Glossary
Digital identity is full of acronyms and specialist terms. This glossary explains them one by one.
View
134 terms found
A
Access management
Access management is deciding and enforcing who may do what: after authentication establishes who you are, authorisation determines what you can reach.
AdES signature formats
AdES formats - PAdES, XAdES, CAdES, JAdES - are the ETSI standards defining how signatures are embedded in PDF, XML, CMS and JSON data.
Advanced electronic signature (AdES)
An advanced electronic signature (AdES) meets all four Article 26 eIDAS criteria: unique link, identification, sole control and tamper detection.
Architecture and Reference Framework (ARF)
The Architecture and Reference Framework (ARF) is the EU's technical blueprint for the EUDI Wallet: formats, protocols, roles and certification.
Attestation rulebook
The specification of one attestation type: attributes, namespaces, encoding, validity and verification rules. What makes wallet credentials interoperable.
Authentic source
An authentic source is the legally authoritative register - such as the BRP - that EUDI Wallet attestations verify attributes against under eIDAS 2.
B
Basisregistratie Personen (BRP)
The Dutch population register: municipalities and the non-residents register, who may receive data, and why it is the authentic source behind PID.
Biometric authentication
Biometric authentication verifies identity using a face, fingerprint or iris, checked with liveness detection to prevent spoofing during onboarding.
Biometric liveness detection
Biometric liveness detection confirms a face sample is from a living person, not a photo or spoof. Essential for remote identity verification.
Burgerservicenummer (BSN)
The unique Dutch personal number: who may use it under Article 46 UAVG, why it is an identifier and not proof, and what wallets carry instead.
C
CAdES
CAdES is the ETSI standard for advanced electronic signatures (AdES) using CMS/PKCS#7 binary data, used when content is not a PDF or XML file.
Certificate authority (CA)
A Certificate Authority issues digital certificates within a PKI, binding identities to public keys so browsers and systems can trust them.
Certificate chain
The path from a certificate through intermediates to a trust anchor, and what path validation checks at every link: signature, validity, usage, revocation.
Certificate revocation
Certificate revocation is how PKI marks a certificate untrusted before expiry, checked via CRL and OCSP after key compromise or data changes.
Certificate validity period
Every certificate carries a notBefore/notAfter window - typically one to three years for end-user certificates.
Cleverbase app
The Cleverbase app (formerly Vidua): one high-assurance digital identity to log in, share data and place qualified electronic signatures from your phone.
Cloud Signature Consortium API (CSC API)
The Cloud Signature Consortium (CSC) API is the open standard for remote signing integrations, used by QTSPs and EUDI Wallet signing flows.
Common Criteria (CC)
Common Criteria (ISO/IEC 15408): security certification of IT products against a protection profile, rated EAL1-7. Used for QSCDs and HSMs.
Conformity assessment body (CAB)
A conformity assessment body (CAB) audits trust service providers against eIDAS and ETSI standards, and may certify EUDI Wallet solutions under eIDAS 2.0.
Conformity assessment report
A conformity assessment report is the audit evidence a CAB issues to prove a trust service provider still meets eIDAS requirements.
CP/CPS
CP and CPS are the public documents defining what a trust service provider promises about certificates and how it delivers on that promise.
CRL
CRL explained: the signed list a certificate authority publishes of revoked certificates, how it works, and how it differs from OCSP.
Cryptographic binding
Cryptographic binding mathematically links a signature, wallet key or authentication to one document, holder or origin, not just an assertion.
Cryptographic key generation
Key generation is creating a cryptographic key pair: a private key (the signature creation data) and the matching public key.
CSR
CSR explained: the self-signed request carrying a public key, sent to a CA to prove key possession before certificate issuance.
Cyberbeveiligingsbesluit
The Dutch decree under the Cyberbeveiligingswet: the duty of care worked out per measure, board training and what an incident report must contain.
Cyberbeveiligingswet (Cbw)
The Cyberbeveiligingswet (Cbw) is the Dutch law implementing NIS2, requiring organisations to manage cyber risk and report incidents.
Cybersecurity Act
The Cybersecurity Act (EU 2019/881) gives ENISA a permanent mandate and sets up the EU framework for certifying ICT products, services and processes.
D
DigiD
DigiD is the Dutch public eID for citizens, issued by Logius, used to log in to government services like the Belastingdienst and municipalities.
Document integrity
Document integrity is the guarantee that content has not changed since a reference moment - the property that turns a digital file into evidence.
DORA
DORA (Regulation 2022/2554) is the EU law on ICT risk, incident reporting and resilience testing for the financial sector, applying since 2025.
DTBS
DTBS is the data a signer intends to sign; DTBS/R is its usually hash-based representation processed by an HSM or QSCD when creating an e-signature.
Dual signature
A dual signature combines a personal electronic signature with an organisational seal on one document under eIDAS, covering intent and origin.
E
eHerkenning
eHerkenning is the Dutch eID scheme for organisations, letting employees log in to government and business services with a registered mandate.
eIDAS
eIDAS (EU Regulation 910/2014) governs electronic signatures, seals and eID across the EU; eIDAS 2 adds the EUDI Wallet and qualified signing.
Electronic attestation of attributes (EAA)
An electronic attestation of attributes (EAA/QEAA) is a signed digital statement - age, diploma, mandate - held in an EUDI Wallet under eIDAS 2.
Electronic identification (eID)
Electronic identification is using an electronic means to prove who you are online.
Electronic machine readable travel document (eMRTD)
The signed chip in a passport or ID card: passive authentication, chip authentication and PACE, and why reading it beats photographing a document.
Electronic registered delivery service (ERDS)
Electronic registered delivery (ERDS) is the trust service that proves sending, receipt and integrity online; QERDS adds legal presumptions under eIDAS.
Electronic seal
An electronic seal is data that organisations attach under eIDAS to prove origin and integrity; creating or validating it is the trust service.
Electronic signature
Under eIDAS, an electronic signature has three levels - simple, advanced (AES) and qualified (QES) - each with different legal effect and use case.
Elliptic curve cryptography (ECC)
Public-key cryptography on elliptic curves: ECDSA, EdDSA and ECDH, short keys, approved curves, and why wallets and smartcards rely on it.
ETSI
ETSI ESI standards define the technical requirements that make eIDAS-based electronic signatures, seals and trust services auditable for QTSPs.
EU Trusted List
The EU Trusted List is the official, machine-readable register of qualified trust service providers and their qualified services.
EUDI Wallet
The European Digital Identity Wallet is the wallet introduced by eIDAS 2. Every member state must offer at least one wallet to its citizens and residents.
European Business Wallet (EBW)
The European Business Wallet is a separate EU regulation proposed in November 2025 for organisations - not an EUDI Wallet issued to a company.
F
FIDO2
FIDO2 and passkeys offer phishing-resistant, passwordless authentication and MFA via a key pair cryptographically bound to the real website.
G
General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR): the EU law on personal data - legal basis, minimisation, breach duties for identity and trust services.
H
Hardware security module (HSM)
A Hardware Security Module (HSM) is certified, tamper-resistant hardware that protects cryptographic keys for eIDAS-qualified signing, seals and PKI.
Hash
A hash is a data fingerprint from a cryptographic function like SHA-256, used to bind electronic signatures and timestamps to exact content.
I
Identity federation
Identity federation lets users authenticate once and be trusted by other services, via protocols like SAML and OpenID Connect.
Identity provider (IdP)
An identity provider (IdP) authenticates users and vouches for their identity, enabling identity federation and single sign-on across trusted services.
Identity verification
Identity verification (identity proofing) confirms someone's identity with the required assurance before issuing a qualified certificate or wallet PID.
Incident reporting
QTSPs must report incidents fast: NIS2 (24h warning, RDI/NCSC), GDPR breach notification (72h) - eIDAS's own Article 19 duty was repealed in 2024.
Information security management system (ISMS)
The management system behind security: risk assessment, approved policy, owned measures and evidence. What eIDAS Article 24 and an audit expect.
J
JAdES
JAdES is the ETSI standard for embedding advanced electronic signatures in JSON data, built on JWS - used in APIs and digital wallets.
K
Key ceremony
The scripted, witnessed procedure in which a CA creates or retires a root key inside an HSM, with split knowledge, dual control and an audited record.
L
Level of assurance (LoA)
eIDAS LoA (low, substantial, high) shows how certain a relying party can be that an eID belongs to its user, per EU Regulation 2015/1502.
Logius
The Dutch government organisation behind DigiD, eHerkenning and PKIoverheid: it manages the schemes while others issue the means and the RDI supervises.
Long-term validation (LTV)
Long-Term Validation (LTV) and Long-Term Archival (LTA) keep eIDAS electronic signatures and seals verifiable for decades using archive timestamps.
LTA
LTA is the ETSI baseline signature level that adds renewable archive timestamps to keep signatures verifiable for decades.
M
Mandate
A mandate is legal authorisation to represent someone else - eHerkenning, DigiD Machtigen and EUDI Wallet attestations make it provable online.
mDL
mDL is a mobile driving licence on a smartphone, standardised under ISO/IEC 18013-5 and required by EU law to be issued for the EUDI Wallet.
mdoc
mdoc is the ISO 18013-5 credential format used in the EUDI Wallet, enabling selective disclosure and offline, in-person identity presentation.
N
NIS2
NIS2 (EU 2022/2555): EU cybersecurity directive for essential and important entities, with 24-hour incident reporting and management liability.
Non-repudiation
Non-repudiation means a signatory cannot credibly deny signing a document: the evidence from an electronic or digital signature binds the act to them.
Notified electronic identification scheme
An eID scheme a Member State notified to the Commission: what Article 9 requires, how peer review works and why public bodies abroad must accept it.
O
OAuth 2.0
OAuth 2.0 is the internet's standard framework for delegated authorisation, granting apps scoped, expiring access tokens instead of passwords.
OCSP
OCSP explained: the real-time protocol for checking certificate revocation status, how it differs from CRL, and what OCSP stapling does.
OpenID Connect (OIDC)
OpenID Connect is the identity layer on OAuth 2.0, providing the signed ID token behind "Log in with ..." buttons and enterprise SSO logins.
OpenID4VC
OpenID4VC covers OpenID4VCI (credential issuance) and OpenID4VP (credential presentation), the OAuth 2.0-based protocols behind the EUDI Wallet.
OpenID4VCI
OpenID4VCI is the OpenID protocol wallets use to request and receive digital credentials from an issuer, used in the EUDI Wallet.
OpenID4VP
OpenID4VP is the OpenID protocol that lets relying parties request and verify credentials from a digital wallet, such as the EUDI Wallet.
P
PAdES
PAdES (EN 319 142) is the ETSI standard for embedding electronic signatures and seals inside PDF documents, keeping the file self-contained.
Passkeys
Passkeys are passwordless, phishing-resistant FIDO2 login credentials synced across devices. Learn how they work and differ from security keys.
Person identification data (PID)
PID is the eIDAS 2 identity set (name, birth date, birth place, nationality) for the EUDI Wallet - which attributes are mandatory and who issues them.
PKIoverheid
PKIoverheid is the Dutch government PKI (Logius, PvE), used for Digikoppeling, DigiD authentication, and qualified digital signatures and seals.
Post-quantum cryptography (PQC)
Cryptography that survives quantum computers: ML-KEM, ML-DSA and SLH-DSA, why key exchange is urgent first, and what migration means for signatures.
PSD2
PSD2 is the EU directive (since 2018) requiring strong customer authentication (SCA) and opening banking APIs to licensed third parties.
Pseudonym
A stand-in name that keeps you accountable but not exposed: how eIDAS protects pseudonyms in wallets, logins and qualified certificates.
Public key infrastructure (PKI)
PKI is the system of asymmetric cryptography, certificates and certificate authorities (CAs) that makes digital trust scale.
Public sector electronic attestation of attributes (Pub-EAA)
Pub-EAA: attribute attestations issued by public sector bodies for the EUDI Wallet, with legal effects equal to a qualified EAA under eIDAS.
Q
Qualified certificate
A qualified certificate is the eIDAS PKI certificate underpinning a QES, giving electronic signatures and seals the highest level of legal assurance.
Qualified electronic archiving service
The eIDAS trust service that keeps documents readable and unaltered: qualified archiving gives a presumption of integrity and accurate origin.
Qualified electronic attestation of attributes (QEAA)
QEAA is the qualified electronic attestation of attributes under eIDAS: issued only by a QTSP, with the legal effect of a paper attestation.
Qualified electronic ledger
The eIDAS trust service for ordered records: a qualified ledger presumes unique chronological ordering and integrity, with no technology prescribed.
Qualified electronic registered delivery service (QERDS)
QERDS (qualified electronic registered delivery service) is the eIDAS-regulated delivery service with an EU-wide presumption of integrity and delivery.
Qualified electronic seal
A qualified electronic seal is an advanced electronic seal under eIDAS that gives EU-wide legal presumption of data integrity and origin for organisations.
Qualified electronic signature (QES)
A qualified electronic signature (QES) is the highest eIDAS signature level, legally equal to a handwritten signature EU-wide. Learn how it works.
Qualified electronic timestamp
A qualified electronic timestamp, issued by a QTSP under eIDAS, proves data existed at a time, with legal presumption of accuracy and integrity.
Qualified signature creation device (QSCD)
A QSCD (qualified electronic signature creation device) is certified hardware, such as an HSM, that creates a qualified signature or seal under EU eIDAS.
Qualified trust service provider (QTSP)
A Qualified Trust Service Provider is audited and listed on the EU Trusted List, giving qualified services the strongest legal recognition under eIDAS.
Qualified website authentication certificate (QWAC)
A QWAC is an EU eIDAS qualified certificate that proves the verified identity behind a website, used widely in PSD2 open banking APIs.
R
Registration authority (RA)
Registration Authority (RA): the PKI party that verifies applicant identity and attributes, then passes verified data to the CA for certificate issuance.
Relying party (RP)
A relying party checks someone's digital identity, signature or certificate under eIDAS; wallet-relying parties must register to use the EUDI Wallet.
Remote signing
Remote signing means the signature is created on a server managed by a QTSP instead of on a card or token held by the user.
Rijksinspectie Digitale Infrastructuur (RDI)
The Rijksinspectie Digitale Infrastructuur (RDI, formerly Agentschap Telecom) is the Dutch supervisory body for trust services under eIDAS.
RSA
RSA is an asymmetric cryptographic algorithm based on prime factorisation, widely used for encryption and digital signatures in PKI.
S
SAML 2.0
SAML 2.0 (Security Assertion Markup Language) is the XML-based federation standard behind single sign-on for DigiD, eHerkenning, and eIDAS nodes.
SD-JWT
SD-JWT is an IETF credential format used in the EUDI Wallet, letting holders selectively disclose individual attributes from a signed token.
Selective disclosure
Selective disclosure lets an EUDI Wallet user share only needed attributes, like proving age without revealing a birth date, per GDPR data minimisation.
Signature activation data (SAD)
SAD (Signature Activation Data), defined in EN 419241, binds signatory, key and DTBS/R via SAP to activate a QSCD for eIDAS remote signing.
Signature activation module (SAM)
Signature Activation Module (SAM): the EN 419 241-2 component that enforces sole control in remote signing before each qualified signature is created.
Signature activation protocol (SAP)
The protocol that delivers signature activation data to the activation module, so a key on a server is only used under the signer's sole control.
Signature creation data (SCD)
Signature creation data (SCD) is the private key used to sign; eIDAS requires sole control and, for qualified signing, a certified QSCD.
Signature validation
Signature validation checks the cryptography, certificate trust chain and validity behind an electronic signature or seal, per eIDAS and ETSI standards.
Signature validation report
A signature validation report records TOTAL-PASSED, TOTAL-FAILED or INDETERMINATE status per ETSI standards, so you can archive proof of what was checked.
Single sign-on (SSO)
Single sign-on lets a user authenticate once and then access multiple applications without logging in again.
Sole control
Sole control is the eIDAS requirement, under Annex II, that only the signatory can use their private key, even when held by a QTSP for remote signing.
Sole control assurance level (SCAL)
Sole Control Assurance Level (SCAL) measures remote signing security; SCAL2 requires strong authentication for qualified electronic signatures.
Status list
How status lists let issuers signal attestation revocation or suspension in the EUDI Wallet, without tracking who checks a credential's status.
Strong authentication
Strong authentication (MFA/2FA) combines two independent factors, such as a password and phone, to secure logins and authorise qualified signatures.
Supervisory body
The national authority under eIDAS that supervises trust service providers and grants or withdraws their qualified status.
T
Tamper resistance
Tamper resistance is a device's ability to withstand physical and logical attacks on its keys, certified via Common Criteria, FIPS 140-3, or EN 419221-5.
Termination plan
The plan a qualified trust service provider must keep for the day it stops: who keeps records and revocation data available, and who is told when.
Time-stamping authority (TSA)
A TSA (Time-Stamping Authority) issues electronic timestamps binding a document hash to a moment in time, under eIDAS and RFC 3161 standards.
Trust service
A trust service is an eIDAS-regulated service such as electronic signatures, seals and timestamps; qualified ones are provided by a QTSP in the EU.
U
Uitvoeringswet Algemene verordening gegevensbescherming (UAVG)
The Dutch act implementing the GDPR: national choices, the Autoriteit Persoonsgegevens as supervisor and limits on using the BSN.
V
Verifiable credential (VC)
A digitally signed set of claims that a holder can present to a verifier without contacting the issuer - the pattern behind EUDI Wallet attestations.
W
Wallet certification
How an EUDI Wallet is certified under Article 5c eIDAS: designated bodies, European and national schemes, five years validity, biennial vulnerability checks.
Wallet connector
A Wallet Connector lets relying parties accept EUDI Wallet attestations without building the underlying wallet protocols themselves.
Wallet provider
Learn what a wallet provider does under eIDAS 2.0: building, certifying and operating an EUDI Wallet, with recognition under the Dutch Wdo.
Wallet secure cryptographic application (WSCA)
WSCA is the software component in the EUDI Wallet that manages cryptographic keys, working with the WSCD device to bind and present attestations.
Wallet secure cryptographic device (WSCD)
WSCD (Wallet Secure Cryptographic Device): secure hardware or service in the EUDI Wallet storing keys, can be QSCD-certified for qualified signatures.
Wallet unit
The configuration a wallet provider gives one user: wallet instance plus secure application and device. Certification and revocation apply here.
Wallet-relying party access certificate
The certificate a wallet-relying party shows to a wallet to prove who it is, issued by an appointed provider and tied to its registration.
Wallet-relying party registration
Under eIDAS Article 5b, organisations must register as a wallet-relying party before requesting data from an EUDI Wallet user.
Wet beveiliging netwerk- en informatiesystemen (Wbni)
Wbni: the Dutch NIS1 law that made essential providers and government secure their networks and report cyber incidents, replaced by the Cyberbeveiligingswet.
Wet digitale overheid (Wdo)
The Wet digitale overheid (Wdo) is the Dutch act governing DigiD, eHerkenning and assurance levels for digital access to government services.
Wwft
The Wwft is the Dutch AML law (anti-money-laundering act), requiring customer due diligence (CDD/KYC); digital identity enables secure remote onboarding.
WYSIWYS
WYSIWYS ensures the document you see when signing matches exactly what is hashed and signed, protecting signer intent and legal validity.
X
X.509
X.509 is the international standard for digital certificates, used for HTTPS/TLS, S/MIME, and other internet security, now in version 3.
XAdES
XAdES (ETSI EN 319 132) is the standard for embedding electronic signatures and seals in XML data, used for e-invoicing and long-term validation.
Z
Zero-knowledge proof (ZKP)
A proof that a statement holds while revealing nothing else: prove you are over 18 without your date of birth, and keep presentations unlinkable.