Skip to content

Implementation Profiles for the Trust Framework

Version 1.0

Version Date Description
0.1 2026-04-19 First release
0.2 2026-06-08 New section on Trust Management Process; editorial changes
1.0 2026-07-27 Added Onboarding Process and Trust Checks sections; expanded Trust Artifacts with Trust Anchor and Entity Sign/Seal Certificates subsections; integrated Register API OAS; structural and editorial changes

Authors:

  • Pasquale Cerqua, Istituto Poligrafico e Zecca dello Stato S.p.A.
  • Gianmario Cortese, Namirial S.p.A.
  • Henry Faure-Geors, Keynectis
  • Francesco Antonio Marino, Istituto Poligrafico e Zecca dello Stato S.p.A.
  • Andrea Moro, Fondazione Bruno Kessler
  • Marco Pernpruner, Fondazione Bruno Kessler
  • Nuno Ponte, Multicert
  • Andreea Prian, iDAKTO
  • Leone Riello, Infocert S.p.A.
  • Giada Sciarretta, Fondazione Bruno Kessler
  • Nikolaos Triantafyllou, University of the Aegean
  • Hoang Van Hoan, Keynectis
  • Maroš Zelenák, ARICOMA Digital S.R.O

Reviewers:

  • Dominik František Bučík, ARICOMA Digital S.R.O
  • Filippos Feizidis, GRNET
  • George Fourtounis, GRNET
  • Byron Georgantopoulos, GRNET
  • Guillaume Hébert, Keynectis
  • Angel Palomares Perez, Bull
  • Leonardo Pio Palumbo, Istituto Poligrafico e Zecca dello Stato S.p.A.
  • Michal Šťava, ARICOMA Digital S.R.O

Feedback:

Introduction

This specification, Implementation Profiles for the Trust Framework, defines the conceptual and architectural requirements for ensuring trust in the APTITUDE piloted environments. At this stage, the specification focuses on articulating the necessary trust architecture, defining the essential trust artifacts, and outlining the high-level evaluation processes. By setting these principles, this document serves as a shared reference to guide subsequent development, ensuring that all implementation efforts remain aligned with the project's objectives for security, privacy, and interoperability.


Scope

This specification defines the trust framework profiles for the APTITUDE Large Scale Pilot. Its scope is limited to establishing the essential mechanisms for trust in interactions between Wallet Units and Wallet-Relying Parties. The scope of this document is organized as follows:

Out of Scope

These specifications does not provide details on:

  • Low-level Implementation: These will be addressed in task T2.3.

  • Registration, Notification, and Publication Processes: The administrative and regulatory processes governing the Registration, Notification, and Publication of Trust Entities between Member States and the European Commission are excluded from this scope. However, the corresponding processes to be implemented in APTITUDE for piloting purposes are described in Onboarding Process.


Normative Language

The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here.