Download presentation
Presentation is loading. Please wait.
1
Architecture proposal
eIDAS connector for STORK Architecture proposal
2
eIDAS connector for STORK (ECS)
STORK - Plugin eIDAS STORK Inbound SAMl engine c-peps eIDAS -decryption Outbound MS - PEPS eIDAS -encryption eIDAS STORK Read config SAMl engine SP interface eIDAS - SAMl engine S-peps Meta data Encrypt Encrypt SP Country selector S/C node interface SP Country selector Proxy service Connector MS - Node
3
A customer/citizen from a "eIDAS MS" wants needs to be authenticated to use some service at a Service Proveder (SP) site. The customer chooses to use the eIDAS/STORK to be authenticated The SP website gets the country selector from the S-PEPS of the country and displays it to the customer/citizen (Problem with SP’s which have their own country selector) The customer/citizen chooses his home country The S-PEPS prepares the authentication request. If the home country has eIDAS node, the S-PEPS sends the request to the ECS. The ECS Marshals the STORK objects and creates a eIDAS authentication request The ECS connector encrypts the authentication request and sends it to the home country eIDAS Proxy Service The eIDAS Proxy service of the home country does its magic to authenticate the customer/citizen. The eIDAS Proxy service s of the home country sends the authentication response to the ECS Connector The ECS Connector decrypts the incoming authentication response The ECS Connector Marshals the eIDAS objects and creates a STORK authentication response The ESC connector sends the response to the defined return URL
4
STORK 2.0 -> eIDAS MS eIDAS MS STORK Proxy service Proxy service
c-peps MS - PEPS ECS MS - PEPS eIDAS STORK SP Plugin Connector S-peps Country selector Connector
5
STORK 2.0 -> eIDAS A customer/citizen from a „STORK MS" needs to be authenticated to use a service at a Service Proveder (SP) site. The customer chooses to use the eIDAS/STORK to be authenticated The SP website gets the country selector from the Connector of the MS and displays it to the customer/citizen (Problem with SP’s which have their own country selector) The customer/citizen chooses his home country The Connector prepares the authentication request and sends it to the ESC Proxy Service of th home country (eIDAS MS have different URL’s in the country selector than a STORK country) The ESC Proxy Service decrypts the incoming authentication request The ESC Proxy Service Marshals the eIDAS objects and creates a STORK authentication request and sends it to the home country C-PEPS The C-PEPS then does its magic to authenticate the customer/citizen The C-PEPS sends the authentication response to the ECS Proxy Service The ECS Proxy Service Marshals the STORK objects and creates a eIDAS authentication response The ECS Proxy Service encrypts the authentication response and sends it to the Connector of the SP (where the request came from) The incoming response is decrypted and returned to the SP
6
eIDAS -> STORK 2.0 MS eIDAS MS STORK Plugin Proxy Service
c-peps Connector node MS - PEPS MS - PEPS Connector Connector S-peps SP Country selector
7
eIDAS -> STORK 2.0 eIDAS SAML STORK SAML Minimal dataset STORK SAML
in eIDAS’ish STORK SAML in STORK’ish Proxy service Proxy service c-peps Connector node MS - PEPS MS - PEPS Sector specific Additional attributes - in STORK’ish if for or from STORK pilots Connector Connector S-peps
8
eIDAS -> STORK 2.0 eIDAS SAML STORK SAML Minimal dataset STORK SAML
in eIDAS’ish STORK SAML in STORK’ish AP Proxy service Proxy service c-peps hasDegree hasDegree Connector node MS - PEPS MS - PEPS Sector specific Additional attributes - in STORK’ish if for or from STORK pilots Connector Connector S-peps SP hasDegree
9
Sector specific Additional attributes -
eIDAS -> STORK 2.0 eIDAS SAML STORK SAML Minimal dataset in eIDAS’ish STORK SAML in STORK’ish AP Proxy service Proxy service c-peps VATRegistration VATRegistration Connector node MS - PEPS MS - PEPS Sector specific Additional attributes - Added to the SAML Connector Connector S-peps SP
Similar presentations
© 2024 SlidePlayer.com. Inc.
All rights reserved.