The Austrian eID Ecosystem in the Public Cloud: How to Obtain Privacy While Preserving Practicality
Bernd Zwattendorfer, Daniel Slamanig

TL;DR
This paper presents a privacy-preserving approach for migrating the Austrian eID ecosystem to a public cloud using cryptographic techniques, ensuring security and privacy while maintaining system functionality.
Contribution
It introduces a novel cryptographic method combining proxy re-encryption and redactable signatures to protect sensitive data in a cloud migration of eID systems.
Findings
Complete eID ecosystem can be migrated to a public cloud securely.
Sensitive data remains confidential with the proposed cryptographic approach.
System supports all main use cases without data disclosure.
Abstract
The Austrian eID system constitutes a main pillar within the Austrian e-Government strategy. The eID system ensures unique identification and secure authentication for citizens protecting access to applications where sensitive and personal data is involved. In particular, the Austrian eID system supports three main use cases: Identification and authentication of Austrian citizens, electronic representation, and foreign citizen authentication at Austrian public sector applications. For supporting all these use cases, several components -- either locally deployed in the applications' domain or centrally deployed -- need to communicate with each other. While local deployments have some advantages in terms of scalability, still a central deployment of all involved components would be advantageous, e.g. due to less maintenance efforts. However, a central deployment can easily lead to load…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
