227 research outputs found
Is Europe ready to provide a pan-European Identity Management System?
European public administrations must manage citizens' digital identities, particularly considering interoperability among different countries. Owing to the diversity of electronic identity management (eIDM) systems, when users of one such system seek to communicate with governments using a different system, both systems must be linked and understand each other. To achieve this, the European Union is working on an interoperability framework. This article provides an overview of eIDM systems' current state at a pan-European level. It identifies and analyzes issues on which agreement exists, as well as those that aren't yet resolved and are preventing the adoption of a large-scale model
Identidade digital federada globaliD
Mestrado em Engenharia de Computadores e TelemáticaO presente texto propõe uma solução para a gestão de identidade digital
online tendo em conta a versatilidade, o anonimato, a privacidade, a
veracidade, a credibilidade e a responsabilidade do utilizador, recorrendo para
isso ao uso do Cartão de Cidadão Electrónico Nacional Português e a outros
meios de autenticação públicos usados diariamente pelos utilizadores. A
dissertação é composta pela apresentação do conceito de identidade e das
suas particularidades, por uma análise aos vários problemas da gestão da
informação pessoal online, uma análise aos vários modelos, mecanismos e
especificações existentes para gerir a identidade digital online (gestão de
identidade digital). Uma solução de gestão de identidade digital baseada no
modelo de identidade federada e associada ao Cartão do Cidadão Electrónico
Nacional Português é apresentada, descrita, analisada, avaliada e comparada
com outras soluções existentes.
Por fim um protótipo de um provedor de identidades digitais federadas
baseado na solução de gestão de identidade digital proposta é apresentado.The following text provides a solution for the digital identity management on the
Web regarding the users’ versatility, anonymity, privacy, veracity,
trustworthiness and accountability by using the Portuguese National Electronic
Citizen Identity Card and other publicly available authentication mechanisms
users use daily. The dissertation consists of the presentation of the concept of
identity and its particularities, an analysis to the several problems of managing
personal information online, and an analysis to the several existing models,
mechanisms and specifications for the management of the digital identity online
(digital identity management). A solution for digital identity management based
on the federated identity model and associated to the Portuguese National
Electronic Citizen Identity Card is introduced, described, analyzed, evaluated
and compared to other several existing solutions. Last, a prototype of a
federated digital identity provider based on the purposed solution for digital
identity management is presented
Tutorial: Identity Management Systems and Secured Access Control
Identity Management has been a serious problem since the establishment of the Internet. Yet little progress has been made toward an acceptable solution. Early Identity Management Systems (IdMS) were designed to control access to resources and match capabilities with people in well-defined situations, Today’s computing environment involves a variety of user and machine centric forms of digital identities and fuzzy organizational boundaries. With the advent of inter-organizational systems, social networks, e-commerce, m-commerce, service oriented computing, and automated agents, the characteristics of IdMS face a large number of technical and social challenges. The first part of the tutorial describes the history and conceptualization of IdMS, current trends and proposed paradigms, identity lifecycle, implementation challenges and social issues. The second part addresses standards, industry initia-tives, and vendor solutions. We conclude that there is disconnect between the need for a universal, seamless, trans-parent IdMS and current proposed standards and vendor solutions
Federated identity architecture of the european eID system
Federated identity management is a method that facilitates management of identity processes and policies among the collaborating entities without a centralized control. Nowadays, there are many federated identity solutions, however, most of them covers different aspects of the identification problem, solving in some cases specific problems. Thus, none of these initiatives has consolidated as a unique solution and surely it will remain like that in a near future. To assist users choosing a possible solution, we analyze different federated identify approaches, showing main features, and making a comparative study among them. The former problem is even worst when multiple organizations or countries already have legacy eID systems, as it is the case of Europe. In this paper, we also present the European eID solution, a purely federated identity system that aims to serve almost 500 million people and that could be extended in midterm also to eID companies. The system is now being deployed at the EU level and we present the basic architecture and evaluate its performance and scalability, showing that the solution is feasible from the point of view of performance while keeping security constrains in mind. The results show a good performance of the solution in local, organizational, and remote environments
A User-Centric Identity Management Framework based on the W3C Verifiable Credentials and the FIDO Universal Authentication Framework
We present a user-centric and decentralized digital identity system that allows anyone to easily benefit from an enriched digital identity made of multi-purpose and multi-origin attributes. It increases usability by the elimination of user passwords. It also makes this digital identity highly trustworthy both for the user (in terms of privacy and sovereignty) and the service provider who requires highly certified information about the user being enrolled to and/or authenticated on its services. We built our system based on the Universal Authentication Framework specified by the FIDO Alliance and the data model proposed by the W3C Verifiable Credentials WG. The whole system has been implemented in a banking scenario
Recommended from our members
Digital Identity Interoperability and eInnovation
This paper, one of three case studies in a transatlantic research project exploring the connection between Information and Communication Technology interoperability and eInnovation, considers the current state and possible evolution of Digital Identity. While consumers would undoubtedly reap convenience benefits from an ubiquitous single sign-on (SSO) technology, the potential for privacy and security issues makes Digital ID a complex issue. The user-centric, federated, and centralized models of Digital ID each have their advantages and drawbacks. While a few companies have previously attempted to establish a single Digital ID standard that they would control, the failure of those efforts has led to a situation where most players in the industry seem to see interoperability as essential to build up the market in the face of frequent ambivalence from consumers, e-commerce merchants, and other potential users.
Broadly, Digital ID could enable a wide range of new Web-based applications, increasing consumers' flexibility and reducing transactions costs. However, having Digital ID be too ubiquitous could threaten the continued viability of anonymous speech in some contexts. It could also lead to more entities having greater access to personal data of consumers, raising the stakes of potential data breaches.
The paper concludes that the route to interoperability most likely to lead to innovation would include continued collaboration among industry players to settle on one or a few consolidated efforts. Except in special areas, governments can best play a peripheral role, encouraging coordination through soft regulatory approaches like bringing stakeholders together and using their market power as major data holders and users. If privacy and security issues are addressed (and current stakeholders seem acutely aware of them), Digital ID interoperability has the potential to be extremely generative, creating new markets and enabling interoperability among other applications and services. If, however, coordination breaks down among market leaders and rival technologies emerge, it seems likely that user adoption will remain low and the benefits will be limited
Service-oriented models for audiovisual content storage
What are the important topics to understand if involved with storage services to hold digital audiovisual content? This report takes a look at how content is created and moves into and out of storage; the storage service value networks and architectures found now and expected in the future; what sort of data transfer is expected to and from an audiovisual archive; what transfer protocols to use; and a summary of security and interface issues
Improvements of Pan-European IDM Architecture to Enable Identity Delegation Based on X.509 Proxy Certificates and SAML
To foster the secure use of telematic services provided by public institutions, most European countries – and others in the rest of the world – are promoting electronic identification systems among their citizens to enable fully reliable identification. However, in today’s globalized environment, it is becoming more common for citizens and entities of a given country, with their own electronic credentials under the legal framework of their country, to seek access to the public services provided by other countries with different legal frameworks and credentials. At present, a number of projects in the European Union are attempting to solve the problem through the use of pan-European identity management systems that ensure interoperability between the public institutions of different Member States. However, the solutions adopted to date are inadequate, for they do not envision all possible cases of user interaction with institutions. Specifically, they fail to address a very important aspect provided in different national legal systems, namely delegation of identity, by which a citizen can authorize another to act on his or her behalf in accessing certain services provided by public institutions. This paper provides a thorough analysis of problems of delegation and proposes an architecture based on X.509 Proxy Certificates and SAML assertions to enable delegation in provision of services in the complex and heterogeneous environment presented by the public institutions of the European Union as a whole
- …