You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This document is the natural-person Person Identification Data (PID) Rulebook
13
-
and is part of the Architecture Reference Framework (ARF) v1.5.0. It specifies
13
+
and is part of the Architecture Reference Framework (ARF). It specifies
14
14
how the mandatory and optional person identification data for the natural
15
15
person, as defined in Tables 1 and 2 in the Annex of the Commission Implementing
16
16
Regulation on PID and EAA [CIR 2024/2977], as well as the metadata specified in
@@ -24,8 +24,7 @@ the PID complies with [ISO/IEC 18013-5] and if it complies with [SD-JWT VC].
24
24
Person identification data for the legal person is out of scope of this document.
25
25
26
26
This PID Rulebook complies with all applicable requirements in Topic 12
27
-
(Attestation Rulebooks) in Annex 2 of the Architecture Reference Framework
28
-
v1.5.0.
27
+
(Attestation Rulebooks) in Annex 2 of the Architecture Reference Framework.
29
28
30
29
### 1.2 Document structure
31
30
@@ -59,7 +58,7 @@ statements of fact.
59
58
60
59
### 1.4 Terminology
61
60
62
-
This document uses the terminology specified in Annex 1 of the ARF v1.5.0.
61
+
This document uses the terminology specified in Annex 1 of the ARF.
63
62
64
63
## 2 Generic High-Level Requirements for PIDs
65
64
@@ -133,7 +132,7 @@ used for such PIDs.
133
132
134
133
| **Data Identifier** | **Definition** |
135
134
|------------------------|--------------|
136
-
| expiry_date | Date (and if possible time) when the person identification data will expire. **Further clarification added in this PID Rulebook:** This attribute, as well as the optional issuance_date attribute specified in [Section 3.6](#36-additional-optional-attributes-specified-in-this-rulebook), pertains to the administrative validity period of the PID. It is up to the PID Provider to decide whether a PID has an administrative validity period. However, if present, it in general is different from the technical validity period of a PID. The technical validity period is a mandatory element of all PIDs (and also attestations) in the EUDI Wallet ecosystem. It typically is short, a few days or weeks, to mitigate any challenges regarding tracking of Users by malicious Relying Parties based on the repeated presentation of the same PID. On the other hand, the administrative validity period is typically at least a few years long. During the administrative validity period of a PID, the PID Provider will therefore provide multiple successive PIDs to a User, typically without any actions being expected from the User. However, when the administrative validity period of a PID ends, typically the User has to apply for an entirely new PID.|
135
+
| expiry_date | Date (and if possible time) when the person identification data will expire. **Further clarification added in this PID Rulebook:** This attribute, as well as the optional issuance_date attribute specified in [Section 3.6](#36-additional-optional-attributes-specified-in-this-rulebook), pertains to the administrative validity period of the PID. It is up to the PID Provider to decide whether a PID has an administrative validity period. However, if present, it in general is different from the technical validity period of a PID. The technical validity period is a mandatory element of all PIDs (and also attestations) in the EUDI Wallet ecosystem. It typically is short, a few days or weeks at most, if not shorter, to mitigate challenges regarding tracking of Users by malicious Relying Parties based on the repeated presentation of the same PID. On the other hand, the administrative validity period is typically at least a few years long. During the administrative validity period of a PID, the PID Provider will therefore provide multiple successive PIDs to a User, typically without any actions being expected from the User. However, when the administrative validity period of a PID ends, typically the User has to apply for an entirely new PID.|
137
136
| issuing_authority | Name of the administrative authority that issued the person identification data, or the ISO 3166 alpha-2 country code of the respective Member State if there is no separate authority entitled to issue person identification data. |
138
137
| issuing_country | Alpha-2 country code, as specified in ISO 3166-1, of the country or territory of the provider of the person identification data. |
139
138
@@ -150,11 +149,11 @@ used for such PIDs.
150
149
| **Data Identifier** | **Definition** |
151
150
|------------------------|--------------|
152
151
| issuance_date | Date (and if possible time) when the person identification data was issued and/or the administrative validity period of the person identification data began. See also the clarification for expiry_date in [Section 3.4](#34-mandatory-metadata-specified-in-cir-20242977). |
153
-
| age_over_18 | Attesting whether the User to whom the person identification data relates is currently an adult (true) or a minor (false). |
154
-
| age_over_NN | Attesting whether the User to whom the person identification data relates is at least NN years old. N <> 18. |
152
+
| age_over_18 | Attesting whether the User to whom the person identification data relates is currently an adult (true) or a minor (false). If present, the requirements in clause 7.2.5 of ISO/IEC 18013-5 are applicable for this attribute. |
153
+
| age_over_NN | Attesting whether the User to whom the person identification data relates is at least NN years old. N <> 18. Multiple instances of this attribute may be present, provided the value of NN is different in each of them. If present, the requirements in clause 7.2.5 of ISO/IEC 18013-5 are applicable for these attributes. |
155
154
| age_in_years | The current age of the User to whom the person identification data relates in years. |
156
155
| age_birth_year | The year when the User to whom the person identification data relates was born. |
157
-
| trust_anchor | This attribute indicates at least the URL at which a machine-readable version of the trust anchor to be used for verifying the PID can be found or looked up. *Note: This attribute corresponds to the location meant in Annex V point h) or Annex VII point h) of the [European Digital Identity Regulation], which is mandatory for QEAAs. This PID Rulebook add this as an optional attribute for PIDs as well, so PID Providers are able to ensure that PIDs can be validated by Relying Parties in the same manner as QEAAs.* |
156
+
| trust_anchor | This attribute indicates at least the URL at which a machine-readable version of the trust anchor to be used for verifying the PID can be found or looked up. *Note: This attribute corresponds to the location meant in Annex V point h) or Annex VII point h) of the [European Digital Identity Regulation], which is mandatory for QEAAs. This PID Rulebook adds this as an optional attribute for PIDs as well, so PID Providers are able to ensure that PIDs can be validated by Relying Parties in the same manner as QEAAs.* |
158
157
159
158
## 4 ISO/IEC 18013-5-compliant encoding of PID
160
159
@@ -186,7 +185,7 @@ all attributes:
186
185
- The first column lists the data identifier specified in
Copy file name to clipboardExpand all lines: docs/annexes/annex-3/annex-3.02-mDL-rulebook.md
+1-3Lines changed: 1 addition & 3 deletions
Original file line number
Diff line number
Diff line change
@@ -13,9 +13,7 @@ final.*
13
13
14
14
## 1 Introduction
15
15
16
-
This document is the mobile driving licence (mDL) Rulebook. It is part of ARF
17
-
v1.5.0. It contains requirements specific to mDL attestations with the EUDI
18
-
Wallet ecosystem.
16
+
This document is the mobile driving licence (mDL) Rulebook. It is part of the Architecture and Reference Framework for the EUDI Wallet ecosystem. It contains requirements specific to mDL attestations with the EUDI Wallet ecosystem.
0 commit comments