
286
Repository of information about authoritative entities and their status.
@@ -274,8 +291,9 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
274
291
Aligned with ARF 1.10.
275
292
276
293
**Verifier**
277
-
Also known as Credential Verifier; a person or entity using a Relying Party Instance.
278
-
Aligned with ARF 1.10.
294
+
**Credential Verifier**
295
+
A person or entity using a Relying Party Instance.
296
+
Not present in ARF 1.10; specific to IT-Wallet.
279
297
280
298
**Wallet Instance**
281
299
Application installed on a User's device, part of the Wallet Unit, providing user interfaces.
@@ -313,10 +331,12 @@ This section aligns the IT-Wallet System's terminology with the definitions prov
313
331
314
332
**Digital Credential Catalogue**
315
333
Electronic catalog containing information about the formats and schemes of Digital Credentials, the data contained and the Authentic Sources. The Catalog contains additional information that allows for the establishment of the authenticity and reliability of the information contained therein.
334
+
Not present in ARF 1.10; specific to IT-Wallet.
316
335
317
336
**Intermediate Entity**
318
-
**Intermediate**
337
+
**Intermediary**
319
338
Intermediate Entity as defined in `OID-FED`_ Section 1.2, for example in IT-Wallet it could be a Relying Party intermediary that offers and manages, on behalf of Relying Party, the Technical Solutions for the remote or proximity verification of Electronic Attestations.
339
+
Aligned with ARF 1.10.
320
340
321
341
.. note::
322
342
For any term not present in ARF 1.10, the IT-Wallet definition is provided as authoritative for the Italian context.
@@ -387,23 +407,33 @@ Below are the main acronyms used in the document:
387
407
* - **AAL**
388
408
- Authenticator Assurance Level as defined in `<https://csrc.nist.gov/glossary/term/authenticator_assurance_level>`_
389
409
* - **ANPR**
390
-
- Italian National Registry of the Resident Population
410
+
- Anagrafe Nazionale della Popolazione Residente (Italian National Registry of the Resident Population)
391
411
* - **API**
392
412
- Application Programming Interface
413
+
* - **CAB**
414
+
- Conformity Assessment Body
393
415
* - **CIE**
394
-
- National Electronic Identity Card
416
+
- Carta di Identità Elettronica (National Electronic Identity Card)
417
+
* - **EAA**
418
+
- Electronic Attestation of Attributes
395
419
* - **IAM**
396
420
- Identity and Access Management
397
421
* - **LoA**
398
422
- Level of Assurance
423
+
* - **NAB**
424
+
- National Accreditation Body
399
425
* - **OID4VP**
400
426
- OpenID for Verifiable Presentation
427
+
* - **PDND**
428
+
- Piattaforma Digitale Nazionale Dati (National Digital Data Platform)
401
429
* - **PID**
402
430
- Person Identification Data
403
431
* - **PII**
404
432
- Personally Identifiable Information
405
-
* - **SPID**
406
-
- Italian Public Digital Identity System
433
+
* - **QEAA**
434
+
- Qualified Electronic Attestation of Attributes
435
+
* - **Pub-EAA**
436
+
- Electronic Attestation of Attributes issued by or on behalf of a public sector body
Copy file name to clipboardExpand all lines: docs/en/user-attribute-deletion.rst
+1-1Lines changed: 1 addition & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -35,7 +35,7 @@ This Wallet Instance functionality allows Users to obtain a list of all Relying
35
35
**Steps 7 - 8:** The Wallet Instance redirects the User to the Erasure Endpoint. It MUST also ensure that a callback mechanism to allow the User-Agent to notify the Wallet Instance (and thus the User) after the Erasure Response is present. Details on the Erasure Request can be found in :ref:`relying-party-endpoint:Erasure Request`.
36
36
37
37
.. note::
38
-
The Relying Party web page will authenticate the User with an appropriate Level of Assurance using any method such as SPID/CIE or the PID presentation. The specific mechanism used for authentication is left to the Relying Party. Upon authenticating the User, the Relying Party MAY prompt the User to perform additional steps needed for the deletion of attributes, e.g., it might require the User to confirm the deletion operation.
38
+
The Relying Party web page will authenticate the User with an appropriate Level of Assurance using any method such as CIE or the PID presentation. The specific mechanism used for authentication is left to the Relying Party. Upon authenticating the User, the Relying Party MAY prompt the User to perform additional steps needed for the deletion of attributes, e.g., it might require the User to confirm the deletion operation.
39
39
40
40
**Step 9:** Upon successful authentication of the User the Relying Party MUST delete all attributes bound to the User in its possession.
0 commit comments