Regulation
REGULATION (EU) No 910/2014 OF THE EUROPEAN PARLIAMENT
AND OF THE COUNCIL of 23 July 2014 on electronic identification and
trust services for electronic transactions in the internal market and repealing
Directive 1999/93/EC
http://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32014R0910&from=EN
Scope
Why eIDAS identication and authentication it is important for cloud systems?
Impact
Practical impact unclear:
Identication
Authentication
Challenges
Incompatible existing examples:
Details
18 September 2015, EU Commission will determine minimum technical specications, standards and procedures with reference to which assurance levels low, substantial and high
After reading the links about incompatible examples, you can take the quiz
For which country authentication is based on symmetric cryptography?
For which country authentication enables tracability of a citizen?
For which country authentication secure against replay attacks?
For which country authentication at public bodies only?
For which country authentication supports a separate pseudonym for each service?
For which country authentication is incompatible with eIDAS?
Article 6: Mutual recognition
Assurance level low
refer to an electronic identification means in the context of an electronic identification scheme, which provides a limited degree of confidence in the claimed or asserted identity of a person, and is characterized with reference to technical specifications, standards and procedures related thereto, including technical controls, the purpose of which is to decrease the risk of misuse or alteration of the identity; fact
Assurance level substantial
... which provides a substantial degree of confidence ... question
Assurance level substantial
... which provides a higher degree of condence in the claimed or asserted identity of a person than electronic identication means with the assurance level substantial, and is characterized with reference to technical specications, standards and procedures related thereto, including technical controls, the purpose of which is to prevent misuse or alteration of the identity.
Details
18 September 2015, EU Commission will determine minimum technical
specifications, standards and procedures with reference to which assurance
levels low, substantial and high.
These security requirements will have crucial importance for the market