Meeting minutes
Meeting Start
Ingo_Wolf: I call in.
Carolynn Bernier: Hi Engle. I think for the moment we're only two of us.
Ingo_Wolf: I just joined.
Carolynn Bernier: Hi from Hi Vo is it okay?
Ingo_Wolf: Hey Make us curious.
Ronald_Koenig: Hi. I'm five.
Ronald_Koenig: It's my first day of vacation.
Rigo: Hey.
Rigo: I leave my camera off because I'm in an unusual
Carolynn Bernier: Okay, we will not ask. Ronald, if this is your day back from vacation, you must be in deep dis despair or I don't know,…
Carolynn Bernier: depression or…
Ronald_Koenig: No, no,…
Ronald_Koenig: no, no, no. I'm fine.
Carolynn Bernier: you're okay.
Ronald_Koenig: Was a very nice vacation. Three weeks.
Ronald_Koenig: So, I'm just try to rejoin now. And it was already a very very full first day. Yeah.
Carolynn Bernier: Yeah, I can understand.
Carolynn Bernier: Hi, Nice to see you.
Ingo_Wolf: Heat.
Carolynn Bernier: By the way, while we're waiting for the others to connect, I have still have to review the article and submit the modifications. I have until the 19th of September. So, you'll probably be hearing from me in the coming weeks of rather.
Michael_Linck: I just realized I was muted when I said hello back.
Carolynn Bernier: I haven't forgot.
Michael_Linck: Hello.
Carolynn Bernier: Okay.
Carolynn Bernier: Ronald, do you know if Carson is coming? Hi. Okay.
Ronald_Koenig: I don't know.
Ronald_Koenig: Doing
Ingo_Wolf: He's also on the way to GDC,…
Ingo_Wolf: so I assume probably not.
Carolynn Bernier: So, if Carsten is not here, unless there's a So, do you want to talk about wallets or DPPS? it's possible. Last week we spoke about DPP. So, we can talk about wallets if you want or we can talk about excellent.
Ingo_Wolf: as you like.
Ingo_Wolf: I have something prepared for our discussion from the last meetings concerning the recognized entity example ACE marking.
Carolynn Bernier: Me too.
Ingo_Wolf: Very good. Yeah.
Carolynn Bernier: Let's do that. Let's do that.
Ingo_Wolf: Kitchen.
Recognized Entity Spec Discussion
Carolynn Bernier: So just for the others who were not at there at the last meeting the recognized entity spec which is I'm going to stick the link to it in the chat here for those who don't know it in annex has an annex on ecosystem examples that show how the recognized entity credential format or at least mechanisms can be used to link and discover a from a given credential.
Carolynn Bernier: So there are two ecosystem examples and they both illustrate two different algorithms for doing this discovery and the algorithms if you look up in section four are described. last week we decided that this work group would attempt to create an ecosystem example based on the DBP to illustrate the concepts and the algorithms that are presented in the recognized entity spec spec. I worked on my side. I hear that Ingo also you worked on it on your side. Go ahead.
Ingo_Wolf: Yeah, maybe I share my screen for a small slide deck that I prepared. Just a moment.
Carolynn Bernier: What?
CE Marking Governance Model
Ingo_Wolf: Yeah. So this is the governance model I would say or trust model that we have for the CE marking.
Ingo_Wolf: So we went through that last time and first of all I had to research the authorities that play a role in the trust chain until you derive the evidence at the bottom right of this diagram. the EU declaration of conformity which product manufacturers need to have when they bring products to the European market and for Germany It's like that the government of the Federal Republic of Germany grants accreditation to an institution called DAX Deutsche accredit.
Ingo_Wolf: So meaning a central authority that is responsible for assessing other organizations that assess conformity. So this is like for example then the Nazi product certification example company in the middle of the diagram. those are the assessment centers for manufacturers and they are accredited by DAX to do so after conformity assessment of their processes was done. they will get the accreditation to issue or to execute assessments on products of a certain category.
Ingo_Wolf: And yeah then after successful assessment they will issue an EU type examination certificate that is…
Ingo_Wolf: then the evidence for the CE mark that's the overall process so to say questions Yes.
Carolynn Bernier: Wait, I have a question about this.
Carolynn Bernier: so I assume that the Federal Republic of Germany is actually a more complicated thing because you probably have a ministry of something or other that is responsible for so I doubt that the Federal Republic of Germany would be the root of trust rather than some ministry of something or…
Ingo_Wolf: Parts of it. You are right. Exactly.
Carolynn Bernier: there and…
Ingo_Wolf: So the ministry that is responsible for consumers protection I guess they will nominate this central accreditation institute which is ducks in our case.
Carolynn Bernier: so Ian has his hand up.
Ingo_Wolf: Yes, Iran, please. A
Ivan_Herman: Caroline, finish your thought and I can come back.
Carolynn Bernier: Be because I have a question about the two boxes under Federal Republic of Germany. there's this ducks which has the possibility to so…
Carolynn Bernier: therefore the accred it goes underneath DAX right DAX accredits an organization that becomes a notified body as…
Ingo_Wolf: Mhm.
Carolynn Bernier: because they notify it to the European Commission and then designate notified body. So if I understand correctly the part on the right designate notified bodies.
Ingo_Wolf: Yeah, there is this …
Carolynn Bernier: Why is it that not ducks?
Ingo_Wolf: because I think this capability lies with the government.
Ingo_Wolf: So they are in the role to inform notification bodies for example also on EU level about the product certification centers that are conformant to the process for a certain product certification.
Carolynn Bernier: we have to dig a little. this is technical and complicated. I wonder if it's not DAX that does the Notifying means that some organization declares which conformity assessment bodies have been notified to the commission. Rio, your hand is up.
Rigo: Yeah, I accidentally read the law and it just creates a system. The root of trust is the commission who will acknowledge so-called notifying authorities but the selection of the notifying authority is on the member state. That means the actual presentation we see is correct and not correct. it's simply that ducks and notifying authority are the same because the federal government of Germany has selected ducks as the notifying authority that is…
Ingo_Wolf: I could merge it in the diagram, right?
Rigo: then cable to the commission who has a list of them. so it's correct and not correct.
Carolynn Bernier: Hi. …
Carolynn Bernier: whose hand is up next? Ivan, why are we doing this?
Notifying Authority Explanation
Ivan_Herman: So first of all as a complete outsider in this near consumer…
Ivan_Herman: which nothing else knows that what happened behind the scene. What the heck is a notifying authority the first place that's the other question you did not talk about the last line. I understand that there is the nor product whatever that issues a certificate but what is the evidence declaration of confirmity etc.
Carolynn Bernier: Yeah. Yeah. Yeah. Yeah. so Ivana, we're learning as well as we do this. So,
Carolynn Bernier: We're trying our best.
Rigo: Can I so no notifying authority simply is a way like the regulation authority for telecommunications is just a name for the administration that actually is capable of recognizing certification authorities in the market.
Carolynn Bernier: Yeah, go ahead, Try to answer question.
Rigo: So this is the market authority and now if you are a private company and this is the example of Nazi product certification is that this is a private company to suit Dra what have you and those issue a request to the notifying authority and then they have to prove that they ful
Rigo: fill certain criteria that are enumerated in the law and the notifying authority will test all of them and once you are then a certification authority you can then certify companies even individuals and once you have that certification they've tested that certain criteria for the DB DDP for the wallet etc.
Rigo: are present and once they have this conformity and that's the conformity to the typical EN that is done either in JTC24 now in Etsy and so on this European norm once they test that you are conformant to this European norm they issue a certificate that says he is conformed to that European norm and then the law says if you are conformed to that European norm you have presumption of conformity. That means if the market authority comes to you and says you're nonconformant, Otherwise, you have to prove it that you're conformant.
Carolynn Bernier: Yeah, except Rio here that we're not talking about the We're talking about conformity of the product. so there are different levels of conformity but anyways here what we see here that in general it's conformity in general and it could be for a battery a motor or any kind of conformity that needs to be checked and…
Carolynn Bernier: Ingo if you don't mind I made the same figure as yours So what?
Ingo_Wolf: You want to show it?
Ivan_Herman: Wait, is a question to which I didn't get an answer yet.
Carolynn Bernier: You didn't get an answer…
Ivan_Herman: I had a question for which I don't have an answer.
Carolynn Bernier: which was what?
Ivan_Herman: Can you put back the slide in The last the bottom line…
Ingo_Wolf: Yeah. Sorry, just a moment. And here it is.
Evidence of CE Mark
Ivan_Herman: what is this evidence with green arrow etc. Carolynn Bernier:
Ingo_Wolf: Yeah, it's meant So, it's very small below the box. no recognized in this last leaf so to say.
Ingo_Wolf: Because the product certification is issued for a certain product to a certain company but it has no direct relation to let's say DPP data for example of the product. So as soon as you have this UT type examination certification that is the result of the conformity assessment from not product for example you have the right to use the CE mark on your product and this evidence is so to say hold at the company but it's not necessarily delivered as a verified
Ingo_Wolf: the credential. Still, it's an evidence that you passed that product certification or assessment. Mhm. Yes.
Ivan_Herman: So from the recognized entity point of view and…
Ivan_Herman: I don't remember the exact terms for that they have introduced a possibility to include references to other schemes of recognition into a recognized entity. they were referring to Etsy list and I don't remember ITF things etc. So this is one example that fits into that construction.
Ingo_Wolf: which we will see later on.
Ivan_Herman: Okay. Yeah,…
Ingo_Wolf: There are more slides.
Ivan_Herman: that's actually good because Yeah.
Carolynn Bernier: Yeah. let me show exactly the same figure…
Ivan_Herman: Shut up.
Carolynn Bernier: but made by me according to my understanding. Exactly the same thing. So that way we may get somewhere. And I applied it according to the battery regulation. Where is the sharing button? Here we go. But I used Phil's colors. I want to get rid of this thing. How can I get rid of this thing? I used Phil's colors.
Ivan_Herman: Yes.
Carolynn Bernier: I don't know if you can see my screen properly because Phil had made an example with these The root of trust was the organizations were in gray. The credentials were in darker gray. And the actual credential was in blue. So I use those colors just to refer to the
Carolynn Bernier: And I did it So what Ingo just shared I didn't put the federal state of Germany. So I didn't put the member state that is above the member states notifying authority. So basically Germany would be here and…
Carolynn Bernier: Germany recognizes the member states notifying authority which would be the company you call DAX or something like that. I don't remember what you called it.
Ingo_Wolf: Mhm. Yes.
Carolynn Bernier: DAC something like that,…
Ingo_Wolf: Yeah. Basically it means German accredititation center. So
Carolynn Bernier: so they notify the commission. That's basically what notifying means. So here rather than choosing the German government, I chose the European Commission as a hypothetical trust anchor which could issue a recognized entity credential to Germany's notifying authority which says that they recognize it as a notifying authority.
Carolynn Bernier: And so here I have several roots of trust because there can be many roots of trust and I think it's pretty cool to have an example where there are multiple roots of trusts hypothetical So the notifying authority itself they accredit assessment bodies who then become notified bodies according to the law. So this notifying authority could issue a recognized entity credential to the accredited conformity assessment which could be TUV for example is an example of a conformity assessment body that performs these tests.
Carolynn Bernier: And for example, for the battery regulation here, if you go to this slide here, you have the list of companies that have been for different countries. They've already been accredited for ulation. Here, this is the battery regulation. So they've been notified to the European Commission that they're accredited to perform tests for compliance in different countries. So TUV for example in Hungary for example.
Carolynn Bernier: So, TUV is an example of a conformity assessment body that's already been notified and So, today they issue European conformity certificates and today these certificates are issued in PDF. But let's be crazy and imagine that it's actually issued as a verifiable credential and suppose it's been actually issued according to the UNP DPP standard for digital conformity credentials. Okay, so this is a verifiable credential but it's not a recognized entity credential. It's just a credential that corresponds to the UNP specification for digital conformity credentials.
Carolynn Bernier: So the issuer of this credential here uses the recognized in construct to point to who recognizes them. So basically this is TUV here for example here this is TUV. they issue this credential but TV is recognized by DAC or some other notifying authority and then they themselves are recognized by the European Commission or they could alternatively be recognized by the German state or the Hungarian state or whichever state you want.
Carolynn Bernier: So they could be also recognized by the German. We could have another trust trust anchor here, the German state like Ingo said. So now you have these conformity certificates. So you have a battery manufacturer here that issues The DPP itself may or may not be issued as a verifiable credential. But the DPP must reference a EU declaration of conformity in order to be able to put the CE marking on their battery. the EU declaration of conformity in general is a PDF document, but let's be crazy and imagine that it was issued as a verifiable credential.
Carolynn Bernier: Again according to the UN UN transparency protocol standard inside this EU declaration of conformity you have to identify the battery model that you described here and the declaration of conformity references the EU conformity certificate and possibly the DPP could also point to the conformity certificate possibly.
Ingo_Wolf: Jesus. Carolynn Bernier:
Carolynn Bernier: This one. I'm not sure if the DPP needs to refer and to just add a little bit of spice in the thing, I assume that there's an additional root of trust which could be the international association of conformity assessment bodies, the TIC council which actually exists and they represent 100 international thirdparty testing inspection certification organizations around the world UV which is a member of KIC and they could also issue a recognized entity credential. So depending on who you trust whether you trust TIC or you trust the European Commission you can get trust about the issuer of the EU conformity certificate.
Ingo_Wolf: All right.
Carolynn Bernier: That's basically…
Carolynn Bernier: where I'm up to. Please I don't know whose hand is up. angle upon.
Ivan_Herman: Yeah. I don't claim to understand or…
Credential Structure and Types
Ivan_Herman: could follow everything but there's a repeating pattern here which bothers me.
Carolynn Bernier: Yes. Here.
Ivan_Herman: Let's say in the lower left hand corner when you say subject isn't it in reality it's a type of credential that you issued on some entity. That's okay.
Carolynn Bernier: I have no idea what subject means. I used what Phil was talking about here.
Carolynn Bernier: Here he said subject is GS1 some member organizations here for example he said subject G10 as GS1 digital link I didn't understand…
Ivan_Herman: That's okay. But when you go down okay that we have to have fear here…
Carolynn Bernier: what they meant by subject here.
Ivan_Herman: because I don't really know So okay that I cannot answer…
Carolynn Bernier: Yeah, I wasn't sure how to so I tried to I think what is meant here is what is the credential about? I wasn't really sure what felt meant Phil meant here. Yeah.
Ivan_Herman: but in general if you take a credential it has a certain type that means a credential…
Ivan_Herman: which is usually used for whatever can you go back to your slide yours?
Carolynn Bernier: This one here.
Carolynn Bernier: I think this one.
Ivan_Herman: So it's a conformity certificate on something and that means that it is a type which you issue a credential of on some specific entity. that's part of the application area…
Carolynn Bernier: But who defines these types?
Ivan_Herman: which defines all the terms which are here for this specific ecosystem. So in a general sense it's part of the DPP vocabulary…
Ivan_Herman: if we are talking about DPP here.
Carolynn Bernier: …
Carolynn Bernier: so I think that Mhm.
Ivan_Herman: So for example up there you have a recognized entity credential. It's a type.
Carolynn Bernier: This is a type. Okay.
Ivan_Herman: It's a type which is defined by the specification of recognized entities. But forget about the fact that it is a C It's an application of VCs which defines its own types the recognized entity credentials. And in this respect I expect somewhere a type.
Carolynn Bernier: This is most likely a type as well.
Ivan_Herman: But then I don't really understand I'm not sure. I think the UNP digital committee credential must be an I don't know.
Carolynn Bernier: This is what we have to figure out.
Ivan_Herman: Yeah, I have to understand a little bit more in detail what's happening. But
Carolynn Bernier: Yeah. Yeah. You're not alone. Sebastian,…
Sebastian_Schmittner: Yeah. Hi. I can't say I understand the slide that we are seeing currently, but at least I understand the other slide, the GS1 ecosystem. So, I can say what the subject and type and stuff there means. yeah.
Carolynn Bernier: there's no type. I guess the first line is are you part of this working group?
Sebastian_Schmittner: Yeah. …
Carolynn Bernier: Cool.
Sebastian_Schmittner: at the bottom. key credential would be the type of the credential and…
Ingo_Wolf: Thank you.
Sebastian_Schmittner: the subject would indeed be the credential subject. this G10 credential is a very simple credential which basically states that this global trade item identification number. So really just the identifier exists. So it's pretty much all that this credential says and it exists in the sense that it was issued according to the GS1 rules of play. So there is a chain of credentials authorizing yeah various parties one after the other to eventually the last one…
Ingo_Wolf: Come on.
Sebastian_Schmittner: who actually brings this identifier into life.
Carolynn Bernier: So the first line here is the credential type and…
Carolynn Bernier: this is the credential subject simply this is what fills how we should interpret this figure
Sebastian_Schmittner: Yeah. with this recognize entity credentials.
Sebastian_Schmittner: I'm not so sure what's that going to be.
Ivan_Herman: That's a type.
Ivan_Herman: That's a type.
Sebastian_Schmittner: So I'm putting a link into the chat.
Ivan_Herman: It's a I'm sorry, Celeste.
Sebastian_Schmittner: So that's the repository. There is also a web view of for that. I meant to post this one. so this is the specification of all these GS and this is not saying recognized entity credential. I think these GS1 credentials are applied in this recognized entity way.
Sebastian_Schmittner: So I don't really know but for the general system the idea is that there's always one credential referring to another but you can interpret it in exactly this way that the holder of the GCP global company prefix credential for example this is a license credential…
Sebastian_Schmittner: which entitles you to issue this gin. So this would be one step up in the credential chain.
Carolynn Bernier: So I'm trying to find…
Carolynn Bernier: what you're talking about as you're speaking. are you referring to section 335 identification key type to so here in Phil's figure you have something called key credential that's…
Sebastian_Schmittner: There is a list of identification key types now.
Sebastian_Schmittner: What do you want to know? Yeah. Yeah.
Carolynn Bernier: what we're looking for
Sebastian_Schmittner: So section depends on what you're looking for. So section 53 is examples. So if you want a deductive introduction. So these are some examples and…
Carolynn Bernier: Here we go.
Carolynn Bernier: Like this.
Sebastian_Schmittner: most of this is just metadata. Yeah. so there's a context, there's a issue.
Sebastian_Schmittner: You can say the type is key credential. That's what I was saying. it's obviously also a verifiable credential, but the type is key credential.
Carolynn Bernier: This is the ID of the VC itself and…
Sebastian_Schmittner: Then there's some human readable stuff like description blah blah blah.
Sebastian_Schmittner: But this is the ID of the credential subject. This is the No, not this one.
Ivan_Herman: No, no,…
Ivan_Herman: no, no, no. That's credential.
Sebastian_Schmittner: The credential subject. Yeah, that's Yeah,…
Ivan_Herman: There's a credential. That's
Sebastian_Schmittner: This one. So, yes, exactly. Yes,…
Carolynn Bernier: and this is the credential subject.
Carolynn Bernier: Okay.
Sebastian_Schmittner: and pretty much this is the whole actual con in principle everything else is metadata and what you're really the real attestation is this one. It says look the ID it also has a certain format just one digit link blah blah blah 01 means it's a gin and the last part of this 081015 and so on and so forth. This would be the gin. So this is a concrete number which is assign which is u stated to exist essentially and then there's this extends credential mechanism…
Sebastian_Schmittner: which is pointing to another credential which entitles the to actually issue this credential. So this is the idea in that system. Sure.
Ivan_Herman: May I just inter one question?
Ivan_Herman: So that's now the extense credential. This is a term that you have defined for GS1.
Sebastian_Schmittner: Yeah. Not me myself, but yeah,…
Ivan_Herman: No, no,…
Sebastian_Schmittner: the group.
Ivan_Herman: but USGS1,…
Sebastian_Schmittner: Yes. Yes. Yes. But I think at work this work as GS1 might have been a little bit too early.
Ivan_Herman: that's what I was referring to. There might be either types or…
Carolynn Bernier: Hello.
Ivan_Herman: terms that we have to define for a specific application area. In this case, it was for GS1.
Sebastian_Schmittner: It was earlier than the recognized entity work. So I think now this story is going to be harmonized and that's why we're here So hopefully it is going to be a nice W3C standard saying maybe this shouldn't be called extends credential but I don't know maybe have a different name should maybe be at a different level in the data model like syntax I think might be under discussion and…
Sebastian_Schmittner: hopefully there's going to be a standard but yeah that was the idea in the GS1 working Mhm.
Carolynn Bernier: What we see in the recognized entity specification,…
Carolynn Bernier: if you go to example nine, they have the key credential example. you have credential subject,…
Carolynn Bernier: you have the ID, but you don't have the recognized the other thing. You just have a name. You don't have what is in the other example in the GS?
Ivan_Herman: in general.
Ivan_Herman: Yeah, that's why I was saying that's…
Carolynn Bernier: We don't have extends credential. Yeah.
Ivan_Herman: why I'm saying that as GS for the time being at least this is the GS1 specific thing which in the example in the spec itself you don't have
Carolynn Bernier: Yeah. Yeah.
Carolynn Bernier: Yeah. this here.
Sebastian_Schmittner: for the…
Sebastian_Schmittner: what are you look can you share that link we see recognized entities GS1 yeah yes maybe I'm missing it Sorry. H
Carolynn Bernier: I thought I'd put it in the chat before, but here we go. And then you go down to example nine. you're going to be there because they have three examples to dis describe. And so, this is the key credential that we found on the other site by GS1.
Carolynn Bernier: And here we have the type.
Carolynn Bernier: So we agree this is key credential is a type of verifiable credential. You have an issuer, then you have the recognized in that's needed.
Sebastian_Schmittner: Yeah, that's like Yeah,…
Sebastian_Schmittner: that's doing the thing a little bit differently. So, the idea here is that you have this recognized in …
Carolynn Bernier: Yep. this is that…
Sebastian_Schmittner: which is now pointing to this recognized companies VC or something. So that's a slightly different syntax.
Carolynn Bernier: what actually I have a question about for her Ivan for Ian is this recognize in thingy this term is defined in the recognized entity recommendation…
Ivan_Herman: What do you mean it's not part of the recognized entity type? Yeah.
Carolynn Bernier: but it's not part of the recognized entity credential.
Carolynn Bernier: ial type is this normal so here you're saying here we have type so we receive key credential okay so this is not a recognized entity credential it's some other type of credential it was defined by JS1 it's called key credential and they're using this recognized in keyword under issuer So what's interesting here is that the whole point of this recommendation was to define a recognized entity credential type. Right?
Ivan_Herman: It's not…
Carolynn Bernier: which is Recognize entity that has the recognized in the issuer fields. Ivan Herman:
Ivan_Herman: what you but if you look at the issuer itself it has also its own type which is recognized issuer.
Carolynn Bernier: Sure.
Ivan_Herman: So as a term is defined for objects of type recognized issuer. So the two things the fact that it is a recognized entity credential and that it recognize is in certain sense independent of one another. The recognize entity credential is just saying that this whole credential as a one thing is used for recogni recognition so to say or I don't know whether that's the right term…
Ivan_Herman: but
Rigo: Ivan I think they are mimicking their own delegation system and…
Rigo: so what you see here is that in certain ranges of numbers if you're licensed to GS1 in the whole numbering string in the GIN you can have a range of numbers that you can issue yourself but how do you make sure that only those who are permitted because they are licensed by GS1 are actually issuing GTS as a matter of control and they securing this with this type of credential this is
Rigo: more or less generic also to the recognized entity problem. We have but uses perhaps different strings in that we have a delegation of power from the commission to the notifying authority issuer to the company wanting to be certified. and the real kind of object will only appear in the relation between the last certification authority that issues the certificate for the company that wants to make assessments on conformity and the rest is just a delegation chain and I don't know in how far dare more than I do in how far the verifiable credential specification
Rigo: has a generic delegation mechanism trust or…
Rigo: power of issuing a delegation mechanism or whether we want to have one specific because I think it's a generic issue.
Carolynn Bernier: Yeah. Yeah.
Carolynn Bernier: Rio for me the entire recognized entity recommendation is the way W3C is creating this delegation the standardized way to create delegations and…
Ivan_Herman: Yeah, kind of.
Carolynn Bernier: so this is my understanding. help. So here. Yep.
Rigo: But then Ivan is right and saying okay this is the W3C way which uses certain words and maybe we need a very specific subtype for batteries for notifying authorities and so on. so that we can actually express within the framework of the recognized entity specification, we can have those specific application profiles. and Ivan I think part of it would be a European profile because it just creates this EU notifying authority certification body certification request chain
Rigo: which is pretty generic would be then in the EU context. so for W3C it must be more generic but for the DPP and the EU wallet must be more specific and there Ian is right we need some kind of vocabulary ways of defining…
Rigo: what we mean and what types we news.
Ivan_Herman: Let's not run ahead on that yet maybe.
Ivan_Herman: But let's try to see whether we can get that without Kaholen. Can you go back to the example of before?
Carolynn Bernier: of which one the GS1 or…
Carolynn Bernier: from the recommendation
Ivan_Herman: No, That one. So if you look at the whole thing. No, no, don't just leave the ex don't move it. So there are two things there which are missing because that entity…
Ivan_Herman: which is here is sort of the middle one which is recognized and it also issuing recognition. So it's sort of in the middle of the chain. That's why it's a bit complicated.
Carolynn Bernier: You're talking about this one here?
Ivan_Herman: The recogniz Yeah.
Carolynn Bernier: it is being recognized by them so this member organization is recognized by them…
Carolynn Bernier: but it's also recognizing them.
Ivan_Herman: Yes, exactly.
Ivan_Herman: And if you go back to the example,…
Carolynn Bernier: Yes. Mhm.
Ivan_Herman: so it has a type which is recognize entity credential and what it refers to is not the fact that the issuer is the way It refers to the credential subject. if you look at a little bit down the credential subject is an array and I don't know whether it is an array here but don't run ahead don't run ahead you go up there and…
Ivan_Herman: in the second type it says it has a subject which is a recognized entity. So that's the essential point that it says yeah exactly.
Carolynn Bernier: Wait, where are you?
Carolynn Bernier: I'm lost.
Sebastian_Schmittner: Credential subject zero type this one.
Ivan_Herman: So what it does it creates a set of recognitions which are in this special subject a core series of them. to see the first one. So the fact that you have this object there, this is what the fact that it is a recognized entity credential gives you. Forget about the issuer part. So as I said it's a middle player. It done
Ivan_Herman: It goes down in a sense that it recognize other entities and it recognize in this case the healthy thoughts example as a recognized entity which has the ability to do certain things and…
Ivan_Herman: independently of that it is also a recognized issuer by recognized in the GS1 top level block.
Carolynn Bernier: You mean like this?
Ivan_Herman: So the same credential in this recognition chain has a middle position.
Carolynn Bernier: I recognize him. Okay.
Ivan_Herman: It is recognized and it does recognize others.
Carolynn Bernier: validator.
Ivan_Herman: Do you understand what I'm saying? And in a very specific role. It says it is recognize to issuing things. It is not recognizing thing GS1 utopia example as a possible validator.
Carolynn Bernier: There are so wait…
Ivan_Herman: it recognizes only as an issuer and because it's an array there in JSON terms it can do that for a whole loads of entities. So this is in a sense you picked by bad luck if you like a relatively complex example because it plays these two roles.
Carolynn Bernier: where the other rule recognize two
Ivan_Herman: one is the fact that it has a special subject which is another recognized entity and it is by itself recognized by someone else. So as an issuer it is recognized by someone else but as an issuer it issues credential subjects…
Carolynn Bernier: You mean this can only recognized entity credentials?
Ivan_Herman: which are recognition entities. Too many words. the one that you list there can only issue the healthy dots example. is recognized as an issuer. That's what it says.
Carolynn Bernier: I must admit though this credential subject type equals recognize entity thing is I'm a bit puzzled by this.
Ivan_Herman: Because that goes only up…
Carolynn Bernier: I would have thought that this would be sufficient.
Ivan_Herman: where this is in your diagram. It is the arrow which comes in and the other one is the arrow which goes out. So if you look at that gray stuff in the middle that's the one we are talking about one level down that one that's the one we are talking about it recognizes things that's the credential subject and it is recognized by which issues it and it's recognized in upstairs by the
Carolynn Bernier: you mean it does simultaneously this and these two arrows are present in the same credential.
Ivan_Herman: Right. Right.
Carolynn Bernier: Someone's hand is up, I think. I have a hard time seeing. I have such a small screen. No. I thought I heard someone. Yes, but both arrows are not mandatory in the recognized entity credential.
Carolynn Bernier: You're going to have here this one only does recognizing, right? Okay.
Ivan_Herman: recogniz the …
Ivan_Herman: I mean in the recognize entity credential nothing is mandatory but if there is no recognition then it's meaningless.
Carolynn Bernier: So the question I had for you Ivan was that this reserved word issuer recognized in it is used in a credential type that is not a recognized entity credential and I was just check wanting to double check that this was indeed correct meaning that this issuer recognized in has nothing to do with recognized entity credential types.
Carolynn Bernier: Do we agree here? Okay. Yes.
Ivan_Herman: Yes, that's correct.
Ivan_Herman: But what I was saying is that recognize entity credential type it was used because it goes down because it recognizes Now you have to
Carolynn Bernier: I see.
Carolynn Bernier: It does this. Okay. I see.
Sebastian_Schmittner: this issuer recognized in this is…
Sebastian_Schmittner: because the issuer has another type in this credential example we were looking at before I think this is where Ian actually started the whole story don't know 10 minutes ago. so the issuer this is the other example so the issuer is himself he also has a type so actually this whole credential I mean all the objects here are a lot more typed than the us just the VC data model for example the credential subject doesn't have any type it can be anything and…
Carolynn Bernier: the other example. Sebastian Schmittner:
Sebastian_Schmittner: here the credential subject it has a type it is a recognized entity. So that's more specific than what we get from the VC data model alone. And I think the same is true for the issue.
Carolynn Bernier: Mhm.
Ivan_Herman: That's correct.
Ivan_Herman: Usually in the basic things, the basic examples, the issuer is either just a URL or an object which has an ID and a name or some metadata. That's the usual thing. But in this case, it becomes more complicated.
Carolynn Bernier: Coming back to my example and I'm sorry Engle Angel left us.
Carolynn Bernier: So I added the word type because these are indeed credential types here. So this is indeed a recognized entity credential This is another one that does some other recognizing but is also recognized in. So this is like Phil's example does the two things at once.
Ivan_Herman: right? That's correct.
Ivan_Herman: Yes. Yes. Exactly. Yeah.
Carolynn Bernier: This is not a recognized entity credential. It's like Phil's examples like the key I don't remember what he called it. It's another type of credential defined by Steve and his friends and from the UNP work. I'm reusing this type of credential to issue a EU conformity credential.
Ivan_Herman: probably for the sake of the example it should be a sort of a DPP type or whatever. I don't know that I understand that But the issuer of a DPP I don't know whether you want to specify it as a separate type or…
Carolynn Bernier: No, this is not a DPP.
Carolynn Bernier: This is a DPP, which may not be a DP.
Carolynn Bernier: That heat.
Ivan_Herman: or not that just we have to see the example in general. So if you the type digital conformity credential I don't know whether we need that maybe a recognized entity issuer is enough we don't necessarily need all the confirmity certificate.
Carolynn Bernier: No because this is the content of the certificate itself. So this is the in EU' certificate. So the subject of this verifiable credential is issued by these people TV according to a specification for conformity credentials defined by the United Nations.
Carolynn Bernier: So basically here I'm creating a profile of a credential format defined by the United Nations for the EU conformity certificate.
Carolynn Bernier: And this is something that probably needs to be checked if this is oops if this is indeed type
Sebastian_Schmittner: I think it's a semantic question.
Sebastian_Schmittner: So this verifiable credential usually a credential says something about something. so there's a subject which you want to give some attributes. so this key credential was super simple. This was just something So this is some subject exists as the most basic thing you can do. you can now so tou I guess you want to say something is according to some norm has been proven to fulfill some requirements or something and then if you want to say that you might say the credential subject is I don't know the machine or the organization or whatever has been assessed and then you want to write into the credential they passed
Sebastian_Schmittner: just this and that assessment and then the subject would be I don't know what the exact use case is actually but you can think about if you want the credential to have a holder if there's a Japanese. which gets this credential and you say okay this company gets the attribute they have passed some assessment in principle you can also just make a credential from a piece of paper saying look there is this document whatever conformity certificate and…
Sebastian_Schmittner: did this exists and there is some text on it…
Carolynn Bernier: It could be a PDF.
Carolynn Bernier: Yes. Yes.
Sebastian_Schmittner: but then it doesn't have a holder then you're really just saying look there is this document
Ivan_Herman: So in a way…
Ivan_Herman: what I'm missing but that's probably because I don't fully understand the whole thing. We are discussing things top to bottom starting with trust anchors and recognitions etc. I would like first to understand…
Ivan_Herman: what kind of certificates are created and issued at the bottom that I mean we have to start bottom up to understand what are the credentials that we are talking about and for the time being I don't fully understand
Carolynn Bernier: Yeah. Yes.
Carolynn Bernier: Here I agree. And I'm not entirely certain what I just removed is the part that I'm not certain about. So I'm just going to put this not and turn this into something else I don't mix it with something else. so there are two types of when I'm a battery manufacturer. I make batteries. I have to issue a DPP for my battery. Okay, let's assume it's a verifiable credential.
Carolynn Bernier: So it would be type is EUDP let's say all right…
Carolynn Bernier: but it could be a VC it could not be let's assume the three battery number because
Ivan_Herman: And the subject is not the battery DPP.
Ivan_Herman: The subject is a specific Battery number one, two, three. And then you have a term…
Carolynn Bernier: It's itemized. So every single item it has its own.
Ivan_Herman: which is a property which you have to define for the DPP. You say that the battery is doing some wonder.
Carolynn Bernier: There's 71 mandatory attributes. Ivan Herman:
Ivan_Herman: Sure. But those are the application specific properties.
Carolynn Bernier: Yes, but among those 71 attributes, you have to reference something called the EU declaration of conformity that is issued by the battery manufacturer. Okay, so it's a self declaration like Rio said. It's
Carolynn Bernier: the manufacturer selfdeclares that they're conformed. There's a presumption of conformity in the EU. And this declaration of conformity must identify which battery you're actually claiming you're conformed to. So this declaration of conformity must identify so there's a kind of a back you have to point back somehow to the battery identifier…
Ivan_Herman: So they are not credentials.
Carolynn Bernier: but today EU declarations of conformity they are PDFs but here no but they could
Carolynn Bernier: So, I'm assuming that it is one. In all cases, an EU declaration of conformity must reference an EU conformity certificate. This means that the battery manufacturer sent a battery to TUV their conformity assessment body that they said please do the tests that check that I'm conformed to all the legislations and standards I must be conformed to.
Carolynn Bernier: They issue a EU conformity certificate in PDF and this PDF must be reference from the EU declaration of conformity references it okay and must be provided to market surveillance authorities if they are audited. if you look at the regulation, if we look at the content of this EU declaration of conformity, if you look at the content, basically it says my battery who I am, I issued it.
Carolynn Bernier: the object of the declaration. I'm saying that These are the relevant harmonized standards and common specifications used for which conformity is declared. This is the notified body that performed the test and issued the certificates in details including date and…
Carolynn Bernier: duration and conditions for its validity and you basically sign it.
Ivan_Herman: for this.
Ivan_Herman: To me this is a verifiable credential.
Carolynn Bernier: But that's why rather than issuing it as a PDF, the logical thing is to issue it as a verifiable credential. We agree. Ivan Herman:
Ivan_Herman: That is what I think it is. Yes. … Ivan Herman:
Carolynn Bernier: Yes, but today it's a PDF.
Carolynn Bernier: That's how it works. Let's Okay.
Ivan_Herman: no, no, I understand. But on long term
Carolynn Bernier: But that's why we're doing here. This is why we're bothering with this event. So, what we see here is that this declaration of conformity references this notified body who performed and issued a certificate of conformity. So it references this and it also references the actual conformity assessment body, So anyways,…
Ivan_Herman: Okay, then I begin to have some very vague idea,…
Carolynn Bernier: And this is pretty hard for us too because we are not at all experts in this domain.
Ivan_Herman: but it's certainly true that what you showed is a typical example of a verifiable credential. It has a number of metab and…
Carolynn Bernier: This thing.
Ivan_Herman: and things which is signed and signed several times etc. and then the signature has a date. I mean all these things are typically verify the credential thing. So that's declaration of conformity is in my view a verifyable credential and…
Carolynn Bernier: It could be made into one.
Ivan_Herman: that's where I have to go back to That's correct.
Carolynn Bernier: And this is exactly why we are proposing this as an ecosystem example for the recognized entity recommendation but for it it will force us to create a credential type for the EU declaration of conformity.
Ivan_Herman: Which is okay.
Ivan_Herman: Let's not worry about editorial things on whether it is an separate document combining these things or not. let's get the structure right.
Carolynn Bernier: Yes. Yes.
Carolynn Bernier: And for the moment it's getting all these arrows correct is pretty hard already.
Ivan_Herman: Yes, the reference is actually easy…
Ivan_Herman: because sorry relatively easy because you say that the EU DPP battery 123 it has something that says it's according to that of over there…
Carolynn Bernier: Yeah. Yeah. Exactly.
Ivan_Herman: but in terms of verify your credential So data model is simpler because you just give a URL you have each verifyable credential has an identity
Carolynn Bernier: Yes.
Ivan_Herman: which is a URL of some form whether in the simplest way it's HTTP URL it's somewhere on the web and the type the EU They would PPP simply says this battery is blah this is the name etc and it references or it's according abides to a URL and the abites to is a term that we define for DPP and that's it and that can be signed etc. So that's the easy part. The reference is easy and the verify by credential that you will create will again says that this abides to a credential which is produced by all this chain of recognition.
Ivan_Herman: So it's a good thing that here everything is a URL.
Ivan_Herman: So that automatically gives you a reference. Yeah.
Carolynn Bernier: But we're trying to stick to examples that are as technically correct as possible.
Carolynn Bernier: So today in August the commission published a guidelines for the content of the battery DPP. So we already know that the DPP must reference the EU declaration of conformity.
Carolynn Bernier: And what I just need to check is if it also needs to reference the conformity certificate. But I don't think so.
Carolynn Bernier: I don't think this is but I to check yes it's application specific but I want to make this example correct for this application.
Ivan_Herman: That's an application specific thing.
Ivan_Herman: Yeah, I think we have run over
Carolynn Bernier: So we've run out of time and I'm going to try to get from Ingo the slides that he didn't have time to share yet so what I think is interesting with this example here is that we have several roots of trusts and we could add the German government here right as an additional
Carolynn Bernier: root of trust or the German ministry of economy or whatever whichever ministry is responsible for designating the notifying authority. And what I think is interesting in the example is the fact that the question of the whole recognized entity concept has to do with finding someone you trust in finding someone you trust and…
Ivan_Herman: Yeah. Correct.
Carolynn Bernier: going up the chain until you find someone you trust. Basically the two examples that were already given in the spec they don't show this possibility of having multiple root anchors.
Carolynn Bernier: So, I thought that was a pretty cool thing to add here, especially since, I'm a Chinese organization and I don't know anything about how EU manages their conformity assessment bodies and all that. I may trust more this international organization that I know better than some unknown, bureau somewhere in Germany. so I think we should end the meeting here. I'm going to try to collect the slides from Ingo.
Carolynn Bernier: put a presentation together with our slides, put them on the GitHub under meetings and we'll continue to work on this ne next week,…
Ivan_Herman: Just to be clear,…
Ivan_Herman: next week we have switched to Wednesdays,…
Carolynn Bernier: Wednesdays. Yes.
Ivan_Herman: right? 4:00 French time.
Carolynn Bernier: Yes. And hopefully Phil will be here and he will help us if we've screwed up somewhere. But I think we're good. But what we do have to do collectively is write an example that describes. So we have to create these examples.
Carolynn Bernier: So here for example in B B1 here we have to explain the things. So that's going to take a while right explain the whole thing and then provide examples for the credentials that are part of the example.
Ivan_Herman: Perfect.
Carolynn Bernier: So there are three examples. So once we agree on the ecosystem example that we want to create, we'll have to create toy examples here. So it's going to take some time if we want to create examples that are correct from a relatively correct because if you in my project we have created a vocabulary for conformity. Ready?
Carolynn Bernier: Let me show you this looks like. In serpass 2, we have created a vocabulary to that looks like So basically for EU declarations of conformity so the conformity is declared with respect to some union harmonized legislation for different requirements of products according to some conform
Carolynn Bernier: formity assessment module which is defined in the regulation so here's the famous notified body that has issued the conformity certificate so the one that is here right but if I have a product which has a DPP. the product has a EU declaration of conformity.
Ivan_Herman: We should
Carolynn Bernier: So we can use this vocabulary. So this is an ontology that is already published in our work.
Carolynn Bernier: So we can use these vocabularies to create the examples. Yeah. Yeah. That's what it was for. But what's pretty cool is that this vocabulary and I hadn't really understood that previously. This vocabular this ontology can be used to issue different types of credentials. So it can be used to issue EU conformity of certificate credentials and digital product passports as credials. centials, three credential types. So here we have an EU Here we have a digital E EU conformity certificate credential type.
Carolynn Bernier: And here we have a declaration of conformity credential type and one of the things that I do have to check and I have to check this on the UNP maybe Mike if you're following the work from path specifications conformity credential this is what I was talking about Ian They already have vocabularies for these credentials…
Carolynn Bernier: but we may need to extend it. So this is the conceptual model.
Ivan_Herman: Okay, Caroline,…
Ivan_Herman: I'm sorry, but I will have to go.
Carolynn Bernier: Yeah. Yeah.
Carolynn Bernier: We're going to have to stop. Okay.
Michael_Linck: I don't really follow I mean I'm not sitting with the UNP folks so I can't add a lot of context beyond what's documented there.
Michael_Linck: Sorry. …
Carolynn Bernier: No, but I'll be going to Geneva tomorrow and meeting the team from UNP. So I'll ask them how much work it takes or what needs to be done to transform their digital conformity credential into a EU conformity certificate. Probably they already have examples that we can reuse.
Michael_Linck: that would be good. Yeah. Yeah. Yeah. Awesome.
Carolynn Bernier: Okay. Thank you.
Michael_Linck: Thank you. Bye.
Sebastian_Schmittner: Thank you. Bye. Meeting ended after 01:16:30 👋 This editable transcript was computer generated and might contain errors. People can also change the text after it was created.