The European Digital Identity (EUDI) Wallet is a user-controlled digital environment that is being developed to be used by all citizens of the European Union. The Architecture and Reference Framework (ARF) of the EUDI Wallet is a set of specifications designed to ensure their interoperability and security. Among specifications, a Wallet Secure Cryptographic Device (WSCD) with a high Level of Assurance must be used. A high LoA is achieved through the multi-factor authentication of the Wallet User and the use of secure hardware for implementing the needed cryptographic and biometric algorithms. Also, EUDI Wallets should include a functionality to generate and manage user-chosen pseudonyms, to authenticate Users when accessing online services. This paper describes a high LoA EUDI Wallet using a remote WSCD, which is the most inclusive, user-friendly and scalable type of WSCD. User authentication is done through something you know (a password), something you have (a smartphone), and who you are (with facial biometrics). As secure hardware for the remote WSCD, we use an Intel SGX enclave. The WSCD allows the generation and management of Passkeys, which are a kind of pseudonyms following the W3C WebAuthn specification. A demonstrator has been developed using a Samsung Galaxy A52 as User device with the Wallet Instance, and a laptop with an Intel® Core ™ i7-10750H at 2.60 GHz and 16 GB RAM with Ubuntu 20.04.6 LTS, Intel SGX1 and disabled hyper-threading to implement the remote WSCD. The experimental results show that the WSCD needs 128MB of RAM and takes 374.2 ms to be bound to a User, 375.2 ms to authenticate the User and create a new Passkey, and 373.8 ms to authenticate the User and sign with an already existing Passkey.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

A High-Level-of-Assurance EUDI Wallet with a Remote WSCD Supporting Biometrics and Passkeys

  • Claudia Franco,
  • Carlos Lancha,
  • Daniel Flores,
  • Rosario Arjona,
  • Iluminada Baturone

摘要

The European Digital Identity (EUDI) Wallet is a user-controlled digital environment that is being developed to be used by all citizens of the European Union. The Architecture and Reference Framework (ARF) of the EUDI Wallet is a set of specifications designed to ensure their interoperability and security. Among specifications, a Wallet Secure Cryptographic Device (WSCD) with a high Level of Assurance must be used. A high LoA is achieved through the multi-factor authentication of the Wallet User and the use of secure hardware for implementing the needed cryptographic and biometric algorithms. Also, EUDI Wallets should include a functionality to generate and manage user-chosen pseudonyms, to authenticate Users when accessing online services. This paper describes a high LoA EUDI Wallet using a remote WSCD, which is the most inclusive, user-friendly and scalable type of WSCD. User authentication is done through something you know (a password), something you have (a smartphone), and who you are (with facial biometrics). As secure hardware for the remote WSCD, we use an Intel SGX enclave. The WSCD allows the generation and management of Passkeys, which are a kind of pseudonyms following the W3C WebAuthn specification. A demonstrator has been developed using a Samsung Galaxy A52 as User device with the Wallet Instance, and a laptop with an Intel® Core ™ i7-10750H at 2.60 GHz and 16 GB RAM with Ubuntu 20.04.6 LTS, Intel SGX1 and disabled hyper-threading to implement the remote WSCD. The experimental results show that the WSCD needs 128MB of RAM and takes 374.2 ms to be bound to a User, 375.2 ms to authenticate the User and create a new Passkey, and 373.8 ms to authenticate the User and sign with an already existing Passkey.