International Association for Cryptologic Research

International Association
for Cryptologic Research

CryptoDB

EU Digital Identity and Anonymous Credentials - A Happy End?

Authors:
Anja Lehmann
Download:
Search ePrint
Search Google
Presentation: Slides
Abstract: The eIDAS regulation of the European Commission establishes a framework for digital identity and authentication. The regulation entered into force in May 2024, and proposes the EU Digital Identity Wallet (EUDI) which shall be a ``fully mobile, secure and user-friendly'' service, enabling users to identify themselves to public and private online services. All member states are now required to offer such an EUDI wallet to all their citizens and residents by end of 2026. The eIDAS regulation mandates several privacy requirements for the EUDI, such as selective disclosure, unlinkability, unobservability and the right to pseudonymous authentication. While this sounds like *the* application anonymous credentials were invented for, they are not considered in the currently proposed Architecture Reference Framework (ARF). Instead, the plan is to use batch issuance of single-use ECDSA credentials with individually hashed attributes. The shortcomings of this approach and the recommendation of anonymous credentials, such as BBS+, have been voiced in the Cryptographers' Feedback on the EU Digital Identity’s ARF. The talk will give an overview of the eIDAS regulation, and the real-world impact this will have. It will also outline the currently proposed technical solution, and the limitations and open challenges therein. For anonymous credentials, a brief overview on their technical advances is given, and why they are not used in the current ARF. We will then look at the remaining challenges in implementing anonymous credentials in EUDI, and how the cryptographic community can contribute to ensuring that our future digital identity system is as privacy-preserving and secure as technically feasible.
Video: https://youtu.be/UpQHWObCx4I
BibTeX
@misc{rwc-2025-35862,
  title={EU Digital Identity and Anonymous Credentials - A Happy End?},
  note={Video at \url{https://youtu.be/UpQHWObCx4I}},
  howpublished={Talk given at RWC 2025},
  author={Anja Lehmann},
  year=2025
}