Skip to main content

Security Architecture

This section provides consolidated architecture documentation for SIROS ID, formalizing the security properties described in individual controls into cross-cutting architecture views.

Each document addresses one or more compliance findings and maps implemented mechanisms to specific framework requirements (EUDI ECCG Security Requirements, ISO 27001 Annex A).

Documents

DocumentFrameworkSummary
Cryptographic Asset InventoryGEN-7.3.2-02, GEN-7.5-02/03, WIN-8.4.4-02All cryptographic keys, algorithms, and protection levels
Wallet Lifecycle SecurityCS-I.3-WUS, CS-I.3-Prov, CS-I.6-ValidWallet unit activation, management, and deactivation
Transport Security ModelWIN-8.4.1-Sec-01/06TLS, JWT auth, WebSocket security, storage protection
Access Control ArchitectureA.8.1, A.8.2, A.8.18Endpoint protection, admin access, device policies
Network ArchitectureA.8.20–A.8.23Port separation, TLS boundaries, network segmentation
STRIDE Threat ModelV1.1, A.8.25, A.8.27Formal STRIDE threat model across all SIROS ID components

Relationship to Controls

These documents consolidate the evidence from individual technical controls into architecture-level views. Each document references the specific controls it draws from: