CDC Confiance Electronique Européenne Presentation of FAST project CDC Confiance Electronique Européenne Bertrand AIT-TOUATI – Architecture & new services.

Slides:



Advertisements
Similar presentations
Chapter 10 Encryption: A Matter of Trust. Awad –Electronic Commerce 1/e © 2002 Prentice Hall 2 OBJECTIVES What is Encryption? Basic Cryptographic Algorithm.
Advertisements

17 March 2010 Workshop on Efficient and Effective eGovernment FASTeTEN : a Flexible Technology in Different European Administrative Contexts
’ ’ 3SKey.
3SKey 3SKey.
Launching Egyptian Root CA and Inaugurating E-Signature Dr. Sherif Hazem Nour El-Din Information Security Systems Consultant Root CA Manager, ITIDA.
Education applications and the FAST project. Jonathan Gay Co-ordinator for Sheffield.
Public Key Infrastructure A Quick Look Inside PKI Technology Investigation Center 3/27/2002.
CONSEJO SUPERIOR DE INFORMÁTICA SECRETARÍA DE ESTADO PARA LA ADMINISTRACIÓN PÚBLICA.
SECURITY IN E-COMMERCE VARNA FREE UNIVERSITY Prof. Teodora Bakardjieva.
PROJECT ON DIGITAL SIGNATURE Submitted by: Submitted to: NAME: Roll no: Reg.no. :
August 2004 Providing Industry-wide Security and Identity Management Solutions.
1 Pertemuan 12 Authentication, Encryption, Digital Payments, and Digital Money Matakuliah: M0284/Teknologi & Infrastruktur E-Business Tahun: 2005 Versi:
6/1/20151 Digital Signature and Public Key Infrastructure Course:COSC Instructor:Professor Anvari Student ID: Name:Xin Wen Date:11/25/00.
Page 1 Issues in and perspectives on electronic authentication of health professionals Pascal POITEVIN Marketing and Communication manager GIP-CPS e-Health.
Principles of Information Security, 2nd edition1 Cryptography.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
Presented by Xiaoping Yu Cryptography and PKI Cosc 513 Operating System Presentation Presented to Dr. Mort Anvari.
Creating a Secured and Trusted Information Sphere in Different Markets Giuseppe Contino.
Elias M. Awad Third Edition ELECTRONIC COMMERCE From Vision to Fulfillment 13-1© 2007 Prentice-Hall, Inc ELC 200 Day 23.
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
Controller of Certifying Authorities PKI Technology - Role of CCA Assistant Controller (Technology) Controller of Certifying Authorities Ministry of Communications.
INTRODUCTION Why Signatures? A uthenticates who created a document Adds formality and finality In many cases, required by law or rule Digital Signatures.
The proof of your digital documents. Copyright Lex Persona – All rights reserved 2 Our approach to paper reduction The current approach –The.
Masud Hasan Secure Project 1. Secure It uses Digital Certificate combined with S/MIME capable clients to digitally sign and.
JVM Tehnologic Company profile & core business Founded: February 1992; –Core business: design and implementation of large software applications mainly.
31.1 Chapter 31 Network Security Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display.
Deploying a Certification Authority for Networks Security Prof. Dr. VICTOR-VALERIU PATRICIU Cdor.Prof. Dr. AUREL SERB Computer Engineering Department Military.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
Copyright © 2008, CIBER Norge AS 1 Using eID and PKI – Status from Norway Nina Ingvaldsen and Mona Naomi Lintvedt 22 nd October 2008.
Chapter 14 Encryption: A Matter Of Trust. Awad –Electronic Commerce 2/e © 2004 Pearson Prentice Hall 2 OBJECTIVES What is Encryption? Basic Cryptographic.
Secure Electronic Transaction (SET)
E-Commerce Security Technologies : Theft of credit card numbers Denial of service attacks (System not availability ) Consumer privacy (Confidentiality.
Market Reform Group Electronic processing The role of standards and how it all fits together Beginners session - 23 rd January 2008 Rob Campbell, MRO.
Logo Add Your Company Slogan China Financial Certification Authority Third-party certification authority Team 13 :吉露露、吴莹莹、潘韦韦 ( CFCA )
Security Protocols and E-commerce University of Palestine Eng. Wisam Zaqoot April 2010 ITSS 4201 Internet Insurance and Information Hiding.
ELECTRONIC CONVEYANCING WORKSHOPS 2009 Simon Libbis Executive Director Ann Kinnear Operations Manager.
Chapter 23 Internet Authentication Applications Kerberos Overview Initially developed at MIT Software utility available in both the public domain and.
CSCD 218 : DATA COMMUNICATIONS AND NETWORKING 1
Web Security : Secure Socket Layer Secure Electronic Transaction.
One Platform, One Solution: eToken TMS 5.1 Customer Presentation November 2009.
1. 2 Overview In Exchange security is managed by assigning permissions in Active Directory Exchange objects are secured with DACL and ACEs Permissions.
31.1 Chapter 31 Network Security Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display.
Network Security Lecture 27 Presented by: Dr. Munam Ali Shah.
DIGITAL SIGNATURE.
Belgian EID Card 15/12/2004 Derette Willy eID program manager.
Digital Signatures and Digital Certificates Monil Adhikari.
Chapter 3 Pre-Incident Preparation Spring Incident Response & Computer Forensics.
 Introduction  History  What is Digital Signature  Why Digital Signature  Basic Requirements  How the Technology Works  Approaches.
Frank Schipplick Work Package Coordinator WP1 - eSignatures.
Training for developers of X-Road interfaces
Efficient and secure transborder exchange of patient data
Paperless & Cashless Poland Program overview
Computer Communication & Networks
Public Key Infrastructure (PKI)
S/MIME T ANANDHAN.
An Office 365 Integration Enables Cloud-Based Digital Signatures Anytime and on Any Device “Thanks to IvSign and our Microsoft Office 365 integration,
NAAS 2.0 Features and Enhancements
E-Commerce for Developing Countries (EC-DC)
Encryption in Office 365 Shobhit Sahay Technical Product Manager
e-government in France
X-Road as a Platform to Exchange MyData
Dashboard eHealth services: actual mockup
Install AD Certificate Services
Microsoft Virtual Academy
e-Security Solutions Penki Kontinentai Vladas Lapinskas
Microsoft Virtual Academy
National Trust Platform
Presentation transcript:

CDC Confiance Electronique Européenne Presentation of FAST project CDC Confiance Electronique Européenne Bertrand AIT-TOUATI – Architecture & new services

Market reasons for the emergence of FAST In certain types of information flow, digitalization has shown a need for: Confidentiality of exchanges Non-tempering of information Authentication of sender and receiver Archiving of exchange in order to be able to use it as a evidence There are several ways of achieving these needs Ex: creation of industry specific EDI systems or through agreement on using specific PKI and certificate processes However, the most user friendly and legally sound way is through the use of a trust infrastructure operated by specialized companies “ADELE” national plan for eGovernment was created as an answer to these issues Plan presented by the French Government in 2004 €1,8Bn budget for the period Composed of 140 measures intended to modernize public services « Trust Infrastructure enabling the digitalization of exchanges between local and central administrations » ADELE 74

What is FAST? FAST is a service that allows secured electronic information transfer with legal value FAST is a combination of: Technological infrastructure Services around the usage of the infrastructure Security and confidentiality warranties Legal follow-up

FAST services FAST offers customizable services Trust services -Administration of certificates -Rights management and authentication -Creation of evidence Infrastructure services -Identity validation -Time stamping -Security -Encryption -Archiving Follow-up services -Consulting on digitalization issues -Call center and support -Training Digitalization services -Portals -Custom made tools that integrate existing client softwares

The FAST platform in public sector in France Legality check between decentralized public bodies and government Fully dematerialized public accounting Birth and death certificates Dematerialization of French social welfare aid system Many other experiments Nowadays, FAST coordinates a multiplicity of users and applications Ministry Interior Ministry Finance INSEE Social org FAS T Local public body CCAS Hospitals Mixt Syndicates Treasuries Regional bodies

Legality check FAST strategy in France Public accounting Health Legal archiving Welfare Convocation of elected people Education Birth and death certificates Urbanism E-procurement FAST Objective: offer a multi-exchanges platform to public sector

FAST value added: be an trust operator FAST allows customers to capitalize on existing platforms thus: Capitalizing on acquired experience Diminishing complexity costs Sharing of costs Follow-up of technological changes Follow-up of legal changes/ constraints Neutrality between parties Management and/or help for deployment Training on site or remote Installation Call center/ helpline of 1st or 2 nd level

FAST value added: be an aggregator Allows users to exchange information of legal value with multiple and heterogeneous points sender receiver FAST Certificates 2 2 Access tools (portals / API) 3 3 Exchange norm 4 4 Trust level 5 5 Installation & Support 5 5

Example of operations done by the transactional platform of FAST a) Preparation of outbound message b) Electronic signature c) Data encryption (optional) a) Preparation of outbound message b) Electronic signature c) Data encryption (optional) Transmission Origination check (authentication) Origination check (authentication) Global archiving Transmission to authenticated receivers Decryption of the data Transmission to authenticated receivers Decryption of the data Validation of transmission (certificate / signature) Time stamping FAST creates evidence at each transaction step Sender FAST Receiver

Electronic evidence Constitution of electronic evidence 1.Transaction 2.Time stamping  Obtain a time stamping token either from FAST or from postal services  Integrate the time stamp 3.Validation  Certificates validation  Technical validation of certificate  Access to control lists  Validation of electronic signatures  Cryptographic check  Validation of authorization 4.Sealing  Archiving index  Adding of validation data  FAST countersignature ArchivingIndex Controllists Transactional Envelop Electronic Signature of signing person Technical signature of admin. responsible Technical signature of moral entity Certificates for users and moral entity TechnicalSeal

The FAST project has been undertaken by Caisse des Dépots* and is now a recognized trust infrastructure in France FAST is a coherent extension of CDC historical activities Financial depositor of legal professions Long term partner of public bodies Two times awarded at the European level FAST is the first trust platform to be officially recognized by French authorities for legal applications uses FAST services have already been successfully tested for several years by several hundreds of French public bodies FAST is being deployed in the UK and in Spain: Project E-Ten *Caisse des Dépôts (CDC) is the French Bank of public bodies Date de l’homologation : 9 mars 2006 Date de l’homologation : 9 mars er Tiers de Télétransmission homologué par le Ministère de l’Intérieur