Authentication and security integration for ecampus services at the university of applied sciences harz using the German electronic identity card/eid and egovernment standards
نویسنده
چکیده
A eCampus security shell architecture was developed and deployed to improve the security of existing university management systems (legacy UMS), integrating innovative eGovernment Standards e.g. the German Electronic Identity Card (GeID), the eGovernment Protocol OSCI and qualified Signatures (QES). 1 Problem and requirements The challenge was to improve the security of an existing university management systems (legacy UMS/HIS), by satisfying of particular interoperability requirements (INTOP) and by integrating innovative eGovernment Standards e.g. the German Electronic Identity Card (GeID), the eGovernment Protocol OSCI [www.xoev.de] and qualified Signatures (QES). Especially, these security requirements should be satisfied: privacy and data protection, integrity, (multi factor) authentication. The additional INTOP requirements included particular boundary conditions and restrictions for the security implementations as follows: no changes of existing (legacy) UMS interfaces and GUI; no discrimination of applicants or students without GeID. 2 The eCampus security shell architecture To achieve the above requirements and conditions, the following eCampus security components must be integrated in an additional security shell for the legacy UMS (as a sort of "security satellite systems"): the eCampus registry to store/check additional security credentials for users (e.g. GeID Pseudonyms, QES certificates, OSCI certificates); the eCampus Server to host additional eCampus secured applications; the eCampus Mediator as a trusted Security Gateway between OSCI based secure communications (incl. signed data) and the legacy http based web interfaces of the
منابع مشابه
Electronic Identity Cards for User Authentication - Promise and Practice
Electronic identity (eID) cards promise to supply a universal, nation-wide mechanism for user authentication. Most European countries have started to deploy eID for government and private sector applications. Are government-issued electronic ID cards the proper way to authenticate users of online services? We use the German eID project as a showcase to discuss eID from an application perspectiv...
متن کاملSecure & privacy-preserving eID systems with Attribute-based credentials
National electronic identification (eID) systems aim to provide universal, unique and reliable identification and authentication mechanisms to the citizens. Many countries in Europe have already introduced or are about to introduce electronic ID cards to their citizens. The increasing number of eID infrastructures and initiatives have been taken to scale the eID systems to support both eGovernm...
متن کاملSecurity and Privacy Improvements for the Belgian eID Technology
The Belgian Electronic Identity Card enables Belgian citizens to prove their identity digitally and to sign electronic documents. At the end of 2009, every Belgian citizen older than 12 years will have such an eID card. In the future, usage of the eID card may be mandatory. However, irresponsible use of the card may cause harm to individuals. Currently, there exist some privacy and security pro...
متن کاملTowards a general purpose identity card
Many countries are currently designing or even rolling out electronic identity cards. Simultaneously, eID applications are developed. In many cases, the eID technology is initially integrated in governmental applications. Thereafter, the technology is adopted by other domains (i.e. the financial sector, eHealth services, social networking, corporate environments, ...). However, security, privac...
متن کاملIntegrating Anonymous Credentials with eIDs for Privacy-Respecting Online Authentication
Electronic Identity (eID) cards are rapidly emerging in Europe and are gaining user acceptance. As an authentication token, an eID card is a gateway to personal information and as such it is subject to privacy risks. Several European countries have taken extra care to protect their citizens against these risks. A notable example is the German eID card, which we take as a case study in this pape...
متن کامل