W3C

VCWG Product and Wallet Vocabularies

17 August 2026

Attendees

Present
Carolynn Bernier, eva_blomqvist, fireflies.ai_notetaker_miguel, ingo_wolf, ivan_herman, Saad Bin Shams, saad_shams
Regrets
-
Chair
-
Scribe
transcriber

Meeting minutes

Ivan_Herman: There you go.

Ingo_Wolf: No.

Eva_Blomqvist: Hello.

Ingo_Wolf: Good on…

Ingo_Wolf: what you found. Hello. Yeah.

Ingo_Wolf: I guess you're experiencing the same GitHub outage at the moment as I am.

Ivan_Herman: Yes, indeed. Hello, Caroline.

Ingo_Wolf: Hello. Yeah.

Carolynn Bernier: Hello. Okay.

Ivan_Herman: It will go away eventually. I see error messages that I have never seen before.

Carolynn Bernier: So, I'm just back from vacation today.

Carolynn Bernier: So, my brain is still foggy and my level of depression is pretty high. I'm actually not in the office.

Ingo_Wolf: No flowers in the office.

Carolynn Bernier: I'm in my holiday house in the Alps because I couldn't dare to go back to the office yet. I have to do things by steps.

Ingo_Wolf: All right. Sorry.

Objective To Come Up With Working Examples

Carolynn Bernier: I noticed that so I noticed there were some activities on the GitHub. I noticed there were some elements that were discussed on the GitHub. I didn't have time to look at that. I did read the minutes from the previous meetings that were held in my absence. So I did note that there is a objective to come up with some very quickly small working examples of DPSPs based on verified credentials. I don't know who's taking this activity on. Is it Suzanne? Is it someone from Sparity?

Ingo_Wolf: Yeah, I think we can provide something there.

Carolynn Bernier: Yeah. Okay. Mhm.

Ingo_Wolf: We were talking about this last week and…

Ivan_Herman: What the heat?

Ingo_Wolf: we have some examples where VCs are used in for DPPs. so far they remain on the VC level.

Ingo_Wolf: So there are no presentations in terms of verifiable presentations and we are still seeking for use cases and requirements that motivate that but from the discussion in the last meetings I come more and more to the impression that we don't have such requirements so maybe it's enough to go with VCs in the context of DPP …

Carolynn Bernier: Mhm.

Ingo_Wolf: but yeah hopefully next week we can present a little bit from our work in rebuild where at the moment I'm currently contributing to data space membership credential or maybe we can generalize it a bit more to membership credential.

Ingo_Wolf: Let's see but yeah this is not closely related to DPPS I would say but indirectly yes because for data spaces we already use the business wallet to onboard and to have the membership verified against verifyable credentials out the business presented out of the business wallet. and once you are a member of the data space you can then share also the PPP information over your database connectors. this would be the indirect relationship so to say.

Carolynn Bernier: Mhm. Okay.

Ingo_Wolf: But that's somehow still not fully linked to our other P activities let's say this where we provide DPP system that is aimed for manufacturers that want to give a product on the market but we are discovering let's say the possible combination of both approaches basically. So DPP system and business wallet

Carolynn Bernier: But I think that what was discussed between Suzanne was on the need to have some small working examples of DPPs that do use VCs. So from the UNP work there must be already many working examples. I'm thinking in I do know some DPP service providers who already issue several actually DPP service providers that already issue DPSPs as verified credentials. I could also contact them.

Carolynn Bernier: Just thinking out loud here, Ian.

Ivan_Herman: Yeah, something that happened while you were away…

Recognized Entities Ecosystem Examples

Ivan_Herman: which might be of interest which is a bit orthogonal to what Ingo said is that in the separate document on recognizable ent recognized entities they have added in two major ecosystem example

Ivan_Herman: The GS1 and the UN grid ones, both of them address the problem you had in Brussels that we want to find the recog the fact of being recognized. You want to find it from the credential and not going up the top and go down. And both of these use two different mechanism that it is now part of the recognized entities. So first of all, it is an answer to your concern that you had in Brussels which is now part of the document. But it may be interesting to have a look whether the DPP environment can work with the facilities that are given today or maybe See them.

Ivan_Herman: produce a third ecosystem example about DPSPs into that document.

Ivan_Herman: I'm sure that they would be happy to take it. let me put the URL into the chat. It is part of the recognized entity spec as an informative appendix. So if you look at the document you will see appendix

Carolynn Bernier: So it's a use case document from the recognized So,…

Carolynn Bernier: I have to go to the right place some and Sure. I think that before I find to navigate…

Ingo_Wolf: I can share my screen if we want to look at it.

Carolynn Bernier: how to get to that specification.

Ivan_Herman: You are into the chat of this to link it.

Carolynn Bernier: No,…

Ingo_Wolf: Yeah, the link is

Ivan_Herman: Let click it and go there directly.

Carolynn Bernier: I wasn't in the chat because I have lots and it's hard for me to find how to get back into the chat and etc. So, yes.

Ingo_Wolf: Yes. I don't like this.

Carolynn Bernier: So perhaps you can zoom in a bit. Yeah, that's fine.

Recognized Entity Credential Examples

Ivan_Herman: That's only the vague there is code which we go down which shows exactly what's happening so this is the recognition itself and…

Ingo_Wolf: Mhm. Yeah. Ivan Herman:

Ivan_Herman: then you go there should be somewhere a credential. Yeah, that's issued by I don't know how they call it in one of their offices. And then here's a real thing. I think that's the one. And there is the recognized in. So if you look at the issuer which had issued that thing, there's a recognized in which essentially goes back to one level to the hierarchy that this is recognized by one of the recognized companies and step by step you get back in this case to GS1.

Ivan_Herman: So that's one approach and then there was another one which is in the UN example which is a little bit more complicated which is essentially if I remember I read it once which essentially reproduces who is service which is on the web for entities. So you can go and find a service that gives you information about the issuer and you can then be certified you can be sure that the issuer is fine through that way. That's

Carolynn Bernier: And h how is that encoded into the VC?

Ivan_Herman: Yes.

Carolynn Bernier: So it's the type equals recognized issuer under issuer. go you have issuer type is recognized issuer whereas before…

Ingo_Wolf: Okay.

Carolynn Bernier: if in the previous example you had recognized in field Right.

Ingo_Wolf: Credential and

Ivan_Herman: Yes. So yes,…

Ivan_Herman: that's the simpler approach and Karolin I am just a go between here so don't ask me all the details.

Carolynn Bernier: So basically I'm an issuer.

Ivan_Herman: But the recognized in is essentially what you were looking for in Brussels if I understood you well. Yeah.

Carolynn Bernier: I'm issuing this VC and I provide a place and a link to a file that said Im this file recognized entity credential Thank you.

Ivan_Herman: No, no, no, no, no, no. Not exactly. maybe go. Yeah, I should share. But if I have no idea, I'll share screen. how do I a window?

Ivan_Herman: How do I share in this thing? I never used Google.

Ingo_Wolf: You have three tabs on the top.

Ingo_Wolf: There is Chrome tab, window and entire screen. If you choose Chrome tab on the left hand side…

Ivan_Herman: Okay, maybe.

Ingo_Wolf: then you have all the open tabs where you choose from.

Ingo_Wolf: Or if you choose for window the middle tab you choose the browser window.

Ivan_Herman: No, that's not the one, Stop sharing. It's not. I shared the window but Something went wrong wrong with sharing. So probably there is a setting there that I don't know. Let's go back to your thing because I Let's not spend time on this.

Ingo_Wolf: No problem.

Ivan_Herman: Go to example So if you look at example nine no don't move away…

Ingo_Wolf: And sorry this

Ivan_Herman: if you look at yeah this is the credential that is sent out to whoever on whatever and the issuer instead of just providing a URL for itself it gives information about itself or…

Ivan_Herman: okay it gives a name but the important is that recognize as in and…

Carolynn Bernier: Mhm. So wait,…

Ivan_Herman: it recognize the ID is the other which is the verify credential of the one which recognized the healthy thoughts. So if now you go Yep. Carolynn Bernier:

Carolynn Bernier: wait, wait, wait, wait. what…

Ivan_Herman: Wait. Yeah.

Carolynn Bernier: what did you just say? So here the recognized in part you have what you said what it's okay the ID of the Mhm.

Ivan_Herman: Is the idea of the credential that lists this issuer as acceptable. So you go to another credential which certifies that you are okay and so you found the one higher up and in that one you might have yet another one going up or…

Ivan_Herman: to another credential which is issued by whatever and then it goes up to whoever the president of the republic if you want so that's the idea Yes.

Ingo_Wolf: So the recognized entity credential would be comparable to a trusted list or…

Ingo_Wolf: what we have today,…

Ivan_Herman: Yes. Yes. So it's over verifiable credentials one after the other…

Ingo_Wolf: right? I see.

Ivan_Herman: but it's always the same block and as I said this is the simple case the other one which is more complicated relies on some service somewhere on some URL where you can inquire details about an institution. that issued that credential. I don't know the details are more fuzzy to me for the other examples.

Ingo_Wolf: The UN grid example.

Ivan_Herman: So I don't want to bluff It's a typing Not necessarily.

Carolynn Bernier: Can you go down Ingo and…

Carolynn Bernier: so that we can look at ID type is recognized issuer. What does that mean actually? Type is recognized issuer. yes. Yes.

Carolynn Bernier: But in the issuer part of the VC, do they all have a type field?

Ivan_Herman: The issue might be a simple URL. In that case, you don't know.

Carolynn Bernier: There's no type.

Carolynn Bernier: But there are other issuer types.

Ivan_Herman: you I don't know maybe not…

Ivan_Herman: but it's perfectly part of the whole structure to add the type just about to anything if you want to put it there are you RDF I mean for any resource you can have a type It's standardized by this specification.

Carolynn Bernier: Okay. …

Carolynn Bernier: yeah. Yeah, I was just wondering if recognized issuer was a standardized term. Yeah, exactly. So it was introduced by that specification the concept of a recognized issuer type and…

Ivan_Herman: Exactly.

Carolynn Bernier: this type is recognized entity and…

Ivan_Herman: And the vocabulary still has to be created by

Carolynn Bernier: the rest so to sum wait I'm just no introduction of recognize times. the issuer type. Okay. So these are the two possible mechanisms of this specification.

Ingo_Wolf: Wait.

Ivan_Herman: Yes. …

Ivan_Herman: by the way, the type is defined in section 3.1. Yes.

Carolynn Bernier: If you go to 3.1 right here. The type of the entity

Carolynn Bernier: All right.

Carolynn Bernier: Thank you, Ian.

Ivan_Herman: So I don't know whether it is worth doing a separate example or…

Ivan_Herman: whether the GS1 structure is sort of the one you would do anyway.

Ivan_Herman: That's something I cannot say.

Carolynn Bernier: I think that both are possible.

Ivan_Herman: Both are possible of course but the question is whether one fits the VPP case better than the other but it would be good to check because this is typically the situation where you can come back to the working group and say hey I need this and you don't offer me this. so that's one of the reasons that we are here.

Ivan_Herman: and Ingo I don't know whether in your world you need something similar and whether these structures are Okay.

Carolynn Bernier: Mhm. …

Recognized Entity Credentials Importance

Carolynn Bernier: I think that in the business wallet world that this mechanism is extremely important for an employee recognized by their company or something like that. What is unclear for me is what are the pros and cons of the two different mechanisms.

Ivan_Herman: Don't ask me. No, I don't know, I am not part of that task force…

Carolynn Bernier: Yeah, right.

Ivan_Herman: because it always has its course at 10:00 at night, which I refuse to take. Carolynn Bernier:

Carolynn Bernier: I understand. Me too. is there a discussion? in the document.

Ingo_Wolf: from there.

Ivan_Herman: There is a whole repository as Ingo said there are problems with GitHub in worldwide right now.

Carolynn Bernier: Mhm. Is there

Ivan_Herman: So yeah something is wrong. but I don't know if there is someone in your group who is willing to go at 10:00 at night in our time to the call but you can raise issues and raise PRs at any time.

Carolynn Bernier: Ingo in the wallet world,…

Carolynn Bernier: how is this linking of credentials? how is this appro done or what are the approaches that are being considered?

Ingo_Wolf: I would say similar to…

Ingo_Wolf: what we've seen here. So you can either work with URLs that are already supported in the data model like we have seen here with an ID including a reference to another VC, right?

Ingo_Wolf: or we can also have it as part of the credential subject as an explicit link to another credential. we also had some options so to where we combine the proofs of the credential or let's say embed another credential that is going to be linked by value explicitly as another VC inside a presentation that you then make with multiple VCs and they can link

Ingo_Wolf: through the cryptographic material that was used binding keys for example an entity that wants to present a VC or multiple VCs generates a binding key and communicates that binding key to the issuer such that credential can be bound to that entity. and this then helps to cryptographically prove the linkage during presentation.

Ingo_Wolf: because you use the key where a credential was bound as an authentication means in the presentation so that you prove control over that key during credential presentation.

Ingo_Wolf: Yeah, there are multiple ways I would say right?

Carolynn Bernier: but none that are standardized.

Carolynn Bernier: There are many ways these two mechanisms are two examples of ways that it can be done,…

Carolynn Bernier: but the goal here is that then these mechanisms are standardized right that's the whole point.

Ivan_Herman: These two mechanism that are in the examples,…

Ivan_Herman: the general underlying structure will be standardized…

Carolynn Bernier: Yes. Yes.

Ivan_Herman: because these terms the properties whatever are to be standard. ized. So I am not sure I understand…

Ivan_Herman: what you said currently. Yeah.

Carolynn Bernier: In this work Ian these the two mechanisms are standardized in the work being done by we build on…

Carolynn Bernier: which is what Ingo is working in another project on for business wallets and use cases around business wallets where there are different the SDVC credential type is also used and other credential types are of course we're pushing for the W3C VCDM credential type to be used but it's not the only one right so fair everybody's free to use whatever so my question was what mechanisms are you using in we build and…

Ivan_Herman: All right.

Ingo_Wolf: Right now I better understood your question first of all Kill.

Carolynn Bernier: and basically said there are many possibilities and my reaction is yes, but none of these are standardized. Okay. Right.

Ingo_Wolf: So in rebuild I mean you were referring to the credential formats. I would rather than differentiate them as credential formats.

Carolynn Bernier: Formats. Yes. Not type.

Ingo_Wolf: That's right.

Carolynn Bernier: Yes. Yes. Formats. Yeah.

Ingo_Wolf: There is SDVC.

Ingo_Wolf: There is MDOG format and…

Carolynn Bernier: and dark. Okay.

Ingo_Wolf: W3C credential data model and we are providing an implementation for a use case where the W3C data model is used and this is possible since we don't have dependencies to other use cases. So we got somehow also the freedom to choose and we have chosen for the membership credential itself. there is no obvious use case for credential chaining. I would say we have the necessity of having a trusted issuer.

Ingo_Wolf: So an issuer that can be id authenticated or recognized as an entity within a trust framework by means of being included in a trust list or…

Carolynn Bernier: Sure, I understand.

Ingo_Wolf: things like this, but credential chaining is maybe a topic that does not fit to that use case very well. Let's say like this.

Carolynn Bernier: But credential chaining for I don't know an employee to their organization it seems like a pretty obvious one. And so h how is that achieved?

Ingo_Wolf: Yeah. In this similar way that we look at it, right?

Ingo_Wolf: We have an trusted issuer which is the organization of the employee that issues credentials into the business wallet. And if that needs third party attestations on top they might be hold in the same business wallet and…

Ingo_Wolf: can be presented as a group of credentials, right? Right.

Carolynn Bernier: So you don't chain credentials you and…

Carolynn Bernier: allow discovery to happen progressively. You just bundle them and throw them at you simultaneously more or less. I'm just speaking very

Ingo_Wolf: That's the current approach we use definitely.

Ingo_Wolf: But as I said there are more options if you want to put it with a cryptographic fundament let's say this. So it's a matter of design choice basically if we want to utilize cryptography to have this credential chaining or if we go with claims mapping approach from trusted credentials. That's the alternative basically.

Carolynn Bernier: But this is possible because basically all these bundles so the linked credentials are more or…

Carolynn Bernier: less under the control of a single organization But in the case of DBPS and…

Ingo_Wolf: Yeah, that's not a problem as long as they are participating in the trust framework,…

Carolynn Bernier: and the example by GS1 here, the credentials are all issued by different organizations.

Ingo_Wolf: right? As well the definitions that's one means to implement a trust framework. Yeah. Carolynn Bernier:

Carolynn Bernier: What does that mean? in a trust framework.

Ivan_Herman: Yeah. Issues this list.

Carolynn Bernier: They're in the same trusted issuer listing? So some organization somewhere holds this list.

Ingo_Wolf: Yeah. issues this list usually that's a responsibility of an organization that takes care of the community.

Carolynn Bernier: Yeah. Yes.

Ingo_Wolf: And…

Carolynn Bernier: So it's a community thing, right? So,…

Ingo_Wolf: All right.

Carolynn Bernier: as long as you're in the same community, you don't really need this type of linking mechanism that we're looking at now because you can always consult the same trusted issuer

Ivan_Herman:

Recognized Entity Hierarchy Discussion

Ivan_Herman: yes, but you don't necessarily find that easily. So that's why it's a community or communities. It's a hierarchy in fact. So to be very specific the example that I use somewhere else is a university can have the right to recognize the various university schools to issue verifiable credentials for alumni.

Ivan_Herman: and the university will not handle the alumni for all the schools but it delegates the authority to the various schools but the university itself is then listed as a recognized entity by the univers by I don't know the ministry of higher education in that country. So it goes both ways. And if you want to be very picky as a verifier, you might be very easygoing and you say you get an alumni and you don't care about the verification because you don't care about the verification of the issuer because you believe it. If you are picky, you look at it and you say, "Yeah, computer science school, does it have the right to issue this credential?" It's not clear. But there is a recognized in going up to the university.

Ivan_Herman: And if it believes the university to be able to issue that then by having the recognized enti verify verification verify the credential somewhere on the web it can see that the university delegated this right to the school of computer science so it's okay if I want to be even more picky then I go up to the ministry of higher education because I don't believe that and even that I don't believe then I go to the prime minister or the president of the republic or whoever. what you mean by community is communities of communities.

Ivan_Herman: You don't start by the president of the republic…

Ivan_Herman: but you might end up in the president of republic if you want to be very very very sure of what you are doing and that kind of hierarchy is there

Carolynn Bernier: Yes. …

Carolynn Bernier: Ivan, what the questions I'm asking Ingo are to try to figure out if in the context of the organizational wallets there is a need a use case around recognized entity credentials. thats I'm trying to figure out with my questions to Ingo.

Ivan_Herman: I understand.

Carolynn Bernier: I understand everything that you said and I do so for me you explain why we need the recognized entity credentials and I have no problems with this. I understand this. so I'm bugging Ingo because I need to understand in their use cases around the organizational wallets,…

Carolynn Bernier: is there a need for the recognized entity credential type? Right.

Ingo_Wolf: I would say it generalizes concepts that we worked on a European level only.

Ingo_Wolf: let's say like this because if you think of u terms like European business wallet owner identification data or app void this already makes clear in the name that we scope towards the European market so to say while the recognized entities I believe take that approach more general.

Ingo_Wolf: anticipating that you will always have a kind of trust framework that defines who can be a trusted issuer or who is authorized to issue credential types XY Z in the context of your country, your region, your whatever hierarchy as Ian described. this can be bigger scale. but they all have the same necessity, To communicate in the credential how I can verify the trust status or trust model that the credential is based on.

Ingo_Wolf: And am I fine with these assertions or is it not trustful Enough.

Carolynn Bernier: So I think that if you're in Europe and…

Carolynn Bernier: you receive a Chinese company credential issued in China, you don't know what the trust framework is, right, for issuing that credential, right?

Ivan_Herman: You might,…

Ivan_Herman: sorry to interrupt, but you might hope that the Chinese and the Europeans somehow meet, let's say, at the World Trade Organization or something like that, and you might have to go up to the World Trade Organization with the Chinese company, But the structure is possible.

Carolynn Bernier: So using the recognized entity context concept if you receive a Chinese company or verifiable credential you would use these either the recognized issuer mechanism or the other mechanism to find the proof about you will discover the trust framework around so basically I think that…

Ivan_Herman: Yeah. Yes.

Carolynn Bernier: what we mean is do you assume that the trust framework ahead of time or…

Carolynn Bernier: do you assume that you will discover it later.

Ivan_Herman: probably there are some issuers that you recognize right away…

Ivan_Herman: which is the higher up that is important for you. So in this example the word rate organization this is something. So if you find a path in the graph that goes up to the vert organization then you are fine. If you do not find one…

Carolynn Bernier: Right. Yes,…

Ivan_Herman: which goes to the vert organism,

Ivan_Herman: ization then you are suspicious.

Carolynn Bernier: so for me this is pretty clear Ivan that this is how it should work. But I don't know how the people in we build are addressing this trust framework discovery and this is…

Ivan_Herman: I strong

Carolynn Bernier: why I'm asking these questions to Ingo

Ingo_Wolf: Yeah, I think the governance model in rebuild is rather predefined so to say.

Ingo_Wolf: So we will have these trust lists communicated and made available to the whole community so to say but ahead so not during request time so to say ahead of time and that's my current understanding how we built

Carolynn Bernier: It's not a posterior approach.

Ivan_Herman: is on the queue.

Ingo_Wolf: Can't hear you.

Carolynn Bernier: Yeah. Sad.

Ivan_Herman: Sad we don't hear you. Yes.

Saad_Shams: I hope you can hear me now.

Qualified Trust Service Providers In Europe

Saad_Shams: Matter of fact, so hello my name is Sad. I am from Semens. we also recently joined VB build and we are interested in developments regarding verifiable credentials and also DBP. I just want to throw in another idea that is discussed within Vbuild as well and perhaps Ingo is aware of it. So I think just my ideas right now and my understanding at the moment within vuild the idea is that we have qualified trust service providers which are recognized by this member states themselves and they go through a rigorous process to become a QTSP and these QTSPs essentially enter into a trusted list that are managed by the European member states themselves and this is the European level

Saad_Shams: sort of trust framework so to speak. Additionally, there are various verifiable credentials that do not specifically need a QTSP per se. so there for example, the contact person verifiable credential, right, which is issued essentially by a company and this problem that you guys are trying to figure out how this is done. this is again address so we are in contact with one of our colleagues in Bosch whom we have worked together previously as well and this credential chaining was a big topic for us as well back then in public funded project projects. and I think there are two variants right now within vill to address this issue.

Saad_Shams: One of them is to make further trust lists which are not essentially by the governed by the member states but more like you could say for example there is a data space of I don't know manufacturers so to speak and they create their own trust list and stuff like that. however the people Bosch they prefer credential chaining instead and the idea is quite simple. What you do is when you issue u a contact person verifiable credential for example, what you do is the verifiable credential that the company gets from the QTSP. You embed this into the header of the contact person verifiable credential. And this way you don't need to have further trust lists. You just rely on the member state trust list on the European level.

Saad_Shams: This is currently just a disclaimer. This is not currently accepted by everyone. These are just ideas that everyone is exploring at the moment. So yep sure the idea is so for example when a company for example semens in this case they are supposed to do business within Europe region and…

Carolynn Bernier: Can you say again…

Carolynn Bernier: how the credential chaining is achieved?

Saad_Shams: for that they get an organizational identity verifiable credential from a QTSP and a QTSP this qualified trust service providers again is recognized ized by all member states and they are in the trust lists provided by the members. So you have this verifiable credential and in case when the company from semens want to appoint a contact person that is responsible for certain activity when they issue a verifiable credential for them instead of relying on a separate trust list which is not in the member states…

Carolynn Bernier: Heat.

Saad_Shams: what they do is they take the verifiable credential that is provided by the QTSP encode it and embed it into the header of the contact person verifiable credential. And this way without relying on further trust lists, you can essentially go up to a QTSP and…

Saad_Shams: go to a trusted trust framework so to speak in the language that we are talking. I hope I just wanted to throw this in u just as an idea that we are discussing.

Ingo_Wolf: Thank you very much S.

Ingo_Wolf: Quite interesting.

Ingo_Wolf: One question comes up to my mind concerning the credential formats that support this approach.

Saad_Shams: Mhm.

Ingo_Wolf: Which credential formats are you working with? I mean is this the same approach implementable with W3C data model S as the job PC M do or are there differences

Saad_Shams: Like I said we joined recently the vuild consortium but from my understanding and the discussions that we have had with Bosch who have been engaged quite since the early days they are working in the BU1 one scenario 3 and the payment use case BA3 and if I am not wrong.

Saad_Shams: They are currently using SDJ VCs but from my understanding this is just my understanding a very high level at the moment. I think this should be translatable to the verifiable credential by W3C's as well.

Carolynn Bernier: So sad just to be sure I understand the approach.

Carolynn Bernier: So you take the higher level VC, so the one that's issued by the QTSP,…

Saad_Shams: H. Mhm.

Carolynn Bernier: you make a hash of that or something like that, or…

Saad_Shams: Mhm. Go.

Carolynn Bernier: and then you put that thing into the header of the new verifiable credential.

Saad_Shams: Mhm.

Carolynn Bernier: Is this correct?

Saad_Shams: That the company issues themselves.

Saad_Shams: Yep. This is another approach.

Ingo_Wolf: Yeah, to me it sounds a bit specific to SDJ…

Ingo_Wolf: since we don't have that same notion of header in the VC data model or…

Ingo_Wolf: in MDO. So I suppose this might be limited to SD jot usage.

Saad_Shams: Mhm.

Ingo_Wolf: But yeah in principle what you describe is incorporating another credential by value into the credential that you present and therefore prove the trust relationship of the individual to the organization for example. Yeah.

Saad_Shams: I would assume that you embed the entire VC.

Carolynn Bernier: But do you embed only a hash or…

Carolynn Bernier: the VC itself? Do you have the possibility to have the entire VC are you talking about Florian Cupil?

Saad_Shams: Like I said, I need to go through the details. What I can offer is I can in invite one of the colleagues from Bosch and they can perhaps explain this in much more details because they are much more involved with this topic than I am. I just want go ahead. Exactly. Yeah.

Carolynn Bernier: Okay.

Saad_Shams: Ver Falcon.

Carolynn Bernier: Actually what would be interesting is that Florian look at the recognized entity specification and…

Saad_Shams: Mhm. True.

Carolynn Bernier: and we have a discussion because this is basically all about different approaches to credential chaining basically right and I assume that each one of these approaches has pros and cons right same for the two approaches that we looked at here right so from a scientific point of view I'm more interested in understanding the different mechanisms that are proposed and…

Saad_Shams: Yep. Mhm. Understood.

Carolynn Bernier: the pros and cons associated to each one of these mechanisms right maybe something that would

Carolynn Bernier: useful is that sad I write to Flora with you in copy and…

Saad_Shams: Mhm.

Carolynn Bernier: I ask Flora to look at the two credential chaining approaches being proposed and that might be something that's useful Excellent.

Saad_Shams: I think go for it. they're quite curious colleagues as well. It's really nice working with them. I'm sure they would be interested. And just a heads up, I think Floren is currently on holidays. would be on holiday next week for about two weeks. So expect something in September, something like that. This is my gut feeling at the moment. But whenever I meet them, I'll also bring this topic up that we discussed it in this specific round.

Carolynn Bernier: Okay. maybe sad,…

Carolynn Bernier: could you please put your email in the chat of the Google meet meeting because I did not connect to the other Yeah.

Saad_Shams: All good.

Saad_Shams: I can do so if I find the chat button. where is it? Yeah.

Ingo_Wolf: So on the bottom right if youize window Yes.

Carolynn Bernier: So we didn't talk about DPP at all. Ingo, do you want to be part of this discussion?

Ingo_Wolf: Would be interesting to me as well.

Carolynn Bernier: Okay. No,…

Ivan_Herman: Sorry, I deviated the agenda that Well,…

Carolynn Bernier: but I think this was very useful. it doesn't really have anything to do with DPP, but it does have to do with a very important topic about credential chaining and the different approaches to credential chaining.

Ivan_Herman: my understanding of Brussels that it was important for DPP to have this.

Carolynn Bernier: Yeah, definitely.

Ivan_Herman: Yeah. Yeah.

Carolynn Bernier: Definitely. especially since a DPP can contain a link to another VC which has been generated by I don't know a certification body who itself obtained their certification credentials from a certification body from another accreditation body so it fun makes fundamental sense in the DPP I'm just trying to figure out if it also makes sense in the wallet world.

Ivan_Herman: Yeah. the question is will you have mainly because I am an outsider in that the energy to put in a structure

Ivan_Herman: these DBPs into the same appendix.

Carolynn Bernier: in the recognized entity technical specifications.

Carolynn Bernier: You mean

Ivan_Herman: I mean the question is it worth having a third or a force entry there? I don't have the answer. This is typically something that Mali should be able to I think he wrote those two. so it's worth checking with him whether it's good to have that but from my point of view looking at the messaging around the whole thing in general having an example like that written down somewhere on the web would be good whether it is in the recognized entity spec or somewhere else at first hand I don't care but it's good to show that these structures work

Ivan_Herman: for real use cases, not only artificial ones like my alumni example.

Saad_Shams: Can I quickly give my opinion on recognized entities and trust lists in general? these are just my opinions of course. my understanding is that the European trust list framework under EIS2.0 regulation I think it's a wonderful thing but I think the limitation that we usually see when we talk to different business units is that it's not a worldwide concept and I think if we are able to contribute in bringing the European trust framework to the world somehow using these specific topics I think it would be a wonderful thing and…

Saad_Shams: I think especially for DBP issuance and verification worldwide I think it would be extremely good this is just how I see Perfect.

Carolynn Bernier: Sad this is…

Carolynn Bernier: why we are here. We all agree and DPPs are shared worldwide and company identities will be shared worldwide. You can't have European trust lists. it doesn't work. It doesn't scale.

Saad_Shams: Mhm. Perfect.

Carolynn Bernier: Coming back to Ivan's question on do we need to add a DPP specific recognized entity example?

Carolynn Bernier: I don't know. I have to read in detail the use cases that are because I think that both Phils and that the two examples are both applicable to digital product passports fundamentally they are both examples that come from the world of digital product passports.

Ivan_Herman: Okay. I understand.

Carolynn Bernier: So I don't know if we need to add an additional example. because Phil's example is about a company being recognized by another company being recognized as issuing a specific product identifier, So it's about a proof of appro and this in the DPP world you do need this otherwise there is no way to know that now this company is authorized is to say that it did issue that DPP that it does own that G10 for example right it's authorized to create a DPP for that G10 and the other example it had to do with an invoice so the

Carolynn Bernier: invoice it's a global trade document right a DPP is you could see it as a global trade document as well so I have to read it in detail with a clear mind to say do we need to add another example and…

Ivan_Herman: Okay.

Carolynn Bernier: maybe on Wednesday we can ask the team if There is some kind of a procon discussion going on the different mechanisms.

Ivan_Herman: You should send a mail to Kufil and Brent to put it on the agenda. I will have a call in one minute with them.

Carolynn Bernier: Perfect. Can you do that so I can read the other mail to Flor?

Ivan_Herman: Yes. Yes, you have quite a lot of mess coming back from that distance. I presume that's not that much.

Carolynn Bernier: Yeah. 400. It's not that bad. Yeah. Sad.

Saad_Shams: Yeah, I just had a separate topic.

Saad_Shams: It's regarding the GDC conference in Geneva.

Carolynn Bernier: Yes. …

Saad_Shams: I'm thinking about attending it. So I believe that there is an invitation process to it. I just wanted to understand so that we can see if I can somehow attend the conference as well.

Ingo_Wolf: Just kidding.

Saad_Shams: Do you guys know who to reach out to where to get the invitation from perhaps?

Carolynn Bernier: I don't know. I'm already registered.

Carolynn Bernier: I got an invitation from somebody.

Saad_Shams: Okay, understood.

Carolynn Bernier: Ivan, will you be there?

Carolynn Bernier: Ivan, will you be there in Geneva in September?

Ivan_Herman: Pardon? Where?

Ivan_Herman: No. yes yes yes there is a way…

Carolynn Bernier: Sorry, sad. I don't know. I assume there's a website somewhere

Saad_Shams: There is a way to get it via W3C as well.

Saad_Shams: I think you just …

Ivan_Herman: but I didn't pay attention too much on the details. Sorry about that. Let me give you wait that's better than that.

Ivan_Herman: I think if you contact Let me I put in an email address.

Saad_Shams: Perfect. Mhm.

Ivan_Herman: It's Simona. What's his full name? Let's see. I want to spell it right 103. Okay.

Ivan_Herman: So that's his He is a colleague of mine and I know that he is dealing with the invitations and if not then he knows what to Refer to me putting in the mail that I am stupid and I don't know the details. but you would like to be in Geneva under the W3C header and you make it clear that you are in this working group and this task force etc.

Saad_Shams: Perfect. Thanks a lot.

Ivan_Herman: Sure guys I have to go…

Ingo_Wolf: All right. Oops.

Ivan_Herman: because I'm expecting on the other end. Bye-bye.

Carolynn Bernier: Yep. Thank you.

Carolynn Bernier: Thank you everybody.

Saad_Shams: All right. Meeting ended after 01:01:57 👋 This editable transcript was computer generated and might contain errors. People can also change the text after it was created.

This transcription was generated by a large language model (LLM) and might contain errors. When in doubt, check the audio recording. This page was formatted by scribe.perl version 248 (Mon Oct 27 20:04:16 2025 UTC).