Meeting minutes
Meeting Time Change Discussion
Phil_Archer: I don't
Dr._Susanne_Guth-Orlowski: All right.
Ingo_Wolf: No. No.
Ivo_Ladenius: Hello everybody.
Carolynn_Bernier: Hi everybody. Hi Suzanne. I saw your mail about requesting to change the meeting time.
Carolynn_Bernier: I understand that this is a difficult time for you.
Dr._Susanne_Guth-Orlowski: Yes. Yeah.
Carolynn_Bernier: I have no problem to move to another time but earlier today is a bit difficult for me.
Dr._Susanne_Guth-Orlowski: whatever you can suggest if it's not Monday 4:00 in the afternoon that would allow me to participate every meeting and…
Dr._Susanne_Guth-Orlowski: and at the moment even DPP schedule is always at every second one I cannot make so that would be really sad It would generally work.
Carolynn_Bernier: Yeah, I understand.
Carolynn_Bernier: What would people think about Wednesdays at 4 just before the entire PCDM meeting? Wednesdays are usually a lighter day for me. I don't know Thank you for reacting. Sad Eva Ivo Rio Rigo, your hand is up.
Ivan_Herman: Sorry, I wasn't at the beginning.
Carolynn_Bernier: Okay. Yes.
Ivan_Herman: You mean Wednesday at 4:00 our time?
Carolynn_Bernier: Paris time.
Ivan_Herman: Example time and grown up time. Not always.
Carolynn_Bernier: Yes. Okay.
Dr._Susanne_Guth-Orlowski: Super. Yeah.
Ivan_Herman: Yeah, that works for me as well.
Carolynn_Bernier: So, all right. how does this administratively happen? you do your ma Ivan, you do the magic sending out the things.
Ivan_Herman: I can do the magic…
Ivan_Herman: but you can also do the magic.
Carolynn_Bernier: Can I …
Carolynn_Bernier: I can you do the math. however, Karsten is not here and…
Ivan_Herman: That's one thing I wanted to ask. I mean before that we should do that. And obviously this is for next week.
Carolynn_Bernier: Yeah. …
Ivan_Herman: So we won't have a meeting this Wednesday do we?
Carolynn_Bernier: no, no, no, no, no, no. And next week we're probably all in Geneva.
Carolynn_Bernier: It's a big wallet conference in Geneva. probably even the entire W vCDM team working group is in Geneva.
Carolynn_Bernier: Next week I will be there Suzanne. Right.
Ivan_Herman: No, we don't have that much money to have the whole team going there,…
Ivan_Herman: but I think two or…
Rigo_Wenning: Simon will be there as far as I understand.
Ivan_Herman: two or three people from the team will be in Geneva. Phil, do you know that better than I do?
Phil_Archer: Brandon, I will be there.
Phil_Archer: I know Simona's going to be there.
Phil_Archer: I was surprised to see Manu's name on the agenda, which suggests he might be there, but I don't think He's going to be remote, I think. Yes, one's going to be there. Yeah. Yeah, you'll be there. Susanna's there. So, Brent and I are there.
Ivan_Herman: one. I will not
Separating Wallet and DPP Meetings
Carolynn_Bernier: So what I suggest is I'm going to write to so we can actually split the wallet meetings and…
Ivan_Herman: That would mean yet another meeting.
Carolynn_Bernier: the DPP meetings because always a bit confusing is which one is occurring which day. So I suggest that we kind of start splitting our work a little bit. so I'm going to inform Karsten that the DPP work is going to happen on Wednesdays at 4 and then he can do whatever he wants with the wallet work if he wants to remain on Mondays.
Carolynn_Bernier: You mean a different task force?
Ivan_Herman: Okay, because that's a lot.
Ivan_Herman: We are already pretty much full of meetings but that would mean there will be a meeting on Monday and there will be a meeting on Wednesday.
Dr._Susanne_Guth-Orlowski: I think Caroline means every fortnight.
Dr._Susanne_Guth-Orlowski: So I don't think there will be Just two meetings of the four will be at a different time. Did I get you correctly, Carolyn?
Carolynn_Bernier: Yeah. C Can we schedule a weekly meeting?
Rigo_Wenning: Hello. Hi.
Ivan_Herman: No, we can schedule.
Ivan_Herman: It's not the mechanics that is a problem. I mean, then we have yet another meeting and we separate the two. But to be honest, I would prefer if possible that car if Carson is okay with the Wednesday meeting to have the same structure as now just moved from Monday to Wednesday.
Carolynn_Bernier: Yes, that would be best. Phil
Phil_Archer: Yeah,…
Phil_Archer: I don't think any of having more meetings. So I think if we were to have different times then the DPP group and the wallet group would meet alternate weeks. So anyone we could either have a meeting on the Monday or the Wednesday as it happens that new time of Wednesday works for me every other week and every other week it doesn't. So in fact it would suit me very well as long as you pick the other week that I'm not already doing something then. But that's just me personally. but ask about more meetings I love.
Ivan_Herman: What are the odds that we will mess it up all the time and we go to Monday when the meeting is in one day and the other way around?
Carolynn_Bernier: Yeah. Yeah.
Ivan_Herman: I can make a bet on that.
Phil_Archer: As we say,
Carolynn_Bernier: No, we have 50%.
Dr._Susanne_Guth-Orlowski: …
Dr._Susanne_Guth-Orlowski: I think Ken is still coming to the meeting later on because he wrote he's still in a customer meeting. So why don't we just start and come back to the topic at the end of the meeting.
Carolynn_Bernier: Okay. Rio, your hand is up.
Rigo_Wenning: Yes it's I'm with Ivan on this. first of all people who are really bored in those meetings should just not be there And secondly if we only split enough times there will be no momentum left. And I'm really kind of burned by those teleconferences where you have three people talking to each other and claiming it's a working group.
Rigo_Wenning: So I'm a bit reluctant to split out the effort as long as we are not 60 people here in Yeah.
Carolynn_Bernier: You mean to split the effort between the wallets and…
Carolynn_Bernier: the DPP?
Rigo_Wenning: To split the group and to say hey you are only wallet you are only DPP while we started all the entire effort by saying hey how about putting the DPP into the wallet and things like that. so I'm really reluctant to kind of abandon the synergies that this brings. Rigo Wenning:
Carolynn_Bernier: All right.
Recognized Entities Work Discussion
Carolynn_Bernier: Let's see when Carson manages to join us and if we can move to the Wednesday. there's a few topics to be discussed.
Carolynn_Bernier: So last week for those who participated we spoke mostly about the recognized entities work in which they have several I don't know if you've been following the work being done in the recognized entities task force but they have some very nice
Carolynn_Bernier: Here let me just put the link in the chat for those of you who are not familiar with this work. So in this task force meets something at 10:00 1000 p.m. weekly. So it's almost impossible for Europeans to actually attend this work. But what's interesting is that they have proposed two mechanisms for the discovery of related basically credential chaining moving up the trust graph right because if I'm not mistaken the goal of the recogniz
Carolynn_Bernier: as entity work is to create trust about the credential issuer because otherwise there a credential issuer…
Carolynn_Bernier: if you have no information about the credential issuer there's no trust in the credential itself Phil is this correct or yeah Ivan So you're talking about a case…
Ivan_Herman: credential issuer or…
Ivan_Herman: The mechanism is such that you can give the same kind of attention to the verifier if a verifier is recognized. You only talked about the issuer but there is also the verifier.
Carolynn_Bernier: where the verifier is presenting their credentials as
Carolynn_Bernier: the verifier.
Ivan_Herman: No, I talk about the case when I list a rifier as a credential. I gave an array of verifiers in a list that these are recognized by me and then if you issue a credential or a holder issues a presentation, it can check whether the verifier is valid is kosher or not. the same way as you check whether an issuer is kosher.
Carolynn_Bernier: But this has to do with verifiable presentations. No.
Ivan_Herman: No, conceptually a verifier always gets a presentation even if it's contains a single credential.
Dr._Susanne_Guth-Orlowski: So for example, the use case would be the global battery alliance has 10 accepted companies that can calculate the carbon footprint with companies, in the supply chain. then they do that and verify the work that the company has done,…
Carolynn_Bernier: I think there's a confusion here. Phil
Dr._Susanne_Guth-Orlowski: And then I can check if that verifier is, an accredited company on your trust list or what are you talking about?
Phil_Archer: Yeah, I think there is confusion.
Phil_Archer: The reality is that anyone can create some software that you call a verification system some sort of verifier and it can be a madeup load of nonsense. I can create something that looks like a green tick and say this is great no matter what you put in. I can create false software. I can create you false positive. So as well as being able I must admit you I didn't realize this although now you say it makes sense to me. We can also say that this verification software is recognized by issuer X. so if you use that software to verify our credentials then we'll stand by so it's very easy to write software to provide software that gives a false impression.
Phil_Archer: So this is a way of saying nope this stuff actually is truth.
Ivan_Herman: And technically if you look at the specification when you give a recognized entity you also add an attribute to it whether this recognized entity is recognized for verification or…
Ivan_Herman: for issuing or both. No,…
Carolynn_Bernier: really. …
Ivan_Herman: not sorry.
Carolynn_Bernier: if we go into the data model of the recognized entity verifier credential, you're referring to
Rigo_Wenning: In 2.4 we have product conformity as a use case in this and…
Rigo_Wenning: product conformity is precisely what we use in the DPP 2.4
Carolynn_Bernier: So action is issue or…
Ivan_Herman: But technically speaking,…
Ivan_Herman: if you look at 3.3, this is the formal classification of recognized action. So when you recognize an entity you say recognize action is issue or verify. Yeah.
Carolynn_Bernier: Okay.
Ivan_Herman: So when I stamp an entity to act in this ecosystem, I also say whether it is stamp for issue Yeah.
Carolynn_Bernier: Okay. That's very interesting.
Carolynn_Bernier: I wasn't aware about the verify.
Carolynn_Bernier: Coming back yeah the…
Phil_Archer: I was not.
Phil_Archer: I didn't realize that, but it makes sense.
Carolynn_Bernier: because for me the verifier in the DPP context is like the consumer who is checking the validity of a verifiable credential. So the idea that a consumer is recognized to able to verify it just doesn't make sense. You Yeah. Okay.
Rigo_Wenning: Yep. That's a semantic clash.
Ivan_Herman: No, that's true. I understand, Caroline. So it may not be relevant for DPP but in general the gives you
Rigo_Wenning: Ivan, it is because it allows you for example to express that you can verify your DPP with a market authority because that market authority has blah blah blah.
Rigo_Wenning: So you can express things that you need in the DPP. but it's all we need to know for the moment it would work. Whether it will be used is another story.
Carolynn_Bernier: Okay.
Carolynn_Bernier: Okay, very good. So coming back to section 2.4. All right, section 2.4. So the we fully understand, we all agree, we all understand, people who work in the DPP context understand that this has these recognized entity credentials, they are applicable in the DPP space, for product conformity.
Verifier Terminology Confusion
Carolynn_Bernier: And this comes back to what Suzanne was talking about ri So for example the assessment body is doing if some verification and is issuing a verifiable credential a VC containing the conformity claims and then the attestations that they are an authorized conformity assessment body and etc etc. But this verification is different from the the verif of the VC model where the verifier is for example the consumer that is performing a check that the verifier credential is correct or still valid. So there's a conflict of term of the word verifier here.
Carolynn_Bernier: It can be used as the verifier is the conformity assessment body who is issuing a VC that a product is conform But the verifier in the VC context is for example the consumer doing the validation check that the VC is still So that we're using the word verifier to mean different things here.
Carolynn_Bernier: So this is why there's a high potential for confusion. Suzanne, is this clear?
Dr._Susanne_Guth-Orlowski: I wouldn't have used the word verifier before this discussion for…
Dr._Susanne_Guth-Orlowski: what I described. So for me, an notified body that is issuing a conformity credential would always have been called an issuer.
Dr._Susanne_Guth-Orlowski: So maybe my confusion just came from when I was trying to understand what you meant. So, I'm not sure if the potential is so high. Mhm.
Carolynn_Bernier: Okay, thanks.
Carolynn_Bernier: Thanks, Phil.
Phil_Archer: I think the jargon for this is that the…
Phil_Archer: what you're calling the verifier is what we would call the relying party.
Carolynn_Bernier: Yes. Yes.
Phil_Archer: The individual who relies on this being true. So the relying party is generally a person or possibly an organization. The verifier is the software that does the calculation of the crypto and everything else. So, I can't do cryptographic calculations in my head.
Dr._Susanne_Guth-Orlowski: Okay.
Phil_Archer: And frankly, nor can you. so I'm a reliant party and I use a verifier.
Carolynn_Bernier: …
Carolynn_Bernier: coming yes, Ro
Rigo_Wenning: Yeah, just I think we are…
Rigo_Wenning: which is usually usual in data protection privacy it's worse is this mixing up and a semantic slip between several terms So the assessment conformity body doesn't need to be the issuer. They may trigger a third party service like two for or such a company that issues the credential because they have verified that the DPP is correct. Yeah. so you have even further slip between the nomenclature or the ontology of the DPP world and the ontology of the verifiable credential work. so I think …
Rigo_Wenning: if there is sustained confusion we would have to do a mapping.
Carolynn_Bernier: Yes, but I think we're all clear now.
Adding Digital Product Passports to Specification
Carolynn_Bernier: So, coming back to the recognized entity, they have several use cases here. product conformity, but there is no explicit mention of digital product passports, which is a bit of a shame. And last week on the Wednesday meeting we discussed this and we think that it would be very useful that we explicitly mention digital product passports in the recognized entity specification or recommendation.
Carolynn_Bernier: So I don't know if it would simply be required to change 4 product conform change it to explicitly mention digital product passports. or we need to add a new use case specifically. RIGO
Rigo_Wenning: in my point of view the DBP verification is just a very special case for product conformity and I think it would be sufficient if we would say in an additional paragraph below 2.4 before saying that the DPP verification can be a specific application of product conformity that has its own rules and that in this way the working group will be forced to actually watch out that the DPP use case works with their specification. I think that could work out as an example.
Carolynn_Bernier: Thank you, Ian.
Rigo_Wenning: I wouldn't change the product conformity as such but I would say look the DPP is a specific use case under this product conformity.
Ivan_Herman: So the question is it a very big work to add a B3 in the ecosystem example for DPP? personally I would believe that having a DPP example worked out in more details it field has a practice of what it requires but it doesn't have to be 100% precise etc and there must be details that you can sort of handwave about but to make it a clear use case there and then we can think about whether we want to have reference
Ivan_Herman: references to that use case in the core text or not whether having an ecosystem example is enough. I don't know how much work it requires.
Carolynn_Bernier: Yeah.
Ivan_Herman: So it's easy for me to say to do that but u
Phil_Archer: I think it's worth doing the ecosystem example for various reasons.
Phil_Archer: So as the eco this is an appendix it's not a normative part of the spec. It's an appendix that says here are some real world use cases that we know about and one is GS1 and one is UNTP grid work. I think it would be really good to have a DPP example in there as well. As Ivan says, it doesn't have to be real. I think you could actually show the use of the surplus ontology in there. We could have a product identifier of your choice that resolves to that in some way. wrapped up in a VC. I don't think that would be too hard to Probably take one of IO's examples and do that. away from the technical discipline of doing that, why is it that there is a GS1 example and a grid example?
Phil_Archer: Because it happens to be that I can turn up at what for me is 9:00 on a Tuesday night and what for Steve Capel is some reason not too bad a time on a Wednesday morning in Canberra and a lot of the discussion in the recognized entity group has been around those use cases and the more techy people in the group have made sure that the recognized entity specification meets that use case and…
Dr._Susanne_Guth-Orlowski: Yeah.
Phil_Archer: one or two very minor changes have been made to do that which Why I do think it's worth a little bit of effort to get a DPP example in there because that…
Phil_Archer: forces the rest of the group to make sure that the use case is covered. Yeah.
Ivan_Herman: Yeah. Heat.
Carolynn_Bernier: So do we agree that the kind of use case we're looking for?
Carolynn_Bernier: So here we would be adding a unique ecosystem example in annexb. do we agree that the type of example we want to talk about for DPP for example would be I have a product carbon footprint claim in a digital product passport and I link it to a VC of the organization that performed the carbon calculation.
Carolynn_Bernier: Is this the kind of use case we want to put?
Dr._Susanne_Guth-Orlowski: So we can do that or…
Dr._Susanne_Guth-Orlowski: we can do something that we need anyway. which is the CE marking for example in the battery passport which comes first as a real example that needs to be issued by notified body that can testify the CE marking or issue the CE marking such as Tiff and…
Dr._Susanne_Guth-Orlowski: I don't think we can maybe even at some point ask them to really particip ated the example and mock it up first. But the tough the …
Carolynn_Bernier: I think that's an excellent idea.
Carolynn_Bernier: So a CE marking DPP example where you have is it a conformity assessment body that no wait the CE marking is a volunteer it's a self declaration isn't
Carolynn_Bernier: That's Damn.
Dr._Susanne_Guth-Orlowski: I think that you have to have it for batteries because it's such a big topic and people accredited for it to become the notified body for the battery regulation. So I cannot believe it's voluntary in this case.
Dr._Susanne_Guth-Orlowski: Ro please you you have an opinion or…
Rigo_Wenning: It was earlier.
Dr._Susanne_Guth-Orlowski: Phil you sorry.
Phil_Archer: There are no benefits of Brexit.
Phil_Archer: One of the features of Brexit is we hear about this all the time. Now conform to European marking has to be conducted by an assessment body that itself is under the jurisdiction of the European call of justice. and it's a legal requirement, I think, for pretty much every product. So no it does have to be an external assessment. Yeah, it can be done by lots of people,…
Rigo_Wenning: Yeah. and…
Phil_Archer: but it is a requirement.
Rigo_Wenning: in Paris Shard airport they blocked 80% of the Chinese products coming in…
Dr._Susanne_Guth-Orlowski: Yeah, that's also my understanding.
Rigo_Wenning: because they had face fake CE marks. So it's mandatory and it's used everywhere.
Phil_Archer: I just share a little bit of Brexit delight with you. They tried to make it after Brexit that you had to have the UKCA mark, which does exactly the same thing in the UK. And everyone said, "Oh, so now we got to pay two different assessment bodies to assess our one product. This is insane. We're not going to do it." And so after a lot of back and forth, the obvious thing happened. And guess what?
Phil_Archer: If you don't want to pay for a UK CA mark and you've already got a CE mark, that's fine in the UK. You don't have to get a UKCA mob which is the whole thing completely pointless. There we go. Brexit Britain.
Dr._Susanne_Guth-Orlowski: Are you coming back soon? I don't know what the status is.
Phil_Archer: The current generation is body foreigners. Yeah.
Dr._Susanne_Guth-Orlowski: Okay. Yeah.
Carolynn_Bernier: Okay.
Dr._Susanne_Guth-Orlowski: We will talk about that over beer in Geneva.
Ivan_Herman: Be careful.
Ivan_Herman: Don't get fear started on Brexit because he was still in the team when it happened. So,
Dr._Susanne_Guth-Orlowski: So I think the use case is val valuable and helps at the same time a lot of people understand of how we think the world should look like tomorrow.
Carolynn_Bernier: So what we have agreed on is that we will propose a new ecosystem. so for chap I'm completely lost. Sorry.
Carolynn_Bernier: I was looking at the rules for requirements for CE marking and then suddenly I got an ecosystem example based on CE marking for a DPP including a verified DE marking certificate or…
Carolynn_Bernier: credential. how were the figures created?
Carolynn_Bernier: The fill for this
Carolynn_Bernier: here. Sure.
Phil_Archer: I don't know.
Phil_Archer: I think managers.
Ivan_Herman: It is.
Ivan_Herman: It is mermaid.
Phil_Archer: Sorry. Yeah.
Ivan_Herman: It is mermaid created probably by money and then processed automatically into the document. Sure.
Phil_Archer: It's relatively easy to generate diagrams like that these days.
Carolynn_Bernier: But it's not the diagram itself. It's more like the content of the diagram that
Phil_Archer: So, yeah, as Ivan said, mermaid is the usual thing. and you can get it to do that kind of thing without much difficulty. You can sort of say to an AI, I want a diagram that shows this and give me the input for mermaid and it will give you then you put it in mermaid and…
Dr._Susanne_Guth-Orlowski: You mean for the CE marking.
Phil_Archer: you get a diagram. So, it's actually not that hard to do these days. It used to take forever. it's the work of minutes now. That's true.
Carolynn_Bernier: Right. But…
Carolynn_Bernier: what is the trust anchor you in our scenario here? Because these examples start with the trust anchor both of them. So in our new example, who is the trust anchor? Yeah. Who is
Dr._Susanne_Guth-Orlowski: So the European Commission I think is we talked about the market surveillance authorities that are being accredited for certain regulations this is how it works for the notified bodies who's accredited for a certain regulations and I think you can find it at the markets website as well…
Carolynn_Bernier: We
Dr._Susanne_Guth-Orlowski: which notified body is allowed to testify for which regulation compliance of which regulation and therefore I would say the European Commission
Rigo_Wenning: Here we have another nice semantic split because you need to I think the VC issuer may be a service that provides the crypto but the issuer in the sense of who issues the DPP P is the responsible the economic So the e economic operator may use a service that provides a securing the DPP they are issuing into the market. And this is especially true when we
Rigo_Wenning: had Kawin, you remember all those talks about fake DPPs from competition from Asia? people were complaining about so the verification of the DPP is by market authorities and by consumers and by recyclers but the issuing of the DPP itself is the economic operator. he has to submit it to the The European Union may have their own verification of an issue DPP which then comes back to who can actually verify my DPP. The market authority will then give me a list of verifiers that can verify that DPP that it's correct.
Rigo_Wenning: And of course you need the shackle file to see whether the DPP itself has all the marks in there. but I think the term of issuer is the service provider in terms of VC and…
Rigo_Wenning: in the DPP it's the one who is responsible for making the DPP.
Carolynn_Bernier: I don't think we're talking about the same thing here.
Carolynn_Bernier: Rigo here we're trying to find I understand what you mean don't use the software with the economic operator. I understand what you're meaning. But I think what we're trying to create here is an ecosystem example where you have a DPP issuer in the sense of is responsible for issuing a DPP that includes that references a credential of a CE marking.
Carolynn_Bernier: So that means that there is a CE marking credential issued by a conformity assessment but this conformity assessment body itself is recognized by Suzanne was saying a service or an administration of you either in an member state administration
Rigo_Wenning: in the notified bodies have to be registered for example with ANI or…
Rigo_Wenning: or some kind of official regulation authority …
Carolynn_Bernier: Exactly. Yes.
Rigo_Wenning: then it's just layered so they have the authority to allow for people to become issuers of CE marks or to then assess whether it's two or three layers deep …
Carolynn_Bernier: Exactly. nested or…
Rigo_Wenning: which then is a very nice additional example because it requires nested verifier credentials.
Ivan_Herman: Yes, it's chain blessed. He
Carolynn_Bernier: rather Chained. Yeah.
Rigo_Wenning: It's not nested.
Carolynn_Bernier: Yeah. Chained. Ivo.
Ivo_Ladenius: Yeah, I was going to say that …
Dr._Susanne_Guth-Orlowski: Yeah. Yes.
Ivo_Ladenius: least in the Netherlands, the national authority is the one that is then the notifying authority, the trust anchor. I think in this example I was correcting Rigo, but you already did that. So,
Carolynn_Bernier: So if we want to make an equivalent figure to the ones that we have already in B1 and B2, basically you have to define a trust anchor which for me is this member state national authority thing that is authorized to accredit a conformity assessment body.
Carolynn_Bernier: So yeah,…
Dr._Susanne_Guth-Orlowski: Yeah, I think it's a European thing…
Dr._Susanne_Guth-Orlowski: but everyone you remember we talked about this market surveillance tool this CSMS and…
Carolynn_Bernier: I see SMS
Dr._Susanne_Guth-Orlowski: for each country has an authority that does the market urveance appoints the market surveillance for their country. I think that's what's also ego means. Yeah, I'm trying to find the site where it shows, which notified bodies we have in the EU for battery regulation, but then they are notified bodies for the entire EU is my understanding,…
Dr._Susanne_Guth-Orlowski: not only for that specific country, but I'm searching while you're talking and I'm trying to provide a link
Carolynn_Bernier: Yeah. …
Carolynn_Bernier: so basically for me the trust anchor in this context is the national authority authorized to accredit conformity assessment bodies. So basically if you take the figure that we have in B1 and B2 that's the trust anchor right and then we would have to say they issue a recognized entity credential subject I guess that would be Netherlands conformity assessment body register and actually there are two methodologies two discovery algorithms there's
Phil_Archer: Yeah.
Carolynn_Bernier: one based on registers and another one is based on identifiers or no credentials. And we have to decide example we want to illustrate. what type of algorithm we want to illustrate? Yes, Ian.
Ivan_Herman: Yeah, I think this is important.
Ivan_Herman: The two examples are different from that point of view because the one which is for JS1 is in my opinion a simpler approach which is not negative which is the verifier can take the VC when it's there and it just goes up a chain from one VC to the other by eventually to the trust anchor.
Ivan_Herman: The UN is slightly different if I understand because at every step it looks at the identifier scheme of the issue the wouldbe checked issuer which is used to get to direct you to a separate service somewhere on the web which is a kind of a who service which sort of gives a certification for that. So there is a separate service which acts as one that you can ask about when you look at the domain name and you can look at who issued the domain name and it's a kind of a service somewhere.
Ivan_Herman: And the question is which of the two is more appropriate for your model or is there a third model that you would prefer which is not represented by these two and…
Ivan_Herman: that's something that you have to decide and if there is a third model which is necessary then we have really the case where you come in with a use case to specifying all that by saying you guys you have to specify a third approach because what you have here doesn't fit my use case
Credential Discovery Mechanisms
Carolynn_Bernier: So if I understand correctly the chaining mechanism …
Carolynn_Bernier: which I don't know if actually this is something that's not clear to me in the text is if the GS1 example is an example of the credential based discovery mechanism or…
Ivan_Herman: Yes, GS1 is a chaining approach.
Carolynn_Bernier: so it's 4.1 or 4.2
Carolynn_Bernier: Thank you.
Ivan_Herman: It let me just go there. Yes, it's the credential based discovery. I think that's the GS1 approach and the other one the identifierbased discovery is the UN approach.
Carolynn_Bernier: Okay. …
Ivan_Herman: And the question is one of these two discovery mechanism good for you? And if not, what else do you need?
Carolynn_Bernier: per personally I would say 4.1 the credential base which is simpler. Rio, do you have an opinion?
Rigo_Wenning: Yeah, I think one is an extension of the other because they differ in detail and in openness. I think the Kaholin, you remember, is extending the content of the DPP to include also track and trace information where you have a multitude of entities. you could have the same with a very complex machinery which is constructed from a dozen DPPs coming from all over the world.
Rigo_Wenning: So I think there is a line the question is should we do and there when we have the DPP and currently the European DPP is leading if we…
Carolynn_Bernier: Yes.
Rigo_Wenning: if we really tell real world hey this is how we mimic the legal framework DC and really cling to the legal framework of the European system by saying look here is the entity like Kofra and they register this entity say in Sweden rise and then the DPP is issued they issue a cert mark the C
Rigo_Wenning: part is issued by here so really being ecosystem very close to the legal framework is of high value for those reading the specification while in principle all those are just applications.
Ivan_Herman: What's the problem of being applications?
Rigo_Wenning: Ivan perhaps I'm burned from my EU project work joining you in being critic about it this is just an application it just an application is a four-letter word meaning you don't add value here because you are just applying…
Rigo_Wenning: what is in the specification just into specific way of doing This
Carolynn_Bernier: So I agree that Rio there's value in mimicking the legal infrastructure.
Carolynn_Bernier: Yeah. What is not clear to me is between the two algorithms described in 4.1 and 4.2 for discovering related credentials. the second one requires somebody hosting a If I understand correctly the second one it requires somebody hosting a list that can be looked up.
Carolynn_Bernier: So if I'm not a great great
Rigo_Wenning: Yeah, let me translate. The first one needs a GIN and in the GIN you have coded that GS1 Utopia member organization has a range of numbers and you have the entity number which is in the GIN and they are mimicking this. in G when Philip is back he can confirm in GS1 you can have your own range of numbers that you can issue yourself to do that you have to register with GS1 and they are mimicking this.
Rigo_Wenning: So this is that again and again and again the double semantics of gins when we are going into here because the gins themselves have a meaning by saying hey I'm number such and such and I'm allowed to issue that subsequent number a range of numbers and this is what they mimic in the first place which is very similar to an issuer saying here I'm the Kufra recognized entity in France and I have this sub entity who issues the CE marks but it's not the same because then you have different organizations being involved and not only GS1 creating a string of numbers which then brings you to the second one which is really
Rigo_Wenning: really tied to the UNDP Steve Capel thingy by saying, "Hey, and by the way, when you do track and trace, you have so many entities all around. You just dynamically collect information via DID and…
Rigo_Wenning: via web. While in our case, we are in between the two because we have several entities doing stuff, but we know them in advance.
Carolynn_Bernier: No, no,…
Carolynn_Bernier: I disagree, just one example, there are multiple entities in the example. If you look at it, you have the global office venue you have the member organizations and then you have the organization like the economic operator. So there are three different entities that are involved in the ecosystem. Suzanne. Yeah.
Rigo_Wenning: But Not there.
Dr._Susanne_Guth-Orlowski: First of all, can forgive me which document are you looking at? Maybe someone can share the link in the chat. second, I wanted to say that I found the single market compliance space that is listing all notified bodies that are allowed to testify compliance for the battery regulation also in the chat. So that's our trust list at least for the second example that we discussed earlier and then I do not understand how this example that you just discussed is related to our dig passport stuff really with the GS1 entities and…
Dr._Susanne_Guth-Orlowski: so forth. I'm not sure…
Carolynn_Bernier: So, right.
Dr._Susanne_Guth-Orlowski: why are we discussing this.
Carolynn_Bernier: So, if you go to the link in the chat here,…
Dr._Susanne_Guth-Orlowski: Yeah. Mhm.
Carolynn_Bernier: the link in the chat takes you to the recommendation being made by the recognized entity work group of the V verified credential work group. the recognized entity task force of the recognized entity and they are proposing two mechanisms. So they're described in chapter 4. If you go to chapter 4 there are two algorithms for how you can discover a credential from another credential.
Carolynn_Bernier: So chain credentials basically. And there's two mechanisms. The first one uses the concept of a recognized in field in the issuer part That means that if I issue a credential, I can say and I'm the issuer of the credential. I can say I am recognized over there. So I can follow the link to find the credential that recognizes me.
Carolynn_Bernier: So for example from that's the first approach and…
Dr._Susanne_Guth-Orlowski: I see.
Dr._Susanne_Guth-Orlowski: Yeah. Yeah. No, I understand. Mhm.
Carolynn_Bernier: there's an example based on GS1 section B.1 in annex B.1 if you go in annex B.1 you will see the example that Rio is talking about so it's an example…
Dr._Susanne_Guth-Orlowski: Okay. Yeah,…
Carolynn_Bernier: where the recognized in property is used to link with a GS1 member organization credential and…
Dr._Susanne_Guth-Orlowski: a ial with company credential or whatever. Okay.
Carolynn_Bernier: related to the GS1 global credential that says that me a member organization of GS1 like GS1 France
Carolynn_Bernier: France is accredited by GS1 global and…
Dr._Susanne_Guth-Orlowski: Mhm.
Dr._Susanne_Guth-Orlowski: Okay. Mhm.
Carolynn_Bernier: GS1 France is indeed authorized to issue those G10s and then the company is indeed allowed to issue those subjins.
Dr._Susanne_Guth-Orlowski: Okay.
Carolynn_Bernier: So it's a way to link credentials to one another. That's why we're talking about that.
Dr._Susanne_Guth-Orlowski: Yeah. Yeah. Okay.
Carolynn_Bernier: But what is it the question coming back to what Ivan was saying is that there are two algorithms for chaining credentials that are proposed in the recognized entity recommendation that we were talking about 4.1 4.1 using the recognized in attribute okay the second one is the one I less understand it
Carolynn_Bernier: has to do with creating a kind of a list somewhere that you're going to check. And this is less clear to me. Ivan, your hand is up.
Ivan_Herman: The second one is more complicated and…
Ivan_Herman: I do not even claim that I did I understand or I know all the details of it.
Carolynn_Bernier: Okay. Yep.
Ivan_Herman: But there is one entry point to it which is important and to see whether that's realistic at all in your world. because as it says it's identifierbased discovery. So what happens is that the issuer has an identifier but it is not just a URL that you just pick up but when you take this URL you would dreference it and you would get a very special document which is a controlled identifier document.
Ivan_Herman: For example, you can DID URL for the identification of your issuer. And it is in this control identifier document that you find additional fields that helps you to identify whether this issuer is valid or not. So it's much more complicated to develop now and to implement. Now the UN has chosen this approach. it's up to them to decide whether it's okay or not. The question is whether is it realistic in the DPP world to deploy a system that require such an additional infrastructure because if it
Ivan_Herman: too complicated for the DPP world, then forget about it. Caroline. I seem to have completely
Carolynn_Bernier: No, no,…
Dr._Susanne_Guth-Orlowski: I think J is reading something.
Carolynn_Bernier: no, no, no. I'm reading the spec. Carolynn Bernier:
Dr._Susanne_Guth-Orlowski: I jump in real quick? so to identify someone and you have the globally unique identifier of the issuer and then you can use this identifier to find more credentials about them. that's the way we were walking working along those lines. So I would go to the wallet of that issuer and ask for a credential of a certain type in its wallet.
Dr._Susanne_Guth-Orlowski: So if I find I don't know a VLI credential in that wallet that can testify that this VLI is issued to the same identifier then I can connect the two credentials. That's what we always worked with that assumption that it works this way. at 30 but Engel wasn't there yet when we implementing it this way. that would be my most obvious approach.
Carolynn_Bernier: Here we go.
Rigo_Wenning: The first the credentialbased one has one big caveat is that the commission will not kind of be able to act like a trust anchor because it's not the com it's democratic government construction type of issue is the European Commission is not able to say only this entity only Kofra in France can issue further accreditation.
Rigo_Wenning: They will give you a list a you are right discoverable list of the 27 national accredititation authorities but they will not be able to say we for example can decide whether Kufra is still in the list or…
Carolynn_Bernier: Why not?
Rigo_Wenning: that means they will not issue a credential so that you can derive a trust from the commission to Kofra to the CEO because this is the same mistake they made in X509 where the University of Philadelphia had to tell whether the French parliament is really the French parliament. It's not going to happen. And that's exactly the point of X509.
Rigo_Wenning: And here we are doing something different by saying hey there is a list of 27 authorities and those are the links where you can discover information and you can get the root certificates and stuff and from there on you can then work out down the path after that national authority which is very different from the GS1 example
Rigo_Wenning: because GS1 global has the authority to say hey you are a national you are now GS1 Netherlands and you are accredited by GS1 global you are part of the family and then they get this credential we could argue for the commission that we can simplify with the credentialbased discovery and saying hey the commission could act as a trust anchor, but this is administratively legally difficult because they would then say this is the one we accept or this is the one we do not accept. And that's a power that the member states don't want to give them.
Carolynn_Bernier: I think so.
Ivan_Herman: But that means… if my I'm sorry. There you go. Ivan Herman:
Ivo_Ladenius: Is it to European Commission or is it the government itself at each country that is the trust anchor the European Commission shouldn't be in there,…
Carolynn_Bernier: Yes. Yes.
Ivo_Ladenius: right? Yeah.
Phil_Archer: It's good.
Rigo_Wenning: as a list. Yes, because the European Commission coordinates, it gives you a list of national authorities. Absolutely.
Ivo_Ladenius: But trust anchor is the government.
Carolynn_Bernier: The trust anchor is whoever you trust.
Carolynn_Bernier: So if you trust it's how high you have to go up until you trust really. it's the final, So if you don't trust the government of Netherlands, you may trust a list published by the European Commission saying that this is the government body in the Netherlands who's authorized to accredit who do you trust really? H much I think that's somebody we're coming to the end of this meeting and so we have to quickly wrap up. Still,
Phil_Archer: the recognized entity spec does support lists that is Etsy trust lists and…
Phil_Archer: X509 certificate lists and…
Carolynn_Bernier: Yeah, exactly.
Phil_Archer: so you go from wherever you're up to up and up and It also says you stop when you find someone you trust. You don't always have to go up at the top.
Phil_Archer: You get to one if you trust person is it stop. You're done. it's in there.
Carolynn_Bernier: And the example with the Etsy trust list is I'm just going to Etsy C.1 Etsy trust list services anchor.
Phil_Archer: Search for It's in there.
Ivan_Herman: There is a very important point here that you will want to emphasize in this example.
Ivan_Herman: There is no one trust what was the name used here there is not necessarily one trust anchor and…
Phil_Archer: Thank you.
Ivan_Herman: I think that's the point of rigor there are several trust anchors and the system in the recognized entities is perfectly valid with that it does not rely on having one trust anchor and you can have a diagram where on the top you have several trust anchors, let's say one per country, and then those may be dependent of their government, but that's sort of the same thing in this respect. And if you find a verified credential and you get up to let's say the Dutch or the Hungarian one, then you are fine. you shouldn't trust the Hungarians, but you can trust the French maybe.
Ivan_Herman: and then you are done. You don't necessarily have one and that's important to emphasize in the example because if you look at the current two appendices of the spec both of them have one root trust anchor up there. So a casual reader might deduce that in this system you have to have something up on the top. and That's not true. And in this example, you have this distribution in there, which is an important feature of the recognized entities.
Carolynn_Bernier: So you mean that you could have an issuer that is recognized in several? So for example, I'm a assessment body in France. I'm recognized by the French authority for accreditating conformity assessment bodies, but I'm also recognized in the international accredititation body association of something.
Ivan_Herman: absolutely in the recognized entity spec this is true regal whether it's the DPP world I cannot comment…
Carolynn_Bernier: No, Rio says no and…
Rigo_Wenning: No, no, no, no.
Carolynn_Bernier: Phil says yes. Ivan Herman:
Ivan_Herman: but in the recognized entity spec having several there is perfectly valid
Carolynn_Bernier: recognized in just so we have to close this meeting.
Rigo_Wenning: which means you need to be as a Swedish person,…
Rigo_Wenning: as a Swedish company, you need to verify a CE mark that was issued in France or even in the UK. so, that's Ivan put it perfectly.
Ivan_Herman: I'm very happy to hear that…
Phil_Archer: I
Ivan_Herman: although I don't know why but
Carolynn_Bernier: We have to close this meeting.
Carolynn_Bernier: Suzanne, you said that in parallel you were making some check for how the accreditation happens.
Dr._Susanne_Guth-Orlowski: I did it's in the chat.
Dr._Susanne_Guth-Orlowski: I posted the trust list if you want with the list of market surveillance authorities that are accredited to issue compliance credentials for the CE marking. That's one link. and then the last thing that I provided in the chat is the list of qualified trust service providers in the EU. that I don't know if that was also part of the discussion that is a list of accredited qualified trust service providers which we also need for DPP because you have to have a seal from them at least the IDAS 1.0 conformant to register at the DPP registry.
Dr._Susanne_Guth-Orlowski: So if you want to go down the lines of a DPP example,…
Dr._Susanne_Guth-Orlowski: we can use just the right stuff at least in our examples.
Carolynn_Bernier: I think the example should just focus on the CE marking that…
Carolynn_Bernier: but I'm a bit surprised…
Dr._Susanne_Guth-Orlowski: Fine with me.
Carolynn_Bernier: though that the link you said only has three countries Hungary Sweden and…
Dr._Susanne_Guth-Orlowski: Yeah. No.
Carolynn_Bernier: Finland. Why all?
Dr._Susanne_Guth-Orlowski: No.
Ivan_Herman: Guys, we Phil and I are Yeah,…
Phil_Archer: Good to go.
Carolynn_Bernier: Okay. Yeah, No problem.
Ivan_Herman: Caroline, you contact me when you ask me to change the calendar entry, right? I don't do anything right now.
Carolynn_Bernier: Okay. Okay.
Phil_Archer: Thanks. Got to go. Thank you.
Carolynn_Bernier: So next week there will not be a meeting…
Dr._Susanne_Guth-Orlowski: Caroline,…
Carolynn_Bernier: unless we keep the Monday because otherwise we'll be in Geneva.
Phil_Archer: Right. Yeah.
Carolynn_Bernier: So I'll send the meeting on I'll send an email to the mailing list.
Ivan_Herman: Okay.
Phil_Archer: Great.
Carolynn_Bernier: Okay. Thank you.
Phil_Archer: Thanks. Ciao B. Dr. Susanne Guth-Orlowski: Dr. Susanne Guth-Orlowski:
Dr._Susanne_Guth-Orlowski: You can look at the list if you still have time.
Carolynn_Bernier: Yeah. Yeah,…
Carolynn_Bernier: So in the link you sent, I have only four. Let me share my screen so they can see…
Dr._Susanne_Guth-Orlowski: Yeah, there are only four credited companies so far that can do the CE marking for the EU battery regulation.
Carolynn_Bernier: what I see.
Dr._Susanne_Guth-Orlowski: Yeah. …
Carolynn_Bernier: Okay. This Dr. Susanne Guth-Orlowski:
Dr._Susanne_Guth-Orlowski: it's very small. I'm not on my big screen yet. Hang on. What are you showing? how can I make this bigger? Yeah, but's that's right. Those are the four companies that can issue a CE marking for batteries. It's correct. and others are applying. So, a lot of are trying to pass this at the moment, but at the moment, those are the ones. and I've met all of those in China because, all batteries come from China and they have to choose between one of the four at the moment to get their CE marking to actually import the battery after February 2027.
Carolynn_Bernier: So coming back to the example that we want to create this is just a list it's not saying that the commission DG grow here is accrediting or…
Dr._Susanne_Guth-Orlowski: Mhm. Yeah.
Carolynn_Bernier: doing anything it's a list published by
Carolynn_Bernier: the single market compliance space. So if you trust this webgate.ec.juropa.eu…
Carolynn_Bernier: then you trust the information basically right. sure…
Dr._Susanne_Guth-Orlowski: kind of…
Dr._Susanne_Guth-Orlowski: because there is no infrastructure for issuing credentials yet. Yeah. But we can use it as an example for how the world should look like tomorrow.
Carolynn_Bernier: but how did this TV get on this list?
Dr._Susanne_Guth-Orlowski: Yeah. Yeah.
Carolynn_Bernier: What did they have to do? to and…
Dr._Susanne_Guth-Orlowski: They had to go through the accreditation process. you have to show that you do all the correct tests along the battery regulations.
Carolynn_Bernier: what is this notification?
Dr._Susanne_Guth-Orlowski: So you have to send some people there they have to get trained and…
Dr._Susanne_Guth-Orlowski: then at some point you get the accreditation. It takes very long. Yeah. Mhm.
Carolynn_Bernier: because in it…
Carolynn_Bernier: because what basically we want to do so I'm just going to paste this into my notes so that What we want to end up with is an example that Looks like this recognized in. And so we want to have some kind of an example of the name of the trust anchor which could be for example this thing space right that issues a recognized entity credential to
Dr._Susanne_Guth-Orlowski: The single market market compliance space to the notified body. Yeah.
Carolynn_Bernier: the accredititation body in each actually we have to figure out who accredits these people is it the commission or is it performed inside the member state I'm going to ask some colleagues who are experts in this topic Okay,…
Dr._Susanne_Guth-Orlowski: By the sorry yeah I see that…
Carolynn_Bernier: just so that we have a working example that looks like that is more grounded in reality.
Dr._Susanne_Guth-Orlowski: if you search in Google you find that to was the first one who became a notified body for the EU battery regulation. So someone at the EU has to pass or some delegated institution.
Carolynn_Bernier: But…
Dr._Susanne_Guth-Orlowski: I don't know. Yeah. But if you search for example other legislations on the left side, you see all notified bodies that are allowed to testify for those. Yeah. Yeah.
Carolynn_Bernier: how did they get into this list? Dr. Susanne Guth-Orlowski:
Dr._Susanne_Guth-Orlowski: Yeah. I don't know. But is that important?
Carolynn_Bernier: I'm not sure it's the EU.
Dr._Susanne_Guth-Orlowski: It's an EU.
Carolynn_Bernier: This is what I need to know if it's the EU or if it's a member state thing.
Dr._Susanne_Guth-Orlowski: No, no, no. It's not a member state thing. It's an EU thing. The European Commission I guess testifies or accredited notified bodies if they can …
Carolynn_Bernier: This is not certain.
Carolynn_Bernier: Not I think it's done in member states.
Dr._Susanne_Guth-Orlowski: that's what If they delegate it to member states, but then I see.
Carolynn_Bernier: Yes. Yes.
Dr._Susanne_Guth-Orlowski: Yeah, possibly.
Carolynn_Bernier: Yes. to ask.
Dr._Susanne_Guth-Orlowski: Possibly. I mean I'm working with TU and all the others as well. I can ask them where they actually did get this from.
Carolynn_Bernier: Yeah. And then that way we can make a nice something like this.
Dr._Susanne_Guth-Orlowski: Yeah. Yeah.
Carolynn_Bernier: that we can discuss next time.
Dr._Susanne_Guth-Orlowski: Okay. I see.
Carolynn_Bernier: I can do this in PowerPoint in three minutes.
Dr._Susanne_Guth-Orlowski: So, yeah,…
Carolynn_Bernier: But the important thing is to understand the reality behind the legal structure.
Dr._Susanne_Guth-Orlowski: of course. Mhm. Okay.
Carolynn_Bernier: Okay. okay. Okay.
Dr._Susanne_Guth-Orlowski: I cannot attend if we do something on Monday. and I lost track where the DVP stuff is after I made some contributions to the document.
Dr._Susanne_Guth-Orlowski: And then I couldn't attend the last meeting. So I don't know where this stands.
Carolynn_Bernier: There has not been that much work…
Carolynn_Bernier: because we were now switched to working on the recognized entity work but I think that the recognized entity example should be pretty easy and…
Carolynn_Bernier: quick to do. That's my hope anyway is and…
Dr._Susanne_Guth-Orlowski: Mhm. Okay.
Dr._Susanne_Guth-Orlowski: Fine. let me check.
Carolynn_Bernier: I think CE marking example is a very good one.
Dr._Susanne_Guth-Orlowski: I think also because everyone who really needs to do something in that area knows And it comes with a battery DPP as a first example. Hope you your holiday must have been great.
Dr._Susanne_Guth-Orlowski: You look so relaxed and tend. …
Carolynn_Bernier: It was amazing.
Carolynn_Bernier: When do you arrive in Geneva?
Dr._Susanne_Guth-Orlowski: I think Tuesday morning.
Carolynn_Bernier: So, you're staying until Friday afternoon.
Dr._Susanne_Guth-Orlowski: Yeah, Friday. Mhm. Excellent.
Carolynn_Bernier: So we have plenty of time to chat. Bye-bye. Meeting ended after 01:14:21 👋 This editable transcript was computer generated and might contain errors. People can also change the text after it was created.