...
首页> 外文期刊>Information Security Technical Report >The Austrian eID ecosystem in the public cloud: How to obtain privacy while preserving practicality
【24h】

The Austrian eID ecosystem in the public cloud: How to obtain privacy while preserving practicality

机译:公用云中的奥地利eID生态系统:如何在保持实用性的同时获取隐私

获取原文
获取原文并翻译 | 示例
           

摘要

The Austrian eID system constitutes a main pillar within the Austrian e-Government strategy. The eID system ensures unique identification and secure authentication for citizens protecting access to applications where sensitive and personal data are involved. In particular, the Austrian eID system supports three main use cases: identification and authentication of Austrian citizens, electronic representation, and foreign citizen authentication at Austrian public sector applications. For supporting all these use cases, several components - either locally deployed in the applications' domain or centrally deployed - need to communicate with each other. While local deployments have some advantages in terms of scalability, still a central deployment of all involved components would be advantageous, e.g., due to less maintenance efforts. However, a central deployment can easily lead to load bottlenecks because theoretically the whole Austrian population as well as -for foreign citizens - the whole EU population could use the provided services. To mitigate the issue on scalability, in this paper we propose the migration of the main components of the ecosystem into a public cloud. However, a move of trusted services into a public cloud brings up new obstacles, particularly with respect to privacy. To bypass the issue on privacy, in this paper we propose an approach on how the complete Austrian eID ecosystem can be moved into a public cloud in a privacy-preserving manner by applying selected cryptographic technologies (in particular using proxy re-encryption and redactable signatures). Applying this approach, no sensitive data will be disclosed to a public cloud provider by still supporting all three main eID system use cases. We finally discuss our approach based on selected criteria.
机译:奥地利的eID系统是奥地利电子政务战略中的主要支柱。 eID系统可确保公民的唯一标识和安全身份验证,从而保护对涉及敏感和个人数据的应用程序的访问。尤其是,奥地利的eID系统支持三个主要用例:奥地利公民的身份和认证,电子代表以及奥地利公共部门应用程序中的外国公民认证。为了支持所有这些用例,需要在应用程序域中本地部署或集中部署的几个组件相互通信。尽管本地部署在可伸缩性方面具有一些优势,但是例如由于较少的维护工作,所有相关组件的集中部署仍然是有利的。但是,集中部署很容易导致负载瓶颈,因为理论上整个奥地利人口以及-对于外国公民-整个欧盟人口都可以使用所提供的服务。为了缓解可扩展性问题,在本文中,我们建议将生态系统的主要组件迁移到公共云中。但是,将可信服务迁移到公共云中会带来新的障碍,尤其是在隐私方面。为了绕开隐私问题,在本文中,我们提出了一种方法,该方法如何通过应用选定的加密技术(特别是使用代理重新加密和可编辑签名)以保护隐私的方式将完整的奥地利eID生态系统移入公共云)。应用此方法,仍然通过支持所有三个主要eID系统用例,不会将任何敏感数据透露给公共云提供商。最后,我们根据选定的标准讨论我们的方法。

著录项

相似文献

  • 外文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号