SlideShare ist ein Scribd-Unternehmen logo
1 von 35
PKI: The View from Down
Under
Presentation to 2001 Institutional Web
Management Workshop
Queen’s University Belfast
Monday 25 June 2001
Ed Bristow, PKI Technical Manager,
Australian Taxation Office
Agenda
• Who am I? Why am I here?
• The what, why and wherefore of PKI
• The Australian Scene
• The ATO PKI
• The Future
Canberra
•Canberra
Some definitions
• PKI - Public Key Infrastructure
– The technology, policies and processes involved in generation,
signing, issue and use of asymmetric ciphers and digital
certificates
• ATO - Australian Taxation Office
• BAS - Business Activity Statement
– Monthly or quarterly business tax report completed by all
Australian businesses
• SSL - Secure Sockets Layer
– Standard for encryption of connection between web server and
browser. Now at Version 3.0.
• S/MIME - Secure Multipurpose Internet Mail Extensions
(RFC 1521)
– A standard for creating securely wrapped messages
More Definitions
• OCSP - Online Certificate Status Protocol.
– Standard (RFC 2560) for the checking of a certificate’s revocation
status in real time
• CRL - Certificate revocation list
– List of serial numbers of revoked certificates, published
periodically by CA. Part of X.509 (RFC 2459)
• DMZ - Demilitarised zone.
– Area between outer and inner firewalls where elements of a site’s
security architecture is deployed
• X.500 - Standard for Internet directories
• LDAP - Lightweight Directory Access Protocol
• PKCS - Proprietary (but industry-wide) standards
developed and maintained by RSA Security Inc
Why PKI
• E-commerce on the rise
• The Internet is a dangerous place
• The importance of standards
• Digital signatures promise remote, un-
repudiable authentication
• The dream of PKI - certificate once,
authenticate everywhere
Key Topics
• Confidentiality
• Authentication
• Authorisation
Confidentiality
• Is SSL good enough?
– Data is vulnerable on the server
– Enforce strong cipher suites
• Consider use of S/MIME
– Decryption is done deeper in DMZ
• Need to pay attention to web site design
• Some products don’t support two key pairs
Authentication
• What to use?
– User ID & Password
• Simple for users, but have to be administered &
can be cracked
– Shared Secret
• Just how secure is the secret?
• Doesn’t also provide integrity & non-repudiation
– Digital Certificates
• It’s not a trivial decision
Authorisation
• The next big challenge
• The unrealised potential of X.500 &
LDAP
• Products starting to emerge
• Active Directory & Kerberos in Windows
2000
• Solutions are policy & directory based
• What’s the degree of fit?
Can PKI be made to work?
• It does cost!
• But it does also deliver
• Many standards based components
• But overall solution will need to be
customised
• Native browser based PKI is just not up
to it at present
What are the major issues?
• Registration
• Key & Certificate distribution
• End-user application design
• Server side design
Registration
• Binds the identity to the public key
• Get this wrong and there’s no point in
worrying about the rest
• Can be logistically difficult (and
expensive)
– Especially with geographically dispersed
population
• Are there opportunities to leverage
another progress?
End-User application design
• Native browser, applet or fat client
• What platforms to support?
– Windows & Mac
– IE & Netscape
• How are private keys stored &
accessed
– Smart card (PKCS#11)
– ‘Soft Key’ (PKCS#12)
Server Side Design
• Performance
• Availability
• Certificate validation
– OCSP vs CRL
• Do responses need to be signed?
• Accept keys and certificates from
multiple CA’s or just one?
Overall
• Assess the value and importance of
transactions
• Threat and risk analysis as first step
• look for leverage opportunities
Australia - Land of Contrasts
• Strengths
– Innovative culture
– Early adopters
– Government sector prepared to lead
– Small enough for national solutions to be
viable
– ‘Can do’ attitude
Australia - Land of Contrasts
• Weaknesses
– 7 + 2 Governments
– Short electoral cycle
– Small population base
– Geographic Isolation
– ‘Branch Office’ Economy
– Slow telecoms in rural and remote areas
– ‘The Tyranny of Distance’
Gatekeeper
• Federal Government has
provided a lead
• Accreditation scheme for CA’s
and RA’s
• Mandated for Federal
government agencies
• Also signed-up to by states (no
mean feat!)
• Cross-recognition of Australian
Identrus CA’s
Gatekeeper - Drawbacks
• High barrier to entry
• Onerous accreditation requirements
– ATO completed 33 different documents
– Can be too slow for commercial
requirements
• Focus to date has been on business
– PKI for individuals still some way off
• But Gatekeeper2 is coming ...
Gatekeeper - Progress
• ATO was first to achieve full accreditation
• Commercial sector (eSign & Baltimore)
now also fully accredited
• Government-sponsored standard for
certificates
– Contains Australian Business Number (ABN)
– Can be used by businesses to deal with
government at all levels
– Can be issued by any accredited or cross-
recognized CA
The ATO
• Main revenue collection authority for
Commonwealth Government
• Collects Income Tax, GST, Excise and
other taxes
• Approx 20,000 Staff
• Facing the ‘electronic challenge’
– Improve services
– Reduce costs
– Change the paradigm of interaction
ATO Electronic Initiatives
• Agent lodged Income Tax returns via
X.25 and proprietary s/w since 1991
– Now accounts for > 75% of all returns
• Self-lodged Income Tax returns via pre-
Gatekeeper PKI-enabled ‘e-tax’ system
– Now in 4th year of operation
– Expect 400,000 lodgments this year
PKI in the ATO
• First full Gatekeeper accreditation
• Support of tax Reform
– GST (VAT type tax) from 1/7/2001
– New reporting regime for business
• Not our core business!
• 100k certificate pairs issued
The ATO PKI Project
• Created and rolled-out an accredited
PKI in less than 9 months
• High pressure project
– Short time frame
– Legislative deadline
– Complex requirements
• Breaking new ground
Features
• Rely on business registration process to
feed the RA
– Integrated with legacy (DB2/OS390)
database
• Centrally-generated keys
• Distribution via Internet
• Two key pairs/certificates
– Authentication (Signing)
– Confidentiality (Encryption)
Constraints
• Very rapid roll-out required
– 145,000 in first month (achieved)
• Security requirements on certificate
download
• Use Baltimore technology (UniCERT)
• Drop dead deadline (legislative)
• Outsourced infrastructure
The Good
• 100,000 sets of keys and certificates distributed in
first year of operation
• 70,000 businesses registered to deal electronically
• Over 500,000 e-BAS’s lodged
• Most find process fairly straightforward
• Businesses appear happy with authentication and
confidentiality provided
• Vastly lower rejection and intervention rates on e-
BAS’s
• Quicker refunds (where payable)
The Bad
• Teething problems - rapid roll-out
• Design issues - eg including ATO-specific
data in certificate
• User experience (eg download) still not
satisfactory
• Lack of perceived value to business
• Process to get certificates and e-BAS
complex - plenty of opportunities for
problems
• logistical delays (eg PIC mailer printing)
• Marketing in a saturated environment
The Ugly
• Keys and certificates delivered in
browser unfriendly package
• Changes in external S/W (eg IE 5.5
SP1) can have near-catastrophic
effects
• Technical (il)literacy of some users
• Security can have serious effects on
useability
• Data quality (esp. e-mail addresses)
Learnings
• Key success factors
– ‘Drop dead’ deadline
– Strong corporate support
– Small, strongly focussed team
– Exploitation of skills and knowledge of partners
• Pay attention to useability
– Otherwise - help desk gets very busy!
• Understand the customer - market
segmentation
The Future - Some Questions
• Will PKI become universal, or is it just
too hard?
• Is the Internet too dangerous a place to
do business?
• Can schemes like Gatekeeper ever
really succeed?
• Can anyone make serious money out of
PKI?
The Future - Some Answers
• RSA appears to be unassailable - for now
– We can be confident about the technology
• Success of PKI depends on
– Robust and trustable registration processes
– Useful applications - there must be a value
proposition
– Making the technology transparent
• Australian model has significant strengths
– Universal scheme
– Standards based - vendor neutral
– Public-Private sector partnership
Links
www.ato.gov.au
www.taxreform.ato.gov.au
www.ato-pki.ato.gov.au
www.govonline.gov.au
www.baltimore.com
www.esign.com.au
www.identrus.com
Thank You

Weitere ähnliche Inhalte

Andere mochten auch

Mm Racing Rus (Nx Power Lite)
Mm Racing Rus (Nx Power Lite)Mm Racing Rus (Nx Power Lite)
Mm Racing Rus (Nx Power Lite)Lysenko Andrey
 
IWMW 2000: A Controversial Proposal
IWMW 2000: A Controversial ProposalIWMW 2000: A Controversial Proposal
IWMW 2000: A Controversial ProposalIWMW
 
100 to 1(ish) unifying a sprawling web estate
100 to 1(ish)   unifying a sprawling web estate 100 to 1(ish)   unifying a sprawling web estate
100 to 1(ish) unifying a sprawling web estate IWMW
 
MoD Spox 19.09
MoD Spox 19.09MoD Spox 19.09
MoD Spox 19.09UAReforms
 
MoD Spox November 7, 2016
MoD Spox November 7, 2016MoD Spox November 7, 2016
MoD Spox November 7, 2016UAReforms
 
Опитування МРІ щодо ОСББ
Опитування МРІ щодо ОСББОпитування МРІ щодо ОСББ
Опитування МРІ щодо ОСББUAReforms
 
КЛМ_Урок 2
КЛМ_Урок 2КЛМ_Урок 2
КЛМ_Урок 2RaynaITSTEP
 
Building a digital_library_from_scratch
Building a digital_library_from_scratchBuilding a digital_library_from_scratch
Building a digital_library_from_scratchrobin fay
 
.NET/C#_19
.NET/C#_19.NET/C#_19
.NET/C#_19RaynaITSTEP
 
PhS - Урок 11
PhS - Урок 11PhS - Урок 11
PhS - Урок 11RaynaITSTEP
 
Collaborative sketching - research through design
Collaborative sketching  - research through designCollaborative sketching  - research through design
Collaborative sketching - research through designNeil Allison
 
The Role of the Library in a Digital World
The Role of the Library in a Digital WorldThe Role of the Library in a Digital World
The Role of the Library in a Digital WorldBobbi Newman
 

Andere mochten auch (18)

Mm Racing Rus (Nx Power Lite)
Mm Racing Rus (Nx Power Lite)Mm Racing Rus (Nx Power Lite)
Mm Racing Rus (Nx Power Lite)
 
IWMW 2000: A Controversial Proposal
IWMW 2000: A Controversial ProposalIWMW 2000: A Controversial Proposal
IWMW 2000: A Controversial Proposal
 
100 to 1(ish) unifying a sprawling web estate
100 to 1(ish)   unifying a sprawling web estate 100 to 1(ish)   unifying a sprawling web estate
100 to 1(ish) unifying a sprawling web estate
 
Виконання програми діяльності Уряду 2015 та плани на 2016
Виконання програми діяльності Уряду 2015 та плани на 2016Виконання програми діяльності Уряду 2015 та плани на 2016
Виконання програми діяльності Уряду 2015 та плани на 2016
 
MoD Spox 19.09
MoD Spox 19.09MoD Spox 19.09
MoD Spox 19.09
 
MoD Spox November 7, 2016
MoD Spox November 7, 2016MoD Spox November 7, 2016
MoD Spox November 7, 2016
 
Les Français et les retraites
Les Français et les retraitesLes Français et les retraites
Les Français et les retraites
 
Опитування МРІ щодо ОСББ
Опитування МРІ щодо ОСББОпитування МРІ щодо ОСББ
Опитування МРІ щодо ОСББ
 
Reform committe. Reform support team
Reform committe. Reform support teamReform committe. Reform support team
Reform committe. Reform support team
 
КЛМ_Урок 2
КЛМ_Урок 2КЛМ_Урок 2
КЛМ_Урок 2
 
Building a digital_library_from_scratch
Building a digital_library_from_scratchBuilding a digital_library_from_scratch
Building a digital_library_from_scratch
 
Donor meeting. Ministry of Infrastructure of Ukraine 6th of December
Donor meeting. Ministry of Infrastructure of Ukraine 6th of DecemberDonor meeting. Ministry of Infrastructure of Ukraine 6th of December
Donor meeting. Ministry of Infrastructure of Ukraine 6th of December
 
.NET/C#_19
.NET/C#_19.NET/C#_19
.NET/C#_19
 
.NET/C#_6
.NET/C#_6.NET/C#_6
.NET/C#_6
 
.NET/C#_2
.NET/C#_2.NET/C#_2
.NET/C#_2
 
PhS - Урок 11
PhS - Урок 11PhS - Урок 11
PhS - Урок 11
 
Collaborative sketching - research through design
Collaborative sketching  - research through designCollaborative sketching  - research through design
Collaborative sketching - research through design
 
The Role of the Library in a Digital World
The Role of the Library in a Digital WorldThe Role of the Library in a Digital World
The Role of the Library in a Digital World
 

Ähnlich wie IWMW 2001: PKI: the View from Down Under

Qtility software ltd
Qtility software ltdQtility software ltd
Qtility software ltdclarkems
 
OFFICE 365- CLOUD OR NOT, YOU SHOULD KNOW HOW IT WILL SHAPE YOUR ORGANISATIO...
OFFICE 365-  CLOUD OR NOT, YOU SHOULD KNOW HOW IT WILL SHAPE YOUR ORGANISATIO...OFFICE 365-  CLOUD OR NOT, YOU SHOULD KNOW HOW IT WILL SHAPE YOUR ORGANISATIO...
OFFICE 365- CLOUD OR NOT, YOU SHOULD KNOW HOW IT WILL SHAPE YOUR ORGANISATIO...Waterstons Ltd
 
Tim Willoughby presentation to cloud workshop 2016
Tim Willoughby presentation to cloud workshop 2016Tim Willoughby presentation to cloud workshop 2016
Tim Willoughby presentation to cloud workshop 2016Tim Willoughby
 
Pros & Cons of Microservices Architecture
Pros & Cons of Microservices ArchitecturePros & Cons of Microservices Architecture
Pros & Cons of Microservices ArchitectureAshwini Kuntamukkala
 
GlobalSign's Hosted OCSP for IoT PKIs
GlobalSign's Hosted OCSP for IoT PKIsGlobalSign's Hosted OCSP for IoT PKIs
GlobalSign's Hosted OCSP for IoT PKIsGlobalSign
 
SplunkLive! Austin Customer Presentation - Xerox
SplunkLive! Austin Customer Presentation - XeroxSplunkLive! Austin Customer Presentation - Xerox
SplunkLive! Austin Customer Presentation - XeroxSplunk
 
Rethinking Quicksign's Digital Onboarding - Confluent Streaming Days Paris
Rethinking Quicksign's Digital Onboarding - Confluent Streaming Days ParisRethinking Quicksign's Digital Onboarding - Confluent Streaming Days Paris
Rethinking Quicksign's Digital Onboarding - Confluent Streaming Days ParisCedric Vidal
 
Managed Services Oracle EDI Integration HOUG 15APR23
Managed Services Oracle EDI Integration HOUG 15APR23Managed Services Oracle EDI Integration HOUG 15APR23
Managed Services Oracle EDI Integration HOUG 15APR23Mike Neadeau
 
TechFuse 2012: Cloud and Mobile Computing
TechFuse 2012: Cloud and Mobile ComputingTechFuse 2012: Cloud and Mobile Computing
TechFuse 2012: Cloud and Mobile ComputingAvtex
 
Controlling Expenses with Web-Based Purchasing for Sage 500
Controlling Expenses with Web-Based Purchasing for Sage 500 Controlling Expenses with Web-Based Purchasing for Sage 500
Controlling Expenses with Web-Based Purchasing for Sage 500 Net at Work
 
gkkCloudtechnologyassociate(cta)day 2
gkkCloudtechnologyassociate(cta)day 2gkkCloudtechnologyassociate(cta)day 2
gkkCloudtechnologyassociate(cta)day 2Anne Starr
 
Micro service architecture
Micro service architecture  Micro service architecture
Micro service architecture Ayyappan Paramesh
 
Scott Rea - IoT: Taking PKI Where No PKI Has Gone Before
Scott Rea - IoT: Taking PKI Where No PKI Has Gone BeforeScott Rea - IoT: Taking PKI Where No PKI Has Gone Before
Scott Rea - IoT: Taking PKI Where No PKI Has Gone BeforeDigiCert, Inc.
 
Bringing banking to digital
Bringing banking to digitalBringing banking to digital
Bringing banking to digitalAzrul MADISA
 
Bridging the Cloud Sign-On Gap
Bridging the Cloud Sign-On GapBridging the Cloud Sign-On Gap
Bridging the Cloud Sign-On GapOracleIDM
 
Outsourcing Your SharePoint Hosting - the clouds fine print magnified
Outsourcing Your SharePoint Hosting - the clouds fine print magnifiedOutsourcing Your SharePoint Hosting - the clouds fine print magnified
Outsourcing Your SharePoint Hosting - the clouds fine print magnifiedSherWeb
 
Sps chicago suburbs outsourcing your share point hosting - the clouds fine ...
Sps chicago suburbs   outsourcing your share point hosting - the clouds fine ...Sps chicago suburbs   outsourcing your share point hosting - the clouds fine ...
Sps chicago suburbs outsourcing your share point hosting - the clouds fine ...SherWeb
 
Sps chicago suburbs outsourcing your share point hosting - the clouds fine ...
Sps chicago suburbs   outsourcing your share point hosting - the clouds fine ...Sps chicago suburbs   outsourcing your share point hosting - the clouds fine ...
Sps chicago suburbs outsourcing your share point hosting - the clouds fine ...SherWeb
 

Ähnlich wie IWMW 2001: PKI: the View from Down Under (20)

PKI Industry growth in Bangladesh
PKI Industry growth in BangladeshPKI Industry growth in Bangladesh
PKI Industry growth in Bangladesh
 
Qtility software ltd
Qtility software ltdQtility software ltd
Qtility software ltd
 
OFFICE 365- CLOUD OR NOT, YOU SHOULD KNOW HOW IT WILL SHAPE YOUR ORGANISATIO...
OFFICE 365-  CLOUD OR NOT, YOU SHOULD KNOW HOW IT WILL SHAPE YOUR ORGANISATIO...OFFICE 365-  CLOUD OR NOT, YOU SHOULD KNOW HOW IT WILL SHAPE YOUR ORGANISATIO...
OFFICE 365- CLOUD OR NOT, YOU SHOULD KNOW HOW IT WILL SHAPE YOUR ORGANISATIO...
 
Tim Willoughby presentation to cloud workshop 2016
Tim Willoughby presentation to cloud workshop 2016Tim Willoughby presentation to cloud workshop 2016
Tim Willoughby presentation to cloud workshop 2016
 
Pros & Cons of Microservices Architecture
Pros & Cons of Microservices ArchitecturePros & Cons of Microservices Architecture
Pros & Cons of Microservices Architecture
 
GlobalSign's Hosted OCSP for IoT PKIs
GlobalSign's Hosted OCSP for IoT PKIsGlobalSign's Hosted OCSP for IoT PKIs
GlobalSign's Hosted OCSP for IoT PKIs
 
SplunkLive! Austin Customer Presentation - Xerox
SplunkLive! Austin Customer Presentation - XeroxSplunkLive! Austin Customer Presentation - Xerox
SplunkLive! Austin Customer Presentation - Xerox
 
Rethinking Quicksign's Digital Onboarding - Confluent Streaming Days Paris
Rethinking Quicksign's Digital Onboarding - Confluent Streaming Days ParisRethinking Quicksign's Digital Onboarding - Confluent Streaming Days Paris
Rethinking Quicksign's Digital Onboarding - Confluent Streaming Days Paris
 
Managed Services Oracle EDI Integration HOUG 15APR23
Managed Services Oracle EDI Integration HOUG 15APR23Managed Services Oracle EDI Integration HOUG 15APR23
Managed Services Oracle EDI Integration HOUG 15APR23
 
TechFuse 2012: Cloud and Mobile Computing
TechFuse 2012: Cloud and Mobile ComputingTechFuse 2012: Cloud and Mobile Computing
TechFuse 2012: Cloud and Mobile Computing
 
Controlling Expenses with Web-Based Purchasing for Sage 500
Controlling Expenses with Web-Based Purchasing for Sage 500 Controlling Expenses with Web-Based Purchasing for Sage 500
Controlling Expenses with Web-Based Purchasing for Sage 500
 
gkkCloudtechnologyassociate(cta)day 2
gkkCloudtechnologyassociate(cta)day 2gkkCloudtechnologyassociate(cta)day 2
gkkCloudtechnologyassociate(cta)day 2
 
Micro service architecture
Micro service architecture  Micro service architecture
Micro service architecture
 
Scott Rea - IoT: Taking PKI Where No PKI Has Gone Before
Scott Rea - IoT: Taking PKI Where No PKI Has Gone BeforeScott Rea - IoT: Taking PKI Where No PKI Has Gone Before
Scott Rea - IoT: Taking PKI Where No PKI Has Gone Before
 
Bringing banking to digital
Bringing banking to digitalBringing banking to digital
Bringing banking to digital
 
Bridging the Cloud Sign-On Gap
Bridging the Cloud Sign-On GapBridging the Cloud Sign-On Gap
Bridging the Cloud Sign-On Gap
 
Outsourcing Your SharePoint Hosting - the clouds fine print magnified
Outsourcing Your SharePoint Hosting - the clouds fine print magnifiedOutsourcing Your SharePoint Hosting - the clouds fine print magnified
Outsourcing Your SharePoint Hosting - the clouds fine print magnified
 
Sps chicago suburbs outsourcing your share point hosting - the clouds fine ...
Sps chicago suburbs   outsourcing your share point hosting - the clouds fine ...Sps chicago suburbs   outsourcing your share point hosting - the clouds fine ...
Sps chicago suburbs outsourcing your share point hosting - the clouds fine ...
 
Sps chicago suburbs outsourcing your share point hosting - the clouds fine ...
Sps chicago suburbs   outsourcing your share point hosting - the clouds fine ...Sps chicago suburbs   outsourcing your share point hosting - the clouds fine ...
Sps chicago suburbs outsourcing your share point hosting - the clouds fine ...
 
MISMO / eMortgage Update
MISMO / eMortgage UpdateMISMO / eMortgage Update
MISMO / eMortgage Update
 

Mehr von IWMW

Look who's talking now
Look who's talking nowLook who's talking now
Look who's talking nowIWMW
 
Introduction to IWMW 2000 (Liz Lyon)
Introduction to IWMW 2000 (Liz Lyon)Introduction to IWMW 2000 (Liz Lyon)
Introduction to IWMW 2000 (Liz Lyon)IWMW
 
Web Tools report
Web Tools reportWeb Tools report
Web Tools reportIWMW
 
Personal Contingency Plan - Beat The Panic
Personal Contingency Plan - Beat The PanicPersonal Contingency Plan - Beat The Panic
Personal Contingency Plan - Beat The PanicIWMW
 
Whose site is it anyway?
Whose site is it anyway?Whose site is it anyway?
Whose site is it anyway?IWMW
 
Open Source - the case against
Open Source - the case againstOpen Source - the case against
Open Source - the case againstIWMW
 
IWMW 2002: Avoiding Portal Wars - an MIS view
IWMW 2002: Avoiding Portal Wars - an MIS viewIWMW 2002: Avoiding Portal Wars - an MIS view
IWMW 2002: Avoiding Portal Wars - an MIS viewIWMW
 
What does open source mean for the institutional web manager?
What does open source mean for the institutional web manager?What does open source mean for the institutional web manager?
What does open source mean for the institutional web manager?IWMW
 
Library 2.0
Library 2.0Library 2.0
Library 2.0IWMW
 
Social participation in student recruitment
Social participation in student recruitmentSocial participation in student recruitment
Social participation in student recruitmentIWMW
 
Supporting Institutions in Changing Times: Manifesto
Supporting Institutions in Changing Times: ManifestoSupporting Institutions in Changing Times: Manifesto
Supporting Institutions in Changing Times: ManifestoIWMW
 
IWMW 2019 photo scavenger hunt highlights
IWMW 2019 photo scavenger hunt highlightsIWMW 2019 photo scavenger hunt highlights
IWMW 2019 photo scavenger hunt highlightsIWMW
 
How to Turn a Web Strategy into Web Services
How to Turn a Web Strategy into Web ServicesHow to Turn a Web Strategy into Web Services
How to Turn a Web Strategy into Web ServicesIWMW
 
Static Site Generators - Developing Websites in Low-resource Condition
Static Site Generators - Developing Websites in Low-resource ConditionStatic Site Generators - Developing Websites in Low-resource Condition
Static Site Generators - Developing Websites in Low-resource ConditionIWMW
 
Looking to the Future
Looking to the FutureLooking to the Future
Looking to the FutureIWMW
 
Looking to the Future
Looking to the FutureLooking to the Future
Looking to the FutureIWMW
 
Developing Communities of Practice
Developing Communities of PracticeDeveloping Communities of Practice
Developing Communities of PracticeIWMW
 
How to train your content- so it doesn't slow you down...
How to train your content- so it doesn't slow you down... How to train your content- so it doesn't slow you down...
How to train your content- so it doesn't slow you down... IWMW
 
Grassroots & Guerrillas: The Beginnings of a UX Revolution
Grassroots & Guerrillas: The Beginnings of a UX RevolutionGrassroots & Guerrillas: The Beginnings of a UX Revolution
Grassroots & Guerrillas: The Beginnings of a UX RevolutionIWMW
 
Connecting Your Content: How to Save Time and Improve Content Quality through...
Connecting Your Content: How to Save Time and Improve Content Quality through...Connecting Your Content: How to Save Time and Improve Content Quality through...
Connecting Your Content: How to Save Time and Improve Content Quality through...IWMW
 

Mehr von IWMW (20)

Look who's talking now
Look who's talking nowLook who's talking now
Look who's talking now
 
Introduction to IWMW 2000 (Liz Lyon)
Introduction to IWMW 2000 (Liz Lyon)Introduction to IWMW 2000 (Liz Lyon)
Introduction to IWMW 2000 (Liz Lyon)
 
Web Tools report
Web Tools reportWeb Tools report
Web Tools report
 
Personal Contingency Plan - Beat The Panic
Personal Contingency Plan - Beat The PanicPersonal Contingency Plan - Beat The Panic
Personal Contingency Plan - Beat The Panic
 
Whose site is it anyway?
Whose site is it anyway?Whose site is it anyway?
Whose site is it anyway?
 
Open Source - the case against
Open Source - the case againstOpen Source - the case against
Open Source - the case against
 
IWMW 2002: Avoiding Portal Wars - an MIS view
IWMW 2002: Avoiding Portal Wars - an MIS viewIWMW 2002: Avoiding Portal Wars - an MIS view
IWMW 2002: Avoiding Portal Wars - an MIS view
 
What does open source mean for the institutional web manager?
What does open source mean for the institutional web manager?What does open source mean for the institutional web manager?
What does open source mean for the institutional web manager?
 
Library 2.0
Library 2.0Library 2.0
Library 2.0
 
Social participation in student recruitment
Social participation in student recruitmentSocial participation in student recruitment
Social participation in student recruitment
 
Supporting Institutions in Changing Times: Manifesto
Supporting Institutions in Changing Times: ManifestoSupporting Institutions in Changing Times: Manifesto
Supporting Institutions in Changing Times: Manifesto
 
IWMW 2019 photo scavenger hunt highlights
IWMW 2019 photo scavenger hunt highlightsIWMW 2019 photo scavenger hunt highlights
IWMW 2019 photo scavenger hunt highlights
 
How to Turn a Web Strategy into Web Services
How to Turn a Web Strategy into Web ServicesHow to Turn a Web Strategy into Web Services
How to Turn a Web Strategy into Web Services
 
Static Site Generators - Developing Websites in Low-resource Condition
Static Site Generators - Developing Websites in Low-resource ConditionStatic Site Generators - Developing Websites in Low-resource Condition
Static Site Generators - Developing Websites in Low-resource Condition
 
Looking to the Future
Looking to the FutureLooking to the Future
Looking to the Future
 
Looking to the Future
Looking to the FutureLooking to the Future
Looking to the Future
 
Developing Communities of Practice
Developing Communities of PracticeDeveloping Communities of Practice
Developing Communities of Practice
 
How to train your content- so it doesn't slow you down...
How to train your content- so it doesn't slow you down... How to train your content- so it doesn't slow you down...
How to train your content- so it doesn't slow you down...
 
Grassroots & Guerrillas: The Beginnings of a UX Revolution
Grassroots & Guerrillas: The Beginnings of a UX RevolutionGrassroots & Guerrillas: The Beginnings of a UX Revolution
Grassroots & Guerrillas: The Beginnings of a UX Revolution
 
Connecting Your Content: How to Save Time and Improve Content Quality through...
Connecting Your Content: How to Save Time and Improve Content Quality through...Connecting Your Content: How to Save Time and Improve Content Quality through...
Connecting Your Content: How to Save Time and Improve Content Quality through...
 

KĂźrzlich hochgeladen

Karra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxKarra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxAshokKarra1
 
Science 7 Quarter 4 Module 2: Natural Resources.pptx
Science 7 Quarter 4 Module 2: Natural Resources.pptxScience 7 Quarter 4 Module 2: Natural Resources.pptx
Science 7 Quarter 4 Module 2: Natural Resources.pptxMaryGraceBautista27
 
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)lakshayb543
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designMIPLM
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...Nguyen Thanh Tu Collection
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONHumphrey A BeĂąa
 
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptxMULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptxAnupkumar Sharma
 
ACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdfACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdfSpandanaRallapalli
 
ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4MiaBumagat1
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptxmary850239
 
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Celine George
 
Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)cama23
 
FILIPINO PSYCHology sikolohiyang pilipino
FILIPINO PSYCHology sikolohiyang pilipinoFILIPINO PSYCHology sikolohiyang pilipino
FILIPINO PSYCHology sikolohiyang pilipinojohnmickonozaleda
 
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYKayeClaireEstoconing
 
Concurrency Control in Database Management system
Concurrency Control in Database Management systemConcurrency Control in Database Management system
Concurrency Control in Database Management systemChristalin Nelson
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfJemuel Francisco
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...JhezDiaz1
 
Barangay Council for the Protection of Children (BCPC) Orientation.pptx
Barangay Council for the Protection of Children (BCPC) Orientation.pptxBarangay Council for the Protection of Children (BCPC) Orientation.pptx
Barangay Council for the Protection of Children (BCPC) Orientation.pptxCarlos105
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSJoshuaGantuangco2
 
Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatYousafMalik24
 

KĂźrzlich hochgeladen (20)

Karra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptxKarra SKD Conference Presentation Revised.pptx
Karra SKD Conference Presentation Revised.pptx
 
Science 7 Quarter 4 Module 2: Natural Resources.pptx
Science 7 Quarter 4 Module 2: Natural Resources.pptxScience 7 Quarter 4 Module 2: Natural Resources.pptx
Science 7 Quarter 4 Module 2: Natural Resources.pptx
 
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
Visit to a blind student's school🧑‍🦯🧑‍🦯(community medicine)
 
Keynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-designKeynote by Prof. Wurzer at Nordex about IP-design
Keynote by Prof. Wurzer at Nordex about IP-design
 
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
HỌC TỐT TIẾNG ANH 11 THEO CHƯƠNG TRÌNH GLOBAL SUCCESS ĐÁP ÁN CHI TIẾT - CẢ NĂ...
 
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATIONTHEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
THEORIES OF ORGANIZATION-PUBLIC ADMINISTRATION
 
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptxMULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
MULTIDISCIPLINRY NATURE OF THE ENVIRONMENTAL STUDIES.pptx
 
ACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdfACC 2024 Chronicles. Cardiology. Exam.pdf
ACC 2024 Chronicles. Cardiology. Exam.pdf
 
ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4ANG SEKTOR NG agrikultura.pptx QUARTER 4
ANG SEKTOR NG agrikultura.pptx QUARTER 4
 
4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx4.18.24 Movement Legacies, Reflection, and Review.pptx
4.18.24 Movement Legacies, Reflection, and Review.pptx
 
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
Incoming and Outgoing Shipments in 3 STEPS Using Odoo 17
 
Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)Global Lehigh Strategic Initiatives (without descriptions)
Global Lehigh Strategic Initiatives (without descriptions)
 
FILIPINO PSYCHology sikolohiyang pilipino
FILIPINO PSYCHology sikolohiyang pilipinoFILIPINO PSYCHology sikolohiyang pilipino
FILIPINO PSYCHology sikolohiyang pilipino
 
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITYISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
ISYU TUNGKOL SA SEKSWLADIDA (ISSUE ABOUT SEXUALITY
 
Concurrency Control in Database Management system
Concurrency Control in Database Management systemConcurrency Control in Database Management system
Concurrency Control in Database Management system
 
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdfGrade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
Grade 9 Quarter 4 Dll Grade 9 Quarter 4 DLL.pdf
 
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
ENGLISH 7_Q4_LESSON 2_ Employing a Variety of Strategies for Effective Interp...
 
Barangay Council for the Protection of Children (BCPC) Orientation.pptx
Barangay Council for the Protection of Children (BCPC) Orientation.pptxBarangay Council for the Protection of Children (BCPC) Orientation.pptx
Barangay Council for the Protection of Children (BCPC) Orientation.pptx
 
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTSGRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
GRADE 4 - SUMMATIVE TEST QUARTER 4 ALL SUBJECTS
 
Earth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice greatEarth Day Presentation wow hello nice great
Earth Day Presentation wow hello nice great
 

IWMW 2001: PKI: the View from Down Under

  • 1. PKI: The View from Down Under Presentation to 2001 Institutional Web Management Workshop Queen’s University Belfast Monday 25 June 2001 Ed Bristow, PKI Technical Manager, Australian Taxation Office
  • 2. Agenda • Who am I? Why am I here? • The what, why and wherefore of PKI • The Australian Scene • The ATO PKI • The Future
  • 4. Some definitions • PKI - Public Key Infrastructure – The technology, policies and processes involved in generation, signing, issue and use of asymmetric ciphers and digital certificates • ATO - Australian Taxation Office • BAS - Business Activity Statement – Monthly or quarterly business tax report completed by all Australian businesses • SSL - Secure Sockets Layer – Standard for encryption of connection between web server and browser. Now at Version 3.0. • S/MIME - Secure Multipurpose Internet Mail Extensions (RFC 1521) – A standard for creating securely wrapped messages
  • 5. More Definitions • OCSP - Online Certificate Status Protocol. – Standard (RFC 2560) for the checking of a certificate’s revocation status in real time • CRL - Certificate revocation list – List of serial numbers of revoked certificates, published periodically by CA. Part of X.509 (RFC 2459) • DMZ - Demilitarised zone. – Area between outer and inner firewalls where elements of a site’s security architecture is deployed • X.500 - Standard for Internet directories • LDAP - Lightweight Directory Access Protocol • PKCS - Proprietary (but industry-wide) standards developed and maintained by RSA Security Inc
  • 6. Why PKI • E-commerce on the rise • The Internet is a dangerous place • The importance of standards • Digital signatures promise remote, un- repudiable authentication • The dream of PKI - certificate once, authenticate everywhere
  • 7. Key Topics • Confidentiality • Authentication • Authorisation
  • 8. Confidentiality • Is SSL good enough? – Data is vulnerable on the server – Enforce strong cipher suites • Consider use of S/MIME – Decryption is done deeper in DMZ • Need to pay attention to web site design • Some products don’t support two key pairs
  • 9. Authentication • What to use? – User ID & Password • Simple for users, but have to be administered & can be cracked – Shared Secret • Just how secure is the secret? • Doesn’t also provide integrity & non-repudiation – Digital Certificates • It’s not a trivial decision
  • 10. Authorisation • The next big challenge • The unrealised potential of X.500 & LDAP • Products starting to emerge • Active Directory & Kerberos in Windows 2000 • Solutions are policy & directory based • What’s the degree of fit?
  • 11. Can PKI be made to work? • It does cost! • But it does also deliver • Many standards based components • But overall solution will need to be customised • Native browser based PKI is just not up to it at present
  • 12. What are the major issues? • Registration • Key & Certificate distribution • End-user application design • Server side design
  • 13. Registration • Binds the identity to the public key • Get this wrong and there’s no point in worrying about the rest • Can be logistically difficult (and expensive) – Especially with geographically dispersed population • Are there opportunities to leverage another progress?
  • 14. End-User application design • Native browser, applet or fat client • What platforms to support? – Windows & Mac – IE & Netscape • How are private keys stored & accessed – Smart card (PKCS#11) – ‘Soft Key’ (PKCS#12)
  • 15. Server Side Design • Performance • Availability • Certificate validation – OCSP vs CRL • Do responses need to be signed? • Accept keys and certificates from multiple CA’s or just one?
  • 16. Overall • Assess the value and importance of transactions • Threat and risk analysis as first step • look for leverage opportunities
  • 17. Australia - Land of Contrasts • Strengths – Innovative culture – Early adopters – Government sector prepared to lead – Small enough for national solutions to be viable – ‘Can do’ attitude
  • 18. Australia - Land of Contrasts • Weaknesses – 7 + 2 Governments – Short electoral cycle – Small population base – Geographic Isolation – ‘Branch Office’ Economy – Slow telecoms in rural and remote areas – ‘The Tyranny of Distance’
  • 19. Gatekeeper • Federal Government has provided a lead • Accreditation scheme for CA’s and RA’s • Mandated for Federal government agencies • Also signed-up to by states (no mean feat!) • Cross-recognition of Australian Identrus CA’s
  • 20. Gatekeeper - Drawbacks • High barrier to entry • Onerous accreditation requirements – ATO completed 33 different documents – Can be too slow for commercial requirements • Focus to date has been on business – PKI for individuals still some way off • But Gatekeeper2 is coming ...
  • 21. Gatekeeper - Progress • ATO was first to achieve full accreditation • Commercial sector (eSign & Baltimore) now also fully accredited • Government-sponsored standard for certificates – Contains Australian Business Number (ABN) – Can be used by businesses to deal with government at all levels – Can be issued by any accredited or cross- recognized CA
  • 22. The ATO • Main revenue collection authority for Commonwealth Government • Collects Income Tax, GST, Excise and other taxes • Approx 20,000 Staff • Facing the ‘electronic challenge’ – Improve services – Reduce costs – Change the paradigm of interaction
  • 23. ATO Electronic Initiatives • Agent lodged Income Tax returns via X.25 and proprietary s/w since 1991 – Now accounts for > 75% of all returns • Self-lodged Income Tax returns via pre- Gatekeeper PKI-enabled ‘e-tax’ system – Now in 4th year of operation – Expect 400,000 lodgments this year
  • 24. PKI in the ATO • First full Gatekeeper accreditation • Support of tax Reform – GST (VAT type tax) from 1/7/2001 – New reporting regime for business • Not our core business! • 100k certificate pairs issued
  • 25. The ATO PKI Project • Created and rolled-out an accredited PKI in less than 9 months • High pressure project – Short time frame – Legislative deadline – Complex requirements • Breaking new ground
  • 26. Features • Rely on business registration process to feed the RA – Integrated with legacy (DB2/OS390) database • Centrally-generated keys • Distribution via Internet • Two key pairs/certificates – Authentication (Signing) – Confidentiality (Encryption)
  • 27. Constraints • Very rapid roll-out required – 145,000 in first month (achieved) • Security requirements on certificate download • Use Baltimore technology (UniCERT) • Drop dead deadline (legislative) • Outsourced infrastructure
  • 28. The Good • 100,000 sets of keys and certificates distributed in first year of operation • 70,000 businesses registered to deal electronically • Over 500,000 e-BAS’s lodged • Most find process fairly straightforward • Businesses appear happy with authentication and confidentiality provided • Vastly lower rejection and intervention rates on e- BAS’s • Quicker refunds (where payable)
  • 29. The Bad • Teething problems - rapid roll-out • Design issues - eg including ATO-specific data in certificate • User experience (eg download) still not satisfactory • Lack of perceived value to business • Process to get certificates and e-BAS complex - plenty of opportunities for problems • logistical delays (eg PIC mailer printing) • Marketing in a saturated environment
  • 30. The Ugly • Keys and certificates delivered in browser unfriendly package • Changes in external S/W (eg IE 5.5 SP1) can have near-catastrophic effects • Technical (il)literacy of some users • Security can have serious effects on useability • Data quality (esp. e-mail addresses)
  • 31. Learnings • Key success factors – ‘Drop dead’ deadline – Strong corporate support – Small, strongly focussed team – Exploitation of skills and knowledge of partners • Pay attention to useability – Otherwise - help desk gets very busy! • Understand the customer - market segmentation
  • 32. The Future - Some Questions • Will PKI become universal, or is it just too hard? • Is the Internet too dangerous a place to do business? • Can schemes like Gatekeeper ever really succeed? • Can anyone make serious money out of PKI?
  • 33. The Future - Some Answers • RSA appears to be unassailable - for now – We can be confident about the technology • Success of PKI depends on – Robust and trustable registration processes – Useful applications - there must be a value proposition – Making the technology transparent • Australian model has significant strengths – Universal scheme – Standards based - vendor neutral – Public-Private sector partnership

Hinweis der Redaktion

  1. The Java language provides a high degree of platform independence and a smaller download size than any alternative technology. Full 128 bit encryption, the strongest available commercially, is used. HTTP (Hyper Text Transport Protocol) allows less different types of data to be carried than FTP (File Transfer Protocol), thereby reducing the ability of hackers to attack the system. Only Windows95, Windows98 and Windows NT are supported at present. A web browser (either Microsoft Internet Explorer Version 4.07 or Netscape Navigator (Version 4.01 or better) is required. There is a practical limit of about 50,000 records in a file. Beyond this the limitations of the physical connections over the Internet mean that transmission start to drop out. Higher numbers may be possible with ISDN lines. Tests indicate that a 50,000 record files takes about 20-25 minutes to transmit using a 28.8 Kbps modem. The files are compressed before transmission, which reduces their size by a up to a factor of 10.
  2. We have been trialing the system with three organisations, and have successfully received and transmitted files and messages in both directions. We are preparing to extend the pilot to up to 50 participants, in time for the lodgment of AVAs for the 1997/98 assessments, due in June 1999. We hope to have the system generally available to Surcharge reporters by October 1999, in time to be used for lodgment of 1998/99 MCS files. One major dependency that may affect this timeframe is the ability to issue and register keys.
  3. ECI not intended to replace other communication channels entirely, but to complement them. Developed as a direct response to Industry requests for an alternative to paper for small volumes of data. Designed to be easy to use - just get your key, connect to the Internet and you’re away. The only software you need is a browser - everything else is supplied - and browsers are free! The validation before sending means that you will only get back errors that result from data you supply being compared with data that the ATO holds. Build your lodgment file on the computer using SDCS and transmit using ECI. No paper anywhere in sight!
  4. Reduced costs for the ATO are always desirable. Improved data quality means less glitches in assessments Superannuation is breaking ground for the rest of the ATO - Tax Reform initiatives will use the same technology and there are a host of applications that will follow.