EUID Wallets Certification

Sławomir Górniak
Senior Security Expert
Market, Certification and Standardisation Unit
26
04
2023
EUID WALLETS CERTIFICATION
undefined
EU LEGISLATION – CYBERSECURITY LANDSCAPE
EUID Wallets certification
undefined
A
 
E
u
r
o
p
e
a
n
 
D
i
g
i
t
a
l
 
I
d
e
n
t
i
t
y
 
W
a
l
l
e
t
 
F
r
a
m
e
w
o
r
k
T
h
e
 
R
e
c
o
m
m
e
n
d
a
t
i
o
n
 
f
o
r
 
a
n
 
E
U
 
T
o
o
l
b
o
x
 
f
o
r
 
a
 
c
o
o
r
d
i
n
a
t
e
d
 
a
p
p
r
o
a
c
h
 
t
o
w
a
r
d
s
 
a
 
E
u
r
o
p
e
a
n
D
i
g
i
t
a
l
 
I
d
e
n
t
i
t
y
 
F
r
a
m
e
w
o
r
k
C
e
r
t
i
f
i
c
a
t
i
o
n
 
o
f
 
E
u
r
o
p
e
a
n
 
D
i
g
i
t
a
l
 
I
d
e
n
t
i
t
y
 
W
a
l
l
e
t
s
 
(
a
r
t
.
 
6
)
 
a
n
d
 
o
f
 
e
l
e
c
t
r
o
n
i
c
 
i
d
e
n
t
i
f
i
c
a
t
i
o
n
s
c
h
e
m
e
s
 
(
a
r
t
.
 
1
2
)
 
u
n
d
e
r
 
t
h
e
 
C
S
A
H
a
r
m
o
n
i
s
e
d
 
a
p
p
r
o
a
c
h
 
t
o
 
t
r
u
s
t
,
 
s
e
c
u
r
i
t
y
 
a
n
d
 
i
n
t
e
r
o
p
e
r
a
b
i
l
i
t
y
 
t
h
r
o
u
g
h
 
s
t
a
n
d
a
r
d
s
 
(
m
u
l
t
i
p
l
e
a
r
t
i
c
l
e
s
)
T
h
r
e
e
 
n
e
w
 
q
u
a
l
i
f
i
e
d
 
t
r
u
s
t
 
s
e
r
v
i
c
e
s
 
(
p
r
o
v
i
s
i
o
n
 
o
f
 
e
l
e
c
t
r
o
n
i
c
 
a
r
c
h
i
v
i
n
g
 
s
e
r
v
i
c
e
s
,
 
e
l
e
c
t
r
o
n
i
c
l
e
d
g
e
r
s
 
a
n
d
 
m
a
n
a
g
e
m
e
n
t
 
o
f
 
r
e
m
o
t
e
 
e
l
e
c
t
r
o
n
i
c
 
s
i
g
n
a
t
u
r
e
 
a
n
d
 
s
e
a
l
 
c
r
e
a
t
i
o
n
 
d
e
v
i
c
e
s
)
A
l
i
g
n
m
e
n
t
 
o
f
 
t
h
e
 
T
r
u
s
t
 
S
e
r
v
i
c
e
 
p
r
o
v
i
s
i
o
n
s
 
w
i
t
h
 
t
h
e
 
r
u
l
e
s
 
a
p
p
l
i
c
a
b
l
e
 
t
o
 
N
I
S
D
v
2
 
(
a
r
t
i
c
l
e
s
 
1
7
,
 
1
8
,
2
0
,
 
2
1
 
a
n
d
 
2
4
)
.
EIDAS REGULATION V2 – UPDATES
EUID Wallets certification
undefined
EUDI Wallet – electronic identification means at assurance level “high” under eIDAS
Recommendation on Member States to work on:
Toolbox including a technical Architecture and Reference Framework
S
et of common standards and technical specifications
S
et of common guidelines and best practices for the implementation of the EUDI framework
Conformity of EUDI Wallets with technical and operational specifications and reference standards
established by means of implementing acts, shall be certified
Certification of the EUDI Wallets will ensure security, trust and robustness
EU-wide certification scheme will bring harmonization and interoperability
Certification should rely as much as possible on the available CSA schemes
I
n practice starting with the EUCC
Supplement the EUCC scheme with additional specifications, procedures and reference standards by
means of adoption of eIDAS implementing acts
Develop protection profiles leveraging on relevant parts of the EU5G and EUCS to support EUDI Wallets
EUDI WALLET FRAMEWORK – PROPOSAL
EUID Wallets certification
undefined
The Common Union Toolbox for a Coordinated Approach Towards a European Digital
Identity Framework
The European Digital Identity Wallet Architecture and Reference Framework
 v1.1.0 –
April 2023
Goal: 
to provide 
spec
ifications to develop an interoperable EUDI Wallet 
s
olution
,
based on common standards and practices
Defines 
European Digital Identity Wallet Ecosystem
Represents 
state-of-play of ongoing work of the eIDAS Expert Group
In the future, 
will be aligned to the outcome of the legislative negotiations of the
proposal for a European Digital Identity Framework
ARCHITECTURE AND REFERENCE FRAMEWORK
EUID Wallets certification
undefined
ARF – 
EUDI 
WALLET ECOSYSTEM
EUID Wallets certification
undefined
R
e
q
u
e
s
t
 
f
o
r
 
t
e
c
h
n
i
c
a
l
 
s
u
p
p
o
r
t
 
f
r
o
m
 
E
N
I
S
A
 
t
o
 
d
e
v
e
l
o
p
 
a
 
c
y
b
e
r
s
e
c
u
r
i
t
y
 
c
e
r
t
i
f
i
c
a
t
i
o
n
s
c
h
e
m
e
 
f
o
r
 
t
h
e
 
E
u
r
o
p
e
a
n
 
D
i
g
i
t
a
l
 
I
d
e
n
t
i
t
y
 
W
a
l
l
e
t
 
Indicate which CSA schemes (EUCC, EU5G, EUCS) can be used for certification
(Protection Profiles, security requirements, evaluation methodologies, etc.).
Gap analysis and proposal of possible solutions if no scheme parts exist
Analysis of the current state of play of European market
Gap analysis for interoperability and functional testing requirements and evaluation
methodology for non-cybersecurity relevant aspects of EUDI Wallets
Collaborate with Member States, SDOs and the Commission to design functional and
interoperability test suites for the EUDI Wallets certification
EUDI WALLET FRAMEWORK – REQUEST
EUID Wallets certification
undefined
EUDI WALLET FORMS AND SECURITY
TECHNOLOGIES
EUID Wallets certification
undefined
Software
Interfaces
Primary 
h
ardware
Secure element (secure
cryptographic material storage)
Secondary hardware
Services
Onboarding of a user
Issuance of the EUDI Wallet
Authentication of the user
Display of the “EU Digital Identity Wallet
Trust Mark”
Request of person identification data
(PID)
EUDI
 
W
ALLET
 COMPONENTS
EUID Wallets certification
Issuance of a PID
Request for a (qualified) electronic
attestation of attribute
Request for a (qualified) electronic
certificate
Storage of PID and/or (Q)EAAs
Deletion PID and/or (Q)EAAs
Validation of a request from a relying
party
Presentation of PID or (Q)EAAs to a
relying party
Electronic identification (authentication)
of an EUDI Wallet user
Enabling the user to sign
Enabling the user to seal
undefined
E
N
I
S
A
 
s
t
u
d
y
 
2
0
2
2
 
 
m
a
j
o
r
 
g
a
p
s
 
i
n
 
s
t
a
n
d
a
r
d
i
s
a
t
i
o
n
 
o
f
 
E
U
D
I
 
W
a
l
l
e
t
 
No standards for the cryptographic device interface (direct interface of the cryptographic
component of the mobile device;
Functional testing requirements missing for elements of the EUDI Wallet except:
PID/(Q)EAA mutual authentication protocols,
qualified electronic signatures
No standards fulfilling the EUDI Wallet needs in 100%
All of the existing ones – designed for pure “on-line” or “off-line” use cases
Draft ISO/IEC 23220 series (PID) designed to target the Digital Identity Wallet
ETSI efforts
Definition of the “What” and not the “How”
Some use cases standardised
DIGITAL IDENTITY STANDARDS
EUID Wallets certification
undefined
EUCC: a horizontal ICT products scheme
Common Criteria, ISO/IEC 17065 & 17025
Defines the “how to certify”
The “what to certify” is for risk owners to define through Protections Profiles
EUCS: a generic cloud services scheme
Defines a baseline of requirements that are applicable to all services.
Enables the same methodology for all services
Does not assess the security of product-specific security features (Security as a Service)
Combining product security evaluation and product lifecycle processes evaluation
As-is transposition of existing scheme elements - GSMA NESAS, SAS-SM Subscription Management, SAS-
UP (UICC Production) and eUICC
Development of the candidate scheme
OTHER CERTIFICATION SCHEMES – UPDATE
EUID Wallets certification
undefined
Transition Scheme
use of the EUCC scheme for the cybersecurity certification of the ICT products parts or components of the EUDIW
use of extended version of the EUCC supplemented by additional specifications (e.g. EUDIW related protection
profiles, state-of-the-art like documents) to cover the ICT services and ICT processes dimensions of the wallet
for cybersecurity requirements not covered by the EUCC or the supplemented EUCC version, and for the non-
cybersecurity requirements, the use of the ISO/IEC 17065
Dedicated CSA scheme for the EUDI Wallet
to be formally launched once the full technical specifications of the wallet will be
for
 non-cybersecurity requirements, the use of the ISO/IEC 17065 framework
POTENTIAL CERTIFICATION PROCESS
EUID Wallets certification
undefined
THANK YOU FOR YOUR ATTENTION
E
u
r
o
p
e
a
n
 
U
n
i
o
n
 
A
g
e
n
c
y
 
f
o
r
 
C
y
b
e
r
s
e
c
u
r
i
t
y
+30 697 00 151 63
slawomir.gorniak
@enisa.europa.eu
www.enisa.europa.eu
Sławomir Górniak
Senior Cybersecurity Expert
Market, Certification and Standardisation Unit
Slide Note
Embed
Share

Stay up to date with the latest EU legislation and updates on EUID wallets certification. Discover the proposed EUDI Wallet Framework and the Architecture and Reference Framework for European Digital Identity Wallets.

  • EUID Wallets
  • certification
  • EU legislation
  • cybersecurity
  • EIDAS regulation
  • EUDI Wallet Framework

Uploaded on Dec 21, 2023 | 4 Views


Download Presentation

Please find below an Image/Link to download the presentation.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.If you encounter any issues during the download, it is possible that the publisher has removed the file from their server.

You are allowed to download the files provided on this website for personal or commercial use, subject to the condition that they are used lawfully. All files are the property of their respective owners.

The content on the website is provided AS IS for your information and personal use only. It may not be sold, licensed, or shared on other websites without obtaining consent from the author.

E N D

Presentation Transcript


  1. EUID WALLETS CERTIFICATION S awomir G rniak Senior Security Expert Market, Certification and Standardisation Unit 26 04 2023

  2. EU LEGISLATION CYBERSECURITY LANDSCAPE EUID Wallets certification 2

  3. EIDAS REGULATION V2 UPDATES A European Digital Identity Wallet Framework The Recommendation for an EU Toolbox for a coordinated approach towards a European Digital Identity Framework Certification of European Digital Identity Wallets (art. 6) and of electronic identification schemes (art. 12) under the CSA Harmonised approach to trust, security and interoperability through standards (multiple articles) Three new qualified trust services (provision of electronic archiving services, electronic ledgers and management of remote electronic signature and seal creation devices) Alignment of the Trust Service provisions with the rules applicable to NISDv2 (articles 17, 18, 20, 21 and 24). EUID Wallets certification 3

  4. EUDI WALLET FRAMEWORK PROPOSAL EUDI Wallet electronic identification means at assurance level high under eIDAS Recommendation on Member States to work on: Toolbox including a technical Architecture and Reference Framework Set of common standards and technical specifications Set of common guidelines and best practices for the implementation of the EUDI framework Conformity of EUDI Wallets with technical and operational specifications and reference standards established by means of implementing acts, shall be certified Certification of the EUDI Wallets will ensure security, trust and robustness EU-wide certification scheme will bring harmonization and interoperability Certification should rely as much as possible on the available CSA schemes In practice starting with the EUCC Supplement the EUCC scheme with additional specifications, procedures and reference standards by means of adoption of eIDAS implementing acts Develop protection profiles leveraging on relevant parts of the EU5G and EUCS to support EUDI Wallets EUID Wallets certification 4

  5. ARCHITECTURE AND REFERENCE FRAMEWORK The Common Union Toolbox for a Coordinated Approach Towards a European Digital Identity Framework The European Digital Identity Wallet Architecture and Reference Framework v1.1.0 April 2023 Goal: to provide specifications to develop an interoperable EUDI Wallet solution, based on common standards and practices Defines European Digital Identity Wallet Ecosystem Represents state-of-play of ongoing work of the eIDAS Expert Group In the future, will be aligned to the outcome of the legislative negotiations of the proposal for a European Digital Identity Framework EUID Wallets certification 5

  6. ARF EUDI WALLET ECOSYSTEM EUID Wallets certification 6

  7. EUDI WALLET FRAMEWORK REQUEST Request for technical support from ENISA to develop a cybersecurity certification scheme for the European Digital Identity Wallet Indicate which CSA schemes (EUCC, EU5G, EUCS) can be used for certification (Protection Profiles, security requirements, evaluation methodologies, etc.). Gap analysis and proposal of possible solutions if no scheme parts exist Analysis of the current state of play of European market Gap analysis for interoperability and functional testing requirements and evaluation methodology for non-cybersecurity relevant aspects of EUDI Wallets Collaborate with Member States, SDOs and the Commission to design functional and interoperability test suites for the EUDI Wallets certification EUID Wallets certification 7

  8. EUDI WALLET FORMS AND SECURITY TECHNOLOGIES EUID Wallets certification 8

  9. EUDI WALLET COMPONENTS Software Interfaces Primary hardware Secure element (secure cryptographic material storage) Secondary hardware Services Onboarding of a user Issuance of the EUDI Wallet Authentication of the user Display of the EU Digital Identity Wallet Trust Mark Request of person identification data (PID) Issuance of a PID Request for a (qualified) electronic attestation of attribute Request for a (qualified) electronic certificate Storage of PID and/or (Q)EAAs Deletion PID and/or (Q)EAAs Validation of a request from a relying party Presentation of PID or (Q)EAAs to a relying party Electronic identification (authentication) of an EUDI Wallet user Enabling the user to sign Enabling the user to seal EUID Wallets certification 9

  10. DIGITAL IDENTITY STANDARDS ENISA study 2022 major gaps in standardisation of EUDI Wallet No standards for the cryptographic device interface (direct interface of the cryptographic component of the mobile device; Functional testing requirements missing for elements of the EUDI Wallet except: PID/(Q)EAA mutual authentication protocols, qualified electronic signatures No standards fulfilling the EUDI Wallet needs in 100% All of the existing ones designed for pure on-line or off-line use cases Draft ISO/IEC 23220 series (PID) designed to target the Digital Identity Wallet ETSI efforts Definition of the What and not the How Some use cases standardised EUID Wallets certification 10

  11. OTHER CERTIFICATION SCHEMES UPDATE EUCC: a horizontal ICT products scheme Common Criteria, ISO/IEC 17065 & 17025 Defines the how to certify The what to certify is for risk owners to define through Protections Profiles EUCS: a generic cloud services scheme Defines a baseline of requirements that are applicable to all services. Enables the same methodology for all services Does not assess the security of product-specific security features (Security as a Service) Combining product security evaluation and product lifecycle processes evaluation As-is transposition of existing scheme elements - GSMA NESAS, SAS-SM Subscription Management, SAS- UP (UICC Production) and eUICC Development of the candidate scheme EUID Wallets certification 11

  12. POTENTIAL CERTIFICATION PROCESS Transition Scheme use of the EUCC scheme for the cybersecurity certification of the ICT products parts or components of the EUDIW use of extended version of the EUCC supplemented by additional specifications (e.g. EUDIW related protection profiles, state-of-the-art like documents) to cover the ICT services and ICT processes dimensions of the wallet for cybersecurity requirements not covered by the EUCC or the supplemented EUCC version, and for the non- cybersecurity requirements, the use of the ISO/IEC 17065 Dedicated CSA scheme for the EUDI Wallet to be formally launched once the full technical specifications of the wallet will be for non-cybersecurity requirements, the use of the ISO/IEC 17065 framework EUID Wallets certification 12

  13. THANK YOU FOR YOUR ATTENTION S awomir G rniak Senior Cybersecurity Expert Market, Certification and Standardisation Unit European Union Agency for Cybersecurity +30 697 00 151 63 slawomir.gorniak@enisa.europa.eu www.enisa.europa.eu

More Related Content

giItT1WQy@!-/#giItT1WQy@!-/#