[{"data":1,"prerenderedAt":82},["ShallowReactive",2],{"news-cybernetica-completes-the-s-po-f2-3-research-project":3},{"articles":4},[5],{"documentId":6,"title":7,"slug":8,"createdAt":9,"publishingDate":10,"description":10,"content":11,"quote":12,"postAuthor":10,"thumbnail":15,"relatedProducts":10,"industry":66,"relatedPosts":71,"metaData":72},"szu8kk2o3bh4nzko23lc874e","Cybernetica completes the SPoF2.3 research project","cybernetica-completes-the-s-po-f2-3-research-project","2023-01-10T11:47:18.000Z",null,"SPoF (Single Point of Failure) was the initial research conducted in 2019-2020. This fault tolerance analysis pointed at the weak links in the eID infrastructure in the Estonian eID ecosystem that could have affected many users. The main weakness identified was the amount of various authentication protocols that are in use in Estonia.\nFollowing this finding, two further researches were carried out. SPoF2.1 studied the authentication tools and services used in Estonia to find out whether it would be possible to harmonise their API and how to avoid man-in-the-middle attacks. SPoF2.2 examined how to reduce the dependence on the validity confirmation service and to ensure the functionality in a situation where the validity confirmation service does not work.\n\nThis brings us to SPoF2.3. The project consisted of two parts – analysis and recommendation.\nIn the first part, we collected and systematised material on crises related to Certificate Authorities, chains of trust, trust lists, and analysed differences of trust models based on their technical and legal aspects. In the second part, we developed a recommendation for a suitable eID trust model for Estonia with all the necessary technical descriptions.\nWe asked Peeter Laud, our Senior Researcher in this project let us in on the details of the research.\n\n**What was the objective of this research?**\n\nThe project was about analysing and constructing trust models for the distribution of public keys used for authentication and signing. Our society is highly dependent on the functioning of public key infrastructure (PKI) – a system for distributing public keys. Hence, we want its implementation and deployment to be robust. The notion of robustness includes the lack of single points of failure, at least in those parts of the system with higher integrity and availability expectations.\nIn Estonia, the current deployment of PKI is very much dependent on a single entity. The failure of this entity could mean that our public key certificates can no longer be trusted, we can no longer log into service providers' information systems relying on this PKI, and the digital signatures we have issued may lose their meaning. While this entity has so far executed its duties commendably, its position as a SPoF is worrying. We should add more redundancy to our PKI, but the necessary changes should not break existing systems.\n\n**Please describe the most notable findings.**\n\nWe were looking at improvements that could be implemented without breaking existing systems. Existing systems implement existing standards and follow existing laws, they body of which has been built up over almost thirty years. It is difficult to change laws and standards, especially the latter. The existing standards have painted us into a corner: in order to implement them, we have to introduce SPoF-s with respect to integrity properties, and almost introduce SPoF-s with respect to availability properties. The existing laws appear to be more permissive in capturing various trust models.\nNevertheless, we provide suggestions on how to reduce the effect of failures on the availability of the PKI. We show, how certain redundancy can be fit with the existing standards, while keeping the increase of costs of running the system under control.\nOur work also produced a couple of significant systematizations. It gave a thorough overview of various incidents that have taken place in certification authorities over the last 20+ years. It also presented various trust models in a unified manner, simplifying their comparison.\n\n**Are the findings being already considered to be put into use in the eID systems?**\n\nNot yet. The results of the project were not about single eID systems, but rather about the configuration of the infrastructure.\nHowever, the suggestions that we made during the project should be implemented and deployed. The necessary work will be a project, but perhaps it will be run internally by RIA (Estonian Information System Authority).\n\n**What should the next researches be about considering the current findings?**\n\nTrust models should be further formalized, compared with each other, extended with models of various kinds of actors.\n",{"content":13,"author":14,"jobTitle":10,"profileImage":10},"Our work produced a couple of significant systematizations. It gave a thorough overview of various incidents that have taken place in certification authorities over the last 20+ years. It also presented various trust models in a unified manner, simplifying their comparison.","Peeter Laud",{"featuredImage":16},{"documentId":17,"url":18,"alternativeText":19,"width":20,"height":21,"formats":22,"mime":27},"jjbe9gn21j5ope0h7dg2dge2","\u002Fuploads\u002Fhelena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a.jpg","People using laptops",4000,2000,{"large":23,"small":32,"medium":38,"xlarge":45,"xsmall":52,"thumbnail":59},{"ext":24,"url":25,"hash":26,"mime":27,"name":28,"path":10,"size":29,"width":30,"height":31},".jpg","\u002Fuploads\u002Flarge_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a.jpg","large_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a","image\u002Fjpeg","large_helena-lopes-2MBtXGq4Pfs-unsplash.jpg",67.58,1000,500,{"ext":24,"url":33,"hash":34,"mime":27,"name":35,"path":10,"size":36,"width":31,"height":37},"\u002Fuploads\u002Fsmall_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a.jpg","small_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a","small_helena-lopes-2MBtXGq4Pfs-unsplash.jpg",24.62,250,{"ext":24,"url":39,"hash":40,"mime":27,"name":41,"path":10,"size":42,"width":43,"height":44},"\u002Fuploads\u002Fmedium_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a.jpg","medium_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a","medium_helena-lopes-2MBtXGq4Pfs-unsplash.jpg",44.17,750,375,{"ext":24,"url":46,"hash":47,"mime":27,"name":48,"path":10,"size":49,"width":50,"height":51},"\u002Fuploads\u002Fxlarge_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a.jpg","xlarge_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a","xlarge_helena-lopes-2MBtXGq4Pfs-unsplash.jpg",170.23,1920,960,{"ext":24,"url":53,"hash":54,"mime":27,"name":55,"path":10,"size":56,"width":57,"height":58},"\u002Fuploads\u002Fxsmall_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a.jpg","xsmall_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a","xsmall_helena-lopes-2MBtXGq4Pfs-unsplash.jpg",1.35,64,32,{"ext":24,"url":60,"hash":61,"mime":27,"name":62,"path":10,"size":63,"width":64,"height":65},"\u002Fuploads\u002Fthumbnail_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a.jpg","thumbnail_helena_lopes_2_M_Bt_X_Gq4_Pfs_unsplash_d01f1d5c2a","thumbnail_helena-lopes-2MBtXGq4Pfs-unsplash.jpg",8.44,245,123,{"title":67,"slug":68,"icon":69},"R&D","randd",{"icon":70},"r_and_d",[],{"metaTitle":7,"metaDescription":73,"shareImage":74},"The completion of the SPoF2.3 research. Explore the outcomes and contributions to advancing the state-of-the-art in security of Estonian digital identity solution.",{"formats":75},{"large":76,"small":77,"medium":78,"xlarge":79,"xsmall":80,"thumbnail":81},{"ext":24,"url":25,"hash":26,"mime":27,"name":28,"path":10,"size":29,"width":30,"height":31},{"ext":24,"url":33,"hash":34,"mime":27,"name":35,"path":10,"size":36,"width":31,"height":37},{"ext":24,"url":39,"hash":40,"mime":27,"name":41,"path":10,"size":42,"width":43,"height":44},{"ext":24,"url":46,"hash":47,"mime":27,"name":48,"path":10,"size":49,"width":50,"height":51},{"ext":24,"url":53,"hash":54,"mime":27,"name":55,"path":10,"size":56,"width":57,"height":58},{"ext":24,"url":60,"hash":61,"mime":27,"name":62,"path":10,"size":63,"width":64,"height":65},1788355407745]