{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T11:41:37Z","timestamp":1782992497155,"version":"3.54.5"},"reference-count":87,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T00:00:00Z","timestamp":1738022400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T00:00:00Z","timestamp":1738022400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["EURASIP J. on Info. Security"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>The European Digital Identity Wallet (EUDI Wallet) plays a pivotal role in shaping digital identity across the EU, necessitating a secure storage solution compliant with eIDAS2 regulation. In this study, we first analyze mobile secure storage solutions for the EUDI Wallet, identifying any gaps between current offerings and the EUDI Wallet\u2019s requirements. Our analysis indicates a significant shortfall in the availability of mobile native solutions, with only approximately 10.5% of mobile phones in the Italian market currently adhering to the stringent requirements mandated by eIDAS2. Consequently, we explore and evaluate alternative design solutions in terms of their feasibility and integration potential.<\/jats:p>","DOI":"10.1186\/s13635-025-00187-6","type":"journal-article","created":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T05:36:16Z","timestamp":1738042576000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Navigating secure storage requirements for EUDI Wallets: a review paper"],"prefix":"10.1186","volume":"2025","author":[{"given":"Zahra","family":"Ebadi\u00a0Ansaroudi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giada","family":"Sciarretta","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andrea","family":"De\u00a0Maria","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Silvio","family":"Ranise","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,1,28]]},"reference":[{"key":"187_CR1","doi-asserted-by":"crossref","unstructured":"Z.E. Ansaroudi, R. Carbone, G. Sciarretta, S. Ranise, in IFIP Annual Conference on Data and Applications Security and Privacy. Control is nothing without trust a first look into digital identity wallet trends (Springer, Cham, 2023), p. 113\u2013132","DOI":"10.1007\/978-3-031-37586-6_7"},{"issue":"2","key":"187_CR2","doi-asserted-by":"publisher","first-page":"381","DOI":"10.1365\/s40702-023-00954-4","volume":"60","author":"P Bastian","year":"2023","unstructured":"P. Bastian, M. Kraus, J. Fischer, Concepts for secure wallets in decentralized identity ecosystems. HMD Prax. Wirtschaftsinformatik 60(2), 381\u2013404 (2023)","journal-title":"HMD Prax. Wirtschaftsinformatik"},{"key":"187_CR3","first-page":"103607","volume":"78","author":"S Rana","year":"2023","unstructured":"S. Rana, F.K. Parast, B. Kelly, Y. Wang, K.B. Kent, A comprehensive survey of cryptography key management systems. J. Inf. Secur. Appl. 78, 103607 (2023)","journal-title":"J. Inf. Secur. Appl."},{"key":"187_CR4","doi-asserted-by":"publisher","first-page":"13898","DOI":"10.1109\/ACCESS.2019.2963480","volume":"8","author":"W Liu","year":"2020","unstructured":"W. Liu, X. Wang, W. Peng, State of the art: Secure mobile payment. IEEE Access 8, 13898\u201313914 (2020)","journal-title":"IEEE Access"},{"key":"187_CR5","doi-asserted-by":"crossref","unstructured":"M. Feiri, J. Petit, F. Kargl, in Proceedings of the 2013 ACM workshop on Security, privacy & dependability for cyber vehicles. Efficient and secure storage of private keys for pseudonymous vehicular communication (ACM, New York, 2013), p. 9\u201318","DOI":"10.1145\/2517968.2517972"},{"key":"187_CR6","doi-asserted-by":"publisher","first-page":"102327","DOI":"10.1016\/j.cose.2021.102327","volume":"108","author":"A Brand\u00e3o","year":"2021","unstructured":"A. Brand\u00e3o, J.S. Resende, R. Martins, Hardening cryptographic operations through the use of secure enclaves. Comput. Secur. 108, 102327 (2021)","journal-title":"Comput. Secur."},{"key":"187_CR7","unstructured":"European Commission: DG Communications Networks Content and Technology. Proposal for amending regulation (eu) no 910\/2014: European digital identity framework. (2021). https:\/\/eur-lex.europa.eu\/legal-content\/EN\/ALL\/?uri=COM:2021:281:FIN. Accessed Jan 2024"},{"key":"187_CR8","unstructured":"European Commission. European digital identity architecture and reference framework (version 1.4). (2024). https:\/\/eu-digital-identity-wallet.github.io\/eudi-doc-architecture-and-reference-framework\/1.4.0\/. Accessed Jan 2024"},{"issue":"3","key":"187_CR9","doi-asserted-by":"publisher","first-page":"219","DOI":"10.1007\/s41635-018-0046-1","volume":"3","author":"J Szefer","year":"2019","unstructured":"J. Szefer, Survey of microarchitectural side and covert channels, attacks, and defenses. J. Hardw. Syst. Secur. 3(3), 219\u2013234 (2019)","journal-title":"J. Hardw. Syst. Secur."},{"key":"187_CR10","doi-asserted-by":"crossref","unstructured":"M. Pernpruner, R. Carbone, S. Ranise, G. Sciarretta, in Proceedings of the Tenth ACM Conference on Data and Application Security and Privacy. The good, the bad and the (not so) ugly of out-of-band authentication with eid cards and push notifications: Design, formal and risk analysis (ACM, New York, 2020), p. 223\u2013234","DOI":"10.1145\/3374664.3375727"},{"key":"187_CR11","doi-asserted-by":"crossref","unstructured":"A. Sharif, F.A. Marino, G. Sciarretta, G. De Marco, R. Carbone, S. Ranise, in Proceedings of the 18th International Conference on Availability, Reliability and Security. Cross-domain sharing of user claims: A design proposal for openid connect attribute authorities (ACM, New York, 2023), p. 1\u201311","DOI":"10.1145\/3600160.3600183"},{"key":"187_CR12","unstructured":"Ministry of the Interior and Kingdom Relations. Nl wallet solution architecture version 1.0.3 draft. (2023). https:\/\/edi.pleio.nl\/file\/download\/e14fb720-26cf-4298-b376-1b464c6b4d75\/nlw-solution-architecture-sad-v1.pdf. Accessed May 2024"},{"key":"187_CR13","unstructured":"European Union, Eu regulation no 910\/2014 on electronic identification and trust services. Off. J. Eur. Union. 57(L 257), 73-114 (2014)"},{"key":"187_CR14","unstructured":"European Commission, Regulation (eu) 2024\/1183 of the european parliament and of the council of 11 april 2024 amending regulation (eu) no 910\/2014 as regards establishing the european digital identity framework. Off. J. Eur. Union (EU 2024\/1183), 1-56 (2024)"},{"key":"187_CR15","unstructured":"European Commission. Eu digital identity: 4 projects launched to test eudi wallet. (2023). https:\/\/digital-strategy.ec.europa.eu\/en\/news\/eu-digital-identity-4-projects-launched-test-eudi-wallet. Accessed Jun 2024"},{"key":"187_CR16","unstructured":"European Commission. European digital identity architecture and reference framework outline. (2022). https:\/\/ec.europa.eu\/transparency\/expert-groups-register\/core\/api\/front\/document\/73759\/download. Accessed May 2024"},{"key":"187_CR17","unstructured":"OpenID Foundation. OpenID for Verifiable Credentials - Specifications. https:\/\/openid.net\/sg\/openid4vc\/specifications\/. Accessed Dec 2024"},{"key":"187_CR18","unstructured":"ISO. ISO\/IEC 18013-5:2021 Personal identification - ISO-compliant driving licence - Part 5: Mobile driving licence (mDL) application. (2021). https:\/\/www.iso.org\/standard\/69084.html. Accessed Apr 2024"},{"key":"187_CR19","unstructured":"D. Fett, K. Yasuda, B. Campbell. Selective disclosure for jwts (sd-jwt) draft-ietf-oauth-selective-disclosure-jwt-07. (2023). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-oauth-selective-disclosure-jwt\/. Accessed Feb 2024"},{"key":"187_CR20","unstructured":"SOG-IS Crypto Working Group. Sog-is crypto evaluation scheme agreed cryptographic mechanisms. (2016). https:\/\/www.sogis.eu\/documents\/cc\/crypto\/obsolete\/SOGIS-Agreed-Cryptographic-Mechanisms-1.0.pdf. Accessed May 2024"},{"key":"187_CR21","unstructured":"Android Developers. Verify hardware-backed key pairs with key attestation. https:\/\/developer.android.com\/privacy-and-security\/security-key-attestation. Accessed Jan 2024"},{"key":"187_CR22","doi-asserted-by":"crossref","unstructured":"J. Schaad. Cbor object signing and encryption (cose): Structures and process. (2022). https:\/\/datatracker.ietf.org\/doc\/html\/rfc9052. Accessed May 2024","DOI":"10.17487\/RFC9052"},{"key":"187_CR23","unstructured":"Internet Assigned Numbers Authority. Json object signing and encryption (jose). (2015). https:\/\/www.iana.org\/assignments\/jose\/jose.xhtml. Accessed May 2024"},{"key":"187_CR24","doi-asserted-by":"crossref","unstructured":"M.B. Jones, J. Bradley, N. Sakimura. Json web signature (jws). (2015). https:\/\/datatracker.ietf.org\/doc\/html\/rfc7515. Accessed May 2024","DOI":"10.17487\/RFC7515"},{"key":"187_CR25","doi-asserted-by":"crossref","unstructured":"M.B. Jones, J. Hildebrand. Json web encryption (jwe). (2015). https:\/\/datatracker.ietf.org\/doc\/html\/rfc7516. Accessed May 2024","DOI":"10.17487\/RFC7516"},{"key":"187_CR26","doi-asserted-by":"crossref","unstructured":"M.B. Jones. Json web key (jwk). (2015). https:\/\/datatracker.ietf.org\/doc\/html\/rfc7517. Accessed May 2024","DOI":"10.17487\/RFC7517"},{"key":"187_CR27","unstructured":"Internet Assigned Numbers Authority. Cbor object signing and encryption (cose). (2017). https:\/\/www.iana.org\/assignments\/cose\/cose.xhtml#algorithms. Accessed May 2024"},{"key":"187_CR28","unstructured":"European Comission. The many use cases of eu digital identity wallets. https:\/\/ec.europa.eu\/digital-building-blocks\/sites\/display\/EUDIGITALIDENTITYWALLET\/The+many+use+cases+of+the+EU+Digital+Identity+Wallet. Accessed Dec 2024"},{"key":"187_CR29","unstructured":"The Open Web Application Security Project. Cryptographic storage cheat sheet. https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Cryptographic_Storage_Cheat_Sheet.html. Accessed May 2024"},{"key":"187_CR30","doi-asserted-by":"publisher","unstructured":"E. Barker. Nist special publication 800-57 part 1 revision 5- recommendation for key management. (2020). https:\/\/doi.org\/10.6028\/NIST.SP.800-57pt1r5","DOI":"10.6028\/NIST.SP.800-57pt1r5"},{"key":"187_CR31","unstructured":"European Commission. COMMISSION IMPLEMENTING REGULATION (EU) 2024\/2981 of 28 November 2024: laying down rules for the application of Regulation (EU) No 910\/2014 of the European Parliament and the Council as regards the certification of European Digital Identity Wallets. (2024). https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=OJ:L_202402981. Accessed Dec 2024"},{"key":"187_CR32","unstructured":"European Parliament and of the Council. Cybersecurity act: Regulation (eu) 2019\/881 of the european parliament and of the council of 17 april 2019 on enisa (the european union agency for cybersecurity) and on information and communications technology cybersecurity certification and repealing regulation (eu) no 526\/2013. (2019). https:\/\/eur-lex.europa.eu\/eli\/reg\/2019\/881\/oj. Accessed Jan 2024"},{"key":"187_CR33","unstructured":"ENISA. Eudi wallets certification: Recommendations for the certification of eudi wallets implementations in the short term (draft v 0.7). (2024). https:\/\/github.com\/eu-digital-identity-wallet\/eudi-doc-architecture-and-reference-framework\/blob\/main\/docs\/annexes\/annex-6\/annex-6-certification-requirements.pdf. Accessed May 2024"},{"key":"187_CR34","unstructured":"Agenzia per la Cybersicurezza Nazionale and Organismo di Certificazione della Sicurezza Informatica. Sogis mutual recognition agreement. https:\/\/www.ocsi.gov.it\/index.php\/organismo\/sogis-mra.html. Accessed 1 Mar 2024"},{"key":"187_CR35","unstructured":"Joint Interpretation Library. Composite product evaluation for smart cards and similar devices. (2020). https:\/\/www.ipa.go.jp\/en\/security\/jisec\/g6ovkg00000067p3-att\/JIL-Minimum-ITSEF-Requirements-SC&SD-v2-1.pdf. Accessed May 2024"},{"key":"187_CR36","unstructured":"ISO. Common criteria for information technology security evaluation. (2022). https:\/\/www.commoncriteriaportal.org\/cc\/index.cfm. Accessed Jan 2024"},{"key":"187_CR37","unstructured":"European Commission, Commission implementing regulation (eu) 2015\/1502 of 8 september 2015 on setting out minimum technical specifications and procedures for assurance levels for electronic identification means pursuant to article 8(3) of regulation (eu) no 910\/2014. Off. J. Eur. Union (EU 2015\/1502). 58(L 235), 7-20 (2015)"},{"key":"187_CR38","unstructured":"Cooperation Network. Guidance for the application of the levels of assurance which support the eidas regulation. (2024). https:\/\/prodstoragehoeringspo.blob.core.windows.net\/47e2ba75-9c1b-4387-945a-8a1995456e14\/LOA%20Guidance.pdf. Accessed Mar 2024"},{"key":"187_CR39","unstructured":"GlobalPlatform Technology. Tee protection profile version 1.3. (2020). https:\/\/globalplatform.org\/specs-library\/tee-protection-profile-v1-3\/. Accessed Jan 2024"},{"key":"187_CR40","unstructured":"D. Cater. Protection profile: Qualcomm trusted execution environment (tee) v5.8 on qualcomm snapdragon 865. (2021). https:\/\/www.tuv-nederland.nl\/assets\/files\/cerfiticaten\/2021\/08\/nscib-cc-0244671-cr-1.0.pdf. Accessed Jan 2024"},{"key":"187_CR41","unstructured":"ARM Limited. Arm security technology building a secure system using trustzone technology. (2009). http:\/\/infocenter.arm.com\/help\/topic\/com.arm.doc.prd29-genc-009492c\/PRD29-GENC-009492C_trustzone_security_whitepaper.pdf. Accessed 02 Aug 2016"},{"key":"187_CR42","doi-asserted-by":"publisher","first-page":"103180","DOI":"10.1016\/j.cose.2023.103180","volume":"129","author":"A Mu\u00f1oz","year":"2023","unstructured":"A. Mu\u00f1oz, R. R\u00edos, R. Rom\u00e1n, J. L\u00f3pez, A survey on the (in)security of trusted execution environments. Comput. Secur. 129, 103180 (2023). https:\/\/doi.org\/10.1016\/j.cose.2023.103180","journal-title":"Comput. Secur."},{"key":"187_CR43","first-page":"1","volume":"18","author":"R Stajnrod","year":"2021","unstructured":"R. Stajnrod, R.B. Yehuda, N.J. Zaidenberg, Attacking trustzone on devices lacking memory protection. J. Comput. Virol. Hacking Tech. 18, 1\u201311 (2021)","journal-title":"J. Comput. Virol. Hacking Tech."},{"key":"187_CR44","unstructured":"Apple Inc. Secure enclave. (2024). https:\/\/support.apple.com\/guide\/security\/secure-enclave-sec59b0b31ff\/web. Accessed Jun 2024"},{"key":"187_CR45","unstructured":"Google Security Blog. Google pixel 7 and pixel 7 pro: The next evolution in mobile security. (2022). https:\/\/security.googleblog.com\/2022\/10\/google-pixel-7-and-pixel-7-pro-next.html#:~:text=Pixel%207%20and%20Pixel%207%20Pro%20have%20built%2Din%20anti,than%20smartphones%20from%20leading%20competitors. Accessed Feb 2024"},{"key":"187_CR46","unstructured":"Samsung Electronics. S3k250a\/s3k232a\/s3k212a 32-bit risc microcontroller for smart card with optional at1 secure libraries including specific ic dedicated software. (2019). https:\/\/www.commoncriteriaportal.org\/files\/epfiles\/anssi-cible-cc-2019_61en.pdf. Accessed Jan 2024"},{"key":"187_CR47","unstructured":"Samsung. Knox vault. https:\/\/docs.samsungknox.com\/admin\/fundamentals\/whitepaper\/samsung-knox-for-android\/core-platform-security\/knox-vault\/#strongbox-keymaster-support. Accessed Jan 2024"},{"key":"187_CR48","unstructured":"Samsung. Devices secured by knox. https:\/\/www.samsungknox.com\/en\/knox-platform\/supported-devices. Accessed 6 Mar 2024"},{"key":"187_CR49","unstructured":"Android Developers. Android keystore system. https:\/\/developer.android.com\/privacy-and-security\/keystore. Accessed 9 Mar 2024"},{"key":"187_CR50","unstructured":"ENISA. Cybersecurity certification-eucc, a candidate cybersecurity certification scheme to serve as a successor to the existing sog-is. (2021). https:\/\/www.enisa.europa.eu\/publications\/cybersecurity-certification-eucc-candidate-scheme-v1-1.1. Accessed Jan 2024"},{"key":"187_CR51","unstructured":"eidasv2 - where are we heading with digital identities? (2023). https:\/\/www.enisa.europa.eu\/events\/cybersecurity_standardisation_2023\/presentations. Accessed Jan 2024"},{"key":"187_CR52","unstructured":"Statcounter Global Stats. Mobile vendor market share italy- december 2023. (2023). https:\/\/gs.statcounter.com\/vendor-market-share\/mobile\/italy\/2023. Accessed Mar 2024"},{"key":"187_CR53","unstructured":"J. Lopez. Canalys: In q1 2023, global high-end smartphones will grow by 4.7%. (2023). https:\/\/www.techgoing.com\/canalys-in-q1-2023-global-high-end-smartphones-will-grow-by-4-7\/. Accessed Feb 2024"},{"key":"187_CR54","unstructured":"Kantar. Google pixel celebrates a record global quarter. (2023). https:\/\/www.kantar.com\/north-america\/inspiration\/technology\/google-pixel-celebrates-a-record-global-quarter. Accessed Jan 2024"},{"key":"187_CR55","unstructured":"Kantar. Android vs. ios- smartphone os sales market share evolution in q4 2022. https:\/\/www.kantar.com\/campaigns\/smartphone-os-market-share. Accessed Jan 2024"},{"key":"187_CR56","unstructured":"Statcounter Global Stats. Mobile operating system market share italy- december 2023. (2023). https:\/\/gs.statcounter.com\/os-market-share\/mobile\/italy. Accessed Jan 2024"},{"key":"187_CR57","unstructured":"T\u00dcV Rheinland Nederland B.V. Certification report kinibi-510a -v007. (2022). https:\/\/www.commoncriteriaportal.org\/files\/epfiles\/NSCIB-CC-0291872-CR.pdf. Accessed Mar 2024"},{"key":"187_CR58","unstructured":"Google LLC. Google pixel devices on android 13- security target. (2023). https:\/\/www.niap-ccevs.org\/MMO\/Product\/st_vid11317-st.pdf. Accessed Feb 2024"},{"key":"187_CR59","unstructured":"FIDO Alliance. Fido recognition for european digital identity systems and eidas grows. (2021). https:\/\/fidoalliance.org\/fido-recognition-for-european-digital-identity-systems-and-eidas-grows\/. Accessed Jan 2024"},{"key":"187_CR60","unstructured":"Samsung. Whitepaper: Samsung knox version 1.5. (2021). https:\/\/image-us.samsung.com\/SamsungUS\/samsungbusiness\/solutions\/topics\/iot\/071421\/Knox-Whitepaper-v1.5-20210709.pdf. Accessed Feb 2024"},{"key":"187_CR61","unstructured":"National Institute of Standards and Technology. C1078 cryptographic algorithm validation program for s3k250af. (2019). https:\/\/csrc.nist.gov\/projects\/cryptographic-algorithm-validation-program\/details?validation=31475. Accessed Feb 2024"},{"key":"187_CR62","unstructured":"GlobalPlatform Technology. Secure element protection profile version 0.0.0.21 (target v1.0). (2020). https:\/\/globalplatform.org\/wp-content\/uploads\/2020\/01\/GPC_SE_PP_v0.0.0.21_PublicRvw.pdf. Accessed Feb 2024"},{"key":"187_CR63","unstructured":"GSMA. Embedded sim remote provisioning architecture version 4.1. (2020). https:\/\/www.gsma.com\/esim\/wp-content\/uploads\/2020\/06\/SGP.01-v4.1.pdf. Accessed Feb 2024"},{"key":"187_CR64","unstructured":"GSMA. esim whitepaper: The what and how of remote sim provisioning. (2018). https:\/\/www.gsma.com\/esim\/wp-content\/uploads\/2018\/12\/esim-whitepaper.pdf. Accessed Feb 2024"},{"key":"187_CR65","unstructured":"Federal Office for Information Security. Bsi-dsz-cc-0963-v3-2021 for infineon smartcard ic (security controller) m7791 b12 with specific ic-dedicated firmware from infineon technologies ag. (2021). https:\/\/www.commoncriteriaportal.org\/files\/epfiles\/0963V3a_pdf.pdf. Accessed Feb 2024"},{"key":"187_CR66","unstructured":"Cyber Security Agency of Singapore. Thales luna k7 cryptographic module. (2022). https:\/\/csrc.nist.gov\/CSRC\/media\/projects\/cryptographic-module-validation-program\/documents\/security-policies\/140sp3205.pdf. Accessed Feb 2024"},{"key":"187_CR67","unstructured":"Organismo di Certificazione della Sicurezza Informatica. Trident version 2.1.3 protection profile. (2020). https:\/\/www.ocsi.gov.it\/documenti\/certificazioni\/i4p\/cr_trident_213_v1.0_en.pdf. Accessed Feb 2024"},{"key":"187_CR68","unstructured":"Briefing Centre. B.est solutions developed a unique esim-based mobile-id. (2023). https:\/\/e-estonia.com\/b-est-solutions-developed-a-unique-esim-based-mobile-id\/. Accessed Mar 2024"},{"key":"187_CR69","unstructured":"Mobilise. esim adoption statistics. (2023). https:\/\/www.mobiliseglobal.com\/50-esim-statistics-in-2023\/. Accessed Jan 2024"},{"key":"187_CR70","unstructured":"Z. Chen, Java card technology for smart cards: architecture and programmer\u2019s guide (Addison-Wesley, Boston, 2000)"},{"key":"187_CR71","unstructured":"FIDO Alliance. Companion programs. https:\/\/fidoalliance.org\/certification\/authenticator-certification-levels\/fido-authenticator-certification-companion-program\/. Accessed Jan 2024"},{"key":"187_CR72","unstructured":"OpenID Connect Workgroup. Openid for verifiable credential issuance. (2022). https:\/\/openid.net\/specs\/openid-4-verifiable-credential-issuance-1_0.html. Accessed Jan 2024"},{"key":"187_CR73","unstructured":"E. Vetillard.\u00a0Certification for EU Digital Identity Wallets.\u00a0Presented at the ETSI\/CEN Workshop on EU Digital Identity Framework Standards\u00a0(Sophia Antipolis, 2024). https:\/\/lnkd.in\/eXyhFk66. Accessed Dec 2024"},{"key":"187_CR74","unstructured":"J. Kjaersgaard.\u00a0CEN: Protection Profile for WSCA.\u00a0Presented at the ETSI\/CEN Workshop on EU Digital Identity Framework Standards\u00a0(Sophia Antipolis, 2024). https:\/\/lnkd.in\/eXyhFk66.\u00a0Accessed Dec 2024"},{"key":"187_CR75","doi-asserted-by":"crossref","unstructured":"K. Shiba, H. Kuzuno, T. Yamauchi, in 2023 Eleventh International Symposium on Computing and Networking Workshops (CANDARW). Prevention method for stack buffer overflow attack in ta command calls in op-tee (IEEE, Piscataway, 2023), p. 274\u2013278","DOI":"10.1109\/CANDARW60564.2023.00052"},{"key":"187_CR76","unstructured":"Y. Chen, Y. Zhang, Z. Wang, T. Wei, Downgrade attack on trustzone. (2017). arXiv preprint arXiv:1707.05082. https:\/\/arxiv.org\/abs\/1707.05082. Accessed Mar 2024"},{"key":"187_CR77","unstructured":"A. Joy, B. Soh, Z. Zhang, S. Parameswaran, D. Jayasinghe, Physical and software based fault injection attacks against tees in mobile devices: A systemisation of knowledge. arXiv preprint. (2023). https:\/\/arxiv.org\/abs\/arXiv:2411.14878. Accessed Mar 2024"},{"key":"187_CR78","unstructured":"Utimaco. esim security concerns and how to solve them with hardware security modules. (2023). https:\/\/utimaco.com\/news\/blog-posts\/esim-security-concerns-and-how-solve-them-hsms. Accessed Mar 2024"},{"key":"187_CR79","doi-asserted-by":"crossref","unstructured":"D. Melotti, M. Rossi-Bellom, A. Continella, in Reversing and Offensive-oriented Trends Symposium. Reversing and fuzzing the google titan m chip (ACM, New York, 2021), p. 1\u201310","DOI":"10.1145\/3503921.3503922"},{"key":"187_CR80","doi-asserted-by":"crossref","unstructured":"M. Sommerhalder, Hardware security module. Trends in Data Protection and Encryption Technologies (Springer, Cham, 2023), p. 83\u201387","DOI":"10.1007\/978-3-031-33386-6_16"},{"issue":"24","key":"187_CR81","doi-asserted-by":"publisher","first-page":"9664","DOI":"10.3390\/s22249664","volume":"22","author":"C Zakaret","year":"2022","unstructured":"C. Zakaret, N. Peladarinos, V. Cheimaras, E. Tserepas, P. Papageorgas, M. Aillerie, D. Piromalis, K. Agavanakis, Blockchain and secure element, a hybrid approach for secure energy smart meter gateways. Sensors 22(24), 9664 (2022)","journal-title":"Sensors"},{"key":"187_CR82","doi-asserted-by":"crossref","unstructured":"R. Nagy, M. Bak, D. Papp, L. Butty\u00e1n, in International ISCIS Security Workshop. T-raid: Tee-based remote attestation for iot devices. (Springer, Cham, 2021)","DOI":"10.1007\/978-3-031-09357-9_7"},{"issue":"1","key":"187_CR83","doi-asserted-by":"publisher","first-page":"609","DOI":"10.1007\/s12652-021-03316-4","volume":"14","author":"S Bojjagani","year":"2023","unstructured":"S. Bojjagani, V. Sastry, C.M. Chen, S. Kumari, M.K. Khan, Systematic survey of mobile payments, protocols, and security infrastructure. J. Ambient Intell. Humanized Comput. 14(1), 609\u2013654 (2023)","journal-title":"J. Ambient Intell. Humanized Comput."},{"key":"187_CR84","unstructured":"GlobalPlatform, Globalplatform technology: The cornerstone of trust and interoperability for the european union digital identity wallet (2023). https:\/\/globalplatform.org\/resource-publication\/the-cornerstone-of-trust-and-interoperability-for-the-european-union-digital-identity-wallet\/. Accessed Jan 2024"},{"key":"187_CR85","unstructured":"ENISA. Eu digital identity wallet: A leap towards secure and trusted electronic identification through certification. https:\/\/www.enisa.europa.eu\/news\/eu-digital-identity-wallet-a-leap-towards-secure-and-trusted-electronic-identification-through-certification?utm_source=chatgpt.com#contentList (2024)"},{"key":"187_CR86","unstructured":"SpearIT. Remote key attestation. https:\/\/spearit.net\/services\/remote-key-attestation. Accessed 10 Mar 2024"},{"key":"187_CR87","unstructured":"M. Ounsworth, H. Tschofenig, H. Birkholz. Use of remote attestation with certificate signing requests draft-ietf-lamps-csr-attestation-08. (2023). https:\/\/datatracker.ietf.org\/doc\/draft-ietf-lamps-csr-attestation\/. Accessed Mar 2024"}],"container-title":["EURASIP Journal on Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00187-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s13635-025-00187-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s13635-025-00187-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T05:36:44Z","timestamp":1738042604000},"score":1,"resource":{"primary":{"URL":"https:\/\/jis-eurasipjournals.springeropen.com\/articles\/10.1186\/s13635-025-00187-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,28]]},"references-count":87,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["187"],"URL":"https:\/\/doi.org\/10.1186\/s13635-025-00187-6","relation":{},"ISSN":["2510-523X"],"issn-type":[{"value":"2510-523X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,28]]},"assertion":[{"value":"30 June 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 January 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 January 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"All authors reviewed and approved the manuscript for the publication.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"Non-financial interests: Giada Sciarretta and Silvio Ranise are guest editors for this special issue \u201cTrends in Digital Identity: Security, Privacy, and Trust\u201d of the EURASIP Journal on Information Security.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"2"}}