11.3. IT-Wallet ID Data Model¶
The IT-Wallet ID (Electronic Attestation of Person Identification Data (national scope)) is an Electronic Attestation of Attributes (EAA) issued by the EAA Provider according to national laws. It is provided in SD-JWT VC format.
The IT-Wallet ID is intended exclusively for national use with Italian Relying Parties to access online services. It MUST NOT be used for cross-border interactions and does not constitute a PID under the European Digital Identity framework.
The main scope of the IT-Wallet ID is allowing natural persons to be authenticated for access to a service or to a protected resource within the national jurisdiction. The User attributes provided within the IT-Wallet ID are the ones listed below:
Current Family Name
Current First Name
Date of Birth
Place of Birth
Nationality
User identification number across public Relying Party services (for example the taxpayer identification number)
In addition to the User attributes listed above, the IT-Wallet ID includes also the following metadata attributes:
Issuing authority
Issuing country
Expiry Date
Validity status information
Identity and data proofing information
The identity proofing information is REQUIRED for IT-Wallet ID to ensure:
The evaluation of User authentication method used.
The level of Assurance compliance of identity proofing during the enrollment process, according to the LoA defined by the eIDAS Regulation.
The auditability upon the User attributes verification processes.
11.3.1. IT-Wallet ID Data Model in SD-JWT VC Format¶
The SD-JWT VC IT-Wallet ID defined in this specification MUST use the vct claim value set with urn:it-wallet:eid:1, where eid is the catalogue credential_type of IT-Wallet ID.
The IT-Wallet ID in SD-JWT VC format includes the following User Attributes:
Claim |
Description |
Reference |
|---|---|---|
given_name |
REQUIRED. String. Current First Name. |
Section 5.1 of OIDC and Commission Implementing Regulation EU_2024/2977 |
family_name |
REQUIRED. String. Current Family Name. |
Section 5.1 of OIDC and Commission Implementing Regulation EU_2024/2977 |
birthdate |
REQUIRED. String. Date of Birth. It MUST be set according to ISO8601-1 (YYYY-MM-DD format). |
Commission Implementing Regulation EU_2024/2977 |
place_of_birth |
REQUIRED. JSON Object. Place of Birth. At least one of country, region, locality MUST be present. |
Commission Implementing Regulation EU_2024/2977 |
nationalities |
REQUIRED. Array of strings. One or more alpha-2 country codes as specified in ISO 3166-1. |
Commission Implementing Regulation EU_2024/2977 |
personal_administrative_number |
REQUIRED if |
Commission Implementing Regulation EU_2024/2977 |
tax_id_code |
REQUIRED if |
Domestic extension |
Note
Identity Matching
For the IT-Wallet ID, the Relying Party MUST first perform identity matching using tax_id_code. Only after a successful identity matching, the Relying Party MAY perform identity reconciliation, linking that natural person to a previous User session or stored User record.
All the User attributed listed above MUST be selectively disclosable. In addition to the mandatory metadata attributes defined in SD-JWT header JOSE Parameters Table and SD-JWT Parameters Table, the following metadata attributes are REQUIRED for a IT-Wallet ID:
date_of_expiry
sub (domestic extension)
iat
cnf
status
verification (domestic extension)
11.3.1.1. SD-JWT-VC IT-Wallet ID Non-Normative Example¶
In the following, the non-normative example of the payload of a IT-Wallet ID represented in JSON format.
{
"iss": "https://pidprovider.example.org",
"sub": "NzbLsXh8uDCcd7noWXFZAfHkxZsRGC9Xs",
"iat": 1683000000,
"exp": 1883000000,
"issuing_authority": "PID Provider Organization",
"issuing_country": "IT",
"date_of_expiry": "2033-03-19",
"status": {
"status_list": {
"idx": 1234,
"uri": "https://pidprovider.example.org/status"
}
},
"vct": "urn:eudi:pid:it:1",
"vct#integrity": "55f5fe57f1e491d49f33672784528532d9d",
"verification": {
"trust_framework": "it_cie",
"assurance_level": "https://trust-anchor.example.it/loa/high"
},
"given_name": "Mario",
"family_name": "Rossi",
"birthdate": "1980-01-10",
"place_of_birth": {
"locality": "Roma"
},
"nationalities": [
"IT"
],
"picture": "data:image/jpeg;base64,/9j/4AAQSkZJRgABAQAAAQABAAD..."
}
The corresponding SD-JWT version for IT-Wallet ID is given by
{
"alg": "ES256",
"typ": "dc+sd-jwt",
"kid": "dB67gL7ck3TFiIAf7N6_7SHvqk0MDYMEQcoGGlkUAAw",
"x5c": [
"<Issuer X.509 Certificate>"
]
}
{
"_sd": [
"GHYjuGUthjtB4q4Oz_ZSGPmCokLOpv2kpFNzz1LfFUY",
"Jkbj8aLr-z2_c-HVxCbiw6YXFNHiyLSv1xGjN8lRogI",
"MWJufQz_DFWc9cR4yxq8XqmTZfglkg2D2Sxa3UFN4Qk",
"tI5s2A_Ez6oZv6plZzUPjYAL-SJGiAUFyRbhzLsluGU",
"uIapUlDTKsB5wN7BF6xuBNTtl74gl5iCu_aQ5nj3YL8",
"R6x9o0j4m3L4Pq6xYdK3rP4nNq8vJ2b7sFqT9cUwI7A"
],
"exp": 1883000000,
"iss": "https://pidprovider.example.org",
"sub": "NzbLsXh8uDCcd7noWXFZAfHkxZsRGC9Xs",
"iat": 1683000000,
"issuing_authority": "PID Provider Organization",
"issuing_country": "IT",
"date_of_expiry": "2033-03-19",
"status": {
"status_list": {
"idx": 1234,
"uri": "https://pidprovider.example.org/status"
}
},
"vct": "urn:eudi:pid:it:1",
"vct#integrity": "55f5fe57f1e491d49f33672784528532d9d",
"verification": {
"trust_framework": "it_cie",
"assurance_level": "https://trust-anchor.example.it/loa/high"
},
"_sd_alg": "sha-256",
"cnf": {
"jwk": {
"kty": "EC",
"crv": "P-256",
"x": "TCAER19Zvu3OHF4j4W4vfSVoHIP1ILilDls7vCeGemc",
"y": "ZxjiWWbZMQGHVWKVQ4hbSIirsVfuecCE6t4jT9F2HZQ"
}
}
}
The disclosure list is presented below.
Claim given_name:
SHA-256 Hash:
Jkbj8aLr-z2_c-HVxCbiw6YXFNHiyLSv1xGjN8lRogIDisclosure:
WyJrZ2h0ZTVNRE5IYlFmZEpIcDg4cENBIiwgImdpdmVuX25hbWUiLCAiTWFyaW8iXQContents:
["kghte5MDNHbQfdJHp88pCA", "given_name", "Mario"]
Claim family_name:
SHA-256 Hash:
MWJufQz_DFWc9cR4yxq8XqmTZfglkg2D2Sxa3UFN4QkDisclosure:
WyJoWDFURXpfejg3N19YQXRyM0NPYVdnIiwgImZhbWlseV9uYW1lIiwgIlJvc3NpIl0Contents:
["hX1TEz_z877_XAtr3COaWg", "family_name", "Rossi"]
Claim birthdate:
SHA-256 Hash:
uIapUlDTKsB5wN7BF6xuBNTtl74gl5iCu_aQ5nj3YL8Disclosure:
WyJZV3RJMDZ4RGRDeXZUYWxjSW5URTNBIiwgImJpcnRoZGF0ZSIsICIxOTgwLTAxLTEwIl0Contents:
["YWtI06xDdCyvTalcInTE3A", "birthdate", "1980-01-10"]
Claim tax_id_code:
SHA-256 Hash:
_C7hoKFt0kV190v2GXIwLUIiDbc_7LcyofQmgDfute8Disclosure:
WyItejM0Y0oxZ0M1VUJQQ0l4OE9oTmlRIiwgInRheF9pZF9jb2RlIiwgIlRJTklULVhYWFhYWFhYWFhYWFhYWFgiXQContents:
["-z34cJ1gC5UBPCIx8OhNiQ", "tax_id_code","TINIT-XXXXXXXXXXXXXXXX"]
Claim place_of_birth:
SHA-256 Hash:
tI5s2A_Ez6oZv6plZzUPjYAL-SJGiAUFyRbhzLsluGUDisclosure:
WyJYY1hsUFZDcWpITnZlQkNubFZQWWdBIiwgInBsYWNlX29mX2JpcnRoIiwgeyJsb2NhbGl0eSI6ICJSb21hIn1dContents:
["XcXlPVCqjHNveBCnlVPYgA", "place_of_birth", {"locality":"Roma"}]
Claim nationalities:
SHA-256 Hash:
GHYjuGUthjtB4q4Oz_ZSGPmCokLOpv2kpFNzz1LfFUYDisclosure:
WyJLTmM1LUdrOUNRaF9UZEdicUJLSTdBIiwgIm5hdGlvbmFsaXRpZXMiLCBbIklUIl1dContents:
["KNc5-Gk9CQh_TdGbqBKI7A", "nationalities", ["IT"]]
The combined format for the IT-Wallet ID issuance is given by:
eyJhbGciOiAiRVMyNTYiLCAidHlwIjogImRjK3NkLWp3dCIsICJraWQiOiAiZEI2
N2dMN2NrM1RGaUlBZjdONl83U0h2cWswTURZTUVRY29HR2xrVUFBdyIsICJ4NWMi
OiBbIjxJc3N1ZXIgWC41MDkgQ2VydGlmaWNhdGU-Il19eyJfc2QiOlsiR0hZanVH
VXRoanRCNHE0T3pfWlNHUG1Db2tMT3B2MmtwRk56ejFMZkZVWSIsIkprYmo4YUxy
LXoyX2MtSFZ4Q2JpdzZZWEZOSGl5TFN2MXhHak44bFJvZ0kiLCJNV0p1ZlF6X0RG
V2M5Y1I0eXhxOFhxbVRaZmdsa2cyRDJTeGEzVUZONFFrIiwidEk1czJBX0V6Nm9a
djZwbFp6VVBqWUFMLVNKR2lBVUZ5UmJoekxzbHVHVSIsInVJYXBVbERUS3NCNXdO
N0JGNnh1Qk5UdGw3NGdsNWlDdV9hUTVuajNZTDgiLCJSNng5bzBqNG0zTDRQcTZ4
WWRLM3JQNG5OcTh2SjJiN3NGcVQ5Y1V3STdBIl0sImV4cCI6MTg4MzAwMDAwMCwi
aXNzIjoiaHR0cHM6Ly9waWRwcm92aWRlci5leGFtcGxlLm9yZyIsInN1YiI6Ik56
YkxzWGg4dURDY2Q3bm9XWEZaQWZIa3hac1JHQzlYcyIsImlhdCI6MTY4MzAwMDAw
MCwiaXNzdWluZ19hdXRob3JpdHkiOiJQSUQgUHJvdmlkZXIgT3JnYW5pemF0aW9u
IiwiaXNzdWluZ19jb3VudHJ5IjoiSVQiLCJkYXRlX29mX2V4cGlyeSI6IjIwMzMt
MDMtMTkiLCJzdGF0dXMiOnsic3RhdHVzX2xpc3QiOnsiaWR4IjoxMjM0LCJ1cmki
OiJodHRwczovL3BpZHByb3ZpZGVyLmV4YW1wbGUub3JnL3N0YXR1cyJ9fSwidmN0
IjoidXJuOmV1ZGk6cGlkOml0OjEiLCJ2Y3QjaW50ZWdyaXR5IjoiNTVmNWZlNTdm
MWU0OTFkNDlmMzM2NzI3ODQ1Mjg1MzJkOWQiLCJ2ZXJpZmljYXRpb24iOnsidHJ1
c3RfZnJhbWV3b3JrIjoiaXRfY2llIiwiYXNzdXJhbmNlX2xldmVsIjoiaHR0cHM6
Ly90cnVzdC1hbmNob3IuZXhhbXBsZS5pdC9sb2EvaGlnaCJ9LCJfc2RfYWxnIjoi
c2hhLTI1NiIsImNuZiI6eyJqd2siOnsia3R5IjoiRUMiLCJjcnYiOiJQLTI1NiIs
IngiOiJUQ0FFUjE5WnZ1M09IRjRqNFc0dmZTVm9ISVAxSUxpbERsczd2Q2VHZW1j
IiwieSI6Ilp4amlXV2JaTVFHSFZXS1ZRNGhiU0lpcnNWZnVlY0NFNnQ0alQ5RjJI
WlEifX19~WyJrZ2h0ZTVNRE5IYlFmZEpIcDg4cENBIiwgImdpdmVuX25hbWUiLCA
iTWFyaW8iXQ~WyJoWDFURXpfejg3N19YQXRyM0NPYVdnIiwgImZhbWlseV9uYW1l
IiwgIlJvc3NpIl0~WyJZV3RJMDZ4RGRDeXZUYWxjSW5URTNBIiwgImJpcnRoZGF0
ZSIsICIxOTgwLTAxLTEwIl0~WyJYY1hsUFZDcWpITnZlQkNubFZQWWdBIiwgInBs
YWNlX29mX2JpcnRoIiwgeyJsb2NhbGl0eSI6ICJSb21hIn1d~WyJLTmM1LUdrOUN
RaF9UZEdicUJLSTdBIiwgIm5hdGlvbmFsaXRpZXMiLCBbIklUIl1d~WyJRaDhMbU
40eFI3dlAyY0tqVDVzWllBIiwgInBpY3R1cmUiLCAiZGF0YTppbWFnZS9qcGVnO2
Jhc2U2NCwvOWovNEFBUVNrWkpSZ0FCQVFBQUFRQUJBQUQuLi4iXQ~