FB pixel

Nein telefon heim: Germany aims to quell fears about server retrieval in EUDI wallet

Government says program is committed to device retrieval that doesn’t ‘phone home’ 
Nein telefon heim: Germany aims to quell fears about server retrieval in EUDI wallet
 

The “phone home” debate over digital identity systems that could use server retrieval continues, as Germany’s government faces questions about data protection and traceability in its European Digital Identity (EUDI)-compliant digital wallet.

A report from Heise says that civil rights organizations such as the American Civil Liberties Union (ACLU), the Center for Democracy and Technology (CDT), the Electronic Frontier Foundation (EFF), the Electronic Privacy Information Center (EPIC) and Epicenter.works have expressed concern that issuing authorities for digital IDs such as mobile drivers licenses (mDL) could have the ability to track their use through so-called phone home models.

In server retrieval, when a request is made, an access token ends up going back to the issuing authority infrastructure to retrieve data. In a recent webinar from Dock Labs, Andrew Hughes, VP of global standards for FaceTec, explains that, at a very high level, server retrieval is exactly what it sounds like: “simply online data retrieval from an internet server.”

But allowing relying parties to “call back” to issuing parties means those issuing parties now know where the ID is being used – opening up the capability for a sort of soft surveillance.

The worries have kicked off a campaign, No Phone Home, which aims to sound the alarm that mDLs can comply with the international standard and still represent a major surveillance risk.

A specific concern of critics is that the ISO/IEC mDL/mDOC 18013-5 standard, which “virtually pre-installs such a server retrieval option,” is “prescribed in the reference architecture for the EUDI wallet and is also widely used in North America.” They don’t want supposed flaws with international standards baked into European systems.

The German government, meanwhile, insists that its system does not phone home. According to the lead digital ministry, “the wallet planned in Germany for the EUDI will only use direct communication between the corresponding app and the receiving verifier.”

In this – the device retrieval model – the relying party requests specific claims or attributes directly from an app on a mobile device, and the app provides whatever data the user chooses to share.

“The German wallet is designed in such a way that signed data is used, the government assures,” says the report. “This means that the issuing authority is not involved in the ID card process. This principle of data sovereignty and purpose limitation is guaranteed by a targeted technical architecture, open standards and comprehensive data protection regulations. This ensures that the movements and activities of users cannot be tracked or disclosed by the issuing authority.”

Related Posts

Article Topics

 |   |   |   |   |   |   | 

Latest Biometrics News

 

Texas on the sidelines as digital driver’s licenses expand nationwide

Texas is emerging as one of the major holdouts in the national shift toward digital identification even as Apple expands…

 

DoD expands research on biometric enabled hearing protection systems

The Department of Defense (DoD) has received a $7.5 million program increase in the Fiscal Year 2026 defense appropriations bill…

 

Veridos and OSD awarded for biometric passport work, KOMSCO finds profits in digital ID

In South Korea, KOMSCO has reinvented itself, moving to find new profitability in mobile IDs. In Georgia, a unified ePassport…

 

Sphinx raises $7.1m to expand AI-powered compliance agents

Identity checks were once reliant on human eyes and human discernment, but making sure people and entities are who they…

 

Identity fraud revs up in the automotive sector as purchases move online

Like most industries, the automotive sector is dealing with a spike in fraud. A survey snapshot released by identity provider…

 

DHS RIVR results suggest most ID document validation disastrously ineffective

The results of the identity document validation track within the 2025 Remote Identity Validation Rally are sobering. They indicate that…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events