---
id: terminology
title: Terminology
description: Refer to our commonly used industry-related terminologies that will help the users understand concepts and find relevant links to dive deep into developer docs
hide_title: true
sidebar_label: Terminology
keywords: [terminology, digital identity, verifiable credentials, data source, consent, EUDI Wallet, glossary, definitions, reference]
slug: /terminology/
---

> **Build this with an AI coding agent.** Install the iGrant.io Agent Skills, then ask your agent to build the integration:
>
> ```bash
> npx skills add L3-iGrant/skills
> ```


## Data Source
**Description:** The role responsible for collecting, storing, and controlling personal data which persons, operators, and data using services may wish to access and use.
**Reference:** [Understanding MyData Operator](https://igrant.io/papers/Understanding-Mydata-Operators.pdf)

## Data Using Service
**Description:** The role responsible for processing personal data from one or more data sources to deliver a service.
**Reference:** [Understanding MyData Operator](https://igrant.io/papers/Understanding-Mydata-Operators.pdf)

## Decentralized Identifier (DID)
**Description:** A Decentralized Identifier (DID) is a type of identifier that is globally unique, resolvable with high availability, and cryptographically verifiable. DIDs are typically associated with cryptographic material, such as public keys and service endpoints, for establishing secure communication channels.
**Reference:** [DID Primer](https://w3c-ccg.github.io/did-primer/)

## Electronic Attestation of Attributes
**Description:** 'electronic attestation of attributes' means an attestation in electronic form that allows the authentication of attributes.
**Reference:** [eIDAS 2 Definitions](https://docs.igrant.io/regulations/reg-eu-digital-id-framework#article-3---definitions)

## European Business Wallet Owner Identification (EBWOID)
**Description:** An identification mechanism for the owner of a European Business Wallet, used during credential issuance to verify the legal identity of the issuing organisation. The EBWOID is checked as part of the issuer validation process before a credential is delivered to the holder's wallet.
**Reference:** [Credential Issuance Lifecycle](/concepts/credential-issuance-lifecycle/)

## Elliptic-curve Diffie–Hellman
**Description:** Elliptic-curve Diffie–Hellman (ECDH) is a key agreement protocol that allows two parties, each having an elliptic-curve public-private key pair, to establish a shared secret over an insecure channel. This shared secret may be directly used as a key, or to derive another key.
**Reference:** [RFC6090](https://datatracker.ietf.org/doc/html/rfc6090)

## European Digital Identity Wallet
**Description:** 'European Digital Identity Wallet' means an electronic identification, which allows the user to securely store, manage and validate identity data and electronic attestations of attributes, to provide them to relying parties and to other users of European Digital Identity Wallets, and to sign by means of qualified electronic signatures or to seal by means of qualified electronic seals.
**Reference:** [eIDAS 2 Definitions](https://docs.igrant.io/regulations/reg-eu-digital-id-framework#article-3---definitions)

## European Digital Identity Wallet Architecture and Reference Framework
**Description:** A toolbox including a technical Architecture and Reference Framework (ARF), a set of common standards and technical specifications, and a set of common guidelines and best practices.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## German eID system
**Description:** Architecture for the German electronic Identity Card and electronic Resident Permit is specified in the BSI Technical Guideline TR-03127.
**Reference:** BSI TR-03127

## GDPR
**Description:** The General Data Protection Regulation (GDPR) is a regulation in EU law on data protection and privacy in the European Union (EU) and the European Economic Area (EEA).
**Reference:** [GDPR as in EU Regulations](https://docs.igrant.io/regulations/reg-eu-gdpr)

## Individual
**Description:** A natural, living human being.
**Reference:** [Understanding MyData Operator](https://igrant.io/papers/Understanding-Mydata-Operators.pdf)

## JSON Web Token
**Description:** JSON Web Token (JWT) is a compact, URL-safe means of representing claims to be transferred between two parties. The claims in a JWT are encoded as a JSON object that is used as the payload of a JSON Web Signature (JWS) structure or as the plaintext of a JSON Web Encryption (JWE) structure, enabling the claims to be digitally signed or integrity protected with a Message Authentication Code (MAC) and/or encrypted.
**Reference:** [RFC7519](https://datatracker.ietf.org/doc/html/rfc7519)

## Hardware Security Module
**Description:** A HSM is a device for providing cryptographic functionalities whereas the life cycle of cryptographic keys and the performance of cryptographic functions is managed within a highly protected hardware environment.

## Identity Owner
**Description:** The entity, such as a natural person, a legal person, or a device, which is subject of verifiable credentials from credential issuers and being in control of the reception, storage, and sharing of such credentials with relying parties.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## Level of Assurance
**Description:** Degree of confidence in the claimed identity of a person – how certain a service provider can be that it is you, the one using your eID to authenticate to the service, not someone else pretending to be you. In other words, it refers to the difficulty of using someone else’s eID to access an online service.
**Reference:** [eIDAS Levels of Assurance](https://ec.europa.eu/digital-building-blocks/sites/display/DIGITAL/eIDAS+Levels+of+Assurance)

## Message Authentication Code
**Description:** The result of a HMAC performance
**Reference:** [RFC8446](https://datatracker.ietf.org/doc/html/rfc8446)

## OpenID for Verifiable Credential Issuance
**Description:** OAuth protected API for the issuance of Verifiable Credentials.
**Reference:** 
- [OpenID4VCI](https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html)
- [Try out OpenID4VCI](/docs/openID4vci-issue-credential-intime/)
- [iGrant.io Organisation Wallet Suite Issuer Demo](https://www.youtube.com/watch?v=qtsyvw9alb4)

## OpenID for Verifiable Presentations
**Description:** A mechanism on top of OAuth 2.0 [RFC6749] that enables presentation of Verifiable Credentials as Verifiable Presentations.
**Reference:** 
- [OpenID4VP](https://openid.net/specs/openid-4-verifiable-presentations-1_0.html)
- [Try out OpenID4VP](/docs/openID4vc-send-verify-credentials/)

## Organisation Wallet Suite
**Description:** An Organisation Wallet Suite is a digital tool for businesses to securely manage (issue, store, and verify) verifiable credentials. It ensures compliance with standards like OpenID4VC (eIDAS 2.0), JWT, SD-JWT credential formats etc, providing interoperability and robust security. The wallet automates credential management processes, enhancing efficiency and ensuring regulatory compliance with data protection laws like GDPR, eiDAS2.0 etc. Organisation Wallets can issue PID, LPID, (Q)EAAs etc depending on the organisation.
**Reference:** 
- [iGrant.io Organisation Wallet Suite Overview](https://docs.igrant.io/docs/organisation-wallet-overview/)
- [iGrant.io Organisation Wallet Suite Issuer Demo](https://www.youtube.com/watch?v=qtsyvw9alb4)
- [OpenID for Verifiable Credential Issuance](https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html)

## Person Identification Data
**Description:** 'person identification data' means a set of data, issued in accordance with Union or national law, enabling the identity of a natural or legal person, or of a natural person representing a natural or legal person, to be established.
**Reference:** [eIDAS 2 Article 3 (45)](https://docs.igrant.io/regulations/reg-eu-digital-id-framework#article-3---definitions)

## Person Identification Data Provider
**Description:** A Member State or other legal entity providing Person Identification Data to Users.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)


## Proof of Possession
**Description:** Evidence provided by the Wallet regarding the possession of the respective key material.
**Reference:** [Wallet Unit Attestation (WUA)](/concepts/wallet-unit-attestation/)

## Qualified Electronic Attestation of Attributes
**Description:** 'qualified electronic attestation of attributes' means an electronic attestation of attributes, which is issued by a qualified trust service provider and meets the requirements laid down in Annex V.
**Reference:** [eIDAS 2 Article 3 (45)](https://docs.igrant.io/regulations/reg-eu-digital-id-framework#article-3---definitions)

## Qualified Electronic Signature
**Description:** 'qualified electronic signature' means an advanced electronic signature that is created by a qualified electronic signature creation device, and which is based on a qualified certificate for electronic signatures.
**Reference:** [eIDAS 2](https://docs.igrant.io/regulations/reg-eu-digital-id-framework)

## Qualified Trust Service Provider
**Description:** A Trust Service Provider who provides one or more Qualified Trust Services and is granted the qualified status by the supervisory body.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## Relying Party
**Description:** 'relying party' means a natural or legal person that relies upon an electronic identification, European Digital Identity Wallets or other electronic identification means, or a trust service.
**Reference:** [eIDAS 2 Article 3 (6)](https://docs.igrant.io/regulations/reg-eu-digital-id-framework#article-3---definitions)

## Selective Disclosure for JWT
**Description:** A composite structure, consisting of an Issuer-signed JWT (JWS, RFC7515), Disclosures and optionally a Key Binding JWT that supports selective disclosure.
**Reference:** [IETF Draft for Selective Disclosure JWT](https://datatracker.ietf.org/doc/draft-ietf-oauth-selective-disclosure-jwt/)

## SD-JWT-based Verifiable Credentials
**Description:** Verifiable Credentials with JSON payloads with and without selective disclosure based on the SD-JWT format.
**Reference:** [IETF Draft for Selective Disclosure JWT](https://datatracker.ietf.org/doc/draft-ietf-oauth-selective-disclosure-jwt/)

## Self-Sovereign Identity (SSI)
**Description:** A model for managing digital identities where individual identity holders can fully create and control their verifiable credentials without being forced to request permission from an intermediary or centralized authority and give control over how their personal data is shared and used.
**Reference:** [W3C DID Core](https://www.w3.org/TR/did-core/)

## Trusted List
**Description:** Repository of information about authoritative entities in a particular legal or contractual context which provides information about their current and historical status.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## TSP (Trust Service Provider)
**Description:** A natural or a legal person who provides one or more Trust Services, either as a qualified or as a non-qualified Trust Service Provider.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## EU Trust List
**Description:** The set of trusted lists published by EU member states under eIDAS, listing qualified and non-qualified trust service providers and aggregated through the European List of Trusted Lists (LoTL). Wallets use it to check whether a credential issuer or verifier is a recognised, accountable entity. When a party cannot be matched against it, the Data Wallet shows a "not verified" notice.
**Reference:** [ETSI TS 119 612](https://www.etsi.org/deliver/etsi_ts/119600_119699/119612/02.01.01_60/ts_119612v020101p.pdf)

## Trust Anchor
**Description:** An authoritative entity, or its cryptographic key, that serves as the root of trust for validating credential issuers and verifiers. In the EBSI model, trust anchors are onboarded through a trust chain of Root Trust Anchor Operator (Root TAO), Trust Anchor Operator (TAO) and Trusted Issuer (TI).
**Reference:** [Trust Overview](/docs/trust-overview/)

## Trusted Issuer (TI)
**Description:** An entity that has been onboarded into a trust framework and is therefore authorised to issue credentials that wallets can recognise as coming from a trusted source. In the EBSI model, a Trusted Issuer is onboarded under a Trust Anchor Operator.
**Reference:** [Trust Anchor APIs](/docs/category/openid4vc-api/trust-anchor)

## Untrusted Service Provider
**Description:** The former name of the wallet's trust-status notice. Current versions show **"Issuer not verified"** (during issuance) or **"Service provider not verified"** (during presentation) when a credential issuer or verifier cannot be matched against a recognised trust list, such as the EU Trust List. It is a trust indicator and not a validation failure: the credential signature may still be valid, but the wallet cannot independently confirm the party's identity.
**Reference:** [The "Issuer / service provider not verified" notice](/docs/trust-untrusted-service-provider/)

## User (Holder)
**Description:** A natural or legal person using a EUDI Wallet. Also referred to as Holder.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## Verifiable Credential
**Description:** A credential created by an Issuer in a way that the integrity and authenticity of the credential can be cryptographically verified.
**Reference:** [OpenID4VCI](https://openid.net/specs/openid-4-verifiable-credential-issuance-1_0.html)

## WSCD (Wallet Secure Cryptographic Device)
**Description:** Hardware-backed secure environment for creating, storing, and/or managing cryptographic keys and data. Examples include Secure Elements (SE), Trusted Execution Environments (TEEs), and (remote or local) Hardware Security Modules (HSM).
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## Secure Element
**Description:** Secure Elements are physical components in electronic devices that securely store and protect sensitive data and applications and may provide certain secure cryptographic operations.
**Reference:** [Secure Elements for mobile platforms](https://en.wikipedia.org/wiki/Secure_element)

## Zero Knowledge Proofs (ZKP)
**Description:** In cryptography, a zero-knowledge proof is a method by which an entity can prove that they know a certain value without disclosing the value itself.

## Wallet Provider
**Description:** A Wallet Provider makes a combination of products and Trust Services available to a User, giving the User sole control over the use of their Person Identification Data and attestations. The Wallet Provider issues and signs the Wallet Unit Attestation and is listed on a Trusted List.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## Wallet Unit
**Description:** A deployed instance of a Wallet Solution, belonging to and under the sole control of one User. A Wallet Unit comprises one or more Wallet Instances together with the Wallet Secure Cryptographic Application(s) and Device(s) it relies on.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## Wallet Unit Attestation (WUA)
**Description:** An attestation, issued and signed by the Wallet Provider, that lets an issuer (and where applicable a Relying Party) verify that a Wallet Unit is genuine and that the keys it will use are protected in a certified Wallet Secure Cryptographic Device. It combines the Wallet Instance Attestation (WIA) and the Key Attestation (KA).
**Reference:** 
- [Wallet Unit Attestation (WUA)](/concepts/wallet-unit-attestation/)
- [ARF 2.9.0 Topic C](https://eudi.dev/2.9.0/discussion-topics/c-rr-wallet-unit-attestations/)

## Wallet Instance Attestation (WIA)
**Description:** The part of the Wallet Unit Attestation that proves the Wallet Instance is a genuine, certified and currently trusted instance of a Wallet Solution from a known Wallet Provider. It is used as client authentication during credential issuance and is short-lived.
**Reference:** [Wallet Unit Attestation (WUA)](/concepts/wallet-unit-attestation/)

## Key Attestation (KA)
**Description:** The part of the Wallet Unit Attestation that attests that the cryptographic keys listed in its `attested_keys` claim were generated in, and are protected by, the same Wallet Secure Cryptographic Device, at a stated level of assurance.
**Reference:** [Wallet Unit Attestation (WUA)](/concepts/wallet-unit-attestation/)

## Wallet Secure Cryptographic Application (WSCA)
**Description:** Software that uses a Wallet Secure Cryptographic Device (WSCD) to protect critical assets and to securely execute cryptographic functions on behalf of a Wallet Unit.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## Electronic Attestation of Attributes issued by a Public Sector Body (PuB-EAA)
**Description:** An Electronic Attestation of Attributes issued by, or on behalf of, a public sector body responsible for an authentic source, meeting the requirements laid down in eIDAS.
**Reference:** [ARF 2.9.0](https://eudi.dev/2.9.0/architecture-and-reference-framework-main/)

## eIDAS
**Description:** electronic IDentification, Authentication and trust Services: the EU framework (Regulation (EU) No 910/2014, amended by Regulation (EU) 2024/1183, known as eIDAS 2) for electronic identification and trust services, which establishes the European Digital Identity Wallet.
**Reference:** [eIDAS 2](https://docs.igrant.io/regulations/reg-eu-digital-id-framework)
**Reference:** [AnonCreds Specification](https://hyperledger.github.io/anoncreds-spec/#term:zero-knowledge-proofs)