W3C

VCWG Product and Wallet Vocabularies

20 July 2026

Attendees

Present
carolynn_bernier, carsten_stöcker, christian_fries, dr._susanne_guth-orlowski, fireflies.ai_notetaker_miguel, ingo_wolf, ivan_herman, ivo_ladenius, ivo_ladenius_gs1_netherlands, m.-a._wolf, phil_archer, ronald_koenig, sebastian_schmittner
Regrets
-
Chair
-
Scribe
transcriber

Meeting minutes

Introduction Of New Participants

Ivo_Ladenius: Good afternoon.

Phil_Archer: Hello.

Carolynn_Bernier: Good

Carolynn_Bernier: Afternoon. Can you hear me?

Phil_Archer: Yes.

Carolynn_Bernier: I see that there is someone called Schmidler in this meeting.

Phil_Archer: Yeah, he's a member of the group. Don't worry.

Sebastian_Schmittner: Yeah. Hi.

Carolynn_Bernier: Hi. just Sebastian just so I know you're from which organization and…

Sebastian_Schmittner: European EPC competent center. I can't type this in the chat.

Carolynn_Bernier: your interest is for rather wallets or Great Cooper.

Sebastian_Schmittner: Both actually

Carolynn_Bernier: Kirsten, if you don't mind, I would like to use this meeting to talk about DPP.

Carsten_Stöcker: It's DPP time this week.

Carolynn_Bernier: It's DPP time.

Carolynn_Bernier: Just so I will disappear from all electronic forms of communication for the next 3 weeks.

Phil_Archer: Have a good time.

M.-A._Wolf: You are smart.

M.-A._Wolf: That's for sure anyway.

M.-A._Wolf: But this is the evidence.

Carolynn_Bernier: Okay.

GitHub Merge Conflict Resolution

Carolynn_Bernier: So, it's too bad an Ivan is here. I need his help to resolve a GitHub merge conflict. so first of all, I would like to apologize to everybody. Yes. Ian. Hi.

Ivan_Herman: Yeah, I had to find the right button. just forget about it and in your copy add the additional attribute in the HTML file and that's it.

Carolynn_Bernier: So, it's Yeah.

Ivan_Herman: The one which is in the PR and then close the merge conflict is always a mess.

Carolynn_Bernier: So that you're talking about the format two points markdown.

Ivan_Herman: Yeah, that forget about the markdown five. It was okay. I tested it a little bit and that's why probably there is a conflict in the index.html file where you can find it. what? Let's take that after that.

Carolynn_Bernier: No, but I know exactly what you're talking about. I think you're talking about line 18 in the index.html. you added format two points markdown. Is this what you're No.

Ivan_Herman: No, no, no. that one as well and the later at the very end in the section include.

Carolynn_Bernier: So I don't know what you're talking about.

Ivan_Herman: Yeah, that's one

Carolynn_Bernier: So as I suggest…

DPP Use Case Document Review

Carolynn_Bernier: so first of all I'd like to apologize to the group because since our meeting on the 29th of June where you provided a lot of feedback to improve the document that we're working on. I hadn't time to actually integrate your comments into the document. I started to do it today. I'm not quite done, but I would like to share with so I'm just going to put the link to the GitHub in the chat so that the sub subsidiary of GS1 Germany and Schwarz Group.

Carolynn_Bernier: Interesting. Yeah, sure.

Sebastian_Schmittner: Yeah, I can do a short introduction if you like. Yeah. Hi everybody. I guess I've seen most people, but in case you don't know Yeah. ECC, we're a small company. Indeed, subsidiary GSM Germany and Trouts Group. and also some shares with our co and I've been in SSI for I don't know 7. eight years working in ID union ID ideal so the German SSI projects the funded projects and we're mostly working with GS1 Germany trying to establish a business wallet so we do have a production wallet developed so this is why I'm obviously interested in the wallet part of this group and we do also work quite a bit on digital product passport stuff we do more with Schwartz's group

Sebastian_Schmittner: And interested to get to know what you guys are working on.

Carolynn_Bernier: Okay, great.

Carolynn_Bernier: Welcome to the group. Just checking if anybody else knew from last time. there's a Christian fries.

Christian_Fries: yellow Chris tries the same story. I just dropped in here because we are intrigued what's going on in the wallet environment.

Christian_Fries: So I just popped by I don't know if I'm can listen to it. You can tell me

Carolynn_Bernier: So you're welcome to stay…

Carolynn_Bernier: if you want in today's meeting. So, we tend to alternate every second week between the topic of the business wallet and the topic of the I'm leading the DPP activities and Karsten is leading the wallet activities. So today we were going to talk about the DPP and…

Christian_Fries: Thank you very much.

Carolynn_Bernier: next week on the wallet. So you can drop out and have some free time and do something else or You're welcome to stay. Because we have this dual topic thing. I prefer to let people understand why are they staying in the meeting?

Carolynn_Bernier: so that we avoid wasting people's All right. So on the DP coming back to the DPP topic as you know we are we started to write a use case note on DPP and the DPP secured by verifiable credentials. so if you go here, you should see so that's the markdown, but if you go here, you will see the HTML version of the documents.

Dr._Susanne_Guth-Orlowski: Are you sharing anything or am I the only person that doesn't see it?

Carolynn_Bernier: I'm sharing my screen.

Carolynn_Bernier: I just put the link to the document in the chat but if you want I can share my screen.

Dr._Susanne_Guth-Orlowski: Why not? Then we can all look at the same thing.

Carolynn_Bernier: All right. So I'm just going to share this screen here. So last time I shared with you a preliminary version of this use case document. So can you see my screen? Yes. Yeah.

Ivo_Ladenius: Yes.

DPP Document Structure And Scope

Carolynn_Bernier: So, I changed following the discussion that we had, I'm in the process of fixing the issue with the numbering of the paragraphs. I don't want them to be subheadings of number one. So, this is the issue Ivan and I were talking about. so there's a few things that I wanted to show So I added an abstract to this document to be reviewed by everybody. I also changed a little bit the structure of the document to talk about DPSPs in international value chains. This was to answer Suzan's questions about the scope of the document.

Carolynn_Bernier: And Suzanne added here a figure and here basically I provided some elements of scope to be again read and pro proof read by and also a little bit more details about the scope the first part of the document is why are verifiable credentials useful for DPPS? and we have a number of use cases. I have not completed it with the contributions provided by last time. so Rio mentioned that we could talk about legal evidence and…

Ivan_Herman: It's awesome.

Carolynn_Bernier: we could also talk about quantum resistance as well. So I have not added that yet. Also I want to split this section into two different sections.

Carolynn_Bernier: one for selfissued and…

Carolynn_Bernier: self-hosted DPPs and a second for third party held DPSPs. So this long list of use cases where VCs provide additional capabilities with respect to HTTPS. I want to split these into two families of use cases. One for self-hosting and one for third party hosted BVPs.

Dr._Susanne_Guth-Orlowski: And… Dr. Susanne Guth-Orlowski:

Dpp Issuer Holder Verifier Model Discussion

Dr._Susanne_Guth-Orlowski: why is that conceptually different?

Carolynn_Bernier: Because I think that we have to be clear that in the DPP case we are not necessarily in the issuer holder verifier model…

Carolynn_Bernier: which is typical of verifiable credentials.

Dr._Susanne_Guth-Orlowski: But I wouldn't agree to that I think we're completely in that model. If someone does it for me, then I'm still I mean technically does that for me that's fine.

Dr._Susanne_Guth-Orlowski: But conceptually that's still the holder issuer verifier model.

Carolynn_Bernier: If…

Carolynn_Bernier: if I'm a responsible economic operator and…

Dr._Susanne_Guth-Orlowski: Mhm. Yeah.

Carolynn_Bernier: I'm creating my own DPPs, I'm the issuer and the holder.

Dr._Susanne_Guth-Orlowski: But no problem with

Carolynn_Bernier: It's not a problem. it's slightly different from the normal VC use case where you have an issuer that is one organization, a holder that's another organization and a verifier that's another organization. It's not a problem. It's just so if the issuer is a holder, does it make sense to issue the DPP as a verifiable credential is the question I'm trying to answer.

Carolynn_Bernier: No. I'm not saying there is no reason not to do it,…

Dr._Susanne_Guth-Orlowski: But yeah, why wouldn't it be? I mean, you can selfissue something.

Carolynn_Bernier: but because it departs from the normal case of using feces. Carolynn Bernier:

Dr._Susanne_Guth-Orlowski: I'm not sure…

Dr._Susanne_Guth-Orlowski: if that's the normal case of having issue a holder and verify three different parties. I would understand if you would say there's a different level of security or a different level of you may trustworthiness maybe but then that depends on how I identify or verify the issuer but conceptually that's still the same thing for me. I wouldn't separate it out is…

Dr._Susanne_Guth-Orlowski: what I'm trying to say.

Carolynn_Bernier: For me,…

Carolynn_Bernier: a VC by definition is the fact that a holder has data that has been issued by somebody else but there are claims about himself,…

Carolynn_Bernier: the holder, but the data was issued by somebody else. my identity papers are issued by the Ministry of the Interior, but I'm the holder of that. Okay. Yeah.

Dr._Susanne_Guth-Orlowski: Yeah, I see completely…

Dr._Susanne_Guth-Orlowski: where you're coming from. you think that we need three parties. I'm just saying I don't think we need three parties. If I'm issuing my own DPP as a verifiable credential, then everyone can check who issued it,…

Dr._Susanne_Guth-Orlowski: which is the same party who holds it, but it just says that I issued it. And the concept is the same no matter where the verifiable credential is found.

Carolynn_Bernier: So I agree with you that we want to Is it in?

Carolynn_Bernier: Because 9% of people who work in the field of verified credentials come with the issuer holder verifier or different organizations model in mind. And here we're saying we're using it differently because the issuer and the holder can be the same organization and there

Dr._Susanne_Guth-Orlowski: I'm not Yeah, I don't think that this is true that we use it differently.

Carolynn_Bernier: Mhm. Ethan.

Dr._Susanne_Guth-Orlowski: But maybe others Yeah, even

Ivan_Herman: Yeah, I think the difference between you two is that the differentiation between order verifier and…

Ivan_Herman: issuer is in the functionalities that they perform not that they are same or different and the fact that there is an entity which is for example an issuer and a holder at the same time is probably something that does exist out there. So it's not necessarily true that the three are sort of physically or in a virtual space they are different entities. It's a matter of the functionalities they perform.

Ivan_Herman: And in this respect, I agree with Susan that there is real difference functionalitywise whether the two the three or…

Ivan_Herman: two out of the three are the same entity.

Carolynn_Bernier: Yes,…

Carolynn_Bernier: I'm just saying it's an unusual way to use verifiable credentials which may be surprising to people. that's all.

Carolynn_Bernier: I don't know if there are many other maybe you've ran into multiple use cases where the issuer is the holder. I don't know.

Carolynn_Bernier: Have you? Mhm.

Ivan_Herman: I am not the person to ask…

Ivan_Herman: because I'm not in the practical field, but the situation would not really be a shock to me that if an issuer and a hoarder is the But okay,…

Dr._Susanne_Guth-Orlowski: So I think we would more confuse Yeah.

Ivan_Herman: I understand that from a use case point of excuse me Susanna.

Dr._Susanne_Guth-Orlowski: No, I think we more confuse people if we say this is a different usage of verified credentials. I don't think it creates clarity for me if I would read that it would create more confusion.

Carolynn_Bernier: Perhaps for for me, it's because of what Ivan said about the functionalities of the issuer and the holder that are different, how that relates to the DPP issuer. and the DPV holder…

Carolynn_Bernier: who are actually the same entities. I need to understand how this relates to what's going to happen that I really understand what is the value of the VC in this case. I really need to understand this. Mar Andre your hand is up.

M.-A._Wolf: Yeah, thank you.

M.-A._Wolf: Maybe it's enough to say this is one of the subtypes of ent self issued verifiable credential versus yeah with an issuer not by the hold of the same entity we have it in our domain for reviews there's an internal revenue and external dependent independent it's all a review but it has an of course different assurance level and you say I agree that people may be surprised that the holder is the one who issues

M.-A._Wolf: Is it this case it could then be identified as a subtype whether it's common or less common is not so important I think it's technically the same what I understand but the assurance level is different and…

M.-A._Wolf: this could be clarified by saying it's a safe issued one

Carolynn_Bernier: For me,…

Carolynn_Bernier: its It's more a question of because a DPP could be self-issued or could be third party held. So, it's not a question of subtype. It's more of a question of value. what are the functionalities that are enabled

M.-A._Wolf: Mhm.

Carolynn_Bernier: if the DPP is self-held or…

Ivan_Herman: Okay.

Carolynn_Bernier: if it's third party held what are the new features that become possible that's what I'm interested in understanding Sebastian your hand is

Sebastian_Schmittner: Yeah, you are currently discussing what to put as the subject, So the credential subject ID essentially and…

Carolynn_Bernier: Yes.

Sebastian_Schmittner: whether that holder would be the same dead as the issuer, so what we usually do when we issue DPP credentials we put the identity of the thing that we are issuing facts or attestating facts about as the credential subject ID because I mean if we did often organization say as the credential subject ID it would look like to me semantically as far as I understand the VC data model,…

Ivan_Herman: Thank you.

Sebastian_Schmittner: it would look like we're at stating some facts about that company. we're talking about facts of a product.

Sebastian_Schmittner: So, we put usually the products into the credential subject ID field. I don't know if this kind of matter has been discussed in this group already.

Carolynn_Bernier: I think I misunderstood your question.

Carolynn_Bernier: The credential subject is indeed the product. The question is who issued it? So the key of the issuer and the key yes the issuer ID and…

Sebastian_Schmittner: So you're talking about the issuer ID,…

Sebastian_Schmittner: not the credential subject ID.

Ivan_Herman: What's that?

Carolynn_Bernier: the holder ID.

Sebastian_Schmittner: Yeah, but I mean who's the holder? Usually the holder would be the credential subject ID. Yeah, that's…

Carolynn_Bernier: I know because the product is not a holder.

Sebastian_Schmittner: what I'm saying. I mean for a digital I mean what you mean by a holder? that's the question in the first place. usually the holder of the verifiable usually if you talk about I don't know an electronic ID credential or something you want to have holder binding in the sense that only a certain person in this case can present a credential so holder binding in this sense is why you usually have this holder in this SSI triangle thing right but this concept doesn't really make sense for I don't

Sebastian_Schmittner: products. So I don't know some object doesn't present something on its own. So we don't need to cryptographically bind the credential to I don't know some object so that only this object can present the credential.

Ronald_Koenig: Thank you.

Sebastian_Schmittner: So certainly we don't need holder binding in this sense. and yeah as I said so what we usually do is we put the credential subject ID we put an identifier of the actual thing we're talking about and…

Sebastian_Schmittner: we do not use holder binding for DPP credentials but yeah…

Carolynn_Bernier: I think we Yeah,…

Carolynn_Bernier: we agree.

Sebastian_Schmittner: but it's kind of like a big topic I don't know if this has been discussed in the group already I don't want to completely steer the conversation of topics.

Carolynn_Bernier: No, no, no, no, no, no, no, no. This is a good comments, Suzanne.

Dr._Susanne_Guth-Orlowski: Yeah. …

Dr._Susanne_Guth-Orlowski: of course I agree to what Sebastian said. and we touched it last time when we were discussing this by saying, do we actually need a verifiable presentations in here? because that's kind of used in this holder binding use. so it's the related to that discussion and the other point that I wanted to say is we made the distinction in the recommendation 49 as well where we said if we're using verifiable credentials or electronically signed documents What?

Dr._Susanne_Guth-Orlowski: are the services that we get from this To get everyone on the same page. Therefore, I added the very first three points I think it is to this list and say first of all I can check the authenticity of the DPP. So meaning that I know who issued the DPP. I know that then I know or I can use non-repudiation which is just the regular things that you can do from digital signatures. Yeah. the issuer cannot claim that he did not issue the DPP which is also a service of electronic signatures in general.

Dr._Susanne_Guth-Orlowski: then I can detect the modification of a DPP saying so I understand that the integrity of the DPP can be secured just in the same way as with any other digitally signed document and that's what you can do and then you can use it for typical DPP use cases and I think maybe we should differentiate

Dr._Susanne_Guth-Orlowski: between the two that's also what we did in recommendation 49 direct use of verify credentials for DPP is this and then there is an almost unlimited list of indirect benefits that you can get from it in the environment of digital product pass such as increase the trust in DPP data…

Dr._Susanne_Guth-Orlowski: but why because you base on the previous three points yeah and I don't Yeah.

Carolynn_Bernier:

Carolynn_Bernier: what you would say is these three here they're like

Dr._Susanne_Guth-Orlowski: I think it's these three. if someone has a better I mean please review it and if someone wants to change it. That's my usual three things that I use for digital signature since 20 years and I've been building on top of that various different services like digital rights management for video files, stuff like that. So, it's always the same. And then in the context of digital product passports, that means we can do this and this and this and this with it.

Dr._Susanne_Guth-Orlowski: For example, we can do updates in the supply chain, but we know that the issuer is someone different, maybe the one who repairs the battery and issues, I don't know, or maybe that's a stupid example because then you have to issue a new product passport. Let's say we have an auditor that issues a certificate about the state of health, but then it has been issued by the auditor and not by the economic operator. And we can see all that and that's the use of these features in the context of disha passports and…

Dr._Susanne_Guth-Orlowski: that's what we can describe but in the end it always comes back to the first three

Carolynn_Bernier: Mhm. …

Carolynn_Bernier: so I think that if you say these first three they refer to the use case for digital signatures that's fine but VCs go beyond just being digital signatures. It's also about machine readable interoperable data.

Carolynn_Bernier: Carson,…

Carsten_Stöcker: I also want to say this.

Ivan_Herman: Close.

Link Data's Usefulness For Dpp

Carsten_Stöcker: I saw yet multiple research activities about knowledge graphs. Yeah. And with the linked data character of the VCs, this is advantageous. And now we see a lot of research in terms of feeding linked knowledge graph data into AI models.

Carolynn_Bernier: I put here some place…

Carsten_Stöcker: And this is Yeah.

Carolynn_Bernier: where you'll be able to add content. Karsten, thinking about what you said,…

Carolynn_Bernier: I added this chapter. Why is link data useful for DPSPs? so there are several reasons and the one you're referring to is this one.

Carsten_Stöcker: There you go.

Carolynn_Bernier: So I suggest that you provide some text to describe very summarized a few sentences that summarize possibly provide a reference to this.

Carsten_Stöcker: Yeah.

Carolynn_Bernier: So I would like to come back to…

Carsten_Stöcker: And I will definitely do this. And now I'm finding multiple research of comp of universities supporting this argument really really this with high quality facts. Good.

Carolynn_Bernier: what Sebastian. Yes, Ian.

Ivan_Herman: or…

Ivan_Herman: do you want to come back to the previous topic?

Carolynn_Bernier: No, go ahead.

Ivan_Herman: No. are we getting into the link data useful for DPP's topic or not?

Carolynn_Bernier: Mhm.

Dr._Susanne_Guth-Orlowski: I just wanted to say that of course I agree we have electronic signatures it gives us services and…

Dr._Susanne_Guth-Orlowski: then we can talk about I don't know interoperability some say yeah or I don't know semantic interoperability that's of course an additional topic that we have in fiber credentials fine with me to you use cases there at a different section.

Carolynn_Bernier: So before we go to the link data topic, I would like to come back to what Sebastian said about the fact that there is no holder binding and the fact that in the normal VC use.

Carolynn_Bernier: case you have the credential subject being the holder and this is the completely of course different topic different appro way to use verifiable credentials in our context here and I wonder again for me this is again an unusual way to use verifiable credentials someone coming from the identity use of VCs may be surprised by this unusual approach to using verify credentials or maybe it's just me that I find this unusual but I wonder if this needs to be explained if or…

Carolynn_Bernier: if this will be obvious to everybody.

Carolynn_Bernier: I was just thinking that it would be useful to describe how we are exploiting VCs in the topic of DPP and how that departs from the normal identity way to use Ronald, do you have

Ronald_Koenig: Yeah, for me there is a little bit missing …

Ronald_Koenig: why we are want to have verifiable credentials here because if I only take the first three points verifiable credentials are not required at all because this are signed documents only. This is nothing with a trust model of verifiable credentials. This is what I can reach if I take a document and sign it. But this is not a ial from my point of to a rifiable credential in this issuer holder verifier is that the issuer makes a statement about something. So as Sestian say this credential subject can prove against the third party that someone else has made claims about it and can prove against this one that this claims are about him and therefore we need verifiable presentations and verifiable credentials.

Ronald_Koenig: But if you only have a document which should be authentic and should have non-repudg cannot be questioned and…

Ronald_Koenig: that every modification of the DPP is recognized okay this is just a signed document it's nothing more and…

Carolynn_Bernier: Mhm. So…

Ronald_Koenig: I think the really value of course you can make selfisssued credentials and you can also present a credential without a verifiable presentation and holder binding and all this one. But this is a very specific case where the real value of a verifiable credential is not really used. So

Carolynn_Bernier: there's a long list of reasons right have you looked at this list Ronald have you and

Carolynn_Bernier: here I'm inviting everybody to proofread this list and tell me have we covered the reasons why we believe VCs are useful in this have we explained it properly because today I don't know if we have explained it properly but the whole for me this group the value of the work we're doing is to make this list a good one to make a very good case for

Carolynn_Bernier: Ian,…

Ivan_Herman: two different things.

Ivan_Herman: One is that you made a statement at some point to say that the holder ID is the same as the subject that is not correct. the holder is different than the subject of the verifiable credential. But probably it was misunderstanding. the credential subject is the holder is the wallet for example I mean the identity is not the person…

Carolynn_Bernier: so how does binding happen if the holder and the credential subject are different. okay.

Carolynn_Bernier: Okay.

Ivan_Herman: who is id So that's very different. I think the one aspect which is sort of missing is the emphasis on the possibilities offered by verifiable presentations and the fact that a verifiable presentations is able to combine several credentials together in one consistent entity. that I think is as far as I can understand a DPP which is very very shallow.

Carolynn_Bernier: Mhm.

Ivan_Herman: this is probably the most important part for DPPS the fact of combining DPSPs coming from all over the places into one coherent thing and…

Ivan_Herman: that's what the presentation can do and can do it in different tricky ways with selective disclosure etc etc so I think and that is made possible by the very existence of VCs so I have the impression that presentations are a little bit under used or…

M.-A._Wolf: Mhm.

Ivan_Herman: underemphasized feature of the model which is important and it's bound to the question of holder because the verifiable presentations are produced by the holder which is a major differentiation in functionality Okay.

Ronald_Koenig: I think you are front office.

Carolynn_Bernier: We're done.

Carolynn_Bernier: We're done. Go ahead.

Dr._Susanne_Guth-Orlowski: Yeah. …

How Vcs Are Used In Dpp

Dr._Susanne_Guth-Orlowski: so I wanted to respond to I think it's right. maybe before we start with the list of the pure services of electronic signatures, maybe we have to explain how dig So verifiable credentials are used in digital product passport contexts. the few sentences that you say for example the economic operator is issuing with its entity. So the issuer ID is the economic operator.

Dr._Susanne_Guth-Orlowski: he makes claims about something that is also clearly identified and makes claims about that subject and subject ID and this is how an economic operator can issue a product passport about a product that he produces. So I think you're right we should combine the electronic signature with the identities that we use and how we use it in this use case. So I think that's right.

Dr._Susanne_Guth-Orlowski: And on Ivan's comment I haven't worked with verifiable project presentations too much and we've been using wallets especially for battery passports where we do not necessarily connect everything that belongs to DPP into a verifiable presentation but we created a wallet that is kind of a battery wallet and every information that belongs to that battery is in is put into that wallet and linked to each other by the same identifier. So that I believe that verified representations are not being created to receive all information about the battery but it's simply connected by the same globally unique identifier.

Dr._Susanne_Guth-Orlowski: But I'm super curious to hear if the verifiable presentation solutions w which I haven't used too much creates an alternative yeah that was my comment Yeah.

Carolynn_Bernier: What? …

Carolynn_Bernier: the whole point of this section, Suzanne, I agree, is to gather, arguments from people who think VPs are useful in the DPP world and people who think BPs are not useful in and what that enables, So, the whole point is to gather input or opinions on people.

Carolynn_Bernier: So from the discussion we had last time, I put a number of advanced what I call them advanced e exploration topics here in order to make sure the conversation happens.

Carolynn_Bernier: I'm going to give the floor to Phil

Phil_Archer: Thank you.

Phil_Archer: just this conversation resonates with one that's happening in the recognized entity group that meets on a Tuesday night …

Carolynn_Bernier: Mhm. Hey, I hope

Phil_Archer: which most Europeans are not going to join because it's at 10:00 c on a Tuesday.

Phil_Archer: It's just early enough for me to go to but there's a discussion just last week the very active discussion about whether verifiable presentations were useful in the context of an issue with saying the reason I am allowed or my accreditation for issuing that kind of credential comes from somewhere else or the reason I can give you this credential is because I got these 17 others or whatever and there are ways that we are defining that to

Phil_Archer: link one credential to another and a mean credential on my presentation where one credential is either linked via the content of the credential itself that says basically also over there or from the identifier. So this was issued by did 1 2 3 4 5 and if you resolve did 1 2 3 4 5 you'll find a bunch of accredititations there. Both those methods are going to be supported and so there's an active discussion about why don't you just use a BP? Why don't you just wrap it all up in that way? and so I guess what I wanted to say is this discussion you're having is also happening in that other task force. Maybe it's something we should bring to the whole group. But I know that the discussion was not conclusive last week as I don't think we're being conclusive here either. But you're not alone in having the same conversation.

Carolynn_Bernier: And it's perfectly good to know that this conversation is happening and that means it's a relevant conversation and I don't think that we need to conclude. I think that we need to show the options that are possible and the pros and cons of the different options.

Phil_Archer: It's great.

Verifiable Presentations In Dpp Context

Carolynn_Bernier: So once this matures a little bit I will be happy to share the link to this draft with the recognized entities because basically how can one know if the VC or DPP issuer is a valid issuer. This is direct impact with the recognized entity work in the VC working group. vote. Yeah.

Carolynn_Bernier: Somebody else had their hand up, I think. No. Okay.

Ronald_Koenig: Yes unfortunately I just one remark to even yes it is right the credential subject doesn't have to be the holder…

Ronald_Koenig: but it could be that the credential subject is the holder we have as we are using very very extensively the holder concept. We have also multiholder binding for credential subjects. For example, if you have let me say a list of legal representatives and issue this one to a wallet where every legal representative has its own identities or cryptographic material which it can express into then I can bind one credential to different holders which are represented in one wallet. So we are not re really assigning a wallet to a credential subject. We are assigning the identity or the controller of a cryptographic material by cryptographic binding to the verifiable credential allowing this person or this identity to authenticate against the verifier.

Ronald_Koenig: So from my understanding is and I think it is very important for Verifiable credentials can be bound to a holder and to more than one holder and the mechanisms of the verifiable presentation allows this holder to authenticate against the verifier and to prove that the statements claims inside the verifiable credentials are about him or he has a certain relationship to this one. I make an example. If I for example have a car title, then the car title for example the car could be the credential subject but the holder of the car is also mentioned in the car title.

Ronald_Koenig: So in this verify the credential and he can then prove that he is the owner of the car by presenting this credential it is bound to him against the third party and then claiming that he is the owner of the car. Of course he is not the credential subject because the credential subject is the car but he is mentioned as a holder of the car and this credential is then bound to him. So then she is a holder of this credential and can present it to someone else. and this is from my point of view something…

Ronald_Koenig: which is very extensively used with verifiable credentials verifiable presentations.

Dr._Susanne_Guth-Orlowski: Is it this product passport use case or…

Dr._Susanne_Guth-Orlowski: is this additional product passport use case?

Ronald_Koenig: Excuse me. I didn't get it.

Ronald_Koenig: a product passport for me from my point of view I really would start with really this issuer holder verifier model because my understanding is okay yes we have also selfisssued product passports of course but my understanding is take a car for example the manufacturer of the car should provide a verifiable credential explaining the properties or the claims of the car and then this property should be bound to the car itself. So that for example if I put the serial number of a car and…

Carolynn_Bernier: Does the car have a wallet?

Ronald_Koenig: put this serial number in direct close contact to this car then I can prove that this digital product passport is about this car. So that means the holder of this verifiable credential is really the car and not the manufacturer. Of course, it can have a wallet. we have identity for machines. We have identity for things. Of course, if you drive later with your car to a charging station, of course, the car will get identity.

Ronald_Koenig: It has to authenticate against the car station so that can prove that on the other side is for example a car from whoever manufacturer you have and it will also prove claims about the car to the charging station. This is what we are already doing to make sure that this car is loaded just to the specifications…

Ronald_Koenig: which are in the digital product passport of this car.

Carolynn_Bernier: Mhm. Okay.

Dr._Susanne_Guth-Orlowski: But…

Dr._Susanne_Guth-Orlowski: but yeah,' that probably my point. can we start with something that we need for digital product passports and then take it from there? Yeah.

Carolynn_Bernier: So I'm taking from this discussion I need to start to add a section how are verified credentials how are used in DBP use cases.

Vc Usage Models For Dpp

Carolynn_Bernier: So we need to describe the selfissue the third party the self we need to explain this a little bit and also the absence of holder binding or the multiholder binding. a question for Ronald just out of my own ignorance is holder binding is the whole concept of binding for verifiable presentations do…

Ronald_Koenig: That's it.

Carolynn_Bernier: if I don't use verifiable presentations do we have any kind of binding requirements

Carolynn_Bernier: Or does the concept of binding only apply to pres presentations?

Ronald_Koenig: No, I don't say that is the topic of presentation. The question is you can do it without any kind of holder binding but it is then questionable why do you need verifiable credentials for this one? Make your example for I think a very valid use case for DPPS is for example battery passport and the battery passport. It is essential that this battery passport is bound to the battery itself because the value comes from if I want to sell a battery, I want to make sure that the claims is precisely about this battery and not any battery something like that. For example, if I want the charging cycles, is I want the sock or the state of charging and all the other things and how long it was operated in which temperature range and so on.

Ronald_Koenig: All this information needs to be bound to the battery itself and it will be done so that the battery gets a unique identifier and maybe this is either embossed or as a NFC code or something like that directly connected to the battery so that I can prove that every claim about this credential subject is more or less about this battery and I can prove And this is from my point of the whole thing of binding of information to a certain product and this binding is from my point of view done in different ways.

Ronald_Koenig: For example, we have a project with the Switzer railway and there the product is a rail itself and of course every rail has at the beginning and the end of the rail a number which cannot be u modified and…

Ronald_Koenig: this goes into the different product passport so that everybody knows this product passport is about this rail.

Carolynn_Bernier: No, that just yes fundamentally my question is so in your understanding the product itself is the holder…

Carolynn_Bernier: if I understand correctly. So the product itself has a wallet because in most the simple use case for a DPP The issuer which is the responsible economic operator. What you're saying is here is that the holder is not the responsible economic operator.

Carolynn_Bernier: It is the product itself.

Ronald_Koenig: And my understanding is the issuer is usually not the holder.

Ronald_Koenig: The issuer makes statement about something let me call it this way and issues it to something so that something can prove it against the third party. This is the idea of verifiable credentials and verifiable presentations. Otherwise, if you just make a statement about something without to issue it to them so that he can prove that it is really the credential subject related to the credential subject,…

Ronald_Koenig: then you can make a normal signed document and prove it and say that's it. You don't need verifiable credentials for it. This is my understanding.

Carolynn_Bernier: We about it.

Dr._Susanne_Guth-Orlowski: But Caroline,…

Dr._Susanne_Guth-Orlowski: yes, I would like to confirm that that's a possibility that the product as an identity has a wallet where it collects all the claims that have been made about it. Yeah. …

Carolynn_Bernier: How do you give a product a wallet? Dr. Susanne Guth-Orlowski:

Dr._Susanne_Guth-Orlowski: I guess they're different ways. is here you can in the battery case for example you put it online or…

Dr._Susanne_Guth-Orlowski: you put it in the battery management system. yeah.

Ronald_Koenig: Yeah. this way that really you have to…

Ronald_Koenig: if we for example talking about things we are also talking about agents everybody who needs the identity gets some wallet functionality in the sense that they can present the credential or I can receive the credential from this one and he can sign it so that I can prove that really this is the object which is the holder of this credential right by the way it doesn't

Ronald_Koenig: Could also be a claim inside the credential subject which is related to the holder.

Dr._Susanne_Guth-Orlowski: So all the articles I wrote on that always assumed that the product has its own wallet especially in the battery use case…

Dr._Susanne_Guth-Orlowski: because we also have the claims that are coming during life cycles such as a state of health and negative events and that's collected in the wallet and we've discussed it a lot of times and always came to the conclusion that this is the best way to do it especially for the battery as a first thing and then for textiles to be discussed yeah because textiles have a lower margin and not clear…

Dr._Susanne_Guth-Orlowski: if every textile gets a wallet maybe online but it cannot be done in the product so to be discussed.

Carolynn_Bernier: H okay so I will add a section and…

Carolynn_Bernier: how are VCs using DPP use cases and I think that's the self-held the third party held the product itself has a wallet and etc. I think we need to spell this out and all this is diversity meaning there are multiple ways to use VCs in the DPP context and…

Carolynn_Bernier: I think that we need to spell it out to be very clear. I think that will be very useful. okay so who Ian Yes.

Ivan_Herman: Yeah, I think it's a little bit more than that, Caroline. I think that you should collect the discussions and…

Carolynn_Bernier: Okay.

Bringing Vc Issues To The Working Group

Ivan_Herman: not necessarily with end results and bring it to the working group as a whole on one of the Thursdays no f Wednesdays. because you are right in one aspect very much so that if I try to recolct all the working group discussions over the years.

Ivan_Herman: the identity card kind of model has always dominated all the use cases that we were discussing. I'm not saying that they are the only ones. But if you look at the various examples in the various documents, they are almost all these kind of identity kind things.

Carolynn_Bernier: That's my fear.

Ivan_Herman: Yeah. driving license or…

Carolynn_Bernier: That's my fear. passports. Yeah.

Ivan_Herman: or university alumni or something like that. And so if you bring these kind of issues to the group as soon as possible and you have to talk to the chairs on how they schedule that it would be very important I believe.

Carolynn_Bernier: I agree, but I want to do this in a clearer way, So that means we Okay. Yeah.

Ivan_Herman: Yeah, I am not saying doing it right now, Caroline, but in the coming weeks it would be really good to have

Carolynn_Bernier: In the next 3 weeks, I will be disconnected from electronic forms of communication. So, nothing is going to happen except so what I promise to do before I leave on my vacation is to take this content and to modify the draft. this document here so that you can start reacting to the content. This is what I would like to invite people in this group to do is to say is to react to what is already here and for example react to this list add content here and also maybe react to this. Okay.

Document Feedback And Contributions

Carolynn_Bernier: So we need to start collecting content from our conversation and putting it on paper because once we have it on paper virtual paper things become clearer. Once we write things down we need to write things down and once we have them written down then at least in our own minds things become clearer. so I promise that before Thursday I will send an email pro show explaining that there I've updated this document and inviting everybody to read the content and to provide feedback on the GitHub.

Dr._Susanne_Guth-Orlowski: Caroline, is this still the same GitHub page that I used and…

Carolynn_Bernier: Yes. Yes.

Dr._Susanne_Guth-Orlowski: simply, published? we just doing it for a while this way or do We have a process in place. Okay.

Carolynn_Bernier: You mean so yes so if you want to make a proposals you create a branch so you commit to your own branch any modifications you want to write or you can create an issue which means you don't make a pull request but you just create an issue if you want to discuss a topic you committed to main and…

Dr._Susanne_Guth-Orlowski: because last time I just deployed okay thanks

Carolynn_Bernier: that's perfectly fine.

Carolynn_Bernier: It was perfectly fine but now I think we need to start communicating through issues and pull requests.

Ronald_Koenig: But Caroline,…

Ronald_Koenig: for you is it fine if I make a branch? I don't need to fork the repository and then send a pull request to you. For you it is fine if I'm branching it only and then make a pull request from the feature branch to the main branch.

Carolynn_Bernier: Yes. Exactly.

Ronald_Koenig: Okay.

Carolynn_Bernier: So hopefully before the end of today I will have modified the structure of the document so it's easier to contribute to it and the important thing that I will add is this section here how are VCs using DPP use cases I think that this conversation here has been valable valuable to understand how we have to make the structure

Carolynn_Bernier: of the document evolves. so I don't know…

Carolynn_Bernier: if I will put it after this section. I think before Yep.

Dr._Susanne_Guth-Orlowski: Yeah, why not?

Dr._Susanne_Guth-Orlowski: It's fine for that, I think.

Carolynn_Bernier: Yep. …

Dr._Susanne_Guth-Orlowski: And I'm also happy to help with that. Yeah. Yeah.

Carolynn_Bernier: you already have,…

Dr._Susanne_Guth-Orlowski: I know.

Carolynn_Bernier: but…

Dr._Susanne_Guth-Orlowski: I'm just saying you maybe don't have to write it alone.

Carolynn_Bernier: and I don't intend to write it alone. I only want to put together a structure so that people can contribute properly.

Dr._Susanne_Guth-Orlowski: The structure. Okay.

Carolynn_Bernier: It's difficult to contribute to a draft that is a real mess.

Carolynn_Bernier: So I wanted to make this draft less of a mess and…

Carolynn_Bernier: also wanted to ask Ivan how do we have field here editors or contributors authors. Yeah.

Ivan_Herman: You mean the two different thing the editors you in the beginning of the HTML file there is a JSON structure and…

Ivan_Herman: there you can add people's name and there are some data that you have to put there you can look at your own data which I filled in at some point and then the same words for anyone who is An editor appear it's the only official thing at W3C and…

Carolynn_Bernier: you can't have all the contributors.

Ivan_Herman: you can have as many editors as you want but the rule is usually that editors for example have the right to merge the PRs etc. So they have a certain responsibility.

Carolynn_Bernier: Yeah. Yes.

Ivan_Herman: We can without any problem add an additional entry in this header which says authors and authors can list any number of people and we can also and one doesn't exclude the other at the end one become a little bit more public…

Ivan_Herman: then at the end we put an acknowledgement section where we can put even more people. and there are no rules for that.

Dr._Susanne_Guth-Orlowski: What?

Ivan_Herman: The only rules there are in W3C is for the role of editors. Everything else is working groupwise.

Carolynn_Bernier: So I would like to add authors here.

Ivan_Herman: You want to add outs.

Carolynn_Bernier: Yes. Okay.

Ivan_Herman: So clean the current stuff and then you tell me when and I can add another and…

Carolynn_Bernier: Okay, super.

Ivan_Herman: then you can multiply

Carolynn_Bernier: Okay, I suggest we end the meeting here. I will stop sharing my screen. I will be present on the Monday of the 17th, but So until then, you will have lots of time to talk about wallets and…

Dr._Susanne_Guth-Orlowski: Yeah.

Carolynn_Bernier: I wish everybody a very No,…

Phil_Archer: It's weird just watching your brain completely shut down. Carolyn, you need a holiday.

Carolynn_Bernier: no, no, no. was reading Sebastian's chat comment. so Sebastian I think a new PR is probably best.

Carolynn_Bernier: Sorry about that. Ivan, can you stay on just two minutes so I don't mess up the Yeah.

Ivan_Herman: Yeah. Don't worry too much.

Ronald_Koenig: I'm

Carolynn_Bernier: Yeah. Yeah. Thanks. Bye.

Sebastian_Schmittner: Many thanks everybody.

Sebastian_Schmittner: Have a good day.

Ingo_Wolf: Thank you.

Phil_Archer: Thanks everyone. Bye.

Ivo_Ladenius_gs1_netherlands: Say goodbye. Fine.

Carolynn_Bernier: I don't want to mess this up. so okay we will add you as soon as we have some merge conflicts and…

Ivan_Herman: Don't honey.

Dr._Susanne_Guth-Orlowski: So Carolyn this is what I think I started in 2021 the topic and I'm glad to see it here now at W3C and I would be happy to be an editor to bring this to an official page other than my Medium articles.

Carolynn_Bernier: I will add you as editor

Dr._Susanne_Guth-Orlowski: Yeah. Yeah. Okay. I know for me is difficult. I just wanted to let you know that I would like to put some of my energy into this.

Ivan_Herman: Done. felt.

Carolynn_Bernier: Excellent. Thank you, Susan. Thank you.

Dr._Susanne_Guth-Orlowski: Wish you a nice evening and a wonderful holiday. And when you're back,…

Phil_Archer: All right.

Dr._Susanne_Guth-Orlowski: I'm on holiday. So, I will be back the beginning of September.

Carolynn_Bernier: Fine. Thanks a lot.

Dr._Susanne_Guth-Orlowski: Yeah. Okay. you. Bye-bye.

Carolynn_Bernier: Byebye. Wait.

Ivan_Herman: Byebye. Susanna statement.

Carolynn_Bernier: Okay.

Ivan_Herman: HTML and include the cont. Data replace. No. Wait, wait.

Carolynn_Bernier: HTML path edit. Mhm. Mhm.

Ivan_Herman: include email.

Carolynn_Bernier: data include format markdown true section. Okay. markdown you Okay.

Ivan_Herman: Wait, exact says to say.

Carolynn_Bernier: When is It's telepathy.

Ivan_Herman: for your deputy for us.

Carolynn_Bernier: No. Minute.

Ivan_Herman: We scient command shift air.

Carolynn_Bernier: Are home control? No.

Ivan_Herman: Control shift.

Carolynn_Bernier: Windows. Ah.

Ivan_Herman: Control shift. for the cash local index.

Carolynn_Bernier: Okay. Fore text HTML editors.

Ivan_Herman: Wait, paste.

Carolynn_Bernier: I don't really know.

Carolynn_Bernier: I know.

Ivan_Herman: Wait. C joining as a member. She's passed escort. Wait, I could

Carolynn_Bernier: Okay. Come on.

Ivan_Herman: CCT. We slash thresh. probably get no address email

Carolynn_Bernier: Are we? Okay.

Carolynn_Bernier: Search through.

Ivan_Herman: Olowski. Sorry.

Carolynn_Bernier: Suzan, Sorry.

Carolynn_Bernier: invited expert ID.

Ivan_Herman: How was it? Wait. Susan.

Carolynn_Bernier: Catherine cat. Okay.

Ivan_Herman: I can account the digit I Suzanne,…

Carolynn_Bernier: Okay.

Ivan_Herman: co-editor I pass one Caroline in back.

Carolynn_Bernier: All right. Mercy. Meeting ended after 01:12:25 👋 This editable transcript was computer generated and might contain errors. People can also change the text after it was created.

This transcription was generated by a large language model (LLM) and might contain errors. When in doubt, check the audio recording. This page was formatted by scribe.perl version 248 (Mon Oct 27 20:04:16 2025 UTC).