Use when implementing transaction logging in the Wallet Unit. Covers log content, retention, access control, and privacy requirements for wallet transaction records. Part 2: covers 4.7 Topic 30 - Interaction between Wallet Units, 4.8 Topic 40 - Wallet Instance installation and Wallet Unit activation and management, 5 Relation to Other Topics ....
| Index | Requirement specification | Proposal |
|---|---|---|
| W2W_08 | Wallet Providers SHALL ensure that a Wallet Unit provides a log of transactions related to Wallet-to-Wallet transactions, allowing the User to view the history of the presentation requests and responses (sent or received respectively, depending on the role of a Wallet Unit in a transaction). | New requirement |
| Index | Requirement specification | Proposal |
|---|---|---|
| WIAM_12a | The Wallet Unit SHALL ensure that the Wallet Provider cannot access the contents of the Wallet Unit, in particular to learn a) which attestations are present on the Wallet Unit, b) the status of these attestations, c) the value of attributes in these attestations, and d) the contents of the Wallet Unit log meant in DASH_02. |
| New requirement |
This topic is related to Topic N - Export and Data Portability. Some further changes to DASH_02 have been proposed, on top of the proposal resulting from the discussion on Topic N. The final wording of the DASH_02 will be thus as proposed in this paper.
Other changes to HLRs related to transaction logs topic proposed in the Topic N Discussion Paper, are valid and remain unchanged.
The risk register for European Digital Identity Wallets [RiskRegister] contains the following risks that are related to the Relying Party registration:
| Risk type | Risk id | Related risk titles |
|---|
More specifically, [RiskRegister] describes the following threats to a Wallet:
| ID | Threat description | Related risks |
|---|
See sections 4 and 5 above. In addition, transactional data related aspects in the main text of the ARF will be updated accordingly.