Digital Identity Management and library services access: preparing for the future

Pasqui, Valdo Digital Identity Management and library services access: preparing for the future. JLIS.it, 2025, vol. 16, n. 3, pp. 12-26. [Journal article (Paginated)]

[thumbnail of jlis_653_1.pdf]
Preview
Text
jlis_653_1.pdf - Published version
Available under License Creative Commons Attribution.

Download (175kB) | Preview

English abstract

Digital identities and their management systems are the core for the next generation ecosystem of trusted ("trusted") digital services. The European Parliament and the European Union Council have set themselves this objective with Regulation 910/2014 (eIDAS), updated in 2024, already transposed by Italy into the Code for Digital Administration (CAD). The architecture and reference framework specification started in 2021 and the ongoing implementations will lead to the adoption by 2026 of the European Digital Identity Wallet (EDIW), whose Italian instance (IT-Wallet) has been released in embryo as recent versions of the App-IO.  We are therefore on the eve of a significant transformation from the current way of managing digital identities and access to digital resources and services that will impact on libraries services too. After describing the concepts and methods of access control management and digital identity with some refererences to current libraries context, the paper describes the new decentralized model and examines some aspects of the transformation process that all stakeholders (decision-makers, operators and users) are called upon to be aware in order to assess the difficulties and seize the opportunities offered.

Italian abstract

Le identità digitali e i sistemi per la loro gestione sono il nucleo centrale per lo sviluppo di un ecosistema di servizi digitali affidabili (“trusted”). Il Parlamento Europeo e il Consiglio dell’Unione Europea si è posto questo obiettivo con il Regolamento 910/2014 (eIDAS), aggiornato nel 2024, già recepito dall’Italia nel Codice per l’Amministrazione Digitale (CAD). Fin dal 2021 è stata avviata la specifica dell’architettura e del framework di riferimento che con le implementazioni in corso porteranno entro il 2026 all’adozione del European Digital Identity Wallet (EDIW), Portafoglio Digitale dell’Identità, la cui istanza italiana (IT-Wallet) è stata rilasciata in embrione con le recenti versioni della App-IO. Siamo dunque alla vigilia di una significativa trasformazione rispetto alle attuali modalità di gestione delle identità digitali e dell’accesso alle risorse e ai servizi digitali che impatterà anche sui servizi bibliotecari. L’articolo, dopo aver descritto i concetti e le modalità di gestione del controllo dell’accesso e dell’identità digitale con alcuni riferimenti all’attuale contesto delle biblioteche, descrive il nuovo modello decentralizzato e esamina alcuni aspetti del processo di trasformazione sottolineando che tutti i soggetti coinvolti (decisori, operatori e utenti) sono chiamati a sviluppare la giusta consapevolezza per valutare le difficoltà e per cogliere le opportunità che si presentano.

Item type: Journal article (Paginated)
Keywords: eIDAS2; Digital Identity; Identity and access management; Library services; Identità Digitale; Controllo dell’accesso; Servizi bibliotecari
Date deposited: 15 Sep 2026 05:10
Last modified: 20 Sep 2026 22:24
URI: http://hdl.handle.net/10760/48994

References

BL (British Library). 2024. Learning lessons from the cyber-attack. British Library cyber incident review, 8 marzo. https://www.bl.uk/home/british-library-cyber-incident-review-8-march-2024.pdf/.

Clusit (Clusit - Associazione Italiana per la Sicurezza Informatica). 2025. Rapporto Clusit sulla Cybersecurity in Italia e nel mondo 2025. Astrea. https://clusit.it/wp-content/uploads/download/Rapporto_Clusit_03-2025_web.pdf.

Codice per l’amministrazione digitale. D.Lgs. 7 marzo 2005, n. 82 e successive modifiche. https://www.normattiva.it/uri-res/N2Ls?urn:nir:stato:decreto.legislativo:2005-03-07;82.

European Commission. 2024. CIR 2024/2977, Commission Implementing Regulation (EU) 2024/2977 of 28 November 2024 laying down rules for the application of Regulation (EU) No 910/2014 of the European Parliament and of the Council as regards person identification data and electronic attestations of attributes issued to European Digital Identity Wallets. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=OJ:L_202402977.

European Commission. 2025. European Digital Identity Wallet Architecture and Reference Framework. https://eu-digital-identity-wallet.github.io/eudi-doc-architecture-and-reference-framework/latest/.

European Parliament and Council. 2014. Regulation (EU) No 910/2014 of the European Parliament and of the Council of 23 July 2014 on electronic identification and trust services for electronic transactions in the internal market and repealing Directive 1999/93/EC. https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:02014R0910-20241018.

Grove, Jack. 2024. “How the British Library cyberattack disrupted research.” Times Higher Education, 21 novembre. https://www.timeshighereducation.com/depth/how-british-library-cyberattack-disrupted-research.

IETF (Internet Engineering Task Force). 2000. RFC 2798 Definition of the inetOrgPerson LDAP Object Class. http://tools.ietf.org/html/rfc2798.

IETF (Internet Engineering Task Force). 2006a. RFC 4519 Lightweight Directory Access Protocol (LDAP): Schema for User Applications. http://tools.ietf.org/html/rfc4519.

IETF (Internet Engineering Task Force). 2006b. RFC 4524 COSINE LDAP/X.500 Schema. http://tools.ietf.org/html/rfc4524.

IETF (Internet Engineering Task Force). 2012. The Oauth 2.0 Authorization Framework. Internet Engineering Task Force (IETF) Request for Comments 6749. https://datatracker.ietf.org/doc/html/rfc6749.

Kime, Chad. 2024. 6 Best Enterprise Password Managers for 2024. eSecurity Planet. https://www.esecurityplanet.com/products/best-password-managers/.

OASIS Open. 2008. Security Assertion Markup Language (SAML) V2.0 Technical Overview, OASIS Security Services TC Draft 02. http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-tech-overview-2.0.html.

OIDF (OpenID Foundation). 2023. OpenID Connect Core 1.0 incorporating errata set 2. https://openid.net/specs/openid-connect-core-1_0.html.

REFEDS (Research and Education FEDerations). 2022. SCHAC – SCHema for Academia. https://wiki.refeds.org/display/STAN/SCHAC.

REFEDS (Research and Education FEDerations). 2023. EduPerson Object Class Specification. https://wiki.refeds.org/display/STAN/eduPerson

W3C (World Wide Web Consortium). 2025. Verifiable Credentials Data Model v2.0. W3C Proposed Recommendation. https://www.w3.org/TR/vc-data-model-2.0/.


Downloads

Downloads per month over past year

Actions (login required)

View Item View Item