An open book

Glossary

Digital identity is full of acronyms and specialist terms. This glossary explains them one by one.

View

134 terms found

A

Access management
Access management is deciding and enforcing who may do what: after authentication establishes who you are, authorisation determines what you can reach.
Read full
AdES signature formats
AdES formats - PAdES, XAdES, CAdES, JAdES - are the ETSI standards defining how signatures are embedded in PDF, XML, CMS and JSON data.
Read full
Advanced electronic signature (AdES)
An advanced electronic signature (AdES) meets all four Article 26 eIDAS criteria: unique link, identification, sole control and tamper detection.
Read full
Architecture and Reference Framework (ARF)
The Architecture and Reference Framework (ARF) is the EU's technical blueprint for the EUDI Wallet: formats, protocols, roles and certification.
Read full
Attestation rulebook
The specification of one attestation type: attributes, namespaces, encoding, validity and verification rules. What makes wallet credentials interoperable.
Read full
Authentic source
An authentic source is the legally authoritative register - such as the BRP - that EUDI Wallet attestations verify attributes against under eIDAS 2.
Read full

B

Basisregistratie Personen (BRP)
The Dutch population register: municipalities and the non-residents register, who may receive data, and why it is the authentic source behind PID.
Read full
Biometric authentication
Biometric authentication verifies identity using a face, fingerprint or iris, checked with liveness detection to prevent spoofing during onboarding.
Read full
Biometric liveness detection
Biometric liveness detection confirms a face sample is from a living person, not a photo or spoof. Essential for remote identity verification.
Read full
Burgerservicenummer (BSN)
The unique Dutch personal number: who may use it under Article 46 UAVG, why it is an identifier and not proof, and what wallets carry instead.
Read full

C

CAdES
CAdES is the ETSI standard for advanced electronic signatures (AdES) using CMS/PKCS#7 binary data, used when content is not a PDF or XML file.
Read full
Certificate authority (CA)
A Certificate Authority issues digital certificates within a PKI, binding identities to public keys so browsers and systems can trust them.
Read full
Certificate chain
The path from a certificate through intermediates to a trust anchor, and what path validation checks at every link: signature, validity, usage, revocation.
Read full
Certificate revocation
Certificate revocation is how PKI marks a certificate untrusted before expiry, checked via CRL and OCSP after key compromise or data changes.
Read full
Certificate validity period
Every certificate carries a notBefore/notAfter window - typically one to three years for end-user certificates.
Read full
Cleverbase app
The Cleverbase app (formerly Vidua): one high-assurance digital identity to log in, share data and place qualified electronic signatures from your phone.
Read full
Cloud Signature Consortium API (CSC API)
The Cloud Signature Consortium (CSC) API is the open standard for remote signing integrations, used by QTSPs and EUDI Wallet signing flows.
Read full
Common Criteria (CC)
Common Criteria (ISO/IEC 15408): security certification of IT products against a protection profile, rated EAL1-7. Used for QSCDs and HSMs.
Read full
Conformity assessment body (CAB)
A conformity assessment body (CAB) audits trust service providers against eIDAS and ETSI standards, and may certify EUDI Wallet solutions under eIDAS 2.0.
Read full
Conformity assessment report
A conformity assessment report is the audit evidence a CAB issues to prove a trust service provider still meets eIDAS requirements.
Read full
CP/CPS
CP and CPS are the public documents defining what a trust service provider promises about certificates and how it delivers on that promise.
Read full
CRL
CRL explained: the signed list a certificate authority publishes of revoked certificates, how it works, and how it differs from OCSP.
Read full
Cryptographic binding
Cryptographic binding mathematically links a signature, wallet key or authentication to one document, holder or origin, not just an assertion.
Read full
Cryptographic key generation
Key generation is creating a cryptographic key pair: a private key (the signature creation data) and the matching public key.
Read full
CSR
CSR explained: the self-signed request carrying a public key, sent to a CA to prove key possession before certificate issuance.
Read full
Cyberbeveiligingsbesluit
The Dutch decree under the Cyberbeveiligingswet: the duty of care worked out per measure, board training and what an incident report must contain.
Read full
Cyberbeveiligingswet (Cbw)
The Cyberbeveiligingswet (Cbw) is the Dutch law implementing NIS2, requiring organisations to manage cyber risk and report incidents.
Read full
Cybersecurity Act
The Cybersecurity Act (EU 2019/881) gives ENISA a permanent mandate and sets up the EU framework for certifying ICT products, services and processes.
Read full

D

DigiD
DigiD is the Dutch public eID for citizens, issued by Logius, used to log in to government services like the Belastingdienst and municipalities.
Read full
Document integrity
Document integrity is the guarantee that content has not changed since a reference moment - the property that turns a digital file into evidence.
Read full
DORA
DORA (Regulation 2022/2554) is the EU law on ICT risk, incident reporting and resilience testing for the financial sector, applying since 2025.
Read full
DTBS
DTBS is the data a signer intends to sign; DTBS/R is its usually hash-based representation processed by an HSM or QSCD when creating an e-signature.
Read full
Dual signature
A dual signature combines a personal electronic signature with an organisational seal on one document under eIDAS, covering intent and origin.
Read full

E

eHerkenning
eHerkenning is the Dutch eID scheme for organisations, letting employees log in to government and business services with a registered mandate.
Read full
eIDAS
eIDAS (EU Regulation 910/2014) governs electronic signatures, seals and eID across the EU; eIDAS 2 adds the EUDI Wallet and qualified signing.
Read full
Electronic attestation of attributes (EAA)
An electronic attestation of attributes (EAA/QEAA) is a signed digital statement - age, diploma, mandate - held in an EUDI Wallet under eIDAS 2.
Read full
Electronic identification (eID)
Electronic identification is using an electronic means to prove who you are online.
Read full
Electronic machine readable travel document (eMRTD)
The signed chip in a passport or ID card: passive authentication, chip authentication and PACE, and why reading it beats photographing a document.
Read full
Electronic registered delivery service (ERDS)
Electronic registered delivery (ERDS) is the trust service that proves sending, receipt and integrity online; QERDS adds legal presumptions under eIDAS.
Read full
Electronic seal
An electronic seal is data that organisations attach under eIDAS to prove origin and integrity; creating or validating it is the trust service.
Read full
Electronic signature
Under eIDAS, an electronic signature has three levels - simple, advanced (AES) and qualified (QES) - each with different legal effect and use case.
Read full
Elliptic curve cryptography (ECC)
Public-key cryptography on elliptic curves: ECDSA, EdDSA and ECDH, short keys, approved curves, and why wallets and smartcards rely on it.
Read full
ETSI
ETSI ESI standards define the technical requirements that make eIDAS-based electronic signatures, seals and trust services auditable for QTSPs.
Read full
EU Trusted List
The EU Trusted List is the official, machine-readable register of qualified trust service providers and their qualified services.
Read full
EUDI Wallet
The European Digital Identity Wallet is the wallet introduced by eIDAS 2. Every member state must offer at least one wallet to its citizens and residents.
Read full
European Business Wallet (EBW)
The European Business Wallet is a separate EU regulation proposed in November 2025 for organisations - not an EUDI Wallet issued to a company.
Read full

F

FIDO2
FIDO2 and passkeys offer phishing-resistant, passwordless authentication and MFA via a key pair cryptographically bound to the real website.
Read full

G

General Data Protection Regulation (GDPR)
General Data Protection Regulation (GDPR): the EU law on personal data - legal basis, minimisation, breach duties for identity and trust services.
Read full

H

Hardware security module (HSM)
A Hardware Security Module (HSM) is certified, tamper-resistant hardware that protects cryptographic keys for eIDAS-qualified signing, seals and PKI.
Read full
Hash
A hash is a data fingerprint from a cryptographic function like SHA-256, used to bind electronic signatures and timestamps to exact content.
Read full

I

Identity federation
Identity federation lets users authenticate once and be trusted by other services, via protocols like SAML and OpenID Connect.
Read full
Identity provider (IdP)
An identity provider (IdP) authenticates users and vouches for their identity, enabling identity federation and single sign-on across trusted services.
Read full
Identity verification
Identity verification (identity proofing) confirms someone's identity with the required assurance before issuing a qualified certificate or wallet PID.
Read full
Incident reporting
QTSPs must report incidents fast: NIS2 (24h warning, RDI/NCSC), GDPR breach notification (72h) - eIDAS's own Article 19 duty was repealed in 2024.
Read full
Information security management system (ISMS)
The management system behind security: risk assessment, approved policy, owned measures and evidence. What eIDAS Article 24 and an audit expect.
Read full

J

JAdES
JAdES is the ETSI standard for embedding advanced electronic signatures in JSON data, built on JWS - used in APIs and digital wallets.
Read full

K

Key ceremony
The scripted, witnessed procedure in which a CA creates or retires a root key inside an HSM, with split knowledge, dual control and an audited record.
Read full

L

Level of assurance (LoA)
eIDAS LoA (low, substantial, high) shows how certain a relying party can be that an eID belongs to its user, per EU Regulation 2015/1502.
Read full
Logius
The Dutch government organisation behind DigiD, eHerkenning and PKIoverheid: it manages the schemes while others issue the means and the RDI supervises.
Read full
Long-term validation (LTV)
Long-Term Validation (LTV) and Long-Term Archival (LTA) keep eIDAS electronic signatures and seals verifiable for decades using archive timestamps.
Read full
LTA
LTA is the ETSI baseline signature level that adds renewable archive timestamps to keep signatures verifiable for decades.
Read full

M

Mandate
A mandate is legal authorisation to represent someone else - eHerkenning, DigiD Machtigen and EUDI Wallet attestations make it provable online.
Read full
mDL
mDL is a mobile driving licence on a smartphone, standardised under ISO/IEC 18013-5 and required by EU law to be issued for the EUDI Wallet.
Read full
mdoc
mdoc is the ISO 18013-5 credential format used in the EUDI Wallet, enabling selective disclosure and offline, in-person identity presentation.
Read full

N

NIS2
NIS2 (EU 2022/2555): EU cybersecurity directive for essential and important entities, with 24-hour incident reporting and management liability.
Read full
Non-repudiation
Non-repudiation means a signatory cannot credibly deny signing a document: the evidence from an electronic or digital signature binds the act to them.
Read full
Notified electronic identification scheme
An eID scheme a Member State notified to the Commission: what Article 9 requires, how peer review works and why public bodies abroad must accept it.
Read full

O

OAuth 2.0
OAuth 2.0 is the internet's standard framework for delegated authorisation, granting apps scoped, expiring access tokens instead of passwords.
Read full
OCSP
OCSP explained: the real-time protocol for checking certificate revocation status, how it differs from CRL, and what OCSP stapling does.
Read full
OpenID Connect (OIDC)
OpenID Connect is the identity layer on OAuth 2.0, providing the signed ID token behind "Log in with ..." buttons and enterprise SSO logins.
Read full
OpenID4VC
OpenID4VC covers OpenID4VCI (credential issuance) and OpenID4VP (credential presentation), the OAuth 2.0-based protocols behind the EUDI Wallet.
Read full
OpenID4VCI
OpenID4VCI is the OpenID protocol wallets use to request and receive digital credentials from an issuer, used in the EUDI Wallet.
Read full
OpenID4VP
OpenID4VP is the OpenID protocol that lets relying parties request and verify credentials from a digital wallet, such as the EUDI Wallet.
Read full

P

PAdES
PAdES (EN 319 142) is the ETSI standard for embedding electronic signatures and seals inside PDF documents, keeping the file self-contained.
Read full
Passkeys
Passkeys are passwordless, phishing-resistant FIDO2 login credentials synced across devices. Learn how they work and differ from security keys.
Read full
Person identification data (PID)
PID is the eIDAS 2 identity set (name, birth date, birth place, nationality) for the EUDI Wallet - which attributes are mandatory and who issues them.
Read full
PKIoverheid
PKIoverheid is the Dutch government PKI (Logius, PvE), used for Digikoppeling, DigiD authentication, and qualified digital signatures and seals.
Read full
Post-quantum cryptography (PQC)
Cryptography that survives quantum computers: ML-KEM, ML-DSA and SLH-DSA, why key exchange is urgent first, and what migration means for signatures.
Read full
PSD2
PSD2 is the EU directive (since 2018) requiring strong customer authentication (SCA) and opening banking APIs to licensed third parties.
Read full
Pseudonym
A stand-in name that keeps you accountable but not exposed: how eIDAS protects pseudonyms in wallets, logins and qualified certificates.
Read full
Public key infrastructure (PKI)
PKI is the system of asymmetric cryptography, certificates and certificate authorities (CAs) that makes digital trust scale.
Read full
Public sector electronic attestation of attributes (Pub-EAA)
Pub-EAA: attribute attestations issued by public sector bodies for the EUDI Wallet, with legal effects equal to a qualified EAA under eIDAS.
Read full

Q

Qualified certificate
A qualified certificate is the eIDAS PKI certificate underpinning a QES, giving electronic signatures and seals the highest level of legal assurance.
Read full
Qualified electronic archiving service
The eIDAS trust service that keeps documents readable and unaltered: qualified archiving gives a presumption of integrity and accurate origin.
Read full
Qualified electronic attestation of attributes (QEAA)
QEAA is the qualified electronic attestation of attributes under eIDAS: issued only by a QTSP, with the legal effect of a paper attestation.
Read full
Qualified electronic ledger
The eIDAS trust service for ordered records: a qualified ledger presumes unique chronological ordering and integrity, with no technology prescribed.
Read full
Qualified electronic registered delivery service (QERDS)
QERDS (qualified electronic registered delivery service) is the eIDAS-regulated delivery service with an EU-wide presumption of integrity and delivery.
Read full
Qualified electronic seal
A qualified electronic seal is an advanced electronic seal under eIDAS that gives EU-wide legal presumption of data integrity and origin for organisations.
Read full
Qualified electronic signature (QES)
A qualified electronic signature (QES) is the highest eIDAS signature level, legally equal to a handwritten signature EU-wide. Learn how it works.
Read full
Qualified electronic timestamp
A qualified electronic timestamp, issued by a QTSP under eIDAS, proves data existed at a time, with legal presumption of accuracy and integrity.
Read full
Qualified signature creation device (QSCD)
A QSCD (qualified electronic signature creation device) is certified hardware, such as an HSM, that creates a qualified signature or seal under EU eIDAS.
Read full
Qualified trust service provider (QTSP)
A Qualified Trust Service Provider is audited and listed on the EU Trusted List, giving qualified services the strongest legal recognition under eIDAS.
Read full
Qualified website authentication certificate (QWAC)
A QWAC is an EU eIDAS qualified certificate that proves the verified identity behind a website, used widely in PSD2 open banking APIs.
Read full

R

Registration authority (RA)
Registration Authority (RA): the PKI party that verifies applicant identity and attributes, then passes verified data to the CA for certificate issuance.
Read full
Relying party (RP)
A relying party checks someone's digital identity, signature or certificate under eIDAS; wallet-relying parties must register to use the EUDI Wallet.
Read full
Remote signing
Remote signing means the signature is created on a server managed by a QTSP instead of on a card or token held by the user.
Read full
Rijksinspectie Digitale Infrastructuur (RDI)
The Rijksinspectie Digitale Infrastructuur (RDI, formerly Agentschap Telecom) is the Dutch supervisory body for trust services under eIDAS.
Read full
RSA
RSA is an asymmetric cryptographic algorithm based on prime factorisation, widely used for encryption and digital signatures in PKI.
Read full

S

SAML 2.0
SAML 2.0 (Security Assertion Markup Language) is the XML-based federation standard behind single sign-on for DigiD, eHerkenning, and eIDAS nodes.
Read full
SD-JWT
SD-JWT is an IETF credential format used in the EUDI Wallet, letting holders selectively disclose individual attributes from a signed token.
Read full
Selective disclosure
Selective disclosure lets an EUDI Wallet user share only needed attributes, like proving age without revealing a birth date, per GDPR data minimisation.
Read full
Signature activation data (SAD)
SAD (Signature Activation Data), defined in EN 419241, binds signatory, key and DTBS/R via SAP to activate a QSCD for eIDAS remote signing.
Read full
Signature activation module (SAM)
Signature Activation Module (SAM): the EN 419 241-2 component that enforces sole control in remote signing before each qualified signature is created.
Read full
Signature activation protocol (SAP)
The protocol that delivers signature activation data to the activation module, so a key on a server is only used under the signer's sole control.
Read full
Signature creation data (SCD)
Signature creation data (SCD) is the private key used to sign; eIDAS requires sole control and, for qualified signing, a certified QSCD.
Read full
Signature validation
Signature validation checks the cryptography, certificate trust chain and validity behind an electronic signature or seal, per eIDAS and ETSI standards.
Read full
Signature validation report
A signature validation report records TOTAL-PASSED, TOTAL-FAILED or INDETERMINATE status per ETSI standards, so you can archive proof of what was checked.
Read full
Single sign-on (SSO)
Single sign-on lets a user authenticate once and then access multiple applications without logging in again.
Read full
Sole control
Sole control is the eIDAS requirement, under Annex II, that only the signatory can use their private key, even when held by a QTSP for remote signing.
Read full
Sole control assurance level (SCAL)
Sole Control Assurance Level (SCAL) measures remote signing security; SCAL2 requires strong authentication for qualified electronic signatures.
Read full
Status list
How status lists let issuers signal attestation revocation or suspension in the EUDI Wallet, without tracking who checks a credential's status.
Read full
Strong authentication
Strong authentication (MFA/2FA) combines two independent factors, such as a password and phone, to secure logins and authorise qualified signatures.
Read full
Supervisory body
The national authority under eIDAS that supervises trust service providers and grants or withdraws their qualified status.
Read full

T

Tamper resistance
Tamper resistance is a device's ability to withstand physical and logical attacks on its keys, certified via Common Criteria, FIPS 140-3, or EN 419221-5.
Read full
Termination plan
The plan a qualified trust service provider must keep for the day it stops: who keeps records and revocation data available, and who is told when.
Read full
Time-stamping authority (TSA)
A TSA (Time-Stamping Authority) issues electronic timestamps binding a document hash to a moment in time, under eIDAS and RFC 3161 standards.
Read full
Trust service
A trust service is an eIDAS-regulated service such as electronic signatures, seals and timestamps; qualified ones are provided by a QTSP in the EU.
Read full

U

Uitvoeringswet Algemene verordening gegevensbescherming (UAVG)
The Dutch act implementing the GDPR: national choices, the Autoriteit Persoonsgegevens as supervisor and limits on using the BSN.
Read full

V

Verifiable credential (VC)
A digitally signed set of claims that a holder can present to a verifier without contacting the issuer - the pattern behind EUDI Wallet attestations.
Read full

W

Wallet certification
How an EUDI Wallet is certified under Article 5c eIDAS: designated bodies, European and national schemes, five years validity, biennial vulnerability checks.
Read full
Wallet connector
A Wallet Connector lets relying parties accept EUDI Wallet attestations without building the underlying wallet protocols themselves.
Read full
Wallet provider
Learn what a wallet provider does under eIDAS 2.0: building, certifying and operating an EUDI Wallet, with recognition under the Dutch Wdo.
Read full
Wallet secure cryptographic application (WSCA)
WSCA is the software component in the EUDI Wallet that manages cryptographic keys, working with the WSCD device to bind and present attestations.
Read full
Wallet secure cryptographic device (WSCD)
WSCD (Wallet Secure Cryptographic Device): secure hardware or service in the EUDI Wallet storing keys, can be QSCD-certified for qualified signatures.
Read full
Wallet unit
The configuration a wallet provider gives one user: wallet instance plus secure application and device. Certification and revocation apply here.
Read full
Wallet-relying party access certificate
The certificate a wallet-relying party shows to a wallet to prove who it is, issued by an appointed provider and tied to its registration.
Read full
Wallet-relying party registration
Under eIDAS Article 5b, organisations must register as a wallet-relying party before requesting data from an EUDI Wallet user.
Read full
Wet beveiliging netwerk- en informatiesystemen (Wbni)
Wbni: the Dutch NIS1 law that made essential providers and government secure their networks and report cyber incidents, replaced by the Cyberbeveiligingswet.
Read full
Wet digitale overheid (Wdo)
The Wet digitale overheid (Wdo) is the Dutch act governing DigiD, eHerkenning and assurance levels for digital access to government services.
Read full
Wwft
The Wwft is the Dutch AML law (anti-money-laundering act), requiring customer due diligence (CDD/KYC); digital identity enables secure remote onboarding.
Read full
WYSIWYS
WYSIWYS ensures the document you see when signing matches exactly what is hashed and signed, protecting signer intent and legal validity.
Read full

X

X.509
X.509 is the international standard for digital certificates, used for HTTPS/TLS, S/MIME, and other internet security, now in version 3.
Read full
XAdES
XAdES (ETSI EN 319 132) is the standard for embedding electronic signatures and seals in XML data, used for e-invoicing and long-term validation.
Read full

Z

Zero-knowledge proof (ZKP)
A proof that a statement holds while revealing nothing else: prove you are over 18 without your date of birth, and keep presentations unlinkable.
Read full