Read the interview with Nikos Fotiou and his winning proposal: Identity and Access Management for Immersive Ecosystems (IMMERSE)

Nikos Fotiou and ExcID

Nikos Fotiou is the CEO of ExcID. He holds a PhD in Computer Science from the Athens University of Economics and Business. Founded in 2023, ExcID develops authentication and authorisation solutions for business-to-business services and supply chain security. Its products focus on security, sovereignty, and interoperability. ExcID integrates emerging technologies and standards, such as Verifiable Credentials and Relationship-Based Access Control. Its solutions have been integrated into CI/CD pipelines, digital identity systems, data spaces, and Next Generation Internet architectures. ExcID is actively involved in EU-wide initiatives, contributing to the development of age verification systems and the implementation of the Cyber Resilience Act (CRA).

Can you give a brief overview of your winning proposal?
What are its key objectives and innovative aspects?

The IMMERSE project will integrate a cloud-based digital wallet into the SPIRIT platform to enable secure user authentication within immersive systems, with a particular focus on human-to-human, holographic-based communication. By supporting the issuance and presentation of Verifiable Credentials, IMMERSE will enable robust identity verification and authorisation within immersive environments. Aligned with initiatives like the European Digital Identity, which emphasise user sovereignty and privacy, the project will adopt emerging standards from the IETF and OpenID Foundation to deliver a secure, privacy-preserving, and interoperable solution. Key objectives include enabling real-time, privacy-aware authorisation; ensuring conformance with EU regulations and standards; maintaining compatibility with existing identity management frameworks; enhancing user-centric credential management; and implementing efficient credential revocation mechanisms. IMMERSE will offer a secure, resilient, and user-friendly alternative to mobile wallets, improving usability and resistance to system failures.

What motivated you to apply for the SPIRIT Open Call?

ExcID’s participation in the SPIRIT open call is driven by the opportunity to leverage SPIRIT’s confidential computing platform and to contribute to the development of an innovative, high-impact use case. SPIRIT’s platform offers strong potential to address the critical trust issues that currently limit the adoption of cloud-based digital wallets. Specifically, concerns over data confidentiality and control in traditional cloud environments are a major barrier for users and organisations. By integrating our cloud-based wallet solution with SPIRIT’s confidential computing capabilities, we aim to provide strong guarantees of data privacy and security, even in untrusted cloud infrastructures. Additionally, SPIRIT offers a unique opportunity to explore the emerging domain of immersive, holographic-based communication systems, which present new and complex challenges in user identification and authorisation. Through this collaboration, we expect to design and validate a secure, privacy-preserving authentication framework tailored to immersive environments, ultimately enhancing both usability and trust in next-generation communication technologies.

How do you envision this project making an impact?

Self-sovereign digital identification is an emerging concept gaining global momentum, aiming to give users greater control over their personal data. Most current initiatives rely heavily on mobile phones as digital wallets, but this approach introduces significant limitations—such as vulnerability to device loss or failure, reliance on mobile platform vendors, reduced usability in multi-device scenarios, and inherent security challenges in authentication flows initiated outside the mobile environment. Additionally, the restricted capabilities of mobile secure elements hinder the implementation of advanced privacy-preserving technologies, such as zero-knowledge proofs. The IMMERSE project envisions a transformative impact by providing a secure, cloud-based alternative that overcomes these limitations while preserving user sovereignty and privacy. By demonstrating our solution in an immersive, holographic communication context—a demanding and novel use case—we aim to validate its robustness, flexibility, and user-friendliness. This will pave the way for broader adoption of secure, interoperable, and user-centric identity solutions across future digital ecosystems.