Digital Identity / EUDI Wallet Architecture
What you will do: Walk five steps: open the EUDI Wallet, get a PID issued, receive a university diploma attestation, present your identity to a bank as relying party, then sign a document with a QTSP.
Worked example: Start Issuance Flow at the PID Issuer to get a P-256-bound mdoc, then Login with Wallet at the bank, Consent & Share family name, given name, degree and age_over_18, and the bank confirms Account Opened.
Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.
For your role
- Developer / Engineer
- Walk the five steps, EUDI Wallet, PID Issuer, University, Bank (RP) and QTSP (QES): the wallet's Credentials, Hardware Keys and History tabs show what is issued, where the keys live and what each relying party asked for.
- Security Architect
- The PQC Readiness note on the wallet step says today's credentials use P-256 and P-384 and where PQC is expected in the ARF; the Hardware Keys tab is where an architecture has to place the post-quantum keys.
- Researcher / Academic
- Follow the OpenID4VCI issuance and the mDoc and QES steps with the History tab open: the log records each exchange, which is the material to compare against the ARF and the standards it cites.
EUDI Wallet Architecture
Step 1: EUDI Wallet
View your credentials and secure keys.
EUDI Wallet
Managed by: María Elena García
PQC Readiness
Current EUDI credentials use classical algorithms (P-256, P-384). Future ARF versions are expected to mandate PQC-safe algorithms (ML-DSA, SLH-DSA) for long-lived credentials to protect against quantum threats. Target: high-risk use cases (which EUDI Wallets qualify as) migrated by the end of 2030, per the NIS Cooperation Group Coordinated Implementation Roadmap (2025) — not ETSI TS 119 182-1, which is the unrelated JAdES JSON-signature format spec.
No credentials installed yet.
This is an educational simulation of the EUDI Wallet Architecture and Reference Framework (ARF). Cryptographic keys are generated in-browser using WebCrypto/WASM (OpenSSL) and stored in memory.
Try it
Try to issue the University diploma before the PID. What happens?
Next step
Turn it into a plan: Deployment PlaybookThis tool practises the Digital ID module, phase 5 (Pilots & Migration); Deployment Playbook produces a deliverable of that phase.