The European Commission recently announced the “European Business Wallet” (EUBW) as business-oriented companion to the human-centric and smartphone-based “European Digital Identity Wallet” (EUDIW) in order to boost the competitiveness of European enterprises. While a very important use case of the EUBW is the trustworthy data exchange in industrial Dataspaces using a suitable “Dataspace Protocol” (DSP), the currently available identity and access management approach based on the “Eclipse Decentralized Claims Protocol” (DCP) is unfortunately limited to self-issued identity tokens and decentralized identifiers lacking a clear trust framework and proprietary protocols for the issuance and presentation of credentials, which completely ignore existing standards in the web authorization domain, such as the “OAuth 2.0 Authorization Framework”, but instead resemble an existing patent, which is held by Microsoft Technology Licensing LLC. This is extremely unfortunate for participants within European Dataspaces, because there is the well established and recently amended eIDAS Regulation (EU) No. 910/2014 in place and one may expect that most European enterprises will soon become “Wallet-Relying Parties” (WRP) in the sense of Art. 2 (1) of (EU) 2025/848 , which are equipped with X.509-based “Wallet-Relying Party Access Certificates” (WRPAC) according to Art. 2 (12) of (EU) 2025/848 . These certificates can not only be used for requesting credentials and claims from the EUDIW, but they can also be used for the automation of many other sensitive business processes using the EUBW and especially the trustworthy identity and access management in industrial Dataspaces across Europe and beyond. Against this background, we propose an alternative identity and access management architecture utilizing the widely accepted OAuth 2.0 framework and introduce the “Open Identity Protocol” (OIP), which can use the functionality of the EUBW together with standardized credentials including WRPACs, which seems to be much better aligned with the foreseeable European developments driven by the eIDAS Regulation and the forthcoming EUBW.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Identity and Access Management for Dataspaces Using the European Business Wallet and eIDAS-Based Credentials

  • Tobias Wich,
  • Detlef Hühnlein,
  • Tina Hühnlein,
  • Mike Prechtl,
  • Michael Rauh,
  • Neil Crossley,
  • Florian Otto,
  • Marina Artis

摘要

The European Commission recently announced the “European Business Wallet” (EUBW) as business-oriented companion to the human-centric and smartphone-based “European Digital Identity Wallet” (EUDIW) in order to boost the competitiveness of European enterprises. While a very important use case of the EUBW is the trustworthy data exchange in industrial Dataspaces using a suitable “Dataspace Protocol” (DSP), the currently available identity and access management approach based on the “Eclipse Decentralized Claims Protocol” (DCP) is unfortunately limited to self-issued identity tokens and decentralized identifiers lacking a clear trust framework and proprietary protocols for the issuance and presentation of credentials, which completely ignore existing standards in the web authorization domain, such as the “OAuth 2.0 Authorization Framework”, but instead resemble an existing patent, which is held by Microsoft Technology Licensing LLC. This is extremely unfortunate for participants within European Dataspaces, because there is the well established and recently amended eIDAS Regulation (EU) No. 910/2014 in place and one may expect that most European enterprises will soon become “Wallet-Relying Parties” (WRP) in the sense of Art. 2 (1) of (EU) 2025/848 , which are equipped with X.509-based “Wallet-Relying Party Access Certificates” (WRPAC) according to Art. 2 (12) of (EU) 2025/848 . These certificates can not only be used for requesting credentials and claims from the EUDIW, but they can also be used for the automation of many other sensitive business processes using the EUBW and especially the trustworthy identity and access management in industrial Dataspaces across Europe and beyond. Against this background, we propose an alternative identity and access management architecture utilizing the widely accepted OAuth 2.0 framework and introduce the “Open Identity Protocol” (OIP), which can use the functionality of the EUBW together with standardized credentials including WRPACs, which seems to be much better aligned with the foreseeable European developments driven by the eIDAS Regulation and the forthcoming EUBW.