Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia.

Slides:



Advertisements
Similar presentations
1 Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market (COM( final) {SWD(2012)
Advertisements

Conclusions from e-Health
Paul Timmers eGovernment Unit Directorate General Information Society & Media European Commission Public eProcurement and EU eGovernment Developments 13.
Current trends and perspectives on e-Services for Public Services in Europe European Network Technical Seminar on Efficient e-Services in social security.
Taxpayers registration and e-services provided by the Estonian Tax and Customs Board Karin Aleksandrov Chief Expert Service Management Department.
European Electronic Identity Practices Country Update of Finland Speaker: Päivi Pösö Date:
Siemens IT Solutions and Services Porvoo 12 – Grosseto, October 2007 Update on EU Common Specifications.
EGovernment Vision, Policies and Implementations in Austria Prof. Dr. Reinhard Posch CHIEF INFORMATION OFFICER.
Digital Identity Group May GIXEL  GIXEL is the professional association of electronic component and system industries in France. It brings together.
1 14 th May 2008 How can pan-European Public Services Benefit from CIP ICT PSP Pilot on eID Dr. Davorka Šel Ministry of Public Administration SLOVENIA.
Digital Stamps of Companies Tarvi Martens SK, Estonia.
Stork is an EU co-funded project INFSO-ICT-PSP STORK PRESENTATION STORK eGov Symposium Bern 09.Nov.2010 Dipl.-Ing. (FH) Klaus J. John.
Internet Voting in Estonia Tarvi Martens Project Manager National Electoral Committee.
Setting Processes for Electronic Signature 1 The ”W-SPES Project” and the “Leuven Report on the Electronic Signatures Directive” – Putting the Project.
European Electronic Identity Practices Country Update of …………… Speaker: Date:
European Electronic Identity Practices Country Update of Belgium Speaker: Maes F. Date: 25 May 2005.
Stork is an EU co-funded project INFSO-ICT-PSP Secure Identity Across Borders Linked Secure Electronic Identity Across Europe! STORK – 4 TH I NDUSTRY.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
UbIdentity Ubiquitous Identity Management in the Cloud 20/03/2014 Dan BUTNARU Product Line Manager Trusted Identity.
August 2004 Providing Industry-wide Security and Identity Management Solutions.
1 Bridge/Gateway CA Project Status Gzim OCAKOGLU European Commission – DG ENTR / IDABC Reykjavik – 27 May 2005.
European Electronic Identity Practices Country Update of Norway Speaker: Sverre Bauck Date:
ID-Card and Mobile-ID Computer Security 2009 world Foundation.
Stork is an EU co-funded project INFSO-ICT-PSP STORK PRESENTATION STORK Presentation Lithuania March 2010.
ISA programme: Secure-related initiatives Miguel Alvarez Rodríguez.
Non-immigration Applications for Incorporation into the Smart ID Card Information Technology and Broadcasting Bureau 20 December 2001.
European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group.
EHealth and Accession - Sofia7 June 2005 eHealth Focal Point for Europe by Marc lange Manager.
Strength in diversity: lessons learnt from the Stork* projects Antonio Lioy Politecnico di Torino Dip. Automatica e Informatica.
Identity management – developments within the European Social Security Sector Pantelis Angelidis.
EGov Interop'05 - Feb 23-24, Geneva (Switzerland) OBSERVATORY ON INTEROPERABLE eGOVERNMENT SERVICES eGov-Interop'05 Annual Conference February.
Synthesis of the Eurosmart’ Technical Day on eID interoperability Bruno Rouchouze, ID SG Convenor Porvoo 12, Grosseto - Italy.
Harmonisation of electronic Identities for the European Citizen Jan van Arkel, co- chair Porvoo group, May 11, 2006 Ljubljana.
Business Register Interoperability Throughout Europe Vito Giannella European Business Register eeig.
Österreich 2006 Austria 2006 Autriche 2006 Präsidentschaft der Europäischen Union Presidency of the European Union Présidence de L’Union européenne ★★★★★★
ISSA European Network Technical Seminar on efficient e-services in Social Security Warsaw, 24 th of May 2012 Dr. Jens Bruhn Deutsche Rentenversicherung.
1 EUPAN: Contribution to the Helsinki 14 th September 2006 Alejandro Moya.
X-Road – Estonian Interoperability Platform
Porvoo7 – Reykjavík 26. May 2005 – Hótel Loftleiðir European Network of National Test-beds for eBusiness, ETeB The Porvoo Group 7th Seminar on Interoperable.
EAuthentication in Estonia and beyond Tarvi Martens SK.
Some identification needs related to workers’ mobility eGovernment – eIDM ad hoc group meeting 4-5 May 2006 CBSS Crossroads Bank for Social Security Frank.
Stork is an EU co-funded project INFSO-ICT-PSP Students Mobility: STORK Project Deployment Paúl Santapau Nebot Vicente Andreu Navarro.
Dr Aniyan Varghese eGovernment Unit eGovernment Unit Directorate General Information Society Dr Aniyan Varghese eGovernment.
The German eID and eIDAS
eIDAS: current state of play and the Luxembourgish approach
Cross-Border Enforcement Proceeding Tool Janek Pool Chairman of the Assembly of Bailiffs of Estonia.
European Electronic Identity Practices Country Update of Estonia Speaker: Ivar Jung Date:
Creating a European entity Management Architecture for eGovernment Id GUIDE Keiron Salt
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
Cross border electronic signature services Ingmar Vali Head of Court Registers Department Centre of Registers and Information Systems
Electronic Signatures Regulation in the European Union Jos Dumortier K.U.Leuven University Belgium Roundtable on Electronic Documents and Electronic Signatures.
Bulding blocks of e- government Ingmar Pappel. Bulding blocks of e-government  Personal Code  Digital Identity  Digital signature  X-Road  Organizations.
Extending eID authentication across Europe September 2013 Stork 2.0 is an EU co-funded project INFSO-ICT-PSP
Citizen Centric Public Service Delivery: the Belgian approach TAIEX Multi-country seminar on eGovernment - April 27 th, 2010 Session: Putting public services.
EID and eSignature programs at National level in Europe Detlef Houdeau Nov 2013 Exploratory seminar on e-signatures for e- business in the South Mediterranean.
Stork is an EU co-funded project INFSO-ICT-PSP STORK PRESENTATION Frank LEYMAN Manager International Relations 04/06/2009.
The Future Digital Identity Landscape in Europe Timothée Mangenot, chairman 14th of December, 2015 ACSIEL partners day.
9/19/ Latest developments in Estonian eID Ivar Jung CMB Estonia.
Information Society Technologies in the 6th Framework Programme Information Society Technologies in the 6th Framework Programme IST Call 6 Thanassis Chrissafis.
Frank Schipplick Work Package Coordinator WP1 - eSignatures.
The Future Digital Identity Landscape in Europe Stefane Mouille/Detlef Houdeau World eID Congress, 27th of Sep. 2017, Marseille, France.
Cross-sector and user-centric AAI
The European Union (EU) policy challenge
eGovernment and Data Protection - Estonian perspective
The Changing Face of Digital Identity
SPOCS : Simple Procedures Online for Crossborder Services
The Once-Only Principle Project
Dashboard eHealth services: actual mockup
Laur Mägi Department of Information Systems and Document Management
E-identities (and e-signatures)
Presentation transcript:

Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Let’s read the title again! “Evolution in cross-border interoperability of eSignatures and eID” Prerequisites: eID eSignature Evolution Cross-border interoperability

European eID landscape

eSignature landscape

Summary of current situation eID deployment: Some countries are leading Some countries have “odd” solutions and/or are stalled Number of countries have plans Number of countries do not even have a plan Deployment: 5-10 years eSignature practice: Used mostly in closed systems No common understanding of “free-flowing digitally signed file”

Use of eID & eSignature in Estonia ID-card launched 6 years ago Rollout “completed”, 1M+ cards out Common system for eSignatures, widely accepted and deployed for 5+ years All major e-services support ID-card Internet voting deployed. ~ users

Cross-border interoperability eID uptake low Even worse with eSignatures <1% of transactions cross-border Cross-border interoperability ???

Manchester declaration By 2010 European citizens and businesses shall be able to benefit from secure means of electronic identification that maximise user convenience while respecting data protection regulations. By 2010 Member States will have agreed a framework for reference to and where appropriate the use of authenticated electronic documents across the EU, as appropriate in terms of necessity and applicable law

The road to Nirvana i2010

Drivers behind interop Political eProcurement Service Directive Business eBanking etc. General Common understanding of digital signature Standardization in industry (cards, tools etc.)

Evolution: yes! Technically repeatedly piloted IDABC Bridge/Gateway v.1. European Bridge-CA (TeleTrust, Germany) Euro-PKI, GUIDE,... openvalidation.org Initatives to be observed today De Norske Veritas e-notary service Spanish eGov Validation Gateway eApostille Upcoming IDABC Bridge/Gateway v.2. Upcoming eID Large Scale Project

Organizational issues Paper-ID interoperability works! Miracles happen in border points Organizational set-up of Paper-ID interop: ICAO sets standards Continuous information exhange by network of MoIA-s to the borderguards etc. Organizational set-up of eID interop ??? Standards are not strict and not imposed Continuous information exhange is missing completely

Need for (foreign) eID info Collecting and managing eID/service info is a daily job, not project-based What info is needed ? Certificate validity (reference) Certificate semantics Certificate quality (!!!) Hardware token vs. software certificate Quality of service provider & certificate Context of certificate issuance......

Handling foreign eID Certification & validation service providers “Identity hub” Certificate quality / semantics / validity Service Provider “What certificate is that?” foreign user

eSignature handling Certification & validation service providers “Identity hub” Certificate quality / semantics / validity “E-notary” “What certificate is that?” Digital signing software providers “translation” and assessment “What document is that?”

Who will run the Indentity Hub ? EC does not have mandate (yet) Single MS cannot afford it (to cover all Europe/World) No actual demand (read: need covered with money) Low volume of international transactions Uptake of national eID-s is still underway We need clear political agreement to create such a service in EU level In future we can envisage situation where every MS runs its own “e-borderguard”

The Other Direction - Harmonization Standardization European Citizen Card (ECC) Common middleware OpenSC Windows Vista plug-and-play for smartcards Various approaches and initiatives to solve differences in middleware layer

Legal problems There is no eAuthentication Directive National legislations hardly touch the subject SP: “Who to sue if I will make wrong assessment on certificate inheritance/validity ?”

Bottom Line We need to create and distribute eID-s first Preferably PKI-based qualified certificates Then teach holders of eID-s to use them Estonian case: penetration ≠ usage But interop shall be addressed NOW Withouht vision, political will and hard work there would never been such thing as EU

Thank You!