Skip to main content

From the eCard-API-Framework Towards a Comprehensive eID-Framework for Europe

  • Chapter
  • 807 Accesses

Abstract

The German eCard-strategy aims at harmonizing the various government projects which issue or use smart cards for authentication and signature purposes. Against this background the German government developed the eCard-API-Framework [eCard-TR] which aims at supporting arbitrary smart cards and facilitating the integration of them into various eID-applications. The present contribution provides a brief overview of the main features of the eCard-API-Framework, highlights current standardization efforts at CEN and ISO and provides an outlook how this approach might form the basis for a comprehensive eID-framework for Europe and beyond.

This is a preview of subscription content, log in via an institution.

Buying options

Chapter
USD   29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD   39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD   54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Learn about institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. Microsoft: CardSpace, via http://cardspace.netfx3.com/

    Google Scholar 

  2. Comité européen de normalisation (CEN): General guidelines for electronic signature verification, CEN Workshop Agreement, May 2004, via ftp://ftp.cenorm.be/PUBLIC/CWAs/e-Europe/eSign/ c wal 4171-00-2004-May.pdf

    Google Scholar 

  3. Comité européen de normalisation (CEN): Application Interface for smart cards used as Secure Signature Creation Devices — Part 2: Additional Services, CEN Workshop Agreement, May 2004, via ftp://ftp.cenorm.be/PUBLIC/CWAs/e-Europe/eSign/cwal4890-02-2004-May.pdf

    Google Scholar 

  4. Comité européen de normalisation (CEN): Identification card systems — European Citizen Card — Part I: Physical, electrical and transport protocol characteristics, prCEN/TS 15480-1, proposed Technical Standard, 2007

    Google Scholar 

  5. Comité européen de normalisation (CEN): Identification card systems — European Citizen Card — Part 2: Logical data structures and card services, prCEN/TS 15480-2, proposed Technical Standard, 2007

    Google Scholar 

  6. Comité européen de normalisation (CEN): Identification card systems — European Citizen Card — Part 3: European Citizen Card Interoperability using an application interface, prCEN/TS 15480-3, Working Draft, 2007

    Google Scholar 

  7. Federal Office for Information Security: eCard-API-Framework — Technical Directive BSI 03112, 2007

    Google Scholar 

  8. gematik: The Specification of the German Electronic Health Card eHC, Part 1: Commands, Algorithms and Functions of the COS Platform, via http://www.gematik.de/upload/gematik_eGK_Specification_Parti_e_Vl_1_0_518.pdf Part 2: Applications and application-related Structures, via http://www.ge-matik.de/upload/gematik_eGK_Specification_Part2_e_Vl_l_l_516.pdf, Part 3: Layout andPhysical Properties, vai http://www.gematik.de/upload/gematik_eGK_Specification_Part3_e_Vl_l_0_514.p

    Google Scholar 

  9. ETSI: Electronic Signature Formats, Electronic Signatures and Infrastructures (ESI) — Technical Specification, ETSI TS 101 733 VI.5.1, 2003-12, via http://portal.etsi.org/docbox/EC_Files/EC_Files/ ts_101733v010501p.pdf

    Google Scholar 

  10. ETSI: XML Advanced Electronic Signatures (XAdES), Technical Specification, TS 101 903 VI.2.2 (2004-04), via http://uri.etsi.org/01903/vl.2.2/ts_101903v010202p.pdf

    Google Scholar 

  11. ETSI: Mobile Signature Service — Web Service Interface, Technical Specification TS 102 204 VI. 1.4, via http://portal.etsi.oig/docbox/EC_Files/EC_Files/ts_l02204v010104p.pdf

    Google Scholar 

  12. ETSI: Provision of harmonized Trust Service Provider (TSP) status information, Technical Specification TS 102 231, via http://portal.etsi.org/stfs/STF_HomePages/STF290/draft_ts_102231v010201p&RGW.doc

    Google Scholar 

  13. Higgins Team: Higgins Trust Framework Project Home, via http://www.eclipse.org/higgins

    Google Scholar 

  14. D. Hühnlein, M. Bach: How to use ISO/IEC 24727-3 with arbitrary Smart Cards, in C. Lambrinou-dakis, G. Pernul, A.M. Tjoa (Eds.): TrustBus 2007, LNCS 4657, SS. 280–289, 2007

    Google Scholar 

  15. ISO/IEC: Identification cards — Integrated circuit cards — Part 4:Organization, security and commands for interchange, ISO7816-4, Version 2005-01-15

    Google Scholar 

  16. ISO/IEC: Information technology — Identification cards — Integrated circuits) cards with contacts — Part 15: Cryptographic information application, ISO/IEC 7816-15, 2003

    Google Scholar 

  17. ISO/IEC: Identification Cards — Integrated Circuit Cards Programming In-terfaces — Part 1: Architecture, ISO/IEC 24727-1, Final Draft International Standard, 2006

    Google Scholar 

  18. ISO/IEC: Identification Cards — Integrated Circuit Cards Programming In-terfaces — Part 2: Generic Card Interface, ISO/IEC 24727-3, Committee Draft, 2006

    Google Scholar 

  19. ISO/IEC: Identification Cards — Integrated Circuit Cards Programming Interfaces — Part 3: Application Interface, ISO/IEC 24727-3, Committee Draft, 2006

    Google Scholar 

  20. ISO/IEC: Identification Cards — Integrated Circuit Cards Programming Interface — Part 4: API Administration, ISO/IEC 24727-4, Working Draft, 2007

    Google Scholar 

  21. B. Kowalski: A survey of the eCard-Strategy of the German Federal Government, (in German), Proceedings of BIOSIG 2007, GI Lecture Notes in Informatics, 2007

    Google Scholar 

  22. F. Leyman: e-ID interoperability large scale pilot — STORK, Talk at the EEMA-Conference “The European e-Identity Conference”, Paris, June 2007

    Google Scholar 

  23. Liberty Alliance Project: The Liberty Alliance, via http://www.projectliberty.org/

    Google Scholar 

  24. Ministerial declaration, approved unanimously on 24 November 2005, Manchester, United Kingdom, via http://archive.cabinetoffice.gov.uk/egov2005conference/documents/proceedings/ pdf/051124declaration.pdf

    Google Scholar 

  25. Microsoft Inc.: Cryptography Reference (Microsoft CryptoAPI), Platform SDK: Security, via http:// msdn.microsoft.com/library/en-us/security/security/cryptographyreference.asp

    Google Scholar 

  26. Microsoft Inc.: Cryptography API: Next Generation http://msdn.microsoft.com/library/en-us/seccrypto/security/cryptography_api_nextgeneration.asp

    Google Scholar 

  27. OASIS: Digital Signature Service Core Protocols, Elements, and Bindings, Version 1.0, OASIS Standard, via http://docs.oasis-open.org/dss/vl.0/oasis-dss-core-spec-vl.0-os.pdf

    Google Scholar 

  28. M. Faher: Onom@Topic — project, presentation at Porvoo 9, May 2006, via http://porvoo9.gov.si/ pdf/FRI_15_1000_MFaher_AXALTO_Porvoo9.pdf

    Google Scholar 

  29. PC/SC Workgroup: PC/SC Workgroup Specifications 1.0/2.0, via http://pcscworkgroup.com

    Google Scholar 

  30. T. Dierks, C. Allen: The TLSProtocol-Version 1.0, RFC2246, via http://www.ietf.org/rfc/rfc2246.txt

    Google Scholar 

  31. M. Myers, R. Ankney, A. Malpani, S. Galperin, C. Adams: X.509 Internet Public Key Infrastructure — Online Certificate Status Protocol — OCSP, IETF RFC 2560, via http://www.ietf.org/rfc/rfc3161.txt

    Google Scholar 

  32. C. Adams, P. Cain, D. Pinkas, R. Zuccherato: Internet X.509 Public Key Infrastructure Time-Stamp Protocol (TSP). IETF RFC 3161, August 2001, via http://www.ietf.org/rfc/rfc3161.txt

    Google Scholar 

  33. R. Housley: Cryptographic Message Syntax (CMS), IETF RFC 3369., via http://www.ietf.org/rfc/ rfc3369.txt

    Google Scholar 

  34. TeleTrusT: SICCT-Spezifikation, Version 1.1.0, 2006-12-19, via http://www.teletrust.de/fileadmin/ files/publikationen/Spezifikationen/SICCTSpezifikationl. 10.pdf

    Google Scholar 

  35. W3C Recommendation: XML Encryption Syntax and Processing, 10. Dezember 2002, via http://www. w3.org/TR/xmlenc-core/

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Rights and permissions

Reprints and permissions

Copyright information

© 2007 Friedr. Vieweg & Sohn Verlag | GWV Fachverlage GmbH, Wiesbaden

About this chapter

Cite this chapter

Hühnlein, D., Bach, M. (2007). From the eCard-API-Framework Towards a Comprehensive eID-Framework for Europe. In: ISSE/SECURE 2007 Securing Electronic Business Processes. Vieweg. https://doi.org/10.1007/978-3-8348-9418-2_29

Download citation

  • DOI: https://doi.org/10.1007/978-3-8348-9418-2_29

  • Publisher Name: Vieweg

  • Print ISBN: 978-3-8348-0346-7

  • Online ISBN: 978-3-8348-9418-2

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics