PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 25, 2026Computers & Security0 citationsOpen Access

A provider-agnostic security framework for PKI-based electronic identity systems: A Swedish case study

View Full Paper
QWQinghua WangKristianstad UniversityOZOmar ZarifaKristianstad UniversityNKNedim KanatKristianstad University

Key Points

  • The aim is to create a provider-agnostic security framework for PKI-based electronic identity systems and apply it to Swedish deployments.
  • Developed a security framework for PKI-based electronic identity systems.
  • Formalized user journeys as state-machine models and derived security invariants.
  • Evaluated platform features and relying-party integrations to analyze compliance with security invariants.
  • Both examined eID ecosystems utilize robust PKI foundations and support the defined security invariants.
  • Real-world issues stem from intent deception, lifecycle abuse, and integration weaknesses rather than cryptographic failures.
  • The framework can be applied to analyze and evaluate other PKI-based electronic identity systems.

Abstract

This article develops a provider-agnostic security framework for public key infrastructure (PKI)-based electronic identity (eID) systems and applies it to two mature Swedish deployments, BankID and Freja eID. We formalize the canonical user journeys—same-device and cross-device authentication and signing—as compact state-machine models, including a middleware variant. From these models, we derive three protocol-level invariants that govern semantically correct execution: freshness of challenges and results, strict session/origin binding, and dynamic linking of user-approved authorization content. We then evaluate how platform features and relying-party integrations enforce these invariants and analyze documented incidents through the same lens. The results show that both ecosystems rely on robust PKI foundations and provide the technical means to satisfy the invariants; real-world harm arises primarily from intent deception, lifecycle abuse, integration weaknesses, and incomplete verifier-side enforcement rather than cryptographic failure. The proposed framework explains these patterns, clarifies which controls are essential, and offers a reusable analytical tool applicable beyond the Swedish context to other PKI-based electronic identity systems. • A provider-agnostic eID operation model is formalized using state machines. • Three security invariants are derived from a structured attacker taxonomy. • A unified threat–invariant–control mapping clarifies end-to-end eID risks. • Real incidents are interpreted through protocol invariants and governance properties, not cryptographic breakage. • The framework generalizes to PKI-based national eID systems and supports future design evaluation.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Wang et al. (2026) studied this question.

synapsesocial.com/papers/69ec598788ba6daa22dab517https://doi.org/10.1016/j.cose.2026.104936
Ask AI
Helpful
Bookmark
Share
View Full Paper