Security & Trust
Cryptography, Keys and Certificates
DIW Gateway uses cryptographic keys and certificates for interactions with the EUDIW ecosystem, credential signing and verification, and securing communication with integrating systems.
Private key operations can be delegated to an HSM through the PKCS#11 interface. In a bank-hosted deployment, production private keys can remain under the control of the integrating organization.
Cryptographic Key Management
DIW Gateway uses cryptographic keys for operations such as signing issued attestations and signing requests used in communication with Wallet Units.
In a bank-hosted deployment, private keys can remain under the control of the integrating organization, typically within its Hardware Security Module (HSM). DIW Gateway accesses the HSM through the PKCS#11 interface and performs the required cryptographic operations without requiring access to exportable private key material.
For issued attestations, DIW Issuer uses the signing key of the corresponding Attestation Provider. Production signing keys can therefore remain within the organization’s HSM and be managed according to its cryptographic policy.
The integrating organization remains responsible for ownership and management of its cryptographic keys and HSM infrastructure, while DIW Gateway provides the integration required to use these keys for supported cryptographic operations.
Certificate Types and Usage
DIW Gateway works with certificates associated with registered entities and their interactions with the EUDIW ecosystem.
Registration Certificates
Registration Certificates are associated with the registration of Relying Parties and Attestation Providers.
For details about registration and certificate provisioning, see Registered Entity Management.
Access Certificates
Access Certificates are used by registered entities when interacting with the EUDIW ecosystem.
For a Relying Party, DIW Gateway uses the Access Certificate issued for that Relying Party when interacting with Wallet Units.
Attestation Signing Certificates
DIW Issuer cryptographically signs issued attestations using the signing key of the corresponding Attestation Provider.
Key and Certificates Lifecycle
Certificate lifecycle management is primarily controlled by the integrating organization.
DIW Gateway provides technical support for generating certificate signing requests and installing new certificates through its REST API. When a certificate is replaced, DIW Gateway starts using the newly configured certificate without requiring a planned service outage.
Expiration monitoring, renewal, rotation, and revocation policies remain under the control of the integrating organization.
Trust Framework and Trust Validation
DIW Gateway integrates with the EUDIW trust infrastructure to establish and validate trust in entities, certificates, and presented credentials.
DIW Verifier and DIW Issuer use the relevant EUDIW Trusted Lists, Registrar CA, and Common Trust Infrastructure as part of technical trust validation.
Trust Model
Trust decisions related to the EUDIW ecosystem use the trust anchors and registries defined by the applicable EUDIW trust framework.
Organization-specific trust anchors can additionally be used for internal integrations or supplementary trust policies, but do not replace the trust sources required by the EUDIW ecosystem:
EUDIW Trust Infrastructure
DIW Gateway works with the trust infrastructure required for technical validation of EUDIW entities and credentials.
-
Trusted Lists: Relevant EUDIW Trusted Lists are used to determine the trust status of entities and certificates.
-
Registrar CA and Common Trust Infrastructure: DIW Verifier and DIW Issuer work with the relevant Registrar CA and Common Trust Infrastructure as part of the EUDIW trust model.
Trust Validation
DIW Gateway performs technical trust validation of counterparties and credentials against the relevant EUDIW trust sources.
For presented credentials, DIW Verifier verifies the cryptographic proofs, issuer trust and signature, and, where applicable, the current credential status or revocation state.
The result of technical validation is provided to the integrating system. Business acceptance decisions remain the responsibility of the integrating organization.
Trust Information Management
Trust information is processed centrally by DIW Gateway.
Relevant trust lists are retrieved when required and maintained in a local cache. The refresh frequency is configurable, with a default refresh interval of 24 hours.
Failed validation of cryptographic material, certificates, or trust information is recorded in the transaction and audit trail.
Data Protection and Privacy
DIW Gateway is designed to process only the data required for the corresponding EUDIW transaction.
The amount and duration of stored data depend on the use case, deployment model, and configured retention policy. Data minimization and selective disclosure can be applied to limit the credentials and claims requested for individual use cases.
Data Processing Principles
DIW Gateway processes client and banking data only to the extent required for the corresponding EUDIW flow.
The integrating organization determines the purpose of processing, the attributes required for individual use cases, the applicable retention policy, and access rules.
In a bank-hosted deployment, DIW Gateway can be operated without the provider having access to the content of client attributes, with the data remaining under the control of the integrating organization.
In a SaaS deployment, access to client data is restricted to authorized personnel and limited to necessary administrative and operational purposes.
Data retention is configurable according to the requirements of the integrating organization.
Transaction and Attestation Data
Personal data is retained according to the configured retention policy, either only for the duration of the transaction or for a configured retention period.
DIW Verifier supports a pass-through configuration in which presentation data is held temporarily in memory during transaction processing and removed after it has been successfully provided to the integrating system.
Detailed retention configuration is described in Data Retention.
Data Minimization
DIW Gateway supports policy-driven data minimization through configurable verification profiles.
Each profile defines the credentials and claims required for a particular Relying Party and use case, allowing the integrating organization to request only the information required for the corresponding purpose.
Selective disclosure is applied according to the supported credential format.
Cryptographic Evidence
The content of Verifiable Presentations and Verifiable Credentials is stored separately from the associated cryptographic material.
Depending on the configured retention policy, the original presentation or credential content can be removed after transaction processing while retaining the relevant cryptographic hashes.
Retained cryptographic material or hashes can subsequently be used to verify the integrity of the corresponding stored record even after its original content has been removed.
For details about retention and deletion of transaction and attestation data, see Data Retention.
Security, Certification and Compliance
DIW Gateway applies security controls appropriate for integration with banking systems and the EUDIW ecosystem.
The product follows the applicable EUDIW technical specifications and is continuously updated in response to changes in the Architecture and Reference Framework (ARF), eIDAS 2.0, and related technical specifications.
Authentication and Access Control
Access to DIW Gateway REST APIs is protected using OAuth 2.0.
DIW Gateway can integrate with the organization’s IAM and internal authentication services. Access to administrative and entity-specific functionality is controlled according to the configured permissions.
Callbacks and webhooks can be protected using HTTP Basic Authentication, mTLS, or OAuth 2.0.
Secure Communication
DIW Gateway uses TLS to protect network communication.
mTLS can be used between system components and integration endpoints. Protocol-specific security mechanisms defined by OpenID4VP and OpenID4VCI are used for communication with Wallet Units.
For OpenID4VCI issuance, DIW Gateway supports DPoP nonce generation and verification at the Credential Endpoint.
Regulatory and Standards Alignment
DIW Gateway is developed in alignment with the applicable EUDIW technical specifications and the Architecture and Reference Framework (ARF).
Wultra continuously monitors changes to ARF, eIDAS 2.0, and related EUDIW specifications and incorporates relevant changes into product releases.
Interoperability is verified through testing with EUDI Wallet implementations, reference implementations, and participation in EUDIW Large Scale Pilot activities.
Wultra maintains an ISO/IEC 27001 certified information security management system.