SlideShare ist ein Scribd-Unternehmen logo
1 von 35
Downloaden Sie, um offline zu lesen
Kopfzeile




            eID and interoperability
            - The Austrian Experience


            Peter Kustor
            27th September 2011
            peter.kustor@bka.gv.at




            Table of contents
                Citizen Card Concept
                eID-innovation: Mobile Phone Signature
                eID interoperability in Austria
                STORK and lessons learned
                Future Challenges




            eID and interoperability | 27.9.2011             2|




Fußzeile                                           Seite 1        29.09.2011
Kopfzeile




             Citizen Card - Major Milestones
                  November 2000: Austrian Cabinet Council decision
                   – … to employ chip-card technology to improve
                     citizen’s access to public services; to supplement
                     the planned health insurance card with electronic
                     signatures
                  February 2003: 1st Citizen Card
                   – Austrian Computer Society membership card
                  March 2004: E-Government Act
                   – Legal basis of the Identity Management System
                  2005 - 2010
                   – Several private-sector and public-sector
                     borne Citizen Card initiatives

            eID and interoperability | 27.9.2011                                 3|




            A valid legal basis – the main ingredient


                                             E-Government Act

                                                                             sector
            citizen               identity-
                                                   mandates   source PIN    specific
             card                   link
                                                                              eID



                                                         standard-
                    source PIN             supplement                 official
                                                         document
                    REGISTER               REGISTER                  signature
                                                         REGISTER




            eID and interoperability | 27.9.2011                                 4|




Fußzeile                                            Seite 2                            29.09.2011
Kopfzeile




                Citizen card (concept)
                    The Austrian citizen card is
                    a concept, not a specific
                    technology

                    The Citizen Card combines                          Identity-Link


                      – electronic signature/
                        declaration of intent
                          Authentication
                      – Unique electronic identity
                          Identification
                      – data on representation,
                        mandates
                          Representation


                eID and interoperability | 27.9.2011                                            5|




            Online Identity = CSP + public register

            Trust Center:                                        public sector registries
            Certification Service Provider
            (CSP)



                                                                                       Supplementary
                                          CSP                                             Register
                 CSP                                                   CRR
                                           …
                A-Trust                                                BMI




                                              Electronic Identity

                eID and interoperability | 27.9.2011                                            6|




Fußzeile                                               Seite 3                                         29.09.2011
Kopfzeile




            eID Austria : Overview

            LEGAL                                                  QUALIFIED
                                                                   SIGNATUR
                                                                               +            IDENTIT
                                                                                            Y
                                                                   E                        LINK



                                                   any private sector          Identity = source
            PUBLIC PRIVATE                         CA for qualified            pin cryptographically
                                                   signatures                  bound to certificate


                                                                                          only on
            DATA PROTECTION                        openly available                       the card
                                                   in a directory                         (HSM)


                                                    SECTOR     SECTOR            SECTOR      SECTOR

                                                                         one way mapping into sectors


            eID and interoperability | 27.9.2011                                                      7|




             Identity Link
                XML data structure stored in the
                Card or in the hardware secure module
                that holds:                                               ...
                                                                          <saml:SubjectConfirmationData>
                 – personal data: name, date of                             <pr:Person xsi:type="pr:Physical
                                                                              <pr:Identification>
                   birth                 source
                                                                                <pr:Value>123456789012</pr:V
                                                                                <pr:Type>http://reference.e-g
                                                                              </pr:Identification>
                 – unique ID “sourcePIN” PIN                                <pr:Name>
                                                                              <pr:GivenName>Herbert</pr:Given
                 – public keys of the                                         <pr:FamilyName>Leitold</pr:Fami
                                                                            </pr:Name>
                   certificates                                           ...
                                                                          <saml:Attribute
                signed by the                                             AttributeName="CitizenPublicKey"
                                                                          ... <dsig:RSAKeyValue>
                authority                                                 <dsig:Modulus>snW8OLCQ49qNefems




            eID and interoperability | 27.9.2011                                                      8|




Fußzeile                                                 Seite 4                                                29.09.2011
Kopfzeile




              Electronic identity of natural persons

                                                                                                Base
                 Central Residents Register                       Supplementary Register
                    Number (CRRegNo)                              Number for non-residents     Registers




                                                     Source PIN




                 ssPIN                           ssPIN             ssPIN                     ssPIN
                education                       Soc. Sec.         taxation                     …



              eID and interoperability | 27.9.2011                                                   9|




              ssPIN: Generation

            irreversible                              Source PIN
               derivation




                            ssPIN a                                              ssPIN b
                                                                           e.g. constructing &
            e.g. taxes & duties
                                                                                  living

                      Conversion impossible!

              eID and interoperability | 27.9.2011                                               10 |




Fußzeile                                                Seite 5                                            29.09.2011
Kopfzeile




              Citizen Cards

                                              Cards:
                                              •Health insurance cards: 100 % coverage,
                                                activation free of charge for citizens
                                              • official’s service card
                                              • Certification service provider signature cards
                                              • student service cards, etc.




                                              Mobile phone signatures:
                                              • Start 2009
                                              • free of charge for citizens




             eID and interoperability | 27.9.2011                                                11 |




             eID citizen card function




                                                    Access to e-gov:
                                                       • eForms               Access to e-business:
                                                       • eHealth                   • eBanking
            Within                                     • eDelivery                 • eBilling
                                                       • eDocument-Safe            • eProcurement
            administration:
                                                       • eUniversity               • CyberDoc
                 • eSignature
                                                       • eVoting                   • Archivium
                 • eRegisters
                                                                                   • eDelivery
                 • eFile System
             eID and interoperability | 27.9.2011                                                12 |




Fußzeile                                                  Seite 6                                       29.09.2011
Kopfzeile




             Server Side – Open Source Programme
                                               Basic modules for integration into
                                               applications
                                                – Open Source, free for public &
                                                  private sector
                                               MOA – Module for On-line
                                               Applications
                                                – Identification (MOA-ID)
                                                – Signature validation / creation
                                                  (MOA-SS/SP)
                                                – Electronic delivery (MOA-ZS)
                                                – Representation (MOA-VV)
                                                – Official signatures (MOA-AS)
            eID and interoperability | 27.9.2011                                    13 |




             Variants
                                                         Minimum-footprint




                                                                Mobile Phone



               Local installation


            eID and interoperability | 27.9.2011                                    14 |




Fußzeile                                              Seite 7                              29.09.2011
Kopfzeile




            Table of contents
                Citizen Card Concept
                eID-innovation: Mobile Phone Signature
                eID interoperability in Austria
                STORK and lessons learned
                Future Challenges




            eID and interoperability | 27.9.2011                  15 |




             Demo


                                                             Log On at
                                                             HELP
                                                               ONLINE




            eID and interoperability | 27.9.2011                  16 |




Fußzeile                                           Seite 8               29.09.2011
Kopfzeile




            mobile phone signature
                server-based citizen card solution for
                qualified electronic signatures via mobile phone
                familiar technology and comfortable alternative to the
                current smartcards
                important step towards usability and dissemination of
                modern eGovernment services because
                  – no software installation on the local PC,
                  – no special computer skills and
                  – no card readers are needed for use.




            eID and interoperability | 27.9.2011                     17 |




             Mobile phone signature
                  Core Aspects
                  – Operated by a Certification Service
                    Provider (CSP) for qualified certificates
                  – Signature-creation data (cryptographic
                    keys) kept at CSP but controlled by the
                    signatory
                          • 2-factor authentication (knowledge &
                            possession) as known from smartcards
                   – Secure Signature-Creation Device
                          • 1999/93/EC Annex III, confirmed by a
                             notified body
            eID and interoperability | 27.9.2011                     18 |




Fußzeile                                           Seite 9                  29.09.2011
Kopfzeile




             Features of mobile phone signature

              No requirement on the mobile phone or SIM
               – Just receiving SMS
              Zero-footprint: no local installation, just the browser
              Revocation of a certificate is definite – the signature-creation
              data are destroyed (unlike with signature cards)
               – Actually, revocation checking could be omitted, if relying on
                 that fact
              Identity data is communicated from the operator directly to the
              application
               – Reduces verification needs and residual risks



            eID and interoperability | 27.9.2011                          19 |




             Features of mobile phone signature
              Free of charge for users
              Alternative to card-based eID
              Platform- and location independent
              Trustworthy and secure
              User-friendly
              High-potential also in private sector applications




            eID and interoperability | 27.9.2011                          20 |




Fußzeile                                           Seite 10                      29.09.2011
Kopfzeile




             Registration possibilities
                                               „self registration“ using a qualified
                                               signature (existing citizen card):
                                               https://www.handy-signatur.at/




                                               Registration authorities/ registration
                                               officers at various institutions (expanding: finance
                                               authorities, post offices…)
                                                   https://www.a-trust.at/Aktivierung/ro/OfficerData.aspx?t=mobile



                                               Using „trusted systems“ (currently e.g. FinanzOnline,
                                               registration via online banking in cooperation with telecom providers)




            eID and interoperability | 27.9.2011                                                                     21 |




            Table of contents
                Citizen Card Concept
                eID-innovation: Mobile Phone Signature
                eID interoperability in Austria
                STORK and lessons learned
                Future Challenges




            eID and interoperability | 27.9.2011                                                                     22 |




Fußzeile                                                         Seite 11                                                   29.09.2011
Kopfzeile




            Integration of foreign eIDs
            Framework for the legal equality of
            foreign signature cards with the
            Austrian citizen card concept:
            § 6 Abs. 5 E-GovG and „equality
            regulation“
            Registration in the Supplementary
            Register without explicit proof of
            registration data, if
             – an Application contains a qualified
               signature, that
             – is based on an equivalent proof of
               unique identity (§ 2 Z 2 E-GovG) in the
               country of origin.
            Currently the eIDs of Belgium,
            Estonia, Finland, Iceland, Italy,
            Liechtenstein, Lithuania, Portugal,
            Sweden, Slovenia and Spain meet
            these interoperability | 27.9.2011
             eID and requirements.                            23 |




            Table of contents
                Citizen Card Concept
                eID-innovation: Mobile Phone Signature
                eID interoperability in Austria
                STORK and lessons learned
                Future Challenges




            eID and interoperability | 27.9.2011              24 |




Fußzeile                                           Seite 12          29.09.2011
Kopfzeile




            EU “Large Scale” pilots
             Electronic Procurement
            Large Scale Pilot PEPPOL
                                                              www.peppol.eu

                Electronic Identity
             Large Scale Pilot STORK
                                                              www.eid-stork.eu

                  Service Directive
             Large Scale Pilot SPOCS
                                                              www.eu-spocs.eu

                          eHealth
             Large Scale Pilot epSOS                          www.epsos.eu

            e-Justice Communication
             Large Scale Pilot e-CODEX                        www.e-codex.eu

            eID and interoperability | 27.9.2011                                 25 |




             STORK-Outcome: it works…
             www.eesti.ee
             https://circabc.europa.eu
             www.myhelp.gv.at
             www.meinbrief.at
             https://abnahme.service-bw.de/idm-web-
             portal/page/protected/index/index.faces?action=init&stor
             k=true
             http://saferchat.eid.is/




            eID and interoperability | 27.9.2011                                 26 |




Fußzeile                                           Seite 13                             29.09.2011
Kopfzeile




            Electronic delivery (www.meinbrief.at)




            eID and interoperability | 27.9.2011              27 |




            Electronic delivery (www.meinbrief.at)




            eID and interoperability | 27.9.2011              28 |




Fußzeile                                           Seite 14          29.09.2011
Kopfzeile




            Electronic delivery (www.meinbrief.at)




            eID and interoperability | 27.9.2011                     29 |




            STORK - mission complete?




                     STORK is about making it happen - i.e. PILOTS
            eID and interoperability | 27.9.2011                     30 |




Fußzeile                                           Seite 15                 29.09.2011
Kopfzeile




            eID and interoperability | 27.9.2011                     31 |




            STORK - mission complete?




                                we currently prepare for STORK 2.0
            eID and interoperability | 27.9.2011                     32 |




Fußzeile                                           Seite 16                 29.09.2011
Kopfzeile




            Table of contents
                Citizen Card Concept
                eID-innovation: Mobile Phone Signature
                eID interoperability in Austria
                STORK and lessons learned
                Future Challenges




            eID and interoperability | 27.9.2011                     33 |




            STORK - mission complete?




                                     we learned what is to be done
            eID and interoperability | 27.9.2011                     34 |




Fußzeile                                           Seite 17                 29.09.2011
Kopfzeile




            eID and interoperability | 27.9.2011              35 |




            Digital Agenda - the next step




            eID and interoperability | 27.9.2011              36 |




Fußzeile                                           Seite 18          29.09.2011
Kopfzeile




            eID - essential challenges

                Non-natural Persons (e.g. companies)
                  – where time equals money and
                  – where identity and privacy (e.g. IP protection ..) really counts
                Mobility - eID with and through mobile devices
                  –   convenience
                  –   availability
                  –   simplicity
                  –   we have to go to the citizen - not vice versa
                Impacts of Cloud Computing on eID
                  – cloud is opening up an ample set of security questions
                  – it is a chance and a challenge
                  – while not a technology by itself it changes assumptions
            eID and interoperability | 27.9.2011                                   37 |




            how to extend take-up and use
                reduce complexity
                  – Amend (simplify!) legal framework and create legally secure
                    conditions
                  – public opinion still assigns high complexity with eID
                  – technology is high up in barriers
                  – these barriers are also perceived by application providers
                    which is hampering services

                easier access to technology
                  – people who used eID once stay with it


                the user must see the need

            eID and interoperability | 27.9.2011                                   38 |




Fußzeile                                           Seite 19                               29.09.2011
Kopfzeile




            Thank you
            for your attention!


            Peter Kustor
            Federal Chancellery of Austria

            Ballhausplatz 2
            1014 Vienna
            Phone: +43 53115 2554
            Peter.Kustor@bka.gv.at
            http://digitales.oesterreich.gv.at or
            http://digital.austria.gv.at




             Components




                                                                User




                                                               Mobile phone




Fußzeile                                            Seite 20                  29.09.2011
Kopfzeile




            Components

                                                                    Web-Frontend




               HSM

               - Creation of crypto-keys
               - Decryption of signature
                 creation data
               - Creation of qualified                              SMS Gateway
                 electronic signatures




                                           Signature key DB

                                           Signature-creation data
                                           (private keys) are encrypted
                                           under
                                           - Citizen password
                                           - Mobile number
                                           - Secret HSM key




            Registration




Fußzeile                                                Seite 21                   29.09.2011
Kopfzeile




            Registration



                                                                 Password
                                                                                   Enter mobile number
                                                                 Mob-Nr.
                Needs to verify possession
                                                                                   Choose password

                Generate one-time code
                (OTC)                                                              Identification


                Send OTC via SMS

                                             OTC




            Registration II



                Possession verified                               Code


                Generate signature-
                creation data (private
                keys) and encrypt under
                                                                            Code




                - Citizen password                  Verify possession
                - Mobile number
                - Secret HSM key


                Encrypted storage in DB      Code




Fußzeile                                      Seite 22                                                   29.09.2011
Kopfzeile




            Registration II



                Possession verified                               Code


                Generate signature-
                creation data (private
                keys) and encrypt under




                                                                              Code
                - Citizen password
                - Mobile number
                - Secret HSM key


                Encrypted storage in DB   Signature-creation data (private keys) only
                                               Code
                                           a) inside the HSM or
                                           b) encrypted storage
                                              (under key (HSM, mobile number ...)




            Signature-creation




Fußzeile                                        Seite 23                                29.09.2011
Kopfzeile




            Signature-creation



                                                        Request

                                                        password   Enter password

                                                        Mob-Nr.
                                                                   Enter mobile number

                                                                   Application redirects to
                                                                   signature website

                                                                   Application prepares a
                                                                   signature request




            Signature-creation I



                                          Display

                Generate hash-value                     Confirm




                Generate SMS one-time
                code (OTC)


                Send OTC and hash-value
                via SMS                   Code




Fußzeile                                     Seite 24                                         29.09.2011
Kopfzeile




            Signature-creation II




                Possession verified
                                                                      Code

                Load and decrypt the                                                      Enter OTC, verify hash
                signature-creation data to
                HSM using




                                                                                 Code
                - Citizen password                      Verify possession
                - Mobile number
                - Secret HSM key

                Signature-creation in the        Code
                HSM




            Signature-creation II




                Possession verified
                Besitz verifiziert
                                                                      Code

                Load and decrypt the                                                      Enter OTC
                Wiederherstellen der to
                signature-creation data
                Signaturerstellungsdaten
                HSM using
                                                                                 Code




                aus Datenbank mit
                - Citizen password                      Verify possession
                - Schlüssel des HSM
                -- Schlüsselnumber
                    Mobile aus Kennwort
                - Secret HSM key

                Signature-creation in
                Signaturerstellung mitthe
                HSM
                Signaturerstellungsdaten
                                             The Code
                                                 one-time code (OTC) verifies possession of the phone

                                             Using the signature-creation data (private keys) only
                                              a) inside the HSM and
                                              b) after having entered the user password
                                              c) linked to the mobile number




Fußzeile                                           Seite 25                                                        29.09.2011
Kopfzeile




            Signature-creation III



                 Returning the XML                           Signature returned to the
                                     Signature
                 signature                                   application




            Mobile Phone Signature – Legal Assessment

            Mobile Phone Signature = Citizen Card?
            Citizen Card = qualified signature + identity link

            Mobile Phone Signature = qualified signature?
            Qualified Signature =   advanced electronic signature
                                  + qualified certificate
                                  + SSCD




Fußzeile                                 Seite 26                                        29.09.2011
Kopfzeile




            Advanced Electronic Signature
            is uniquely linked to the signatory
            it is capable of identifying the signatory
            it is created using means that the signatory can maintain
            under his sole control
            it is linked to the data to which it relates in such a manner
            that any subsequent change of the data is detectable




            Advanced Electronic Signature
            is uniquely linked to the signatory
            it is capable of identifying the signatory
            it is created using means that the signatory can maintain
            under his sole control
            it is linked to the data to which it relates in such a manner
            that any subsequent change of the data is detectable




Fußzeile                              Seite 27                              29.09.2011
Kopfzeile




            „is uniquely linked to the signatory“

            the signature-creation-data used for signature
            generation (and the corresponding signature
            verification data) can practically occur only once




            Advanced Electronic Signature
            is uniquely linked to the signatory
            it is capable of identifying the signatory
            it is created using means that the signatory can maintain
            under his sole control
            it is linked to the data to which it relates in such a manner
            that any subsequent change of the data is detectable




Fußzeile                              Seite 28                              29.09.2011
Kopfzeile




              „ it is capable of identifying the signatory “
            Authenticity
              practically impossible to create the same key pair twice
              ensured that a signature that is verifiable using signature
              verification data (public key in the certificate) has been
              created with the corresponding signature-creation data
              (private key)
              practically impossible that signature-creation data can be
              derived




              Advanced Electronic Signature
              is uniquely linked to the signatory
              it is capable of identifying the signatory
              it is created using means that the signatory can maintain
              under his sole control
              it is linked to the data to which it relates in such a manner
              that any subsequent change of the data is detectable




Fußzeile                                Seite 29                              29.09.2011
Kopfzeile




             „using means that the signatory can maintain under
             his sole control “
              Signature-creation authorised only by the signatory
               Multifactor authentication: knowledge and possession
            Does “can maintain under sole control” mean that it must
              be ensured by hardware means? NO!
            „…to be assumed that ‘sole control’ can be achieved with appropriate
              technical or organisational means even with software certificates
              […] … security measures need to be in place providing that the
              signatory can enforce his sole control…“ (RV 293 BlgNR 23. GP)
               – see also FESA - working paper on advanced
               electronic signatures and “Public Statement on Server
               Based Signature Services”: “…FESA members believe that
               sole control at least of the signature creation data can be achieved
               and that advanced electronic signatures can be created by a
               server based signature service…“!




             Advanced Electronic Signature
              is uniquely linked to the signatory
              it is capable of identifying the signatory
              it is created using means that the signatory can maintain
              under his sole control
              it is linked to the data to which it relates in such a manner
              that any subsequent change of the data is detectable




Fußzeile                                    Seite 30                                  29.09.2011
Kopfzeile




            „it is linked to the data to which it relates in such a manner that any
            subsequent change of the data is detectable “

             Integrity
                practically impossible that different electronic data result in
                the same signature or can be created from a given
                electronic signature.




                Advanced Electronic Signature
                is uniquely linked to the signatory
                it is capable of identifying the signatory
                it is created using means that the signatory can maintain
                under his sole control
                it is linked to the data to which it relates in such a manner
                that any subsequent change of the data is detectable




Fußzeile                                     Seite 31                                 29.09.2011
Kopfzeile




              Qualified Signature?

            Qualified Signature =      advanced el. signature

                                    + qualified certificate

                                    + SSCD




              Qualified Certificate



                                      Qualified
                                    Certficate




              Certificate content                   Requirements
                    Annex I                           Annex II
                 1999/93/EC                          1999/93/EC




Fußzeile                            Seite 32                       29.09.2011
Kopfzeile




            Certificate Content (Annex I)
             indication that the certificate is issued as a qualified
             certificate
             identification of the CSP and the State in which it is
             established
             name of the signatory (or a pseudonym identified as
             such)
             signature-verification data which correspond to
             signature-creation data under the control of the signatory
             beginning and end of the period of validity of the
             certificate
             identity code of the certificate
             advanced electronic signature of the CSP issuing it
             Further options: limitations on scope, value of
             transaction, specific attributes of the signatory




            Requirements on the CSP (Annex II)
             reliability necessary for providing certification services
             secure directory and a secure and immediate revocation service
             precise date and time when a certificate is issued or revoked
             verify identity and, if applicable, specific attributes of the signatory
             personnel with expert knowledge, experience, and qualifications
             (managerial level, electr. signature technology, security
             procedures)
             trustworthy systems and products - protected against modification
             and ensuring the technical and cryptographic security;
             measures against forgery of certificates, and, in cases where the
             CSP generates signature-creation data, guarantee its
             confidentiality
             sufficient financial resources (to bear the risk of liability for
             damages)
             etc.




Fußzeile                                    Seite 33                                    29.09.2011
Kopfzeile




            Qualified Signature?

            Qualified Signature =      advanced el. signature

                                     + qualified certificate

                                     + SSCD




            SSCD
              Confirmation by a designated body (Art. 3(4) of
              1999/93/EC)
              § 6 Abs. 3 Signature Order 2008: Organisational
              security measures possible, if components are
              operated in a “controlled environment” (e.g., qualified
              and reliable personnel, appropriate physical and
              logical access control).
              A-SIT conformity certificate: 2.11.2009
              According to Art. 3 para 4 second subpara of the
              Directive, this attestation (“determination of
              conformity with the requirements laid down in Annex
              III”) is to be recognised by all Member States.




Fußzeile                             Seite 34                           29.09.2011
Kopfzeile




            Qualified Signature?

            Qualified Signature =       advanced el. signature

                                      + qualified certificate

                                      + SSCD




            Mobile Phone Signature – Legal Assessment

            Mobile Phone Signature = Citizen Card?
            Citizen Card = qualified signature + identity link


            Mobile Phone Signature = qualified signature?
            Qualified Signature =       advanced electronic signature
                                      + qualified certificate
                                      + SSCD




Fußzeile                              Seite 35                          29.09.2011

Weitere ähnliche Inhalte

Was ist angesagt?

Higgins Overview 2008 [Compatibility Mode]
Higgins Overview 2008 [Compatibility Mode]Higgins Overview 2008 [Compatibility Mode]
Higgins Overview 2008 [Compatibility Mode]Markus Sabadello
 
SG(Signgate) PKI Abroad Business
SG(Signgate) PKI Abroad Business SG(Signgate) PKI Abroad Business
SG(Signgate) PKI Abroad Business Jinhwan Shin
 
Experience and Outcomes of the New German Electronic ID Card
Experience and Outcomes of the New German Electronic ID CardExperience and Outcomes of the New German Electronic ID Card
Experience and Outcomes of the New German Electronic ID CardAtos_Worldline
 
SmartCard Forum 2010 - Secured Access for enterprise
SmartCard Forum 2010 - Secured Access for enterpriseSmartCard Forum 2010 - Secured Access for enterprise
SmartCard Forum 2010 - Secured Access for enterpriseOKsystem
 
SmartCard Forum 2008 - Securing digital identity
SmartCard Forum 2008 - Securing digital identitySmartCard Forum 2008 - Securing digital identity
SmartCard Forum 2008 - Securing digital identityOKsystem
 
28032012 Irma vander Ploeg: e portfolio als digitale identiteit
28032012 Irma vander Ploeg: e portfolio als digitale identiteit28032012 Irma vander Ploeg: e portfolio als digitale identiteit
28032012 Irma vander Ploeg: e portfolio als digitale identiteitStichting ePortfolio Support
 
2013 feb13 introduction to ppi generic
2013 feb13 introduction to ppi   generic2013 feb13 introduction to ppi   generic
2013 feb13 introduction to ppi genericRichard O'Brien
 
electronic_payment_system_in_korea_eng
electronic_payment_system_in_korea_engelectronic_payment_system_in_korea_eng
electronic_payment_system_in_korea_engFrank Mercado
 
Eco [3 c] introduction of national pki-sg-jaejung kim-15_apr10
Eco [3 c] introduction of national pki-sg-jaejung kim-15_apr10Eco [3 c] introduction of national pki-sg-jaejung kim-15_apr10
Eco [3 c] introduction of national pki-sg-jaejung kim-15_apr10Hai Nguyen
 
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...OKsystem
 
Multi purpose ID : A Digital Identity to 134 Crore Indians
Multi purpose ID : A Digital Identity to 134 Crore IndiansMulti purpose ID : A Digital Identity to 134 Crore Indians
Multi purpose ID : A Digital Identity to 134 Crore IndiansRishabh Garg
 
Techno Smart Card : Digital ID for Every Indian
Techno Smart Card : Digital ID for Every IndianTechno Smart Card : Digital ID for Every Indian
Techno Smart Card : Digital ID for Every IndianRishabh Garg
 
International Webinar - Global ID Through Blockchain
International Webinar - Global ID Through BlockchainInternational Webinar - Global ID Through Blockchain
International Webinar - Global ID Through BlockchainRishabh Garg
 
Ireland - The location of choice for International Payments firms
Ireland - The location of choice for International Payments firmsIreland - The location of choice for International Payments firms
Ireland - The location of choice for International Payments firmsMartina Naughton
 
Comodo Overview Presentation Read Only
Comodo Overview Presentation Read OnlyComodo Overview Presentation Read Only
Comodo Overview Presentation Read OnlyJayHicks
 
Trends and Development in Government Sector: Building e-Government Backbone
Trends and Development in Government Sector: Building e-Government BackboneTrends and Development in Government Sector: Building e-Government Backbone
Trends and Development in Government Sector: Building e-Government BackboneArab Federation for Digital Economy
 
Cidway Byod Authentication
Cidway Byod AuthenticationCidway Byod Authentication
Cidway Byod Authenticationlfilliat
 
Challenges in the Management of Strategic Government Projects: The Case of th...
Challenges in the Management of Strategic Government Projects: The Case of th...Challenges in the Management of Strategic Government Projects: The Case of th...
Challenges in the Management of Strategic Government Projects: The Case of th...Arab Federation for Digital Economy
 

Was ist angesagt? (20)

Higgins Overview 2008 [Compatibility Mode]
Higgins Overview 2008 [Compatibility Mode]Higgins Overview 2008 [Compatibility Mode]
Higgins Overview 2008 [Compatibility Mode]
 
SG(Signgate) PKI Abroad Business
SG(Signgate) PKI Abroad Business SG(Signgate) PKI Abroad Business
SG(Signgate) PKI Abroad Business
 
Experience and Outcomes of the New German Electronic ID Card
Experience and Outcomes of the New German Electronic ID CardExperience and Outcomes of the New German Electronic ID Card
Experience and Outcomes of the New German Electronic ID Card
 
SmartCard Forum 2010 - Secured Access for enterprise
SmartCard Forum 2010 - Secured Access for enterpriseSmartCard Forum 2010 - Secured Access for enterprise
SmartCard Forum 2010 - Secured Access for enterprise
 
SmartCard Forum 2008 - Securing digital identity
SmartCard Forum 2008 - Securing digital identitySmartCard Forum 2008 - Securing digital identity
SmartCard Forum 2008 - Securing digital identity
 
28032012 Irma vander Ploeg: e portfolio als digitale identiteit
28032012 Irma vander Ploeg: e portfolio als digitale identiteit28032012 Irma vander Ploeg: e portfolio als digitale identiteit
28032012 Irma vander Ploeg: e portfolio als digitale identiteit
 
2013 feb13 introduction to ppi generic
2013 feb13 introduction to ppi   generic2013 feb13 introduction to ppi   generic
2013 feb13 introduction to ppi generic
 
electronic_payment_system_in_korea_eng
electronic_payment_system_in_korea_engelectronic_payment_system_in_korea_eng
electronic_payment_system_in_korea_eng
 
Eco [3 c] introduction of national pki-sg-jaejung kim-15_apr10
Eco [3 c] introduction of national pki-sg-jaejung kim-15_apr10Eco [3 c] introduction of national pki-sg-jaejung kim-15_apr10
Eco [3 c] introduction of national pki-sg-jaejung kim-15_apr10
 
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
 
Multi purpose ID : A Digital Identity to 134 Crore Indians
Multi purpose ID : A Digital Identity to 134 Crore IndiansMulti purpose ID : A Digital Identity to 134 Crore Indians
Multi purpose ID : A Digital Identity to 134 Crore Indians
 
Techno Smart Card : Digital ID for Every Indian
Techno Smart Card : Digital ID for Every IndianTechno Smart Card : Digital ID for Every Indian
Techno Smart Card : Digital ID for Every Indian
 
20120510 università
20120510 università20120510 università
20120510 università
 
International Webinar - Global ID Through Blockchain
International Webinar - Global ID Through BlockchainInternational Webinar - Global ID Through Blockchain
International Webinar - Global ID Through Blockchain
 
History of Identity in Computers
History of Identity in ComputersHistory of Identity in Computers
History of Identity in Computers
 
Ireland - The location of choice for International Payments firms
Ireland - The location of choice for International Payments firmsIreland - The location of choice for International Payments firms
Ireland - The location of choice for International Payments firms
 
Comodo Overview Presentation Read Only
Comodo Overview Presentation Read OnlyComodo Overview Presentation Read Only
Comodo Overview Presentation Read Only
 
Trends and Development in Government Sector: Building e-Government Backbone
Trends and Development in Government Sector: Building e-Government BackboneTrends and Development in Government Sector: Building e-Government Backbone
Trends and Development in Government Sector: Building e-Government Backbone
 
Cidway Byod Authentication
Cidway Byod AuthenticationCidway Byod Authentication
Cidway Byod Authentication
 
Challenges in the Management of Strategic Government Projects: The Case of th...
Challenges in the Management of Strategic Government Projects: The Case of th...Challenges in the Management of Strategic Government Projects: The Case of th...
Challenges in the Management of Strategic Government Projects: The Case of th...
 

Andere mochten auch

Tutorial 4 francisco garcia moran
Tutorial 4 francisco garcia moranTutorial 4 francisco garcia moran
Tutorial 4 francisco garcia moranegovernment
 
Tutorial 2 bong up cho
Tutorial 2 bong up choTutorial 2 bong up cho
Tutorial 2 bong up choegovernment
 
Tutorial 2 omar salim
Tutorial 2 omar salimTutorial 2 omar salim
Tutorial 2 omar salimegovernment
 
Tutorial 3 irakli gvenetadze
Tutorial 3 irakli gvenetadzeTutorial 3 irakli gvenetadze
Tutorial 3 irakli gvenetadzeegovernment
 
Tutorial 1 janowski wimmer
Tutorial 1 janowski wimmerTutorial 1 janowski wimmer
Tutorial 1 janowski wimmeregovernment
 
Tutorial 3 pedro janices
Tutorial 3 pedro janicesTutorial 3 pedro janices
Tutorial 3 pedro janicesegovernment
 
Tutorial 2 francisco camargo salas
Tutorial 2 francisco camargo salasTutorial 2 francisco camargo salas
Tutorial 2 francisco camargo salasegovernment
 
Tutorial 1 maria wimmer
Tutorial 1 maria wimmerTutorial 1 maria wimmer
Tutorial 1 maria wimmeregovernment
 
Plenary1 ivar tallo
Plenary1 ivar talloPlenary1 ivar tallo
Plenary1 ivar talloegovernment
 
Tutorial 4 mihkel miidla
Tutorial 4 mihkel miidlaTutorial 4 mihkel miidla
Tutorial 4 mihkel miidlaegovernment
 
Plenary2 maria carolina hoyos
Plenary2 maria carolina hoyosPlenary2 maria carolina hoyos
Plenary2 maria carolina hoyosegovernment
 
Tutorial 3 francisco garcia moran
Tutorial 3 francisco garcia moranTutorial 3 francisco garcia moran
Tutorial 3 francisco garcia moranegovernment
 
Tutorial 4 iurie turcanu
Tutorial 4 iurie turcanuTutorial 4 iurie turcanu
Tutorial 4 iurie turcanuegovernment
 
Tutorial 4 peter kustor
Tutorial 4 peter kustorTutorial 4 peter kustor
Tutorial 4 peter kustoregovernment
 
Tutorial 2 arvo ott
Tutorial 2 arvo ottTutorial 2 arvo ott
Tutorial 2 arvo ottegovernment
 
Tutorial 2 jeremy millard
Tutorial 2 jeremy millardTutorial 2 jeremy millard
Tutorial 2 jeremy millardegovernment
 
Tutorial 4 john r. savageau
Tutorial 4 john r. savageauTutorial 4 john r. savageau
Tutorial 4 john r. savageauegovernment
 
Tutorial 3 frank leyman
Tutorial 3 frank leymanTutorial 3 frank leyman
Tutorial 3 frank leymanegovernment
 

Andere mochten auch (19)

Tutorial 4 francisco garcia moran
Tutorial 4 francisco garcia moranTutorial 4 francisco garcia moran
Tutorial 4 francisco garcia moran
 
Tutorial 2 bong up cho
Tutorial 2 bong up choTutorial 2 bong up cho
Tutorial 2 bong up cho
 
Tutorial 2 omar salim
Tutorial 2 omar salimTutorial 2 omar salim
Tutorial 2 omar salim
 
Tutorial 3 irakli gvenetadze
Tutorial 3 irakli gvenetadzeTutorial 3 irakli gvenetadze
Tutorial 3 irakli gvenetadze
 
Tutorial 1 janowski wimmer
Tutorial 1 janowski wimmerTutorial 1 janowski wimmer
Tutorial 1 janowski wimmer
 
Tutorial 3 pedro janices
Tutorial 3 pedro janicesTutorial 3 pedro janices
Tutorial 3 pedro janices
 
Tutorial 2 francisco camargo salas
Tutorial 2 francisco camargo salasTutorial 2 francisco camargo salas
Tutorial 2 francisco camargo salas
 
Tutorial 1 maria wimmer
Tutorial 1 maria wimmerTutorial 1 maria wimmer
Tutorial 1 maria wimmer
 
Plenary1 ivar tallo
Plenary1 ivar talloPlenary1 ivar tallo
Plenary1 ivar tallo
 
Tutorial 4 mihkel miidla
Tutorial 4 mihkel miidlaTutorial 4 mihkel miidla
Tutorial 4 mihkel miidla
 
Plenary2 maria carolina hoyos
Plenary2 maria carolina hoyosPlenary2 maria carolina hoyos
Plenary2 maria carolina hoyos
 
Tutorial 3 francisco garcia moran
Tutorial 3 francisco garcia moranTutorial 3 francisco garcia moran
Tutorial 3 francisco garcia moran
 
Tutorial 4 iurie turcanu
Tutorial 4 iurie turcanuTutorial 4 iurie turcanu
Tutorial 4 iurie turcanu
 
Tutorial 4 peter kustor
Tutorial 4 peter kustorTutorial 4 peter kustor
Tutorial 4 peter kustor
 
Tutorial 2 arvo ott
Tutorial 2 arvo ottTutorial 2 arvo ott
Tutorial 2 arvo ott
 
Tutorial 2 jeremy millard
Tutorial 2 jeremy millardTutorial 2 jeremy millard
Tutorial 2 jeremy millard
 
Tutorial 4 john r. savageau
Tutorial 4 john r. savageauTutorial 4 john r. savageau
Tutorial 4 john r. savageau
 
Central banks
Central banksCentral banks
Central banks
 
Tutorial 3 frank leyman
Tutorial 3 frank leymanTutorial 3 frank leyman
Tutorial 3 frank leyman
 

Ähnlich wie Tutorial 3 peter kustor

Can e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedterCan e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedterE-Government Center Moldova
 
SmartCard Forum 2011 - Evolution of authentication market
SmartCard Forum 2011 - Evolution of authentication marketSmartCard Forum 2011 - Evolution of authentication market
SmartCard Forum 2011 - Evolution of authentication marketOKsystem
 
FIDO, Strong Authentication and elD in Germany
FIDO, Strong Authentication and elD in GermanyFIDO, Strong Authentication and elD in Germany
FIDO, Strong Authentication and elD in GermanyFIDO Alliance
 
User Authentication for Government
User Authentication for GovernmentUser Authentication for Government
User Authentication for GovernmentCarahsoft
 
Authentication means in electronic environments
Authentication means in electronic environmentsAuthentication means in electronic environments
Authentication means in electronic environmentsStevenSegaert
 
BCS ITNow 201509 - Identity
BCS ITNow 201509 - IdentityBCS ITNow 201509 - Identity
BCS ITNow 201509 - IdentityGareth Niblett
 
Smart Cards & Devices Forum 2012 - Securing Cloud Computing
Smart Cards & Devices Forum 2012 - Securing Cloud ComputingSmart Cards & Devices Forum 2012 - Securing Cloud Computing
Smart Cards & Devices Forum 2012 - Securing Cloud ComputingOKsystem
 
ASFWS 2011: Harmonizing Identity and Privacy in Digital Identity and Authenti...
ASFWS 2011: Harmonizing Identity and Privacy in Digital Identity and Authenti...ASFWS 2011: Harmonizing Identity and Privacy in Digital Identity and Authenti...
ASFWS 2011: Harmonizing Identity and Privacy in Digital Identity and Authenti...Cyber Security Alliance
 
A digital society needs a digital id
A digital society needs a digital idA digital society needs a digital id
A digital society needs a digital idCapgemini
 
Mobile Authentication on the Internet
Mobile Authentication on the InternetMobile Authentication on the Internet
Mobile Authentication on the Internetevidos
 
Electronic credentials
Electronic credentialsElectronic credentials
Electronic credentialsAmir Neziri
 
Belgian eID cards - technicalities
Belgian eID cards - technicalitiesBelgian eID cards - technicalities
Belgian eID cards - technicalitiesbeires
 
E-Signature Webcast for Financial Services Legal Counsel (Slides)
E-Signature Webcast for Financial Services Legal Counsel (Slides)E-Signature Webcast for Financial Services Legal Counsel (Slides)
E-Signature Webcast for Financial Services Legal Counsel (Slides)eSignLive by VASCO
 
Creating Smarter Cities 2011 - 16 - Bart Noels - Customisation and e-service ...
Creating Smarter Cities 2011 - 16 - Bart Noels - Customisation and e-service ...Creating Smarter Cities 2011 - 16 - Bart Noels - Customisation and e-service ...
Creating Smarter Cities 2011 - 16 - Bart Noels - Customisation and e-service ...Smart Cities Project
 
Over the Air 2011 Security Workshop
Over the Air 2011 Security Workshop Over the Air 2011 Security Workshop
Over the Air 2011 Security Workshop Ericsson Labs
 

Ähnlich wie Tutorial 3 peter kustor (20)

Can e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedterCan e government work in the cloud reichstaedter
Can e government work in the cloud reichstaedter
 
SmartCard Forum 2011 - Evolution of authentication market
SmartCard Forum 2011 - Evolution of authentication marketSmartCard Forum 2011 - Evolution of authentication market
SmartCard Forum 2011 - Evolution of authentication market
 
FIDO, Strong Authentication and elD in Germany
FIDO, Strong Authentication and elD in GermanyFIDO, Strong Authentication and elD in Germany
FIDO, Strong Authentication and elD in Germany
 
User Authentication for Government
User Authentication for GovernmentUser Authentication for Government
User Authentication for Government
 
Authentication means in electronic environments
Authentication means in electronic environmentsAuthentication means in electronic environments
Authentication means in electronic environments
 
BRIEFING ON THE UAE NATIONAL ID CARD PROJECT
BRIEFING ON THE UAE NATIONAL ID CARD PROJECTBRIEFING ON THE UAE NATIONAL ID CARD PROJECT
BRIEFING ON THE UAE NATIONAL ID CARD PROJECT
 
BCS ITNow 201509 - Identity
BCS ITNow 201509 - IdentityBCS ITNow 201509 - Identity
BCS ITNow 201509 - Identity
 
Session 1. e-ID_esign
Session 1. e-ID_esignSession 1. e-ID_esign
Session 1. e-ID_esign
 
Smart Cards & Devices Forum 2012 - Securing Cloud Computing
Smart Cards & Devices Forum 2012 - Securing Cloud ComputingSmart Cards & Devices Forum 2012 - Securing Cloud Computing
Smart Cards & Devices Forum 2012 - Securing Cloud Computing
 
ASFWS 2011: Harmonizing Identity and Privacy in Digital Identity and Authenti...
ASFWS 2011: Harmonizing Identity and Privacy in Digital Identity and Authenti...ASFWS 2011: Harmonizing Identity and Privacy in Digital Identity and Authenti...
ASFWS 2011: Harmonizing Identity and Privacy in Digital Identity and Authenti...
 
Estonian Experience electronicID, mobileID
Estonian Experience electronicID, mobileIDEstonian Experience electronicID, mobileID
Estonian Experience electronicID, mobileID
 
A digital society needs a digital id
A digital society needs a digital idA digital society needs a digital id
A digital society needs a digital id
 
Mobile Authentication on the Internet
Mobile Authentication on the InternetMobile Authentication on the Internet
Mobile Authentication on the Internet
 
Chris Boyer
Chris BoyerChris Boyer
Chris Boyer
 
Tdl
TdlTdl
Tdl
 
Electronic credentials
Electronic credentialsElectronic credentials
Electronic credentials
 
Belgian eID cards - technicalities
Belgian eID cards - technicalitiesBelgian eID cards - technicalities
Belgian eID cards - technicalities
 
E-Signature Webcast for Financial Services Legal Counsel (Slides)
E-Signature Webcast for Financial Services Legal Counsel (Slides)E-Signature Webcast for Financial Services Legal Counsel (Slides)
E-Signature Webcast for Financial Services Legal Counsel (Slides)
 
Creating Smarter Cities 2011 - 16 - Bart Noels - Customisation and e-service ...
Creating Smarter Cities 2011 - 16 - Bart Noels - Customisation and e-service ...Creating Smarter Cities 2011 - 16 - Bart Noels - Customisation and e-service ...
Creating Smarter Cities 2011 - 16 - Bart Noels - Customisation and e-service ...
 
Over the Air 2011 Security Workshop
Over the Air 2011 Security Workshop Over the Air 2011 Security Workshop
Over the Air 2011 Security Workshop
 

Kürzlich hochgeladen

Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityGeoBlogs
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxVishalSingh1417
 
fourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writingfourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writingTeacherCyreneCayanan
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Disha Kariya
 
Unit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxUnit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxVishalSingh1417
 
Gardella_PRCampaignConclusion Pitch Letter
Gardella_PRCampaignConclusion Pitch LetterGardella_PRCampaignConclusion Pitch Letter
Gardella_PRCampaignConclusion Pitch LetterMateoGardella
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfJayanti Pande
 
Seal of Good Local Governance (SGLG) 2024Final.pptx
Seal of Good Local Governance (SGLG) 2024Final.pptxSeal of Good Local Governance (SGLG) 2024Final.pptx
Seal of Good Local Governance (SGLG) 2024Final.pptxnegromaestrong
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfciinovamais
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdfQucHHunhnh
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfAyushMahapatra5
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfAdmir Softic
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingTechSoup
 
psychiatric nursing HISTORY COLLECTION .docx
psychiatric  nursing HISTORY  COLLECTION  .docxpsychiatric  nursing HISTORY  COLLECTION  .docx
psychiatric nursing HISTORY COLLECTION .docxPoojaSen20
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxVishalSingh1417
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxAreebaZafar22
 
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...Shubhangi Sonawane
 
PROCESS RECORDING FORMAT.docx
PROCESS      RECORDING        FORMAT.docxPROCESS      RECORDING        FORMAT.docx
PROCESS RECORDING FORMAT.docxPoojaSen20
 

Kürzlich hochgeladen (20)

Paris 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activityParis 2024 Olympic Geographies - an activity
Paris 2024 Olympic Geographies - an activity
 
Unit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptxUnit-IV- Pharma. Marketing Channels.pptx
Unit-IV- Pharma. Marketing Channels.pptx
 
fourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writingfourth grading exam for kindergarten in writing
fourth grading exam for kindergarten in writing
 
Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..Sports & Fitness Value Added Course FY..
Sports & Fitness Value Added Course FY..
 
Unit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptxUnit-IV; Professional Sales Representative (PSR).pptx
Unit-IV; Professional Sales Representative (PSR).pptx
 
Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1Código Creativo y Arte de Software | Unidad 1
Código Creativo y Arte de Software | Unidad 1
 
Gardella_PRCampaignConclusion Pitch Letter
Gardella_PRCampaignConclusion Pitch LetterGardella_PRCampaignConclusion Pitch Letter
Gardella_PRCampaignConclusion Pitch Letter
 
Advance Mobile Application Development class 07
Advance Mobile Application Development class 07Advance Mobile Application Development class 07
Advance Mobile Application Development class 07
 
Web & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdfWeb & Social Media Analytics Previous Year Question Paper.pdf
Web & Social Media Analytics Previous Year Question Paper.pdf
 
Seal of Good Local Governance (SGLG) 2024Final.pptx
Seal of Good Local Governance (SGLG) 2024Final.pptxSeal of Good Local Governance (SGLG) 2024Final.pptx
Seal of Good Local Governance (SGLG) 2024Final.pptx
 
Activity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdfActivity 01 - Artificial Culture (1).pdf
Activity 01 - Artificial Culture (1).pdf
 
1029 - Danh muc Sach Giao Khoa 10 . pdf
1029 -  Danh muc Sach Giao Khoa 10 . pdf1029 -  Danh muc Sach Giao Khoa 10 . pdf
1029 - Danh muc Sach Giao Khoa 10 . pdf
 
Class 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdfClass 11th Physics NEET formula sheet pdf
Class 11th Physics NEET formula sheet pdf
 
Key note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdfKey note speaker Neum_Admir Softic_ENG.pdf
Key note speaker Neum_Admir Softic_ENG.pdf
 
Grant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy ConsultingGrant Readiness 101 TechSoup and Remy Consulting
Grant Readiness 101 TechSoup and Remy Consulting
 
psychiatric nursing HISTORY COLLECTION .docx
psychiatric  nursing HISTORY  COLLECTION  .docxpsychiatric  nursing HISTORY  COLLECTION  .docx
psychiatric nursing HISTORY COLLECTION .docx
 
Unit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptxUnit-V; Pricing (Pharma Marketing Management).pptx
Unit-V; Pricing (Pharma Marketing Management).pptx
 
ICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptxICT Role in 21st Century Education & its Challenges.pptx
ICT Role in 21st Century Education & its Challenges.pptx
 
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
Ecological Succession. ( ECOSYSTEM, B. Pharmacy, 1st Year, Sem-II, Environmen...
 
PROCESS RECORDING FORMAT.docx
PROCESS      RECORDING        FORMAT.docxPROCESS      RECORDING        FORMAT.docx
PROCESS RECORDING FORMAT.docx
 

Tutorial 3 peter kustor

  • 1. Kopfzeile eID and interoperability - The Austrian Experience Peter Kustor 27th September 2011 peter.kustor@bka.gv.at Table of contents Citizen Card Concept eID-innovation: Mobile Phone Signature eID interoperability in Austria STORK and lessons learned Future Challenges eID and interoperability | 27.9.2011 2| Fußzeile Seite 1 29.09.2011
  • 2. Kopfzeile Citizen Card - Major Milestones November 2000: Austrian Cabinet Council decision – … to employ chip-card technology to improve citizen’s access to public services; to supplement the planned health insurance card with electronic signatures February 2003: 1st Citizen Card – Austrian Computer Society membership card March 2004: E-Government Act – Legal basis of the Identity Management System 2005 - 2010 – Several private-sector and public-sector borne Citizen Card initiatives eID and interoperability | 27.9.2011 3| A valid legal basis – the main ingredient E-Government Act sector citizen identity- mandates source PIN specific card link eID standard- source PIN supplement official document REGISTER REGISTER signature REGISTER eID and interoperability | 27.9.2011 4| Fußzeile Seite 2 29.09.2011
  • 3. Kopfzeile Citizen card (concept) The Austrian citizen card is a concept, not a specific technology The Citizen Card combines Identity-Link – electronic signature/ declaration of intent Authentication – Unique electronic identity Identification – data on representation, mandates Representation eID and interoperability | 27.9.2011 5| Online Identity = CSP + public register Trust Center: public sector registries Certification Service Provider (CSP) Supplementary CSP Register CSP CRR … A-Trust BMI Electronic Identity eID and interoperability | 27.9.2011 6| Fußzeile Seite 3 29.09.2011
  • 4. Kopfzeile eID Austria : Overview LEGAL QUALIFIED SIGNATUR + IDENTIT Y E LINK any private sector Identity = source PUBLIC PRIVATE CA for qualified pin cryptographically signatures bound to certificate only on DATA PROTECTION openly available the card in a directory (HSM) SECTOR SECTOR SECTOR SECTOR one way mapping into sectors eID and interoperability | 27.9.2011 7| Identity Link XML data structure stored in the Card or in the hardware secure module that holds: ... <saml:SubjectConfirmationData> – personal data: name, date of <pr:Person xsi:type="pr:Physical <pr:Identification> birth source <pr:Value>123456789012</pr:V <pr:Type>http://reference.e-g </pr:Identification> – unique ID “sourcePIN” PIN <pr:Name> <pr:GivenName>Herbert</pr:Given – public keys of the <pr:FamilyName>Leitold</pr:Fami </pr:Name> certificates ... <saml:Attribute signed by the AttributeName="CitizenPublicKey" ... <dsig:RSAKeyValue> authority <dsig:Modulus>snW8OLCQ49qNefems eID and interoperability | 27.9.2011 8| Fußzeile Seite 4 29.09.2011
  • 5. Kopfzeile Electronic identity of natural persons Base Central Residents Register Supplementary Register Number (CRRegNo) Number for non-residents Registers Source PIN ssPIN ssPIN ssPIN ssPIN education Soc. Sec. taxation … eID and interoperability | 27.9.2011 9| ssPIN: Generation irreversible Source PIN derivation ssPIN a ssPIN b e.g. constructing & e.g. taxes & duties living Conversion impossible! eID and interoperability | 27.9.2011 10 | Fußzeile Seite 5 29.09.2011
  • 6. Kopfzeile Citizen Cards Cards: •Health insurance cards: 100 % coverage, activation free of charge for citizens • official’s service card • Certification service provider signature cards • student service cards, etc. Mobile phone signatures: • Start 2009 • free of charge for citizens eID and interoperability | 27.9.2011 11 | eID citizen card function Access to e-gov: • eForms Access to e-business: • eHealth • eBanking Within • eDelivery • eBilling • eDocument-Safe • eProcurement administration: • eUniversity • CyberDoc • eSignature • eVoting • Archivium • eRegisters • eDelivery • eFile System eID and interoperability | 27.9.2011 12 | Fußzeile Seite 6 29.09.2011
  • 7. Kopfzeile Server Side – Open Source Programme Basic modules for integration into applications – Open Source, free for public & private sector MOA – Module for On-line Applications – Identification (MOA-ID) – Signature validation / creation (MOA-SS/SP) – Electronic delivery (MOA-ZS) – Representation (MOA-VV) – Official signatures (MOA-AS) eID and interoperability | 27.9.2011 13 | Variants Minimum-footprint Mobile Phone Local installation eID and interoperability | 27.9.2011 14 | Fußzeile Seite 7 29.09.2011
  • 8. Kopfzeile Table of contents Citizen Card Concept eID-innovation: Mobile Phone Signature eID interoperability in Austria STORK and lessons learned Future Challenges eID and interoperability | 27.9.2011 15 | Demo Log On at HELP ONLINE eID and interoperability | 27.9.2011 16 | Fußzeile Seite 8 29.09.2011
  • 9. Kopfzeile mobile phone signature server-based citizen card solution for qualified electronic signatures via mobile phone familiar technology and comfortable alternative to the current smartcards important step towards usability and dissemination of modern eGovernment services because – no software installation on the local PC, – no special computer skills and – no card readers are needed for use. eID and interoperability | 27.9.2011 17 | Mobile phone signature Core Aspects – Operated by a Certification Service Provider (CSP) for qualified certificates – Signature-creation data (cryptographic keys) kept at CSP but controlled by the signatory • 2-factor authentication (knowledge & possession) as known from smartcards – Secure Signature-Creation Device • 1999/93/EC Annex III, confirmed by a notified body eID and interoperability | 27.9.2011 18 | Fußzeile Seite 9 29.09.2011
  • 10. Kopfzeile Features of mobile phone signature No requirement on the mobile phone or SIM – Just receiving SMS Zero-footprint: no local installation, just the browser Revocation of a certificate is definite – the signature-creation data are destroyed (unlike with signature cards) – Actually, revocation checking could be omitted, if relying on that fact Identity data is communicated from the operator directly to the application – Reduces verification needs and residual risks eID and interoperability | 27.9.2011 19 | Features of mobile phone signature Free of charge for users Alternative to card-based eID Platform- and location independent Trustworthy and secure User-friendly High-potential also in private sector applications eID and interoperability | 27.9.2011 20 | Fußzeile Seite 10 29.09.2011
  • 11. Kopfzeile Registration possibilities „self registration“ using a qualified signature (existing citizen card): https://www.handy-signatur.at/ Registration authorities/ registration officers at various institutions (expanding: finance authorities, post offices…) https://www.a-trust.at/Aktivierung/ro/OfficerData.aspx?t=mobile Using „trusted systems“ (currently e.g. FinanzOnline, registration via online banking in cooperation with telecom providers) eID and interoperability | 27.9.2011 21 | Table of contents Citizen Card Concept eID-innovation: Mobile Phone Signature eID interoperability in Austria STORK and lessons learned Future Challenges eID and interoperability | 27.9.2011 22 | Fußzeile Seite 11 29.09.2011
  • 12. Kopfzeile Integration of foreign eIDs Framework for the legal equality of foreign signature cards with the Austrian citizen card concept: § 6 Abs. 5 E-GovG and „equality regulation“ Registration in the Supplementary Register without explicit proof of registration data, if – an Application contains a qualified signature, that – is based on an equivalent proof of unique identity (§ 2 Z 2 E-GovG) in the country of origin. Currently the eIDs of Belgium, Estonia, Finland, Iceland, Italy, Liechtenstein, Lithuania, Portugal, Sweden, Slovenia and Spain meet these interoperability | 27.9.2011 eID and requirements. 23 | Table of contents Citizen Card Concept eID-innovation: Mobile Phone Signature eID interoperability in Austria STORK and lessons learned Future Challenges eID and interoperability | 27.9.2011 24 | Fußzeile Seite 12 29.09.2011
  • 13. Kopfzeile EU “Large Scale” pilots Electronic Procurement Large Scale Pilot PEPPOL www.peppol.eu Electronic Identity Large Scale Pilot STORK www.eid-stork.eu Service Directive Large Scale Pilot SPOCS www.eu-spocs.eu eHealth Large Scale Pilot epSOS www.epsos.eu e-Justice Communication Large Scale Pilot e-CODEX www.e-codex.eu eID and interoperability | 27.9.2011 25 | STORK-Outcome: it works… www.eesti.ee https://circabc.europa.eu www.myhelp.gv.at www.meinbrief.at https://abnahme.service-bw.de/idm-web- portal/page/protected/index/index.faces?action=init&stor k=true http://saferchat.eid.is/ eID and interoperability | 27.9.2011 26 | Fußzeile Seite 13 29.09.2011
  • 14. Kopfzeile Electronic delivery (www.meinbrief.at) eID and interoperability | 27.9.2011 27 | Electronic delivery (www.meinbrief.at) eID and interoperability | 27.9.2011 28 | Fußzeile Seite 14 29.09.2011
  • 15. Kopfzeile Electronic delivery (www.meinbrief.at) eID and interoperability | 27.9.2011 29 | STORK - mission complete? STORK is about making it happen - i.e. PILOTS eID and interoperability | 27.9.2011 30 | Fußzeile Seite 15 29.09.2011
  • 16. Kopfzeile eID and interoperability | 27.9.2011 31 | STORK - mission complete? we currently prepare for STORK 2.0 eID and interoperability | 27.9.2011 32 | Fußzeile Seite 16 29.09.2011
  • 17. Kopfzeile Table of contents Citizen Card Concept eID-innovation: Mobile Phone Signature eID interoperability in Austria STORK and lessons learned Future Challenges eID and interoperability | 27.9.2011 33 | STORK - mission complete? we learned what is to be done eID and interoperability | 27.9.2011 34 | Fußzeile Seite 17 29.09.2011
  • 18. Kopfzeile eID and interoperability | 27.9.2011 35 | Digital Agenda - the next step eID and interoperability | 27.9.2011 36 | Fußzeile Seite 18 29.09.2011
  • 19. Kopfzeile eID - essential challenges Non-natural Persons (e.g. companies) – where time equals money and – where identity and privacy (e.g. IP protection ..) really counts Mobility - eID with and through mobile devices – convenience – availability – simplicity – we have to go to the citizen - not vice versa Impacts of Cloud Computing on eID – cloud is opening up an ample set of security questions – it is a chance and a challenge – while not a technology by itself it changes assumptions eID and interoperability | 27.9.2011 37 | how to extend take-up and use reduce complexity – Amend (simplify!) legal framework and create legally secure conditions – public opinion still assigns high complexity with eID – technology is high up in barriers – these barriers are also perceived by application providers which is hampering services easier access to technology – people who used eID once stay with it the user must see the need eID and interoperability | 27.9.2011 38 | Fußzeile Seite 19 29.09.2011
  • 20. Kopfzeile Thank you for your attention! Peter Kustor Federal Chancellery of Austria Ballhausplatz 2 1014 Vienna Phone: +43 53115 2554 Peter.Kustor@bka.gv.at http://digitales.oesterreich.gv.at or http://digital.austria.gv.at Components User Mobile phone Fußzeile Seite 20 29.09.2011
  • 21. Kopfzeile Components Web-Frontend HSM - Creation of crypto-keys - Decryption of signature creation data - Creation of qualified SMS Gateway electronic signatures Signature key DB Signature-creation data (private keys) are encrypted under - Citizen password - Mobile number - Secret HSM key Registration Fußzeile Seite 21 29.09.2011
  • 22. Kopfzeile Registration Password Enter mobile number Mob-Nr. Needs to verify possession Choose password Generate one-time code (OTC) Identification Send OTC via SMS OTC Registration II Possession verified Code Generate signature- creation data (private keys) and encrypt under Code - Citizen password Verify possession - Mobile number - Secret HSM key Encrypted storage in DB Code Fußzeile Seite 22 29.09.2011
  • 23. Kopfzeile Registration II Possession verified Code Generate signature- creation data (private keys) and encrypt under Code - Citizen password - Mobile number - Secret HSM key Encrypted storage in DB Signature-creation data (private keys) only Code a) inside the HSM or b) encrypted storage (under key (HSM, mobile number ...) Signature-creation Fußzeile Seite 23 29.09.2011
  • 24. Kopfzeile Signature-creation Request password Enter password Mob-Nr. Enter mobile number Application redirects to signature website Application prepares a signature request Signature-creation I Display Generate hash-value Confirm Generate SMS one-time code (OTC) Send OTC and hash-value via SMS Code Fußzeile Seite 24 29.09.2011
  • 25. Kopfzeile Signature-creation II Possession verified Code Load and decrypt the Enter OTC, verify hash signature-creation data to HSM using Code - Citizen password Verify possession - Mobile number - Secret HSM key Signature-creation in the Code HSM Signature-creation II Possession verified Besitz verifiziert Code Load and decrypt the Enter OTC Wiederherstellen der to signature-creation data Signaturerstellungsdaten HSM using Code aus Datenbank mit - Citizen password Verify possession - Schlüssel des HSM -- Schlüsselnumber Mobile aus Kennwort - Secret HSM key Signature-creation in Signaturerstellung mitthe HSM Signaturerstellungsdaten The Code one-time code (OTC) verifies possession of the phone Using the signature-creation data (private keys) only a) inside the HSM and b) after having entered the user password c) linked to the mobile number Fußzeile Seite 25 29.09.2011
  • 26. Kopfzeile Signature-creation III Returning the XML Signature returned to the Signature signature application Mobile Phone Signature – Legal Assessment Mobile Phone Signature = Citizen Card? Citizen Card = qualified signature + identity link Mobile Phone Signature = qualified signature? Qualified Signature = advanced electronic signature + qualified certificate + SSCD Fußzeile Seite 26 29.09.2011
  • 27. Kopfzeile Advanced Electronic Signature is uniquely linked to the signatory it is capable of identifying the signatory it is created using means that the signatory can maintain under his sole control it is linked to the data to which it relates in such a manner that any subsequent change of the data is detectable Advanced Electronic Signature is uniquely linked to the signatory it is capable of identifying the signatory it is created using means that the signatory can maintain under his sole control it is linked to the data to which it relates in such a manner that any subsequent change of the data is detectable Fußzeile Seite 27 29.09.2011
  • 28. Kopfzeile „is uniquely linked to the signatory“ the signature-creation-data used for signature generation (and the corresponding signature verification data) can practically occur only once Advanced Electronic Signature is uniquely linked to the signatory it is capable of identifying the signatory it is created using means that the signatory can maintain under his sole control it is linked to the data to which it relates in such a manner that any subsequent change of the data is detectable Fußzeile Seite 28 29.09.2011
  • 29. Kopfzeile „ it is capable of identifying the signatory “ Authenticity practically impossible to create the same key pair twice ensured that a signature that is verifiable using signature verification data (public key in the certificate) has been created with the corresponding signature-creation data (private key) practically impossible that signature-creation data can be derived Advanced Electronic Signature is uniquely linked to the signatory it is capable of identifying the signatory it is created using means that the signatory can maintain under his sole control it is linked to the data to which it relates in such a manner that any subsequent change of the data is detectable Fußzeile Seite 29 29.09.2011
  • 30. Kopfzeile „using means that the signatory can maintain under his sole control “ Signature-creation authorised only by the signatory Multifactor authentication: knowledge and possession Does “can maintain under sole control” mean that it must be ensured by hardware means? NO! „…to be assumed that ‘sole control’ can be achieved with appropriate technical or organisational means even with software certificates […] … security measures need to be in place providing that the signatory can enforce his sole control…“ (RV 293 BlgNR 23. GP) – see also FESA - working paper on advanced electronic signatures and “Public Statement on Server Based Signature Services”: “…FESA members believe that sole control at least of the signature creation data can be achieved and that advanced electronic signatures can be created by a server based signature service…“! Advanced Electronic Signature is uniquely linked to the signatory it is capable of identifying the signatory it is created using means that the signatory can maintain under his sole control it is linked to the data to which it relates in such a manner that any subsequent change of the data is detectable Fußzeile Seite 30 29.09.2011
  • 31. Kopfzeile „it is linked to the data to which it relates in such a manner that any subsequent change of the data is detectable “ Integrity practically impossible that different electronic data result in the same signature or can be created from a given electronic signature. Advanced Electronic Signature is uniquely linked to the signatory it is capable of identifying the signatory it is created using means that the signatory can maintain under his sole control it is linked to the data to which it relates in such a manner that any subsequent change of the data is detectable Fußzeile Seite 31 29.09.2011
  • 32. Kopfzeile Qualified Signature? Qualified Signature = advanced el. signature + qualified certificate + SSCD Qualified Certificate Qualified Certficate Certificate content Requirements Annex I Annex II 1999/93/EC 1999/93/EC Fußzeile Seite 32 29.09.2011
  • 33. Kopfzeile Certificate Content (Annex I) indication that the certificate is issued as a qualified certificate identification of the CSP and the State in which it is established name of the signatory (or a pseudonym identified as such) signature-verification data which correspond to signature-creation data under the control of the signatory beginning and end of the period of validity of the certificate identity code of the certificate advanced electronic signature of the CSP issuing it Further options: limitations on scope, value of transaction, specific attributes of the signatory Requirements on the CSP (Annex II) reliability necessary for providing certification services secure directory and a secure and immediate revocation service precise date and time when a certificate is issued or revoked verify identity and, if applicable, specific attributes of the signatory personnel with expert knowledge, experience, and qualifications (managerial level, electr. signature technology, security procedures) trustworthy systems and products - protected against modification and ensuring the technical and cryptographic security; measures against forgery of certificates, and, in cases where the CSP generates signature-creation data, guarantee its confidentiality sufficient financial resources (to bear the risk of liability for damages) etc. Fußzeile Seite 33 29.09.2011
  • 34. Kopfzeile Qualified Signature? Qualified Signature = advanced el. signature + qualified certificate + SSCD SSCD Confirmation by a designated body (Art. 3(4) of 1999/93/EC) § 6 Abs. 3 Signature Order 2008: Organisational security measures possible, if components are operated in a “controlled environment” (e.g., qualified and reliable personnel, appropriate physical and logical access control). A-SIT conformity certificate: 2.11.2009 According to Art. 3 para 4 second subpara of the Directive, this attestation (“determination of conformity with the requirements laid down in Annex III”) is to be recognised by all Member States. Fußzeile Seite 34 29.09.2011
  • 35. Kopfzeile Qualified Signature? Qualified Signature = advanced el. signature + qualified certificate + SSCD Mobile Phone Signature – Legal Assessment Mobile Phone Signature = Citizen Card? Citizen Card = qualified signature + identity link Mobile Phone Signature = qualified signature? Qualified Signature = advanced electronic signature + qualified certificate + SSCD Fußzeile Seite 35 29.09.2011