Identity provider (IdP)
Provision of own electronic identities (internal identity providers AGOV, CH-LOGIN, SG-PKI, Kerberos, MDM)
- AGOV:
- eIAM provides the electronic identity www.agov.ch for citizens and business representatives in Switzerland and abroad. AGOV identities are available in self-registered (unverified) and verified quality. Cantons and their municipalities can use the eIAM identity provider "AGOV" by directly connecting their applications or IAM systems to AGOV. The Federal Administration uses AGOV exclusively through the "eIAM" IAM system.
- CH-LOGIN:
- CH-LOGIN is the predecessor of AGOV. It is still operated in parallel with AGOV for the time being but will be phased out step by step.
- FED-LOGIN using Smartcard (SG-PKI):
- Employees of the Federal Administration and SG-PKI affiliates from cantons and municipalities use FED-LOGIN with the SG-PKI smartcard in the enterprise context for authentication at the highest security level.
- FED-LOGIN with Active Directory:
- Employees of the Federal Administration using their personal office automation devices within the Federal Administration networks use FED-LOGIN with Active Directory Single Sign-On in the enterprise context.
- FED-LOGIN without Smartcard:
- Employees of the Federal Administration and affiliates from cantons and municipalities can use their SG-PKI smartcard to register complementary credentials (FED-LOGIN Access App or FIDO2 security keys) and subsequently use them for FED-LOGIN authentication. This enables FED-LOGIN to be used from the Internet, on devices without a smartcard reader, and on mobile devices (tablets and smartphones).
- FED-LOGIN totally Smartcardless:
- Employees of the Federal Administration who are not intended to receive a smartcard have access to a process for registering complementary credentials (FED-LOGIN Access App or FIDO2 security keys) and subsequently using them for FED-LOGIN authentication.
- MDM:
- Electronic identities of Federal Administration employees can also be provided without using a smartcard through Citrix Secure Hub, which is deployed as a sandbox on iOS devices as part of the Federal Administration's Mobile Device Management (MDM). Web applications running in the sandbox browser (Citrix Secure Web Browser) as well as native mobile apps within this sandbox automatically receive these identity attributes, allowing employees to access them without performing a login. In this scenario, access to the sandbox itself, handled by the local security mechanisms of the iOS device, serves as the authentication and identity proof for the automatic, invisible in-sandbox authentications. This method of identity provisioning results in a reduced assurance level for the conveyed subject-identifying attributes.
Note
An MDM-integrated device can only be registered in one operating environment (stage). Therefore, a device registered in the MDM PROD environment cannot access integrated applications in the REF or ABN environments, and vice versa. If a resource in the ABN environment is to be accessed using the Secure Web Browser, the device must also be registered in the MDM ABN environment.
- Electronic identities of Federal Administration employees can also be provided without using a smartcard through Citrix Secure Hub, which is deployed as a sandbox on iOS devices as part of the Federal Administration's Mobile Device Management (MDM). Web applications running in the sandbox browser (Citrix Secure Web Browser) as well as native mobile apps within this sandbox automatically receive these identity attributes, allowing employees to access them without performing a login. In this scenario, access to the sandbox itself, handled by the local security mechanisms of the iOS device, serves as the authentication and identity proof for the automatic, invisible in-sandbox authentications. This method of identity provisioning results in a reduced assurance level for the conveyed subject-identifying attributes.