Authentication and eID Services
Motivation
Authentication (including eID) constitutes the process of verifying a person’s identity to be authentic. In every system authentication is an essential mechanism ensuring that a user is the very person he claims to be. In the overall eGov-Bus scenario and during every life event process the authenticity of a user must be assured. The authentication service provides a means of authenticating a citizen using his or her national electronic identification (eID) scheme to the eGov-Bus portal. It therefore addresses following security requirements:
- eGov-Bus Portal wants User to be authenticated.
Authentication of a citizen’s eID is a necessity for most eGovernment services. On member state level various different eID authentication and identity management approaches exist. Since there exists a large variety of different national authentication methods, no identical authentication level can be assumed. Some member states use low level username/password authentication whereas other member states use strong authentication using qualified electronic signatures. The eGov-Bus authentication service deals with this problem by defining and communicating different authentication levels.
Description
Following an overview about the eGov-Bus authentication is presented. No citizen authentication at national or regional eGovernment services is performed; rather, the citizen is authenticated at the eGov-Bus portal using his or her accustomed national or regional eID technology.
Synthesizing, the main challenges resolved by the eGov-Bus authentication service are the
- Generalization of heterogeneous national and regional eID services
- Integration of different authentication levels
Due to the lack of a consistent European eID by now, no unique authentication mechanism is developed respectively used for entity authentication to the eGov-Bus portal. Instead, the eGov-Bus authentication service integrates different national eID solutions for authentication at the eGov-Bus portal. This approach enforces interoperability of heterogeneous national eID solutions. Examples for national authentication mechanisms are username/password schemes, PKI (certificate) based authentication or citizen card based authentication using qualified digital signatures.
Downloads
Please note the open source license terms.
| Title | Version | Date | |
|---|---|---|---|
| Specification |
1.0.2 | 2007-06-27 | |
| Documentation | 1.2.0 | 2008-04-10 | |
| Release | 1.2.0 | 2008-04-10 | |
| Files for Liferay integration and documentation | 1.0.0 | 2008-04-10 | |
| Source code | 1.1.0 | 2007-11-13 | |
History
| Bemerkung | Version | Datum |
|---|---|---|
| Documentation | 1.1.0 | 2007-11-13 |
| Release | 1.1.0 | 2007-11-13 |
| Specification (Specification of the authentication and eID services) |
1.0.0 |
2007-05-30 |
| Documentation | 1.0.0 | 2007-09-13 |
| Release | 1.0.0 | 2007-09-12 |
| Source code | 1.0.0 | 2007-09-12 |


