Security Analysis of eIDAS – The Cross-CountryAuthentication Scheme in Europe

Nils Engelbertz, Nurullah Erinola, Herring, David, Juraj Somorovsky, Vladislav Mladenov, Jörg Schwenk · Zenodo (CERN European Organization for Nuclear Research) · 2020

In 2014, the European Commission released the eIDASregulation to target the compatibility of cross-country electronic services within the European Union. eIDAS (electronic IDentification, Authentication, and Trust Services) defines implementation standards and technologies for electronic signatures, digital certificates, SingleSign-On (SSO), and trust services. It is based on well-established standards, such as SAML, to achieve highsecurity and compatibility between EU countries.In this paper, we present the first security study of authentication schemes used in eID services. Our security analysis shows that 7 of the 15 European eID services were vulnerable to XML-based attacks which enabled efficient Denial-of-Service (DoS) and Server Side Request Forgery (SSRF) attacks. On 5 of the 15 eID services, we were even able to exfiltrate locally stored files and send these files to an arbitrary domain. To support the developers and security teams of eID services,we implemented a Burp Suite extension to execute fully-automated or semi-automated tests. Additionally, we summarize best practices related to eID-based authentication and SSO in general.

Read the paper · More papers on PaperTik