82
L. Hanzlik and M. Kutyłowski
tion of an eID to a reader and processing all information locally. The second option
is using an eID as a secure token that enables us to create authenticated connections
with a remote terminal. An alternative is to use no eID and realize its functions using
an ID infrastructure. Each option has its advantages and disadvantages:
Option 0: Virtual ID An ID document contains data that may be fetched from an
appropriate registry. So one can use a “virtual ID document” containing only a key
to a database (e.g., an ID number printed on a sheet of paper). There are certain
advantages of this approach: a negligible technical effort for issuing and delivery of
an ID document, and ease of ID document updating and revocation. However, this
solution has also substantial disadvantages:
• The service operator (as well as a cyber criminal that breaks into the system)
is aware of all activities concerning identity verification. This violates the data
minimization principle of security engineering.
• In the case of a system failure (e.g., due to a cyber attack, telecommunication
infrastructure failure, etc.), all activities requiring identity verification are suspended.
• There is a non-negligible communication latency and overhead.
• Responding to a query should be preceded by checking the rights to get an
answer. This is hard if the verifier has no eID.
Option 1: Local Use An eID token holding crucial ID data and verifiable for its
originality has substantial advantages in certain situations:
• The presence of an eID is indirect proof of the physical presence of its holder.
• Identity and data verification does not require online access despite strong
guarantees originating from the eID issuer.
• Interaction with a chip may enable biometric verification without the involvement
of any external database. The biometric data obtained by the reader can be
directly compared with data stored in the eID. Consequently, any security breach
in the system would not expose the biometric data of the whole population.
Option 2: Remote Use In this case an eID serves as a secure cryptographic token
for remote authentication. The advantages of this approach are as follows:
• An eID is involved in the authentication process as a “what you have” and a
“what you know” component, since typically an eID requires us to provide the
user’s activation password.
• In remote authentication it is hard to check that the user is really on the other side
of the line. An eID serves as indirect proof of this presence: its participation in a
protocol execution is checked in a cryptographic way, while one can reasonably
assume that the owner of the eID would not borrow/give it to a third person.
L. Hanzlik and M. Kutyłowski
tion of an eID to a reader and processing all information locally. The second option
is using an eID as a secure token that enables us to create authenticated connections
with a remote terminal. An alternative is to use no eID and realize its functions using
an ID infrastructure. Each option has its advantages and disadvantages:
Option 0: Virtual ID An ID document contains data that may be fetched from an
appropriate registry. So one can use a “virtual ID document” containing only a key
to a database (e.g., an ID number printed on a sheet of paper). There are certain
advantages of this approach: a negligible technical effort for issuing and delivery of
an ID document, and ease of ID document updating and revocation. However, this
solution has also substantial disadvantages:
• The service operator (as well as a cyber criminal that breaks into the system)
is aware of all activities concerning identity verification. This violates the data
minimization principle of security engineering.
• In the case of a system failure (e.g., due to a cyber attack, telecommunication
infrastructure failure, etc.), all activities requiring identity verification are suspended.
• There is a non-negligible communication latency and overhead.
• Responding to a query should be preceded by checking the rights to get an
answer. This is hard if the verifier has no eID.
Option 1: Local Use An eID token holding crucial ID data and verifiable for its
originality has substantial advantages in certain situations:
• The presence of an eID is indirect proof of the physical presence of its holder.
• Identity and data verification does not require online access despite strong
guarantees originating from the eID issuer.
• Interaction with a chip may enable biometric verification without the involvement
of any external database. The biometric data obtained by the reader can be
directly compared with data stored in the eID. Consequently, any security breach
in the system would not expose the biometric data of the whole population.
Option 2: Remote Use In this case an eID serves as a secure cryptographic token
for remote authentication. The advantages of this approach are as follows:
• An eID is involved in the authentication process as a “what you have” and a
“what you know” component, since typically an eID requires us to provide the
user’s activation password.
• In remote authentication it is hard to check that the user is really on the other side
of the line. An eID serves as indirect proof of this presence: its participation in a
protocol execution is checked in a cryptographic way, while one can reasonably
assume that the owner of the eID would not borrow/give it to a third person.
