Wallet secure cryptographic applications
Article 5
1. Wallet providers shall ensure that wallet secure cryptographic applications: (a) perform wallet cryptographic operations involving critical assets other than those needed for the wallet unit to authenticate the wallet user only in cases where those applications have successfully authenticated wallet users; (b) where they authenticate wallet users in the context of performing electronic identification at assurance level high; perform authentication of wallet users, in accordance with, the requirements for the characteristics and design of electronic identification means at assurance level high, as set out in Implementing Regulation (EU) 2015/1502; (c) are able to securely generate new cryptographic keys; (d) are able to perform secure erasure of critical assets; (e) are able to generate a proof of possession of private keys; (f) protect the private keys generated by those wallet secure cryptographic applications during the existence of the keys; (g) comply with the requirements for the characteristics and design of electronic identification means at assurance level high, as set out in Implementing Regulation (EU) 2015/1502; (h) are the only components able to execute wallet cryptographic operations and any other operation with critical assets in the context of performing electronic identification at assurance level high. 2. Where wallet providers decide to provide a wallet secure cryptographic application to an embedded secure element these wallet providers shall base their technical solution on the technical specifications listed in Annex I or on other equivalent technical specifications.