EBA欧洲银行-EBA-Opinion-on-the-use-of-eIDAS-certificates-under-the-RTS-on-SCACSC_7页_398kb
报告摘要
EBA Opinion on the Use of eIDAS Certificates under the RTS on SCA and CSC
Introduction and Legal Basis
The European Banking Authority (EBA) issued this opinion to support the objectives of Directive (EU) 2015/2366 (PSD2), which aims to enhance competition, facilitate innovation, protect consumers, and improve security in the retail payments market. The EBA is tasked with developing regulatory technical standards (RTS) on strong customer authentication (SCA) and common and secure communication (CSC), which were published as Regulation (EU) 2018/389 and will apply from 14 September 2019.
Article 34(1) of the RTS mandates that payment service providers (PSPs) use qualified certificates for electronic seals (QSealCs) or website authentication (QWACs) for identification purposes. This opinion clarifies the use of these certificates in the context of the RTS and supervisory convergence across the EU/EEA.
Use of QSealCs or QWACs
- QSealC ensures the integrity and authenticity of data, allowing the recipient to verify the origin and that the data has not been altered.
- QWAC provides confidentiality, integrity, and authenticity of data during transport via TLS, but does not offer legal proof of transaction origin to third parties.
- The EBA outlines three possible approaches for using these certificates:
- Parallel use of QWACs and QSealCs – allows both identification and secure communication.
- Use of QWACs only – enables secure communication but not evidence of data origin.
- Use of QSealCs with an additional secure communication element – ensures identification but requires additional measures for secure communication.
The EBA recommends that competent authorities (CAs) encourage ASPSPs to use both types of certificates in parallel, although it clarifies that the use of eIDAS certificates is not mandatory for secure communication under the RTS.
Decision on Certificate Type by PSPs
- Article 34(1) of the RTS does not explicitly assign the responsibility of choosing certificate types to specific PSPs.
- The EBA clarifies that ASPSPs should be the ones deciding which type of eIDAS certificate to use, as they are responsible for providing the interface and ensuring communication security.
- ASPSPs must ensure that AISPs, PISPs, and CBPIIs can identify themselves using eIDAS certificates, either QSealC or QWAC, or preferably both.
Use of Single and Multiple eIDAS Certificates
- The RTS does not specify whether PSPs should use single or multiple certificates for the same role.
- The EBA states that PSPs can decide whether to use one or multiple certificates per role.
- In cases where services are provided through agents, EEA branches, or outsourced to technical service providers, multiple certificates are recommended to ensure business continuity and better risk management.
- The legitimacy of one certificate is not affected by the revocation of another, and PSPs remain fully responsible for their certificates and any acts of their agents or outsourced providers.
Roles of Payment Service Providers in eIDAS Certificates
-
The RTS specifies four roles that can be assigned to PSPs in eIDAS certificates:
- Account servicing – for ASPSPs maintaining payment accounts.
- Payment initiation – for PISPs initiating payments.
- Account information – for AISPs accessing account data.
- Issuing of card-based payment instruments – for CBPIIs issuing payment instruments.
-
Payment institutions and electronic money institutions must be authorised for each payment service they provide under Article 11 of PSD2.
-
Authorised credit institutions, however, can provide all payment services in Annex I to PSD2 under their general authorisation from Directive 2013/36/EU, without needing separate authorisations for each service.
CA Involvement in Certificate Revocation
-
The EBA outlines a standardised process for the exchange of notifications regarding eIDAS certificate issuance and revocation:
- Issuance: CAs should inform the EBA of an email address for receiving notifications from QTSPs.
- Revocation: PSPs must initiate revocation with QTSPs, and CAs should be notified accordingly.
- Revocation requested by a CA: If a CA withdraws authorisation/registration of a PSP, they may request the revocation of the eIDAS certificate from the QTSP.
-
CAs should not obtain information about the attributes of the actual certificates, but should update their national public registers, the EBA electronic central register, and the EBA Credit Institutions Register promptly when authorisation/registration status changes.
-
CAs are encouraged to proactively inform QTSPs of any changes in authorisation or registration status of PSPs.
Conclusion
This opinion provides clarity on the use of eIDAS certificates (QSealCs and QWACs) for identification and secure communication under the RTS on SCA and CSC. It outlines the roles of PSPs, the responsibilities of CAs, and the recommended practices for certificate management. The EBA emphasizes the importance of secure communication and identification while acknowledging the flexibility in certificate type and number.
试读结束,高清完整版pdf/doc/ppt,请点下载