Standardising digital identity in the EU
eIDAS defines a new era for online ID verification
“The section of the eIDAS Regulation concerning electronic identification establishes a predictable regulatory environment to enable secure and seamless electronic interactions between businesses, citizens and public authorities.” (Trends in electronic identification)
From a strictly legal standpoint, the eIDAS Regulation ensures cross-border access to public services: people and organisations within one EU Member State shall be able to use their own eID means to access public services in other EU Member States (provided those public services offer secure login to their web services as an option to their own citizens).
For example, a French student who wants to attend university in Sweden will not be prevented from accessing and completing the online registration process if she doesn’t have BankID (the most widely used eID means in Sweden) to authenticate her identity. Under eIDAS, her FrenchConnect eID will be just as valid.
Two key points to note:
- eIDAS doesn’t mandate the use of eID, but rather enables and protects its use.
- By providing an EU-wide legal framework, the regulation has major implications for the use of eID in the private sector as well.
As of 2023, the EU is in the process of revising the eIDAS Regulation as well as participating in an ambitious, long-term project – the EU Digital Identity Wallet – to support the use of digital identities throughout the EU, which you can learn about in this downloadable eBook
Definitions
Before going further, a few basic definitions will help this discussion:
Electronic identification/eID can refer to:
- an electronic method that “can guarantee the unambiguous identification of a person” (1)
- an individual’s electronically-stored identity data, the digital equivalent of their traditional, physical ID card
- the act of identifying or authenticating oneself in a digital environment
eID scheme: according to eIDAS, “a system for electronic identification under which electronic identification means are issued to natural or legal persons, or natural persons representing legal persons” (2); schemes have been developed by public organisations, private companies and public-private joint ventures
eID means: “a material and/or immaterial unit containing person identification data and which is used for authentication for an online service” (3); a specific method for identifying oneself in a digital environment which conforms to an eID scheme and is issued to users by an eID provider; think of it as the citizen-/customer-facing component of an eID ecosystem; examples: the chip-based eID embedded in Germany’s National Identity Card, Belgium’s Itsme mobile app
Goals of eIDAS for public and private sectors
The eIDAS regulation will impact the private sector just as much as, if not more than, the public sector.
“The section of the eIDAS Regulation concerning electronic identification, coming into effect in September 2018, establishes a predictable regulatory environment to enable secure and seamless electronic interactions between businesses, citizens and public authorities. One of its core objectives is to ensure that people and businesses can use their own national eIDs to access online public services in other EU countries, requiring the establishment of a mutually interoperable network of eID schemes in Europe.” (4)
Facilitating private sector commerce in the digital age is another major goal of the eIDAS Regulation. In support of this aim, the European Commission offers online resources promoting the benefits of eID and trust services for businesses, including a guide on how to go about adopting these tools in their operations. (5)
Both public and private organisations (as well as joint public-private alliances) have been active in developing eID schemes, means and infrastructure, based on their varying mandates and motivations. The banking industry has been and continues to be particularly active. “Banks now collectively spend more than $1 billion per year funding the research and development of identity solutions, making them the world’s leading investors, over even national governments and police agencies“. (6)
Levels of Assurance
In order to legally guarantee interoperability between Member States, the eIDAS regulation clearly defines the standards that an eID scheme must meet. These standards in turn guide the technical and security specifications of eID means, as well as their use and acceptance.
To illustrate the value of having a common EU-wide legal framework, consider one of the key specifications: the levels of assurance (LoA). (7) Each eIDAS-compliant eID scheme is classified according to one or more of three different levels of assurance: Low, Substantial and High. “Levels of Assurance characterise the degree of confidence in the electronic identification credential used in establishing the identity of a person, providing assurance that the person claiming an identity is in fact the person to which the identity was assigned.” (8)
The three levels of assurance according to eIDAS are based on the ISO/IEC 2915 standard, which is the basis for many assurance frameworks throughout the world. (Low, Substantial and High correspond to ISO/IEC 2915 levels 2, 3 and 4, respectively.) Two key factors that help determine the degree of confidence each level offers are:Identity assurance at the time of registration: how rigorous was the process of identifying the person or entity when they applied for their eID?
- Identity assurance at the time of registration: how rigorous was the process of identifying the person or entity when they applied for their eID?
- Authentication assurance: strength of the methods used at the time of authentication
In addition to identity assurance and authentication assurance, other important factors include “the reliability and quality of”: the procedures for issuing the eID means, the entity issuing the eID means and “any other body” that might be involved in applying for the issuance of the eID means. (9)
Using this framework, legislatures can then easily specify what assurance level an eID means must have for a given type of transaction. Private businesses may at their discretion require an even higher assurance level than the law may require if they decide their own business risk warrants it. The benefits of extra security, of course, must be weighed against the quality of the customer experience and the extra transaction costs for the business.
Level of Assurance | Identity assurance (identity proofing at registration) | Authentication assurance |
---|---|---|
Low | Present ID from authoritative source (remote or in-person) | Single factor (e.g., password or PIN) |
Substantial | • Present ID (remote or in-person) • ID verification performed by registration authority | Multi-factor (e.g., mobile phone + PIN) |
High | • In-person ID proofing at registration authority • ID verification using official government sources and documents | • Multi-factor • Must access private data/keys stored on tamper-resistant hardware token • Cryptographic protection of personally identifying information (PII) |
Formalising and implementing eID schemes: Notification and the eIDAS Network
Enabling interoperability of eID schemes of different Member States requires a method for managing and performing cross-border authentication, as well as a process for formalising eIDAS-approved eID schemes.
The process of formally approving an eID scheme is known as “notification”. Each Member State is responsible for notifying its own eID schemes, ensuring that they meet all the eIDAS security and quality requirements. (10) The process involves a peer review by Member States, and once the eID scheme has been officially added to the eIDAS Network (see below), EU Member States will be required to recognise it “no later than 12 months after the publication to the Official Journal of the European Union”. (11)
The technical infrastructure connecting the various eID schemes and means is known as the eIDAS Network. This network is based on a series of nodes (eIDAS-Nodes), which are implemented at the Member State level. In the context of an individual transaction, each node can both request and provide cross-border authentication.
Driving eID adoption, facilitating commerce
New eID schemes are gradually being developed and added to the eIDAS network. But businesses don’t have to wait for notification in order to benefit from the advantages of electronic identification, including meeting compliance requirements (at the national level), managing business risk and enhancing the customer experience.
The impact of eIDAS on commerce becomes clear when you consider the implications of a clear legal definition of eID throughout the EU. The eIDAS regulation:
- provides legislatures in Member States with a common legal framework when drafting laws governing electronic identity…
- …which in turn creates a stronger incentive for the development of eID schemes and means within each Member State, and
- provides businesses a recognised legal basis for offering their customers eID as a method for verifying their identity and authenticating themselves in a digital environment and signing documents that meet the eIDAS standard for Advanced and Qualified electronic signatures.
While the EC’s promotion of eIDAS stresses cross-border cooperation, note that electronic identification offers tremendous value even for businesses and customers within the same Member State. A good example is Sweden, one of a few Member States where electronic identification achieved wide adoption long before eIDAS.
Swedish BankID, an eID scheme and means developed by a group of large banks, was first issued in 2003. Recognised under Swedish law and widely trusted, BankID has 7.5 million regular users (73% of the population) who routinely use it to authenticate themselves online, authorise transactions and access public services.
BankID is also used for uniquely identifying the signatory when signing agreements. Although eID is not a mandatory element of a valid electronic signature, if signatories of a contract use BankID to uniquely identify themselves, the contract is considered to have been signed with an electronic signature on the advanced level, which has the equivalent legal effect of a handwritten signature in Sweden (i.e., a special legal effect). Due to the existing security infrastructure of BankID, there aren’t any types of contracts that require the use of a qualified electronic signature, which can only be obtained using an electronic signature solution fulfilling industry standards that are not technology-neutral.
Compliance and customer experience
To illustrate the importance of eIDAS for commerce, consider two big challenges facing today’s banking industry:
- Stricter compliance regulations
- Tighter competition
The Anti-Money Laundering Directive (AMLD) is an EU act affecting the banking and finance industry in particular. For example, new Know-Your-Customer (KYC) requirements now hold banks to a higher standard for identifying their customers. KYC includes verifying the identity of new customers and authenticating the identity of existing customers when accessing certain services.
At the same time, traditional banks are facing new competition from emerging players who are much better at offering the customer experience that today’s consumers expect: a digital experience, first and foremost.
The AMLD recognises multiple methods a bank can use to verify their customer’s identity, each involving trade-off’s such as time and expense to implement on the one hand versus the impact on the customer experience and brand. In-person ID check and eID are both compliant methods under the AMLD, but in terms of providing a modern customer experience, offering eID as a verification method is obviously preferable to requiring customers to pay a visit to a brick-and-mortar bank.
So what are the barriers to implementing eID? Institutional inertia and risk aversion probably top the list. Obtaining approval from internal legal counsel for new digital tools can be a formidable challenge. But not digitalising operations has risks of its own, especially in an increasingly competitive market.
One purpose of eIDAS is to help lower the barriers to digital commerce, which it does in this case by providing clear definitions and categories of electronic identification. The AMLD, in turn, refers to those definitions to specify the requirements for a compliant KYC check using eID. So a bank that wants to offer eID only needs to choose an eID means, with the required level of assurance, under a scheme that conforms to eIDAS. There’s no need to devote extensive legal and IT resources to ensure compliance.
Get eBook
Compliance & customer experience: it’s not a trade-off
Learn about agile strategies for regulated businesses to achieve both at scale. Spoiler: it’s not all about better technology.
Fill out the form to get your copy.
Conclusion
The eIDAS regulation constitutes a major step towards the vision of a Single Digital Market in the EU, fostering and hastening digital transformation in the public and private sectors. It’s key to understand that unlike laws that mandate and restrict behaviour, eIDAS is about enablement, setting legally-recognised standards for digital commerce and public services. With an EU-wide legal framework in place, legislatures at the EU and Member State levels have a common reference for drafting laws, making it easier for private enterprises to roll out new digital tools and services.