New Authentication Concepts for Electronic Identity Tokens

The national funded project [BioP@ss] researches the possibilities of an IP based smart card interface based on the international smart card application interface standards [CEN 15480] and [ISO/IEC 24727]. Instead of the classical APDU based communication a TCP/IP based web service communication with the smart card is established. This solution offers the benefit that this interface relies on well established standardized Internet protocols and hence reduces the necessity of an intermediate middleware implementation which translates web service calls into APDU’s. Additionally, we define a [SAML(v2.0)] profile, which allows the implementation of an Identity Provider directly on a smart card.

[1]  Reinhard Posch,et al.  Security architecture of the Austrian citizen card concept , 2002, 18th Annual Computer Security Applications Conference, 2002. Proceedings..

[2]  Jörg Schwenk,et al.  SAMLizing the European Citizen Card , 2009, BIOSIG.

[3]  Tom Scavo,et al.  SAML V2.0 Holder-of-Key Web Browser SSO Profile Version 1.0 , 2009 .