Project No.prCEN/TS 18098-2 rev
TitleThis document describes the requirements to be met for the user identification and authentication used in the on-boarding workflow described in part 1 of this series so that the on-boarding reaches the Level of Assurance “High”. In addition, this document also proposes recommendations to be applied. For each requirement and recommendation, this document identifies the role(s) responsible for its fulfilment and provides explanations and possible way to implement it, where applicable. More precisely, this part covers the following User identification and authentication operations: • identification and authentication of User to Wallet Unit to protect and use PID keys, • identification and authentication of the User to the PID Provider when requesting PID. This is relevant for the “Identity proofing & Wallet Unit credentials binding”, • identification and authentication of the Subject and binding with the User requesting a PID. This is relevant for the “Identity proofing & Wallet Unit credentials binding”. The User identification and authentication operations in relation to the User Account and the User identification and authentication operations to the Wallet Unit to access the Wallet Unit (excluding the use of PID keys) are not covered by this document but are covered in part 3. In addition, the use of the Wallet Unit by the User to identify and authenticate itself to a third party (e.g. a Relying Party) is not covered by this document and series as it is out of scope of the on-boarding process.
Registration number (WIID)84570
ScopeThis document describes the requirements to be met for the user identification and authentication used in the on-boarding workflow described in part 1 of this series so that the on-boarding reaches the Level of Assurance “High”. In addition, this document also proposes recommendations to be applied. For each requirement and recommendation, this document identifies the role(s) responsible for its fulfilment and provides explanations and possible way to implement it, where applicable. More precisely, this part covers the following User identification and authentication operations: • identification and authentication of User to Wallet Unit to protect and use PID keys, • identification and authentication of the User to the PID Provider when requesting PID. This is relevant for the “Identity proofing & Wallet Unit credentials binding”, • identification and authentication of the Subject and binding with the User requesting a PID. This is relevant for the “Identity proofing & Wallet Unit credentials binding”. The User identification and authentication operations in relation to the User Account and the User identification and authentication operations to the Wallet Unit to access the Wallet Unit (excluding the use of PID keys) are not covered by this document but are covered in part 3. In addition, the use of the Wallet Unit by the User to identify and authenticate itself to a third party (e.g. a Relying Party) is not covered by this document and series as it is out of scope of the on-boarding process.
StatusIzstrādē
ICS groupNot set