【24h】

Middleware architecture for cross-border eID

机译:跨境eID的中间件架构

获取原文
获取原文并翻译 | 示例

摘要

Many European states have issued electronic identities (eID) to its citizens since the early 2000s. Several have reached full coverage and usually high assurance credentials, such as smartcards, USB crypto tokens, or mobile phone eIDs are used. This lead to an impressive security infrastructure to authenticate at online services that, however, evolved as national silos — interoperability was no priority for a while. To overcome this, 18 European states have joined forces in the large scale pilot STORK. A SAML-based technical solution for cross-border eID federation between states has been designed, implemented, and finally piloted in a number of production services. In this paper we present the STORK middleware architecture that has been developed by Austria and Germany. Its main characteristic is a decentralized deployment that gives some end-to-end security and privacy advantages, but also needs particular attention to meet scalability challenges. This is compared to the STORK proxy model, an alternative centralized deployment approach that was chosen by other states. Federation between the two architectures is described, with particular attention to security and privacy aspects.
机译:自2000年代初以来,许多欧洲国家已经向其公民发布了电子身份(eID)。其中一些已经达到了全面覆盖,通常使用高保证凭证,例如智能卡,USB加密令牌或手机eID。这导致了一个令人印象深刻的安全基础结构,可以在在线服务上进行身份验证,但是随着国家孤岛的发展,互操作性在一段时间内没有被优先考虑。为了克服这个问题,欧洲的18个国家共同参与了大规模的STORK试点。已经设计,实施了基于SAML的跨州eID联邦技术解决方案,并最终在许多生产服务中进行了试验。在本文中,我们介绍了由奥地利和德国开发的STORK中间件体系结构。它的主要特征是分散式部署,它具有一些端到端的安全性和隐私优势,但还需要特别注意以应对可伸缩性挑战。将此与STORK代理模型进行了比较,后者是其他州选择的替代集中式部署方法。描述了两种体系结构之间的联合,特别注意安全性和隐私性方面。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号