Siemens IT Solutions and Services - 2007 Porvoo 12 – Grosseto, October 2007 Update on EU Common Specifications.

Slides:



Advertisements
Similar presentations
Session 3: Safer Services in a Digital Society Security with RFID Gérald Santucci European Commission Head of Unit DG INFSO/D4.
Advertisements

1 Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market (COM( final) {SWD(2012)
© fedict All rights reserved Legal aspects Belgian electronic identity card Samoera Jacobs – November 2008.
S.O.S. eHealth Project Open eHealth initiative for a European large scale pilot of patient summary and electronic prescription Daniel Forslund, Head of.
GEOSS Data Sharing Principles. GEOSS 10-Year Implementation Plan 5.4 Data Sharing The societal benefits of Earth observations cannot be achieved without.
HIPAA Security Presentation to The American Hospital Association Dianne Faup Office of HIPAA Standards November 5, 2003.
A strategy for a Secure Information Society –
1 European Interoperability Framework for pan-European eGovernment Services Paulo Lopes European Commission, Directorate General Information Society Presentation.
EUPAN, Dublin 4 April 2013 EU e-Government Action Plan Harnessing ICT to promote smart, sustainable & innovative Government.
1 FPEG Identity theft & payment fraud point December 2007.
Seminar "Open Government in the Making" Brussels, 4 October 2012 Andrea Halmos European Commission, DG CONNECT Unit H3 Public Services.
Conclusions from e-Health
Paul Timmers eGovernment Unit Directorate General Information Society & Media European Commission Public eProcurement and EU eGovernment Developments 13.
Interoperability of electronic road toll systems in the EU The European Electronic Toll Service (EETS) Directive 2004/52/EC & Decision 2009/750/EC Charles.
European Union Cohesion Policy
© ITU Telecommunication Development Bureau (BDT) – E-Strategy Unit.. Page - 1 Seminar on Standardization and ICT Development for the Information.
Current trends and perspectives on e-Services for Public Services in Europe European Network Technical Seminar on Efficient e-Services in social security.
1 The impact of important Single Market policies on the development of Pan- European Services and Products i2010 Conference Information Society at the.
Cornel Vintila Expert in IT&C policies and regulations, Enterprise Architect, BPM Expert.
1 The interconnection of business registers Judit Fischer – DG Internal Market and Services Budapest, 14 June 2010.
The European Activities of BR Communication e-CODEX e-Justice Communication via Online Data Exchange Bucharest, June 14 th 2013.
EGovernment Vision, Policies and Implementations in Austria Prof. Dr. Reinhard Posch CHIEF INFORMATION OFFICER.
1 Insights on cross-border ex ante controls – Polish experiences 27th Conference of Directors of EU Paying Agencies Oviedo, April 2010.
1 14 th May 2008 How can pan-European Public Services Benefit from CIP ICT PSP Pilot on eID Dr. Davorka Šel Ministry of Public Administration SLOVENIA.
Stork is an EU co-funded project INFSO-ICT-PSP STORK PRESENTATION STORK eGov Symposium Bern 09.Nov.2010 Dipl.-Ing. (FH) Klaus J. John.
Stork 2.0 is an EU co-funded project INFSO-ICT-PSP Robert Scharinger & Gottfried Heider (Ministry of Health, AT) WP 5.4 eHealth pilot - epSOS OpenNCP.
CEN WS/BII2 1 Spreading interoperability in eProcurement processes across Europe Open Seminar Brussels December 6, 2012.
Setting Processes for Electronic Signature 1 The ”W-SPES Project” and the “Leuven Report on the Electronic Signatures Directive” – Putting the Project.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
European Electronic Identity Practices Country Update of …………… Speaker: Date:
Stork is an EU co-funded project INFSO-ICT-PSP Secure Identity Across Borders Linked Secure Electronic Identity Across Europe! STORK – 4 TH I NDUSTRY.
Intra-ASEAN Secure Transactions Framework Project Progress Report
Stork is an EU co-funded project INFSO-ICT-PSP STORK PRESENTATION STORK Presentation Lithuania March 2010.
Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia.
UN Economic Commission for Europe 23rd UN/CEFACT FORUM 7-11 April rd UN/CEFACT FORUM – Geneva Tahseen A. Khan Project Proposal : Trusted Third Party.
European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group.
1st MODINIS workshop Identity management in eGovernment Frank Robben General manager Crossroads Bank for Social Security Strategic advisor Federal Public.
Identity management – developments within the European Social Security Sector Pantelis Angelidis.
Synthesis of the Eurosmart’ Technical Day on eID interoperability Bruno Rouchouze, ID SG Convenor Porvoo 12, Grosseto - Italy.
Harmonisation of electronic Identities for the European Citizen Jan van Arkel, co- chair Porvoo group, May 11, 2006 Ljubljana.
Österreich 2006 Austria 2006 Autriche 2006 Präsidentschaft der Europäischen Union Presidency of the European Union Présidence de L’Union européenne ★★★★★★
How can I trust the rest of Europe ? Requirements and a possible organisation with regard to epSOS and eHealth Frank Robben General manager eHealth platform.
1 EUPAN: Contribution to the Helsinki 14 th September 2006 Alejandro Moya.
The Porvoo Group Tapio Aaltonen Director, CA-services, co- chair Porvoo Group Population Register Centre Finland.
LANDSCAPE eID in Europe in CY 2013 Udo Sommer, Detlef Houdeau Open Identity Summit,10 th of Sep.
Some identification needs related to workers’ mobility eGovernment – eIDM ad hoc group meeting 4-5 May 2006 CBSS Crossroads Bank for Social Security Frank.
Stork is an EU co-funded project INFSO-ICT-PSP Students Mobility: STORK Project Deployment Paúl Santapau Nebot Vicente Andreu Navarro.
Dr Aniyan Varghese eGovernment Unit eGovernment Unit Directorate General Information Society Dr Aniyan Varghese eGovernment.
The German eID and eIDAS
Authentication and Authorisation for Research and Collaboration Licia Florio AARC Workshop The AARC Project Brussels, 26 October.
JRA1.4 Models for implementing Attribute Providers and Token Translation Services Andrea Biancini.
Creating a European entity Management Architecture for eGovernment Id GUIDE Keiron Salt
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
Electronic Signatures Regulation in the European Union Jos Dumortier K.U.Leuven University Belgium Roundtable on Electronic Documents and Electronic Signatures.
Extending eID authentication across Europe September 2013 Stork 2.0 is an EU co-funded project INFSO-ICT-PSP
EID and eSignature programs at National level in Europe Detlef Houdeau Nov 2013 Exploratory seminar on e-signatures for e- business in the South Mediterranean.
Stork is an EU co-funded project INFSO-ICT-PSP STORK PRESENTATION Frank LEYMAN Manager International Relations 04/06/2009.
The Future Digital Identity Landscape in Europe Timothée Mangenot, chairman 14th of December, 2015 ACSIEL partners day.
The European Union (EU) policy challenge
SPOCS : Simple Procedures Online for Crossborder Services
Why eIDAS? eID under eIDAS compliance
European Citizens’ Initiative, Commission regulation proposal Focus on IT aspects Jérôme Stefanini DIGIT.B.2 05/06/2018.
CEF eID SMO The use of eID in eHealth
E-invoicing Training conference Towards electronic invoicing in 2020:
Directorate General Information Society & Media
The e-government Conference main issues
Ministerial Declaration
Ministerial Declaration
E-identities (and e-signatures)
UNECE International Conference
Presentation transcript:

Siemens IT Solutions and Services Porvoo 12 – Grosseto, October 2007 Update on EU Common Specifications

Page 2 Oct 07 Siemens IT Solutions and Services Background – The Manchester Ministerial Declaration (2005) About eIDs By 2010 European citizens and businesses shall be able to benefit from secure means of electronic identification […] made available under the responsibility of the Member States but recognized across the EU About eDocs By 2010 Member States will have agreed a framework for […] authenticated electronic documents across the EU Source:

Page 3 Oct 07 Siemens IT Solutions and Services Background – The i2010 Action Plan (2006) i2010 eGovernment Action Plan: Accelerating eGovernment in Europe for the Benefit of All "Member States recognize the importance of eIDM for ensuring that by 2010 European citizens and businesses will be able to benefit from secure and convenient electronic means, issued at local, regional or national levels and complying with data protection regulations, to identify themselves to public services in their own or in any other Member State" Source:

Page 4 Oct 07 Siemens IT Solutions and Services Background: i2010 actions (to promote eID as key enabler for e-Government) Agree with Member States … on the way to a European eIDM framework by 2010 based on interoperability and mutual recognition of national eIDM Agree common specifications for interoperable eIDM in the EU. Monitor large scale pilots of interoperable eIDMs in cross-border services eSignatures in eGovernment: Undertake review of take- up in public services Review the uptake by the Member States of the European eIDM framework for interoperable eIDMs. Source:

Page 5 Oct 07 Siemens IT Solutions and Services The project (eID interoperability for PEGS) represents one of IDABC contributions to the i2010 Action Plan Project details:  Project name: eID Interoperability for PEGS  Project owner: European Commission (IDABC)  Contractor: Siemens IT Solutions and Services (Timelex as subcontractor)  Project start date: January 2007 Entities also involved in the review of the deliverables:  IDABC eID Interoperability Expert Group  i2010 eGovernment sub-group of DG INFSO

Page 6 Oct 07 Siemens IT Solutions and Services Main objectives of the project  To analyze the eIDM and authentication interoperability requirements stemming from the pan-European or cross- border eGovernment services  To describe the required interoperability functions in eIDM and provide a comparative assessment of existing eID interoperability models  To derive common specifications for interoperable eIDM in the EU.

Page 7 Oct 07 Siemens IT Solutions and Services Status of work (1/2) Done: analysis of main eIDM schemes, available solutions for interoperability and impact on cross-border e-Gov. Country Profiles of MS (with a comprehensive analysis of current eIDM schemes) Report on Analysis and assessment of similarities and differences of eIDM schemes (with respect to both legal and technical aspects) Report on impact on eIDM interoperability (of the similarities and differences of the various eIDM schemes) Report on interoperable eIDM technical solutions (key attributes of each eIDM model for possible use in a cross-border application) Report on comparison and assessment of eIDM solutions interoperability (technical comparison of the respective models)

Page 8 Oct 07 Siemens IT Solutions and Services Status of work (2/2) Current & next steps: Multilevel Authentication and Common Specifications models: Draft Common specifications for eIDM interoperable solutions Summary of existing national and other authentication schemes Proposal for multi-level authentication mechanism and a mapping of existing authentication mechanisms Report on the Impact and the implementation of the multi-level authentication mechanism and recommendations for the adoption of a multi-level authentication mechanism

Page 9 Oct 07 Siemens IT Solutions and Services Main results (1/5) Complexity of the scenario The country survey revealed an heterogeneous scenario with regard to the adoption and use of identity resources. Particularly, with regard to identity tokens, the study found that out of 32 countries, 28 issue identity cards and only 7 are deploying eID cards (Austria, Belgium, Estonia, Finland, Italy, Portugal and Spain) Even unique identification numbers are not always used, due to privacy concern or other reasons However, almost 50% of the MS are in the process of designing eID cards for future roll-out

Page 10 Oct 07 Siemens IT Solutions and Services Main results (2/5) Complexity of the available technologies The preliminary analysis of the existing eIDM schemes and solution models showed a large number of existing solutions, often similar but sometimes very different and even not interoperable. Landscape of IDPs (source: IDABC site)

Page 11 Oct 07 Siemens IT Solutions and Services Main results (3/5) Necessity of a country inclusive and user protective approach The proposed specification has to preserve or at least to take into account local preferences and existing infrastructures of 30+ MS A must is the protection of citizen data, so that their amount has to be minimized and an informed consent of their owners clearly obtained; use of general unique identification numbers should be excluded. Data protection regulations should be addressed in a set of standardized policy documents to be used by the application owners. Electronic identity should be defined to be technology neutral, require a minimal data set of user data, comply with legal restrictions and be commonly accepted by all MS Multiple authentication levels supported in favor of trust

Page 12 Oct 07 Siemens IT Solutions and Services Main results (4/5) – Common specification of a multilevel authentication model Risk assessment / Definition of required auth. level (on behalf of SPs/Appl. Owners) Registration policies (on behalf of Issuing Authorities) Authentication process (on behalf of citizens/IDPs/SPs) Multilevel Authentication model

Page 13 Oct 07 Siemens IT Solutions and Services Multilevel authentication – Example matrix Risk assessment / Definition of required auth. level Registration policy Authentication Process Level 1 Low risk/damages Claim based; no requirements for proving the claimed identity Standard passwords accepted Level 2 Low-medium risk/damages No personal presence of the applicant still acceptable, but basic validation of claimed identity attributes is required Authentication based on ID Tokens (SW or HW) always acceptable; no passwords, except OTPs Level 3 Medium-high risk/damages Personal presence of applicant is required, or availability of official identity resources for secure on-line verification of claimed id OTP is still tolerated, but ID Tokens (SW or HW) strongly recommended Level 4 High risk/damages Personal presence of applicant required; on-line registration only possible if qualified signatures of official identity resources are used Only hard crypto tokens are accepted (e.g. eID cards)

Page 14 Oct 07 Siemens IT Solutions and Services Main results (5/5) – Common specification of a Pan European Proxy Service PEPS architecture (source: IDABC site)

Page 15 Oct 07 Siemens IT Solutions and Services Copyright © Siemens AG Alle Rechte vorbehalten. Thank you for your attention! Andrea Biasiol Siemens IT Solutions and Services