Securitylayer
The Securitylayer is a protocol that was originally developed to provide access to the Austrian Citizen Card (Bürgerkarte).
The complete specification is available at:
- german: https://sl.eid.egiz.gv.at/konzept/securitylayer/spezifikation/20140114/ (original)
- english: https://sl.eid.egiz.gv.at/konzept/securitylayer/spezifikation/20140114-en/
Since the introduction of the Securitylayer protocol, both the product and the legal framework have undergone several changes. The resulting adaptations for the Handy-Signatur, ID Austria, and EU-Identity products are described in the following document.
Handy-Signatur, ID Austria, and EU-Identity
Handy-Signatur, ID Austria, and EU-Identity are qualified remote signatures which are triggered via signature password and a second authenticating factor (e.g. cellphone).
Phonenumber, signature password and verification TAN must always be entered on A-Trust web pages starting with https://service.a-trust.at/mobile/, https://www.a-trust.at/mobile/.
Therefore it is not permitted to parse the web page or have it filled in automatically using a program/script. This is stated in the user agreement for the remote signature.
Local applications that utilize Handy-Signatur have to use a local web browser or a browser control to display the A-Trust page. see https://github.com/A-Trust/HandySignaturClientDemo
iframe sizes
The following iframe sizes have been tested explicitly:
- width 300px, height 300px (300x300)
- width 350px, height 350px (350x350) - recommended size
- width 450px, height 450px (450x450)