← Latest papers
💻 computer science

OpenID for European Digital Identity: An architectural analysis of user-centric identity management

This paper critiques the current EUDI and OpenID4VCI/VP frameworks for relying on an outdated, document-centric concept of identity and introducing risky centralized trust mechanisms, arguing instead for a deeper definition of identity and technical alternatives that better support genuine self-sovereign and user-centric identity management.

Original authors: Wouter Termont, Beatriz Esteves

Published 2026-03-24
📖 6 min read🧠 Deep dive

Original authors: Wouter Termont, Beatriz Esteves

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

Imagine the European Union is trying to build a Master Key for the digital world. This "Master Key" (called the European Digital Identity or EUDI) is supposed to let every citizen walk into any shop, bank, or government office across Europe without carrying a physical wallet, proving who they are instantly and securely.

The architects of this system chose a specific blueprint called OpenID. They promised this new system would be a revolution: giving you total control over your data, keeping your secrets private, and letting you carry your identity anywhere (portability).

However, this paper argues that the blueprint they chose is flawed. It's like trying to build a futuristic, self-driving car using the engine and chassis of a 1990s sedan. The result is a system that is clunky, limited, and actually makes you less safe and less in control than you think.

Here is the breakdown of the paper's arguments, using simple analogies:

1. The "Identity" Confusion (The Definition Problem)

The Problem: The people writing the laws and the tech specs never actually agreed on what "Identity" means.
The Analogy: Imagine a chef trying to bake a "Perfect Cake" but never defining what a cake is. Is it a sponge? A pie? A brownie? Because they didn't define it, they ended up baking only one very specific type of cake (a standard vanilla cupcake) and calling it "The Cake."
The Reality: The system only understands "Identity" as a static list of facts (like a digital ID card). It doesn't understand that your identity changes depending on the situation (e.g., you are a "parent" at school, a "customer" at a store, or a "driver" on the road). The system is too rigid to handle these different roles.

2. The "Wallet" Trap (Technical Limitations)

The system relies on a "Digital Wallet" app where you store your credentials. The paper argues this wallet is actually a straitjacket, not a superpower.

  • The "Menu" Problem: In a good system, you should be able to ask for any proof you need. In this system, the Issuer (the government or bank) gives you a pre-printed "Menu" of options. You can only pick what's on the menu. You can't ask for a custom combination of facts.
    • Analogy: Imagine going to a restaurant where the waiter says, "We only serve three fixed meals. You can't mix and match ingredients, and you can't ask for a custom dish."
  • The "Language" Barrier: To ask for information, the system uses a weird, custom language that only works with specific formats. It's like trying to order food using a secret code that only the chef understands, rather than just speaking normally.
  • The "Human" Bottleneck: The system requires you to be awake and clicking "Yes" for every single transaction. It can't automate things.
    • Analogy: Imagine buying a coffee where the barista has to call your boss to ask for permission every time you want a latte. It kills efficiency.

3. The "Privacy" Illusion

The system promises you will have more privacy because your data stays in your wallet, not on the government's server. The paper says this is a magic trick.

  • The Middleman Shift: In the old system, the Government (Issuer) knew you were buying coffee at the Shop (Verifier). In the new system, the Government doesn't know, but now the Wallet App knows everything.
    • Analogy: It's like moving your diary from your bedroom (Government) to a friend's house (The Wallet App). You think you're safer, but you've just swapped one person who can read your diary for another.
  • The "One-Time" Rule: To be truly private, the system tells you to throw away your digital ID after every use and get a new one. This is annoying, hard to manage, and doesn't actually stop the system from tracking you if you aren't careful.

4. The "Gatekeeper" Problem (The Politics)

This is the most dangerous part. To get a digital ID, you must be on a "Trusted List" maintained by the government. Only companies and banks approved by the government can issue these IDs.

  • The Club Membership: Imagine a giant club where only members of the "Approved List" can enter. If you are a small startup or a new innovator, you can't join unless the government says so.
  • The Risk: This creates a monopoly. Big, rich companies get in; small players get locked out.
  • The Surveillance Risk: Because the government controls the list, they can also control who gets to see your data. The paper warns this could lead to a system where the government can monitor what you do, who you talk to, and what you buy, under the guise of "security."
    • Analogy: It's like the government handing out keys to your house, but keeping a master list of every time you open the door and who you let in. They claim it's for safety, but it feels like a surveillance state.

5. The Solution: "Open the Door"

The authors suggest we don't need to reinvent the wheel. We already have better tools.

  • Use the "Universal Remote": Instead of building a new, clunky remote (OpenID), we should use the existing, flexible universal remote (OAuth and other open standards) that already works with every device.
  • Let Users Drive: Instead of a system where the government dictates the rules, we need a system where you (the user) can choose who you trust, just like you choose which apps to install on your phone today.
  • Stop the "Trusted List": We need to remove the government's power to act as the sole gatekeeper. If we let the market and open standards decide who is trustworthy, we get more innovation and less risk of abuse.

The Bottom Line

The European Digital Identity is trying to solve a big problem, but it's using a small, outdated toolbox.

  • It promises you freedom but gives you a leash.
  • It promises privacy but creates a new spy (the wallet provider).
  • It promises innovation but builds walls around who can participate.

The paper concludes that unless the rules change to remove the government's "gatekeeper" power and the technical specs are updated to be more flexible, this new system will fail to protect us and might actually make our digital lives more restricted and monitored.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →