Registered Entity Management
DIW Gateway provides the technical capabilities required to manage entities acting as Relying Parties and Attestation Providers in the EUDIW ecosystem.
The organization acting as the Relying party or Attestation Provider remains responsible for its formal registration with the applicable Registrar and for the correctness of the registration information.
DIW Gateway provides the technical tooling required to support the registration and configuration process.
Managed Entity Types
DIW Gateway supports the management of two main types of entities:
- Relying Party — an entity that requests and verifies attestations presented by Wallet Units.
- Attestation Provider — an entity that issues attestations to Wallet Units.
A DIW Gateway deployment can contain multiple Relying Party and Attestation Provider entities.
Each entity is managed according to its role and the configuration required for the corresponding EUDIW interactions.
Relying Party Management
A Relying Party represents an entity that requests and verifies attestations presented by Wallet Units.
DIW Gateway provides administration capabilities for managing the Relying Party configuration required for its participation in the EUDIW ecosystem.
Relying Party Registration
Before a Relying Party can request attestations from Wallet Units, it must be registered with the applicable Registrar.
DIW Gateway supports the technical part of the registration process by providing administration APIs for:
- managing Relying Party metadata,
- preparing registration information,
- generating Certificate Signing Requests (CSRs),
- uploading the issued Access and Registration certificates.
The formal registration with the applicable Registrar and the correctness of the registration information remain the responsibility of the organization acting as the Relying Party.
A DIW Gateway deployment can support multiple Relying Parties and Relying Party Instances, each with its own configuration.
Core Scenario Steps
- Create the Relying Party and configure its metadata.
- Configure Relying Party Instances where required.
- Prepare the registration information required by the Registrar.
- Generate Certificate Signing Requests for the required certificates.
- Complete the registration process with the applicable Registrar.
- Upload and configure the issued certificates in DIW Gateway.
Intermediary Relying Party Model
DIW Gateway supports a deployment in which the integrating organization acts as an Intermediary Relying Party in the EUDIW ecosystem.
The solution supports management of multiple Relying Parties and Relying Party Instances and can operate both standard Relying Party and Intermediary Relying Party models within the same deployment.
Each managed Relying Party can maintain its own configuration, including certificates, metadata, profiles, mappings, and permissions relevant to its EUDIW interactions.
Attestation Provider Management
An Attestation Provider represents an entity that issues attestations to Wallet Units.
DIW Gateway provides administration capabilities for managing the Attestation Provider configuration required for credential issuance.
Attestation Provider Registration
DIW Gateway supports the technical part of the Attestation Provider registration process by providing administration capabilities for:
- managing Attestation Provider metadata,
- preparing registration information,
- generating Certificate Signing Requests (CSRs),
- uploading the issued certificates.
The formal registration of the Attestation Provider and authorization to issue specific types of attestations remain the responsibility of the organization acting as the Attestation Provider.
Core Scenario Steps
- Create the Attestation Provider and configure its metadata.
- Prepare the registration information required by the Registrar.
- Generate Certificate Signing Requests for the required certificates.
- Complete the registration process with the applicable Registrar.
- Upload and configure the issued certificates in DIW Gateway.
Credential types, attributes, validity, data mappings, and issuance rules are configured separately according to the corresponding issuance use case.
Certificates
Registered entities use certificate material required for their participation in the EUDIW ecosystem.
As part of the registration process, DIW Gateway supports the generation of Certificate Signing Requests (CSRs) and the upload and configuration of issued certificates.
Registration Certificates
Registration Certificates are associated with the registration of a Relying Party or Attestation Provider in the EUDIW ecosystem.
DIW Gateway provides the technical capabilities required to prepare the corresponding Certificate Signing Request and to configure the issued Registration Certificate for the registered entity.
The formal registration process and issuance of the certificate are performed outside DIW Gateway.
Access Certificates
DIW Gateway also supports the preparation and configuration of Access Certificates used by registered entities for interactions with the EUDIW ecosystem.
The corresponding Certificate Signing Request can be generated by DIW Gateway and the issued Access Certificate can subsequently be uploaded and associated with the registered entity.
Private keys associated with the certificates can remain under the control of the integrating organization, for example in its HSM.
For details about cryptographic keys and certificates, see Cryptography, Keys & Certificates.
Administration and Access Control
DIW Gateway provides administration APIs for entity and system management.
Each Relying Party has its own configuration. Creation of a Relying Party requires a general administrator, while roles are available for managing a specific Relying Party.