A Trust Service Model Adaptable to Various Assurance Levels by Linking Digital IDs and Certificates
Junichiro Hayata, Kenta Nomura, Yuta Takata, Hiroshi Kumagai, Masaki Kamizono, Tsuyoshi Kono, Yoshihiro Maeda, Naohisa Fukuda · 2024
Trust services based on regulations and guidelines such as those provided by eIDAS and NIST SP800-63 are rapidly proceeding toward the realization of sound electronic transactions. The assurance level of the entire service is determined by the assurance level of the trust service provider, identity verification, and authentication. For example, transactions in compliance with the law require identity authentication using digital certificates with a high level of assurance. However, since personal information is required for strict authentication, there is a privacy trade-off. Therefore, it is preferable to have the ability to use different digital certificates for different services depending on the appropriate assurance level and legal requirements. However, there are some practical issues, such as the inability to link services across multiple digital certificates and complexities involved in managing them. Therefore, this study proposes a trust service model that is adaptable to various assurance levels by defining replaceable service components. Specifically, users are issued multiple digital certificates with different assurance levels, which they can link with their digital ID, enabling certificate switching and flexible inter-service collaboration. This study introduces domestic examples based on this model, whereby the scalability of the services is studied in relation to passport identity verification.