Orange EUDIW Security Architecture and Rapid Compliance

Author
Regulations

eIDAS 2.0

The European Digital Identity Wallet (EUDIW) is a major initiative under eIDAS 2.0, requiring EU Member States to give citizens, residents, and businesses a secure, interoperable way to store and share digital identity credentials across Europe. Because it handles sensitive identity credentials and must support trusted authentication and transactions, it demands a high level of assurance — aligned with eIDAS Level High. For Orange France, the EUDIW was both a compliance obligation and a market opportunity: the solution had to meet strict security expectations while staying scalable, operationally realistic, and deployable within a tight timeframe.

Client / Project Need

Objectives & drivers

Orange France needed to design a secure, compliant EUDIW solution — fast. The real question was architectural: which design could satisfy eIDAS Level High, deliver the required security assurance, and still hit the time-to-market window, all while remaining compatible with Orange’s existing infrastructure and operations. The key technical components in play were Secure Application Modules, Certificate Service Provider functions, and Hardware Security Modules.

Challenge

Key hurdles

The core challenge was finding the fastest credible path to eIDAS Level High. Orange faced a genuine architectural fork: build a new solution around eUICC SAM / CSP components, or reuse Orange’s existing telecom-certified HSM infrastructure. Choosing well required a system-wide security analysis across the mobile application, the HSM, and the backend cloud, with each component assessed against its role in the overall trust chain. And the decision couldn’t be judged on technical merit alone — the chosen approach had to be credible to ENISA, BSI, and the European regulatory stakeholders shaping the EUDIW certification framework. Regulatory acceptance was as much the deliverable as the architecture.

Approach

What we did

01

Assessed both architecture options, analysing each one’s impact on security, certification, and deployment timeline.

02

Ran a system-wide security analysis across the Orange mobile application, HSM, and backend cloud — identifying threats, vulnerabilities, and assurance expectations for each component.

03

Defined the required security level for each part of the architecture and mapped it to the certification paths that support eIDAS Level High.

04

Set the concrete certification targets: CSPN for the mobile application, Common Criteria EAL5+ for the HSM, and Protection Profiles to standardise the security and certification criteria.

05

Engaged directly with ENISA, BSI, and European regulatory bodies to build recognition of telecom-certified HSM infrastructure as a legitimate, immediately deployable solution.

Key outcomes

Impact delivered

Lessons learned

What we took away

High-assurance digital identity systems aren’t won on technical controls alone — they’re won on an architecture that can be justified, certified, and accepted by the regulatory ecosystem around them. The sharper lesson from Orange: existing certified infrastructure can be a faster and more robust route to compliance than building a new stack from scratch — but only when the security argument is clear, evidence-based, and accepted by the regulators who decide. The engineering choice and the regulatory-acceptance strategy have to be made together, not in sequence.

Related materials

Keep exploring

ODSI: A Building-Block Approach to Secure Isolation

Read case study →

2IdO: Securing the Industrial Internet of Things

Read case study →

SECREDAS

SECREDAS: Building Trustworthy Automated Systems Across Critical Industries

Read case study →

Contact us

Request this document

We’ll send you access by email.