Identity Assurance in the UK: technical implementation and legal implications under eIDAS

J. Web Sci. Pub Date : 2017-12-06 DOI:10.1561/106.00000010
Niko Tsakalakis, Sophie Stalla-Bourdillon, K. O’Hara
{"title":"Identity Assurance in the UK: technical implementation and legal implications under eIDAS","authors":"Niko Tsakalakis, Sophie Stalla-Bourdillon, K. O’Hara","doi":"10.1561/106.00000010","DOIUrl":null,"url":null,"abstract":"Gov.UK Verify, the new Electronic Identity (eID) Management system of the UK Government, has been promoted as a state-of-the-art privacy-preserving system, designed around demands for better privacy and control, and is the first eID system in which the government delegates the provision of identity to competing private third parties. Under the EU eIDAS, Member States can allow their citizens to transact with foreign services by notifying their national eID systems. Once a system is notified, all other Member States are obligated to incorporate it into their electronic identification procedures. The paper offers a discussion of Gov.UK Verify's compliance with eIDAS as well as Gov.UK Verify's potential legal equivalence to EU systems under eIDAS as a third-country legal framework after Brexit. To this end it examines the requirements set forth by eIDAS for national eID systems, classifies these requirements in relation to their ratio legis and organises them into five sets. The paper proposes a more thorough framework than the current regime to decide on legal equivalence and attempts a first application in the case of Gov.UK Verify. It then assesses Gov.UK Verify's compliance against the aforementioned set of requirements and the impact of the system's design on privacy and data protection. The article contributes to relevant literature of privacy{preserving eID management by offering policy and technical recommendations for compliance with the new Regulation and an evaluation of interoperability under eIDAS between systems of different architecture. It is also, to our knowledge, the first exploration of the future of eID management in the UK after a potential exit from the European Union.","PeriodicalId":405637,"journal":{"name":"J. Web Sci.","volume":"48 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-12-06","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"7","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"J. Web Sci.","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1561/106.00000010","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 7

Abstract

Gov.UK Verify, the new Electronic Identity (eID) Management system of the UK Government, has been promoted as a state-of-the-art privacy-preserving system, designed around demands for better privacy and control, and is the first eID system in which the government delegates the provision of identity to competing private third parties. Under the EU eIDAS, Member States can allow their citizens to transact with foreign services by notifying their national eID systems. Once a system is notified, all other Member States are obligated to incorporate it into their electronic identification procedures. The paper offers a discussion of Gov.UK Verify's compliance with eIDAS as well as Gov.UK Verify's potential legal equivalence to EU systems under eIDAS as a third-country legal framework after Brexit. To this end it examines the requirements set forth by eIDAS for national eID systems, classifies these requirements in relation to their ratio legis and organises them into five sets. The paper proposes a more thorough framework than the current regime to decide on legal equivalence and attempts a first application in the case of Gov.UK Verify. It then assesses Gov.UK Verify's compliance against the aforementioned set of requirements and the impact of the system's design on privacy and data protection. The article contributes to relevant literature of privacy{preserving eID management by offering policy and technical recommendations for compliance with the new Regulation and an evaluation of interoperability under eIDAS between systems of different architecture. It is also, to our knowledge, the first exploration of the future of eID management in the UK after a potential exit from the European Union.
英国的身份保证:eIDAS下的技术实施和法律含义
Gov.UK Verify是英国政府新的电子身份(eID)管理系统,已被推广为最先进的隐私保护系统,旨在满足更好的隐私和控制需求,并且是第一个政府委托竞争的私人第三方提供身份的eID系统。根据欧盟电子信息系统,成员国可以通过通知其国家电子信息系统,允许其公民与外国服务进行交易。一旦一个系统被通知,所有其他成员国都有义务将其纳入其电子识别程序。本文讨论了Gov.UK Verify对eIDAS的合规性,以及Gov.UK Verify在英国脱欧后作为第三国法律框架在eIDAS下与欧盟系统的潜在法律等效性。为此目的,它审查了eIDAS对国家eID系统提出的要求,将这些要求按照其比率法律进行分类,并将其组织为五组。该文件提出了一个比现行制度更彻底的框架来决定法律等效,并尝试在Gov.UK Verify的情况下进行首次应用。然后,它根据上述要求评估Gov.UK Verify的合规性,以及系统设计对隐私和数据保护的影响。本文通过提供符合新法规的政策和技术建议以及评估不同架构的系统之间在eIDAS下的互操作性,为保护隐私的eID管理提供了相关文献。据我们所知,这也是英国可能退出欧盟后对eID管理未来的首次探索。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信