Collected research
Security Analysis of eIDAS — The Cross-Country Authentication Scheme in Europe
A security analysis of eIDAS, the cross-border electronic identity scheme European member states must recognise. Testing national eIDAS-Connector and eIDAS-Service implementations found XML attacks reaching them through SAML: 7 of 15 services were open to denial of service or server-side request forgery, and 5 let local files be read and sent to the attacker via XML external entities.
Record
- Published by
- USENIX
- Date
- Topic
- Identity
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of USENIX, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .