Reference articles on history, science, culture and more
Encyclopedia

EIDAS

EU electronic identification regulation

Image credit is listed at the end of this article.

The eIDAS Regulation ("electronic IDentification, Authentication and trust Services") is a European Union regulation with the stated purpose of governing "electronic identification and trust services for electronic transactions". It passed in 2014 and its provisions came into effect between 2016 and 2018.

The eIDAS Regulation was fundamentally amended by Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024. The main purpose of the amendment is to introduce a voluntary digital wallet (European Digital Identity) that member states must issue at the request of EU citizens.

01Description

The eIDAS-Regulation oversees electronic identification and trust services for electronic transactions in the European Union's internal market. It regulates electronic signatures, electronic transactions, involved bodies, and their embedding processes to provide a safe way for users to conduct business online like electronic funds transfer or transactions with public services. Both the signatory and the recipient can have more convenience and security. Instead of relying on traditional methods, such as mail or facsimile, or appearing in person to submit paper-based documents, they may now perform transactions across borders, like "1-Click" technology.

eIDAS has created standards for which electronic signatures, qualified digital certificates, electronic seals, timestamps, and other proof for authentication mechanisms enable electronic transactions, with the same legal standing as transactions that are performed on paper.

The regulation came into effect in July 2015, as a means to facilitate secure and seamless electronic transactions within the European Union. Member states are required to recognise electronic signatures that meet the standards of eIDAS.

Regulated aspects in electronic transactions

The Regulation provides the regulatory environment for the following important aspects related to electronic transactions:

  • Digital identity: a European-wide framework (European Digital Identity Wallet, EDIW) for digital authentication of citizens, with legal validity. Nine principles of European digital identity have been defined: user choice, privacy, Interoperability and security, trust, convenience, user consent and control, proportionality, counterpart knowledge, and global scalability.
  • Advanced electronic signature (AdES): An electronic signature is considered advanced if it meets certain requirements:
    • It provides unique identifying information that links it to its signatory.
    • The signatory has sole control of the data used to create the electronic signature.
    • It must be capable of identifying if the data accompanying the message has been tampered with after being signed. If the signed data has changed, the signature is marked invalid.
    • There is a certificate for electronic signature, electronic proof that confirms the identity of the signatory and links the electronic signature validation data to that person.
    • Advanced electronic signatures can be technically implemented, following the XAdES, PAdES, CAdES or ASiC Baseline Profile (Associated Signature Containers) standard for digital signatures, specified by the ETSI.
  • Qualified electronic signature, an advanced electronic signature that is created by a qualified electronic signature creation device based on a qualified certificate for electronic signatures.
  • Qualified digital certificate for electronic signature, a certificate that attests to a qualified electronic signature's authenticity that has been issued by a qualified trust service provider.
  • Qualified website authentication certificate, a qualified digital certificate under the trust services defined in the eIDAS Regulation.
  • Trust service, an electronic service that creates, validates, and verifies electronic signatures, time stamps, seals, and certificates. Also, a trust service may provide website authentication and preservation of created electronic signatures, certificates, and seals. It is handled by a trust service provider.
  • European Union Trusted Lists (EUTL)

Design requirements

Database information has to be linked to some kind of identity number. To certify that a person has the right to access some personal information involves several steps.

  • Connecting a person to a number, which can be done through methods developed in one country, such as digital certificates.
  • Connecting a number to specific information, done in databases.
  • For eIDAS it is needed to connect the number used by a country having information, to the number used by the country issuing the digital certificates.

eIDAS has as minimum identity concept, the name and birth date. But in order to access more sensitive information, some kind of certification is needed that identity numbers issued by two countries refer to the same person.

European Self-Sovereign Identity Framework

The European Union started creating an eIDAS compatible European Self-Sovereign Identity Framework (ESSIF), but in many countries, users need to be Google or Apple customers to use eIDAS services.

European Union Trusted Lists

The European Union Trusted Lists (EUTL) is a public list of over 200 active and legacy Trust Service Providers (TSPs) that are specifically accredited to deliver the highest levels of compliance with the EU eIDAS electronic signature regulation.

The EU trust mark for qualified trust services
The EU trust mark for qualified trust services

03Controversy

In 2023, a proposed change to the law was scrutinized as it would potentially enable EU governments to perform man-in-the-middle attacks, including encrypted communications. The proposal was condemned by groups of cyber security researchers, NGOs, and civil society, as a threat to human rights, privacy, and dignity. The proposal worked via the same mechanism as a 2019 attempt at mass surveillance in Kazakhstan.

At the core of this controversy is the second paragraph of the amendment to the article 45, which states:

Qualified certificates for website authentication referred to in paragraph 1 shall be recognised by web-browsers. [...] Web-browsers shall ensure support and interoperability with qualified certificates for website authentication referred to in paragraph 1, with the exception of enterprises, considered to be microenterprises and small enterprises in accordance with Commission Recommendation 2003/361/EC in the first 5 years of operating as providers of web-browsing services.

Critics claimed that allowing certification authorities (CA) to issue certificates without going through auditing and vetting procedures put in place by browser vendors can jeopardize the security of the Internet as a whole and open the door for man-in-the-middle attacks. This would possibly allow government mandated CAs to issue certificates for any domain name and use it for impersonation, and most critically, without browsers being able to remove them as trustworthy. This is considered particularly concerning in countries with weaker rule of law, where state and state-connected actors would be able to use the law to spy on their own citizens for political repression and personal gain. There was additional concern that this allow private actors with state connections to gain access to and misuse the power for their own purposes.

In the final draft, however, provisions were made to enable browser vendors to continue to implement security provisions that in practice would make this type of interception difficult to perform without being discovered. Specifically, the final draft text states that:

By way of derogation to paragraph 1 and only in case of substantiated concerns related to breaches of security or loss of integrity of an identified certificate or set of certificates, web-browsers may take precautionary measures in relation to that certificate or set of certificates.

which has been interpreted as allowing browser vendors to continue to use mechanisms such as certificate transparency to maintain browser security. The statement of the European Commission on amendment of the article 45 clarifies this statement and denotes that through an agreement with browser vendors, no restriction are imposed on browsers' "own security policies".

Vulnerabilities

In October 2019, two security flaws in eIDAS-Node (a sample implementation of the eID eIDAS Profile provided by the European Commission) were discovered by security researchers; both vulnerabilities were patched for version 2.3.1 of eIDAS-Node.

Watch videos about EIDASExplainers and documentaries on YouTube (opens in a new tab)

Sources and credits

This article is adapted from the Wikipedia article EIDAS, written by its contributors and licensed under CC BY-SA 4.0. Fathomly has changed the layout, removed citation markers, navigation and maintenance notices, and adjusted punctuation. This adapted version is shared under the same license. For references, see the original article.

Images, from Wikimedia Commons:

Fathomly is not affiliated with or endorsed by the Wikimedia Foundation. Spotted a problem? Tell us.