W3C

VCWG Product and Wallet Vocabularies

3 August 2026

Attendees

Present
dr._susanne_guth-orlowski, fireflies.ai_notetaker_miguel, ingo_wolf, ivan_herman, m.-a._wolf, phil_archer, ronald_koenig
Regrets
-
Chair
-
Scribe
transcriber

Meeting minutes

Ingo_Wolf: Yes, that would come.

M.-A._Wolf: Can you actually hear me? Okay, because rophone the headphones don't work anymore.

Dr._Susanne_Guth-Orlowski: Hello. Yes.

M.-A._Wolf: Thank you. Then it uses this one from the laptop, I guess.

Dr._Susanne_Guth-Orlowski: Ronald. Hello.

Ronald_Koenig: Hello. Yeah.

Dr._Susanne_Guth-Orlowski: Rick and I have sign.

Ronald_Koenig: Yeah, I know.

Dr._Susanne_Guth-Orlowski: Meeting DPP wallet is vocabulary.

Ronald_Koenig: What does DPP?

Dr._Susanne_Guth-Orlowski: Yeah. PPP discrete the text. Hey, Ivon.

Ingo_Wolf: So last week we discussed about the business wallet.

Ingo_Wolf: So this week it's DPP and the alternating schedule.

Dr._Susanne_Guth-Orlowski: And for the DPP meeting, we would need Carolyn maybe not a drama either. But are we waiting for her? I didn't see a message that she isn't coming or…

Ingo_Wolf: Yes.

Ronald_Koenig: Thank you.

Dr._Susanne_Guth-Orlowski: couldn't come. yeah. she said she wouldn't be here for the next three weeks,…

Dr._Susanne_Guth-Orlowski: didn't she?

M.-A._Wolf: Yeah. Yeah.

M.-A._Wolf: She is detoxing from electronic devices for three weeks.

Understanding GitHub PR Process

Dr._Susanne_Guth-Orlowski: So maybe what we can do last week I wasn't there because I was thinking the discussions were mainly around wallet vocabulary. but then afterwards I saw that there were comments made in the public document to me to complete a section in it which I did. and maybe it's something that we can look at. Evan, I don't know if you saw it. I did create A change request I think to the site. So this time I didn't immediately deploy it to the site. I created a change request with a note.

Dr._Susanne_Guth-Orlowski: and maybe it's good for everyone to know how this can then be approved or are we discussing this here and how the process works to get this in the document. Hi Phil.

Phil_Archer: Sorry, I was a bit late. The drone is Mhm.

Dr._Susanne_Guth-Orlowski: No, no problem. Ian, I don't know if you hear me. you're on mute as well in case you're talking. Yeah, he was here. we saw him on camera, then the camera went off and he went on mute. So maybe he's off for a bio break or…

Dr._Susanne_Guth-Orlowski: something. Okay.

Phil_Archer: A grandson may be involved.

Phil_Archer: You never know.

Dr._Susanne_Guth-Orlowski: Phil, can you help with how the pro process usually works in other working groups…

Phil_Archer: Yes,…

Dr._Susanne_Guth-Orlowski: because I don't think we have a process here for the changes in GitHub.

Phil_Archer: Yeah, the basic principle is that anyone in the group can write a PR that is a pull request or people are encouraged to do so. it only gets merged into the document by unless they wrote it themselves. basically everything that gets put in is reviewed by somebody else.

Phil_Archer: So typically what happens is lots of people contribute and the editor will merge it and usually after a discussion in the relevant call but if you write it you generally don't merge your own bul requests right yes it depends

Dr._Susanne_Guth-Orlowski: So this time that means we have exactly the complicated case…

Dr._Susanne_Guth-Orlowski: because I'm an editor of the document. I did write a pull request. I'm not allowed to merge it myself and there's also potential for discussion. Yeah. But I couldn't do it myself,…

Phil_Archer: if it becomes silly Caroline's on holiday for a couple of weeks so it would be really unhelpful to stick to that kind of protocol in a situation where if everyone on the call is content with what you've written and I have no doubt that they will be then plug the button merge it go for it

Dr._Susanne_Guth-Orlowski: I think.

Dr._Susanne_Guth-Orlowski: I'm not sure. thing. I'm not entirely sure.

Phil_Archer: No. That's a different mountain.

Dr._Susanne_Guth-Orlowski: Let me also open up the GitHub. I think we can discuss…

Phil_Archer: I can but yes please do that.

Dr._Susanne_Guth-Orlowski: because there's some interesting part to discuss on it. So I have to open up the file right and I didn't had different calls before this one. So it's not open yet. I have to find it first. you do maybe you can just share it.

Phil_Archer: I've got it on my screen if it helps. hang on a sec. which one is it that you're particularly interested in?

Dr._Susanne_Guth-Orlowski: I think it's the update index MD.

Phil_Archer: Yeah, this one so you've changed one file, which is this one. you've added some text there which I admit I haven't looked at but there we are. I mean generally speaking with this kind of thing it's much easier to merge it and then read it afterwards. but…

Phil_Archer: what you're doing here so I'm looking at this very quickly. I hope other people will do the same. okay.

Dr._Susanne_Guth-Orlowski: Yeah, please take your time.

Dr._Susanne_Guth-Orlowski: Basically Caroline asked me to clarify the first part on the issuing of DPSPs. Yeah, let me explain one thing…

Phil_Archer: Which you're done. So I mean from my point of view there's no reason not to merge this. I'm one voice. There are many others on the call. Sure.

Dr._Susanne_Guth-Orlowski: because it's maybe something that we want to discuss. So if you scroll down a little bit. so I did make please go Back it up again. Yeah, here. So this is the different ways how digital product passport can be issued.

Dr._Susanne_Guth-Orlowski: two different wallets because we had that discussion last time. A DPP can be issued to the wallet Of the product itself or to an economic operator or maybe to the wallet of a marketplace. However, and this is the last point I made finally a VPP VC can simply made available on a product website not using wallets. and that's something that I want to discuss if everyone sees it in the same way because I believe that's the way where we will be seeing dish product passport VCs is probably as part of a web page that can be verified rather than really in a wallet of a product or at least that's also potentially possible.

Dr._Susanne_Guth-Orlowski: because a digital product passport is signed by the economic operator and if you verify that signature you can see it's actually coming from the economic operator and…

Dr._Susanne_Guth-Orlowski: that's all that you need to do. You don't have to have it in a wallet. You don't have to have this holder binding stuff. and therefore I believe it's an option that we should also list here. discussion opened. I don't see a queue.

Phil_Archer: Sorry, I can't see the queue.

Phil_Archer: Okay. …

Dr._Susanne_Guth-Orlowski: Yeah, I think you can. It's just you. Yeah. Phil Archer:

Phil_Archer: I'll just jump in so, yes, this is very much a personal thing, have I come out in a rash whenever I see the term digital twin. because it's used by so many people to mean so many different things. It does have a specific definition. Yes. and when it's used to mean what it was originally defined to mean, that is a system that you can modify the parameters in a digital system to see how the real life system would respond. That's a digital twin. But you and I and everyone on this call is used to people saying digital twin. And sometimes they mean a PDF, which is not a digital twin. so it's purely a personal thing.

Phil_Archer: I hate the term digital twin. I never use it. but that's where I come out in hives when I see this. However, to your basic point, I think you're absolutely Of course, you're right that it could be in a wallet. It could just be published. It could be that the whole point about a variable credential is there are lots of ways to pass it around. And that's an important point…

Phil_Archer: which you've made here. So, I'm happy with that.

Dr._Susanne_Guth-Orlowski: And Phil,…

Dr._Susanne_Guth-Orlowski: I actually have the same feeling when I read digital twin because it's not defined really and other people understand other words. I for some reason still used it in the sentence. So maybe that was stupid.

Dr._Susanne_Guth-Orlowski: Maybe we find a better term. it's just we can also write a digital representation of the product on the web which maybe makes it Yeah.

Phil_Archer: That would do.

Phil_Archer: Yeah, I can hit it again,…

Dr._Susanne_Guth-Orlowski: Okay. how do I change my own pull request?

Phil_Archer: I think. hang on a sec. Let me see. Could I do it? I'm not sure I can. yeah.

Dr._Susanne_Guth-Orlowski: I'm still learning the GitHub stuff to be honest. Mhm. Phil Archer:

Phil_Archer: Yeah, we all Just when I think I've got it. then something happens. I edit this? there's got to be a way. Yes, I can edit it. So, I can edit your edit.

Dr._Susanne_Guth-Orlowski: Okay.

Phil_Archer: So now I've lost me color coding and…

Dr._Susanne_Guth-Orlowski: And why don't you further up?

Phil_Archer: I can't find where you were. Hang on. There we are.

Dr._Susanne_Guth-Orlowski: Did you remove digital twin? I'm actually very happy.

Phil_Archer: The product concept. okay.

Dr._Susanne_Guth-Orlowski: to a digital representation of a product. I think we said okay. Mhm.

Phil_Archer: So, I can make my little change. which I meant to not try. Sorry, that was a typo. I'll go through the process here. I'm going to create a new branch that is a branch of your thing. So then you get to merge that request into your pull request. I think that's what it happens.

Dr._Susanne_Guth-Orlowski: But you didn't click on merge it directly to Susanna's branch. That's Aha.

Phil_Archer: No, because I wanted to give you a chance to do that.

Dr._Susanne_Guth-Orlowski: I have to go back to mine thing. I don't know…

Dr._Susanne_Guth-Orlowski: what to do now. Files changed. I don't know what to do. I don't

Ronald_Koenig: So then you have to request 13 and…

Phil_Archer: Hopefully. Do you have this button here,…

Ronald_Koenig: merge it.

Phil_Archer: Susanna? Okay.

Dr._Susanne_Guth-Orlowski: Yeah, I think so.

Phil_Archer: See what happens.

Ivan_Herman: But are you at the 13? Not another one.

Dr._Susanne_Guth-Orlowski: No. Aha.

Ronald_Koenig: has request exploding.

Dr._Susanne_Guth-Orlowski: I have pull request Thank you. and I Confirm merge. I just do it. And then we can see what happens.

Phil_Archer: Great. Yep.

Phil_Archer: So, that's been done.

Phil_Archer: Did I change yours or did I change the master? that wasn't the idea. I'm sorry.

Dr._Susanne_Guth-Orlowski: I think you changed the master…

Dr._Susanne_Guth-Orlowski: because you could have chosen merch to Susanna's pull request and then I think it would have looked differently.

Phil_Archer: That's annoying. I'm sorry. Then I've made it.

Dr._Susanne_Guth-Orlowski: So it says Susanna merged one commit into Susanna Gutolski's patch one from Phil Archer's patch one.

Phil_Archer: I'm sorry. yeah. Okay, then that's right. I've done it into yours.

Dr._Susanne_Guth-Orlowski: I have no idea. what does the Mhm. Okay.

Phil_Archer: Look here. So, I'm looking at yours now and it says digital representation. It doesn't say digital twin. So yeah.

Dr._Susanne_Guth-Orlowski: Amazing. Good.

Phil_Archer: So tell what I can do I can submit my review and I can do that. So it means okay so all right before I do it let me show you.

Dr._Susanne_Guth-Orlowski: And what does that mean? Let go. Time is up.

Phil_Archer: So when you created this, it suggested two reviewers, Caroline and…

Dr._Susanne_Guth-Orlowski: Yeah. Mhm.

Phil_Archer: Revan. But I can add one as well. there's a way to add a review.

Phil_Archer: I had it anyway. I can't remember. There was a way to I had it there. I could have hit a It was there.

Ivan_Herman: It was there.

Ivan_Herman: If you No,…

Phil_Archer: But then I moved away.

Ivan_Herman: no. If you click on the cog wheel now on your screen and you are fill archer down there. You click on fill archer. the review.

Phil_Archer: And then I do that. No, I don't want to do that. I know who he is. What I mean is I'm going to add my review.

Ivan_Herman: Your review Phil Archer:

Phil_Archer: That's So, I do this and I submit review.

Phil_Archer: I say it looks good to me. Approve. So, I do that. I submit the review. And Susanna, hopefully you can now merge that.

Dr._Susanne_Guth-Orlowski: Merge my own number.

Phil_Archer: Have a look. if you can. Yeah, because you had it reviewed by somebody else. Yeah, makes sense.

Dr._Susanne_Guth-Orlowski: I think I was able to merge it previously as but I didn't want to do that because I wanted to understand…

Phil_Archer: Yeah. You've done it.

Dr._Susanne_Guth-Orlowski: what the proposed it and…

Phil_Archer: That's it.

Dr._Susanne_Guth-Orlowski: then it should be on the main page as well.

Phil_Archer: That's it. Yeah. Yep. It should be there. don't know if it's instant, but it should be pretty much open up. I see. Right. There you go.

Ivan_Herman: They take the time…

Ingo_Wolf: Yes.

Ivan_Herman: because it brings in markdown into HTML.

Dr._Susanne_Guth-Orlowski: I think it's a different document.

Dr._Susanne_Guth-Orlowski: It's not that document.

Phil_Archer: This one.

Dr._Susanne_Guth-Orlowski: The Yeah.

Phil_Archer: Thank you. Okay, good.

Dr._Susanne_Guth-Orlowski: Good. Yeah. What I did seems to be there. Mhm. And …

Dr._Susanne_Guth-Orlowski: what we can do now is to discuss any of the other topics. Maybe Engle.

Ingo_Wolf: Yeah, Susanna,…

Verifiable Credentials and Presentations

Ingo_Wolf: you were asking if need VCs or VPs in the context of DPP at all, right? …

Dr._Susanne_Guth-Orlowski: What? Say that again. Are you breaking out or I'm breaking out?

Ingo_Wolf: you were asking if we need VCs or…

Ingo_Wolf: VPs. So, verify the credentials or verify the presentations for DPPs, right?

Dr._Susanne_Guth-Orlowski: only you for verifiable credentials I'm pretty sure we can use them for verified presentations I'm not really sure…

Dr._Susanne_Guth-Orlowski: if we need

Ingo_Wolf: Then I would like to understand if we need selective disclosure as a capability for those credentials

Dr._Susanne_Guth-Orlowski: Yeah, it's a good question. I think in the long run, yes, and maybe we have to make our, design decisions based on that. in short term, that's nowhere required really today. I think maybe others would say something different but I don't see it realistic that selective disclosures will be used at the moment raise his hand maybe you have a different opinion

Ingo_Wolf: Because then I Yeah,…

Phil_Archer: No, no,…

Phil_Archer: no. Cargo, carry on. You'll

Ingo_Wolf: just to finish because if we would like to have that capability, there is linked verifiable presentations that might be used in the context of TPP. So you can publish those linked verifiable presentations on your web domain.

Ingo_Wolf: can even link it to your economic operator did and still profit from elective disclosure mechanisms.

Phil_Archer: That's interesting. I'd like to see that develop.

Dr._Susanne_Guth-Orlowski: No. Phil Archer:

Phil_Archer: Thank you, this exact same conversation came up a couple of weeks ago in the recognized density work where Steve Capel was saying to Manu and Tulleand I'm not sure we need very parallel presentations in the world of supply chains and this kind of thing to which the people who've been working on this for years whose use cases are the driver's licenses the educational qualification ations and so on and the proof of age sort of automatically react saying no of course you need presentations of course you need balar presentations and it's interesting that it's come up in this conversation as well because some of us are thinking not sure we do all right nothing wrong with

Phil_Archer: but not sure we need them. so I think it's interesting that you're raising I don't have an answer. I'm just saying that it isn't that this question is being raised elsewhere and…

Phil_Archer: it's being raised basically since we all turned up and started talking about use cases that are not to do with driving licenses, proof of age and educational certificates.

Dr._Susanne_Guth-Orlowski: I think we maybe should leave verify presentations out of the use cases…

Dr._Susanne_Guth-Orlowski: until we find a use case that is needed for digital product passports.

Phil_Archer: The use case…

Phil_Archer: where I think it might be very relevant in our world is within the supply chain where you want to prove that something is organic, was not built through slave labor, was not cause of deforestation. But you don't want to reveal the name of the company that did the work. In other words, you can turn up at the back of a distribution center and prove that you are an authorized person to hand over the goods without them knowing who you are. so you true. Yep.

Dr._Susanne_Guth-Orlowski: But that's not the DPP use case for me. that's a identity company certificate use case and…

Dr._Susanne_Guth-Orlowski: I think wide also made a similar examples in one of the previous calls.

Ronald_Koenig: I'm calling it Yeah,…

Dr._Susanne_Guth-Orlowski: No, I just was mentioning that I think you made a similar example in one of the previous calls for verifiable presentations, but here it also was actually a verified representation for a company identity, not for a product identity.

Ronald_Koenig: I'm currently thinking about it…

Dr._Susanne_Guth-Orlowski: Yeah. Yeah.

Ronald_Koenig: if we need for my understanding is the following. The verifiable presentations are used to provide cryptographic proof with the authentication proof that I'm the holder of this credential or at least I mentioned in the credential and I want to prove that I am or the claim inside the credential is related to me and I can prove that this person which is presenting this credential is really the person which is referenced to

Ronald_Koenig: in this credential my understanding was always okay yes we need this one because for example I would like to know that the economic operator is presenting this credential to me and the economic operator for example is mentioned inside the product passport with his web decentralized identifier and…

Ronald_Koenig: can use his private key to prove that he is the economic operator and is presenting this product passport to someone. In this case, you need a presentation.

Dr._Susanne_Guth-Orlowski: Yeah, but presenting a digital product passport to someone is not a relevant use case and…

Dr._Susanne_Guth-Orlowski: that he has to prove that it's presenting it at this point in time when it is signed by this economic operator.

Dr._Susanne_Guth-Orlowski: the DPP can lay everywhere and you can still prove that has been issued. and also the digital product passport at all times need to carry the identity of the issuer. So I'm not sure if that's the case for your driver's license or…

Dr._Susanne_Guth-Orlowski: but we don't have that use case that we need to prove that we're presenting it at the moment. that's just not existing because the British border passport credential can also be stored at your online marketplace for example it can be everywhere Yeah.

Ronald_Koenig: I think we are confusing now issuer and…

Ronald_Koenig: and holder because the issuer is proving the credential with the assertion proof and the holder can then present this credential to someone else and proves that he was referred to in the credential itself. let me explain this way. So for example you are a company and you have a production process for example u manufacturing I take the example from the last time a rail right and you want to prove to someone else that you are the guy who is producing this one and you have received a credential from certifier that your production process is generating. this amount of carbon.

Ronald_Koenig: Then in this case the certification entities is signing proving the credential by proving that at least for example 10 tons of carbon is generated and the manufacturer is presenting it for example to some verifier who wants to calculate in a verifiable session the overall footprint of this rail. then you need this one if you have the requirement that you need this and you need a producer of this one in this process. So what I mean with this is really every time the same.

Ronald_Koenig: If we don't need cryptographic verification of the holder of the credential then you don't need a presentation is my understanding…

Dr._Susanne_Guth-Orlowski: Yeah. Yeah.

Ronald_Koenig: because the only difference to a credential is that in the presentation you have this a author authentication proof which is attached to the list of credentials the list of credential is proofed with this authentication proof so that this guy who is presenting this one with this presentation can prove that this credentials are about him in any Hey, heat.

Dr._Susanne_Guth-Orlowski: Probably good to look at a diagram at such discussion sometimes difficult to follow but Phil you raise your hand.

Phil_Archer: just only very briefly to Ronald's point,…

Phil_Archer: the confidence method spec that Joe and Denan are working on is designed in a more general way to handle how can you have confidence that the person handing you this credential is either the subject or the credential is in some way authorized to present it to you which is where the whole concepts of a ver presentation and a credential and a confidence method and all this stuff they all actually overlap. so what we're working on here is one piece of the puzzle.

Phil_Archer: And so I think it may be maybe that the competence method work is relevant to what Ronald was saying, but if you think otherwise then okay

Dr._Susanne_Guth-Orlowski: Yeah. I mean,…

Ronald_Koenig: What I really is maybe I can share my screen so that we talk everybody about the same.

Dr._Susanne_Guth-Orlowski: I don't know that.

Ronald_Koenig: You say it is easier to follow a diagram than my explanations. I'm referring to the VC data model 2.0 zero but more or less is some kind something of foundation we have right and the verifiable presentation is from my point of view nothing more than a verifiable list of verifiable credentials and a proof which is attached to this verifiable list of verifiable presentations if you look more detail these proofs are of course not the proof about the claims inside the verifiable credentials because these are part of the verifiable credentials

Ronald_Koenig: it is the authentication proof of the presenter of this verifiable presentation. Maybe I can also go to where it is encoded. Hopefully it is somewhere. Do we have it very presentation here? Basic structure. Okay, just a moment. I don't find okay unfortunately the proofs are not shown

Dr._Susanne_Guth-Orlowski: Yeah, I mean let's maybe can we do it for now that if we don't find a use case where we need that feature Down. then We leave it out as long as we don't have a use case where we need it. I think we can be more focused in our work for the moment and I really believe that the examples that you made and also Phil made is kind of a second layer check that you can do about a company.

Dr._Susanne_Guth-Orlowski: But then it's company identity and company attributes that you're checking. it's not a pure product passport use case in my view. You don't have to prove anyone that you really own the product passport that I don't think that's happening anywhere.

Dr._Susanne_Guth-Orlowski: And if we can live with that assumption for now, unless someone comes up with a use case where we actually need it, I would suggest that we leave it out.

Ronald_Koenig: But from my point of view,…

Ronald_Koenig: this is a very general statement because I would say then we don't need wallets at all. Right? because then I can really as you said issue or publish this credential somewhere because there is no need to have it which is in a wallet which is responsible to maintain the holder keys right so that means you can put it somewhere on the internet and you can verify the assertion proof of the issuer and you don't need it in a wallet and you don't need a presentation protocol or…

Ronald_Koenig: you can only retrieve it using a get http hi.

Dr._Susanne_Guth-Orlowski: Yeah, I mean I think we should leave open…

Dr._Susanne_Guth-Orlowski: which exchange protocols people use to retrieve the data because it might be very handy if the battery has a wallet. and then you make a request for a certain credential of that wallet because then you can use your DICOM or your open ID for VC protocol. and if you want to use it, you can use it. You have it in a wallet.

Dr._Susanne_Guth-Orlowski: if you don't want to use it because no one has a wallet yet and that's honestly the migration path the verifiable credentials that sits somewhere where you can retrieve it and verify it I think that also should be possible the more sophisticated the technology gets and…

Dr._Susanne_Guth-Orlowski: the more people and companies and products have wallets I doubt that you won't use a wallet for these Yes. No, and…

Ronald_Koenig: Yeah. This is…

Ronald_Koenig: but what I'm saying if we make a statement here that we don't need presentations this is Okay.

Dr._Susanne_Guth-Orlowski: I didn't say that. I said we leave it out for the moment or we not considering it for the moment because the use case is not clear and then we focus on how do we structure and make concepts for verify credentials.

Dr._Susanne_Guth-Orlowski: And if we're fine with that for today or…

Phil_Archer: Let's go.

Dr._Susanne_Guth-Orlowski: maybe for the next rounds, we can focus more on verify the credentials and handling them as digital passports and is someone against this approach? Then …

Phil_Archer: Little talk.

Dr._Susanne_Guth-Orlowski: why don't we decide that for today we can make a note that we think that we don't have to consider it or…

Dr._Susanne_Guth-Orlowski: a nice sentence that maybe a native speaker or speak can much nicer than me and then we put it on the side and I make another pull request for it.

Phil_Archer: Tall Ted will go through and…

Phil_Archer: correct every construction of every sentence. He does a brilliant job at it. I mean shouldn't rely on him but he does a great job.

Phil_Archer: He makes more commits than anyone else because he does that and he will don't worry he will clean up every language. Don't worry.

Dr._Susanne_Guth-Orlowski: Okay, good.

Dr._Susanne_Guth-Orlowski: So, I put that on my to- there were other yellow marked sections in this document. for example, why is link data useful for DPPS? I also added one section there and last time it seems you have list you have written down that elaboration is needed. Should we use that as the next topic to discuss if you don't mind maybe I can share my screen. I'm just on a small laptop here a bit reduced in functionality but I'm talking about this section here.

Linked Data Usefulness For DPPs

Dr._Susanne_Guth-Orlowski: And what I added to this one was this here and I think maybe we should elaborate of what we actually mean with linked data to be very concrete.

Dr._Susanne_Guth-Orlowski: My understanding is that we use the context element and connect JSON LD schemas to a document and then we describe what we do with it. Is that everyone's understanding in the context of DPSPs?

Phil_Archer: Yes. I just want to read something for you. Dr. Susanne Guth-Orlowski: Phil Archer:

Phil_Archer: And this might be directly relevant to our conversation here. Forgive me, Susanna. so, some of us are going to be in eva, in a month's time, and I am nervous about that event because I know that I'm going to be in front of people who, are going to be asking all sorts of awkward questions.

Dr._Susanne_Guth-Orlowski: Mhm. No. Mhm.

Phil_Archer: So, I've been preparing some answers to exactly the kind of question that you're raising, Susanna. because I think we're going to get asked this and I think I'm probably going to be challenged sometimes face to face and sometimes on stage. so there's a little Google doc that I've been putting together some answers to some of these questions which includes the one you're asking. Lisa said why is link data useful for VCs? It doesn't then talk about DPPs particularly but everything you're saying here is relevant. and again I think I mean I get asked what's the difference between a VC and just a simple signature. I get the usual complaints from various people about it doesn't scale, it's not secure and all the other things because apparently we're idiots know what we're doing. and all that kind of stuff. So what you're doing here is very interesting.

Phil_Archer: Sorry, I just wanted to say that it's all part of the overall battle's too strong a word.

Phil_Archer: I don't know. But we do have to write exactly this kind of thing because we do get attacked.

Dr._Susanne_Guth-Orlowski: Yeah, I will also be in Geneva by the way.

Dr._Susanne_Guth-Orlowski: So, if you need support in whatever you're doing or…

Phil_Archer: Look forward to seeing you.

Dr._Susanne_Guth-Orlowski: want to put on stage, please feel free to involve me.

Phil_Archer: Yeah. Thank you.

Dr._Susanne_Guth-Orlowski: So what I added to this one so first of all thank you for the document. do you want to incorporate maybe…

Dr._Susanne_Guth-Orlowski: what fits into this document from your document.

Phil_Archer: If you find it useful,…

Phil_Archer: use it. If not, it's just purely there's some people who've helped write some answers to some of the kind of questions we get. And if it's useful, great. Not well,…

Dr._Susanne_Guth-Orlowski: Okay. Okay…

Phil_Archer: I'm not upset.

Dr._Susanne_Guth-Orlowski: then I can go through it and use what I find useful and write another pull request.

Dr._Susanne_Guth-Orlowski: What I wanted to mention is that in the context of the DPP registry which now is available and also the regulation is available. the registry regulation says that it does checks for completeness of the DPP which is in my view also something that we can do with linked data. So the idea is that the DPP registry will have In that repository, we'll hopefully find a JSON LD file. and if you issue a digital product passport, you would have to provide all elements that are in this JSON schema.

Dr._Susanne_Guth-Orlowski: So what it would also allow us is to check for data completeness in the DPP and…

Dr._Susanne_Guth-Orlowski: this is why I added this here. Mhm. Yeah. This is…

Ronald_Koenig: Zuz I don't think that's true.

Ronald_Koenig: Yeah,…

Dr._Susanne_Guth-Orlowski: what I wanted to discuss because I wasn't sure because Yeah.

Ronald_Koenig: just but my understanding is okay linked data gives you the references to the semantic right. So therefore you get a reference to this one but you are not defining is it mandatory or optional something like that. So that means yeah

Dr._Susanne_Guth-Orlowski: Yeah. Yeah. Yeah. but hang on and even I see you raised your hand. if it doesn't meet the file in the semantic repository of the registry, you won't be able to register your DPP. So it somehow for me is a means to check for completeness.

Dr._Susanne_Guth-Orlowski: And please, tell me differently because that's not what I do every day. Ivan, you had raised your hand.

Ivan_Herman: Ronald said more or…

Ivan_Herman: less what I wanted to say and link data is not for that. It does all kinds of wonderful thing but this is not one of them. I would almost say that it is the contrary because one of the basic feature of link data is what is called an open world. So there are statements which are outside a place but that's fine. I mean you never know whether you are complete so to say…

Ivan_Herman: because there might be also statement about your stuff on the link data somewhere on the other end of the globe. So it's not really relevant for this.

Dr._Susanne_Guth-Orlowski: Yeah, I see…

Dr._Susanne_Guth-Orlowski: what you mean as well.

JSON Schemas Versus Shackle

Ivan_Herman: I'm not questioning the validity of your need for that. But if you want something like checking that then you would have to use JSON schemas some other tools which are not link data per se. So if you make these kind of statements then you can be sure that you will have people saying no you are not true and it would be very difficult to defend. Okay.

Dr._Susanne_Guth-Orlowski: Yeah. Do you have an idea how you might maybe formulate it differently to explain that that is what the registry will be doing because they will have a schema definition somewhere and your DPP has to include all elements that are in the schema otherwise you're not complete and…

Ivan_Herman: Then that's…

Dr._Susanne_Guth-Orlowski: that's Yeah.

Ivan_Herman: what JSON schemas are for example although they are relatively difficult to use in my case…

Ronald_Koenig: Maybe I can.

Ivan_Herman: but that's essentially what they do they describe your JSON file Then they have requirement which says a certain term is required etc. This is what you're looking for which is completely over data. Sorry Ronald

Dr._Susanne_Guth-Orlowski: Mhm. Yeah.

Dr._Susanne_Guth-Orlowski: Yeah. Mhm.

Ronald_Koenig: Yeah, maybe I can add to this one was even saying because we are in the semantic hoop and are currently discussing this one because my understanding and the statement from Ian were completely right even the ontology definition which is defining the data model and not the JSON ID. It's really defining the data model or the semantic model is an open board assumption. So that means it is declaring something about the object but it is not meant to close the It is to define whatever it knows about this word and provide the semantic of the terms which are used but is not restricting the terms itself. and therefore also the JSON ID context is generated out of the ontology will not do this. What you can do are two things.

Ronald_Koenig: The first one even has already mentioned is use JSON schema because they define a closed word.

Dr._Susanne_Guth-Orlowski: Yeah. Okay. Mhm.

Ronald_Koenig: So you go to a validator and the validator says you are all the data in or is the optional data missing something like a manditarian parameter missing or…

Ivan_Herman: All right.

Ronald_Koenig: something like that. But I don't like it because if you do this one you are back again to structure definition and not to semantic definitions. what you can do in instead is using Shekele is defining constraints on top of ontology. And if you are doing this one, you can say okay you have for example a class in the ontology like a data product class and can say okay with a constraint on top of the ontology of the oval.

Ronald_Koenig: You can say okay this attribute inside or…

Ronald_Koenig: this term inside this class have to be present otherwise it is semantically not complete.

Ivan_Herman: It brings

Dr._Susanne_Guth-Orlowski: Mhm. So that means I would have a context element that points to a JSON LD file and…

Dr._Susanne_Guth-Orlowski: I don't know where's the shekele file related in the

Ronald_Koenig: Yeah. The checker file is pretty simple. What you have if you look into the verifiable credential there is something like a credential schema and the credential schema. The first example is what Iban has already said is that it could be a JSON schema…

Ronald_Koenig: which makes the things very explicit because then you have a data structure validation and your outcome of the credential has to follow this has to satisfy this credential schema or you put in a shekele file. What I would prefer because then you can make semantic constraints on No,…

Dr._Susanne_Guth-Orlowski: Yeah. Yeah.

Dr._Susanne_Guth-Orlowski: No, I understand. And I think I used it some time ago, but I'm not using it on a day-to-day business. So, I forgot where I have to connect Am I connecting the shekele file in the JSON ID file or where do I in the No.

Ronald_Koenig: no, the JSON ID file is just a mapping.

Ivan_Herman: Excuse me.

Dr._Susanne_Guth-Orlowski: Okay. …

Ronald_Koenig: So the

Dr._Susanne_Guth-Orlowski: but the other question is do we want to go down this route here or…

Ivan_Herman: Yeah,…

Dr._Susanne_Guth-Orlowski: do we want to mention it at all or leave it out? sorry, Ivan. I see your hand.

VCs And RDF Graph Limitations

Ivan_Herman: I mean I have to put up some warning signs about shekele and I'm sorry to be the bearer of the bad news but it cannot properly be used with verifiable credentials in the entirey and they are only for the credential part there are some technical things that are there we are talking about RDF graphs and data sets etc. Shekele is not prepared to handle data sets and the very very precisely a verifiable credential consists of several RDF graphs. The credential itself and the signature is separated in this respect and shackle cannot handle that today.

Ivan_Herman: that's why we have never added a shackle representation of verify credentials to the lot only vocabularies and JSON ID context. that means that you can have a shekele which can check the credential which might be okay with you. so that might be enough but it cannot verify credential. So it cannot check the presence or not presence of proofs and whatever is within the proof…

Ivan_Herman: because that's these two different RDF graphs and check cannot handle

Ronald_Koenig: This is pretty interesting…

Ronald_Koenig: because even my understanding is that or maybe I'm wrong with the credential schema because my understanding is the credential schema can contain a lot of schemas and the schema can also define a part of the credential and in my case my understanding was that the credential

Ronald_Koenig: schema can be used to only address the credential subject so that I don't have only one graph or…

Ronald_Koenig: this means that the credential subject should only be one that it means the main graph or the default graph how it is called right and I agree completely with you yes it is a problem with the verifiable credential for the entire credential because there we have different graphs right one for the credential subject and the one for the surroundings and so on. Yeah.

Ivan_Herman: Yes. not the credential subject for the credential.

Ivan_Herman: that all the metadata about the credential plus the subject plus whatever we say about the subject.

Ivan_Herman: These are all in the default graph and…

Ronald_Koenig: Yeah. Yeah.

Ivan_Herman: the proofs are into separate graphs. that's the one that is built up.

Ronald_Koenig: Yeah. On my understanding was that the credential schema is only describing…

Ivan_Herman: What is micro schema object?

Ronald_Koenig: what the credential schema is or is called just a moment I have to look into it. Not that I'm using the wrong term so that you can is the term inside data schemas.

Ivan_Herman: That's what …

Ronald_Koenig: Yeah. Now it is called credential schema. It is a property inside the verifiable credential.

Ivan_Herman: but that's what you can assign to the credential.

Ivan_Herman: You can assign a JSON schema,…

Ronald_Koenig: Yeah, but you can also define others…

Ronald_Koenig: because you have only to define the type, right?

Ivan_Herman: But I mean what do you want to use it for?

Dr._Susanne_Guth-Orlowski: Maybe I can come in again.

Ivan_Herman: Mhm. No.

Dr._Susanne_Guth-Orlowski: I would like to understand what is the best way to check if certain data fields are part of the verifyable credential. maybe mainly of the subject part but yeah we also need the issuer ID for example

Ivan_Herman: So I think Ronald is right that there is a separate specification which is not a recommendation at this moment yet…

Ronald_Koenig: This is this one.

Ivan_Herman: which does that's from the data model actually but there is a separate specification for that which can assign JSON schema to credential.

Ivan_Herman: Yeah, that's the one.

Dr._Susanne_Guth-Orlowski: And that's…

Dr._Susanne_Guth-Orlowski: what you meant at the beginning, Ivan. And Bronard said it's very strict and then you cannot change the structure.

Ivan_Herman: Yeah, that's what stop there. so you can see the credential schema. It says you have the credential there with all the subject and ID and type and blah blah. And you can assign a schema to it which is this schema email.json. And the verifier is supposed to check the consistency of the credential via this schema. That's the simplest setup which is there. and you can make it a little bit more complicated but let's not get there. So that's what there. the interesting point about this one is

Ivan_Herman: that it is a candidate recommendation because we have never received enough implementations for this spec to be used as a recommendation. So if you have an environment where you use this that would be very good for the working group because we can then go and publish it as a recommendation. But for the time being we have defined that and then somehow the community did not pick it up. But again if this community here needs something like that. This is what we are looking for. whether the same mechanism could be used to assign a shekele file.

Ronald_Koenig: Yep.

Ivan_Herman: probably yes but that's to require some sort of an extension of this thing but you are right the fundamental structure is there and could be used and…

Ivan_Herman: that's probably the answer for Susan's questions of where do you put the credential schema the answer is wherever you want as long as it has a URL and then you put the credential itself Yes.

Dr._Susanne_Guth-Orlowski: Mhm. …

Dr._Susanne_Guth-Orlowski: just for me to repeat u making sure I understood it correctly. in my credential which is a DPP, I can use credential schema attribute to point at a DPP JSON which is then a JSON schema which is put on the DP registry semantic repository

Ivan_Herman: Yes. Yes. Yes. Yes.

Dr._Susanne_Guth-Orlowski: where it's permanent and this is what the European

Dr._Susanne_Guth-Orlowski: in commission defines and then I have to go and check it against that file. Okay. Yeah.

Ivan_Herman: And you can make it a little bit more complicated just to that instead of pointing to a schema, you can point to another verifiable credential which contains that schema. So you can essentially add signature structure to the indirectly schema as well…

Dr._Susanne_Guth-Orlowski: Mhm. but…

Ivan_Herman: which might be a more preferred way of doing that. But then that these are okay…

Dr._Susanne_Guth-Orlowski: if the schema is placed on an EU site, then I think that's good enough. we hope that the EU keeps control over the domain.

Ivan_Herman: if you trust the EU then that's fine but okay…

Dr._Susanne_Guth-Orlowski: Not sure I should, but Ivan Herman:

Ivan_Herman: but for the time we Right.

Ronald_Koenig: But here…

Semantic Work vs. JSON Schema

Ronald_Koenig: but here are for my point the problem with this one. Yes, it works this way. That's right. You can do this with a JSON schema. But the next question What will be asked then is why you are not using JSON schema from the beginning on because you have to provide it anyway. So then why you are doing semantic work and…

Ronald_Koenig: all the other stuff if you have to provide JSON schema which is very limiting because it is a closed word to have to use it anyway.

Dr._Susanne_Guth-Orlowski: Yeah, but…

Dr._Susanne_Guth-Orlowski: but I see where you're coming from entirely.

Dr._Susanne_Guth-Orlowski: Yeah, no question.

Ronald_Koenig: Yeah. Yeah.

Dr._Susanne_Guth-Orlowski: Why I'm trying to at least have one solution here is because they have to make a concrete solution to the European Commission that they can use to make it very strict but just for the use case of ing EU regulated products under the EU DPP registry. We're not saying we have to do that for all DPPs and we can add additional other data as well.

Dr._Susanne_Guth-Orlowski: But it's one use case. Yeah. Yeah.

Ronald_Koenig: But then we should not say it in general for DPPs…

Dr._Susanne_Guth-Orlowski: And yeah.

Ronald_Koenig: because DPP is one use case we are using to promote JSON ID and ontologies to describe it. So if you say DPP of course for DPPS we are defining anyway every time a JSON schema then I know what happens. So this is unfort this is the unfortunate circumstance we have this is just…

Dr._Susanne_Guth-Orlowski: Yeah. Yeah. Okay. so the discussion should be continued…

Ronald_Koenig: what I wanted to mention now We can yeah the others are…

Dr._Susanne_Guth-Orlowski: but at least for me that was very helpful. Run can you maybe make a suggestion for next time how we can use JSON LD with shackle or do we have other options that we want to promote?

Dr._Susanne_Guth-Orlowski: Because this seems to be one option. do we have others?

Ronald_Koenig: then that institutes what you see here is the type is JSON schema you can also put in shekele but asan Ian has said that was never done before so that means this is already something…

Dr._Susanne_Guth-Orlowski: Yeah. Yeah,…

Ronald_Koenig: which was not used and therefore has no proving let me say it this way but to do this with shekele is more or less what we thought we can do and nobody has done before let me say it this Yeah.

Dr._Susanne_Guth-Orlowski: but that doesn't matter. I do since five years things no one has done before. I'm not,…

Ronald_Koenig: Yeah. Yeah.

Dr._Susanne_Guth-Orlowski:

Ronald_Koenig: Okay.

Dr._Susanne_Guth-Orlowski: it doesn't scare me away.

Ronald_Koenig: Then if…

Dr._Susanne_Guth-Orlowski: Yeah,…

Ronald_Koenig: then I can do it.

Dr._Susanne_Guth-Orlowski: why don't you make a proposal and then maybe you come with a piece of code and we can discuss it next time.

Ronald_Koenig: Because this is a long discussion in the semantic group because in the semantic group we are defining a vocabulary which is open world assumption. So that you are not doing any restrictions. By the way, this is also a way very easy to do selective disclosure because if you have a JSON schema in and you have a lot of mandatory parameters inside, then you cannot selective disclose anything because the result has to satisfy the JSON schema.

Dr._Susanne_Guth-Orlowski: Which working group did you mean?

Dr._Susanne_Guth-Orlowski: The one in JDC4.

Ronald_Koenig: we have the semantic working group inside from vbuild…

Ronald_Koenig: where we are defining this European business wallet vocabulary and…

Dr._Susanne_Guth-Orlowski: Mhm. Yeah.

Ronald_Koenig: we are not using JSON schema because all the other guys defining SDVCs and I see the lot of troubles they have to defining all these for example pyc records using JSON schema and…

Dr._Susanne_Guth-Orlowski: Yeah. I see. Yeah. Yeah.

Ronald_Koenig: I don't want to go into this direction because then I'm really

Dr._Susanne_Guth-Orlowski: Yeah. Yeah. No. Okay. Great. Yeah. And then I can make the same proposal maybe in other working groups in JTC 24 which is where the discussion is coming up in August.

Dr._Susanne_Guth-Orlowski: So it would be really good if we had the at least two proposals maybe with a preferred one that we can introduce with examples that would be great. Okay. we have one minute left. I have three to-dos two for me. I'm going to write a sentence that VPs are out of scope for the moment because we didn't find a use case.

Ivan_Herman: But one

Dr._Susanne_Guth-Orlowski: And then Donard is doing the example for the JSON LD schema with shackle maybe. and I'm also removing the part that I added which Phil accepted that we can check the completeness with the link data stuff because it's wrong. Those are the things that I noted down. Did I forget anything?

Ivan_Herman: thing before we go Susan the problem is the JSON schema works so that's all fine but this is not a good enough proof that link data is useful for DPP that's…

Ivan_Herman: where we started with and for which we do not have yet the right set of arguments so and this is what Phil will have to defend in Geneva because that's exactly the kind of thing that you have to emphasize in the text.

Dr._Susanne_Guth-Orlowski: Yeah. know that I don't have a problem with defending that…

Dr._Susanne_Guth-Orlowski: because luckily the digital product passport has a mandatory piece of data that it needs to provide but luckily the European Commission also is open to add additional data which is relevant for different actors in the supply chain which then can be added through the context element. Yeah.

Dr._Susanne_Guth-Orlowski: Yeah, no problem. Maybe I can write additional stuff about that. but we also need one mechanism where we can give, the European Commission instrument to check if the military data is in the DPP. If we don't have that,…

Ivan_Herman: I understand Susan I didn't say that this tracking mechanism is without interest.

Dr._Susanne_Guth-Orlowski: we also have a problem. Yeah. Yeah.

Ivan_Herman: The only thing is that we started with the link data arguments and this is not one of them.

Dr._Susanne_Guth-Orlowski: No, that's clear. Sorry. it was completely my thinking about we have to solve this problem as well but we have enough use cases for using link data for all the other use cases which are not mandatory…

Ivan_Herman: Bye-bye.

Dr._Susanne_Guth-Orlowski: but are also carried on the back of the DPP.

Ingo_Wolf: Thank you. Right.

Dr._Susanne_Guth-Orlowski: Okay, so I think we are at the hour and…

Ronald_Koenig: All right.

Dr._Susanne_Guth-Orlowski: thank you for the great discussion everyone. Bye-bye.

Phil_Archer: Thanks everyone. Meeting ended after 01:01:10 👋 This editable transcript was computer generated and might contain errors. People can also change the text after it was created.

This transcription was generated by a large language model (LLM) and might contain errors. When in doubt, check the audio recording. This page was formatted by scribe.perl version 248 (Mon Oct 27 20:04:16 2025 UTC).