European Electronic Identity Practices Country Update of Spain Date: 26 May 2005.

Slides:



Advertisements
Similar presentations
1 Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market (COM( final) {SWD(2012)
Advertisements

© fedict All rights reserved Legal aspects Belgian electronic identity card Samoera Jacobs – November 2008.
Mobile Devices in the DoD
Residents’ register service under the Ministry of the Interior
European Electronic Identity Practices Country Update of Finland Speaker: Päivi Pösö Date:
Launching Egyptian Root CA and Inaugurating E-Signature Dr. Sherif Hazem Nour El-Din Information Security Systems Consultant Root CA Manager, ITIDA.
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
© Southampton City Council Sean Dawtry – Southampton City Council The Southampton Pathfinder for Smart Cards in public services.
Setting Processes for Electronic Signature 1 The ”W-SPES Project” and the “Leuven Report on the Electronic Signatures Directive” – Putting the Project.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
European Electronic Identity Practices Country Update of …………… Speaker: Date:
European Electronic Identity Practices Country Update of Belgium Speaker: Maes F. Date: 25 May 2005.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
Update on European Citizen Card: Part 4 Kristina Unverricht Consumer Council of DIN, Germany Chairperson of ANEC Information Society Working Group October.
August 2004 Providing Industry-wide Security and Identity Management Solutions.
Implementation of Electronic Signature Law Kęstutis Andrijauskas Information Society Development Committee under the Government of the Republic.
1 Bridge/Gateway CA Project Status Gzim OCAKOGLU European Commission – DG ENTR / IDABC Reykjavik – 27 May 2005.
Respecting Privacy in Global Networks/ Guernsey, Wednesday 11 th April, Paula Ortiz López Spanish Data Protection Agency.
Civil Registry Agency of the Ministry of Justice, Georgia Digital Signature Services in Georgia Mikheil Kapanadze.
Page 1 Issues in and perspectives on electronic authentication of health professionals Pascal POITEVIN Marketing and Communication manager GIP-CPS e-Health.
European Signatures versus Global SignaturesRome, 7 April, 2003 EESSI open specifications and interoperability The state of the art in Italy Giovanni Manca.
Federal Information Processing Standard (FIPS) 201, Personal Identity Verification for Federal Employees and Contractors Tim Polk May.
European Electronic Identity Practices Country Update of Norway Speaker: Sverre Bauck Date:
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
Polytechnic University of Tirana Faculty of Information Technology Computer Engineering Department Identification of on-line users and Digital Signature.
Copyright, 1996 © Dale Carnegie & Associates, Inc. Digital Certificates Presented by Sunit Chauhan.
SESSION D: What You Know - What You Have - What You Are: The Role of Hardware Technologies to Provide Identity Assurance BELGIUM’s Experience Washington.
Civil Registry Agency of the Ministry of Justice, Georgia Georgian ID card Mikheil Kapanadze.
Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia.
Controller of Certifying Authorities PKI Technology - Role of CCA Assistant Controller (Technology) Controller of Certifying Authorities Ministry of Communications.
Virginia Tech Overview of Tech Secure Enterprise Technology Initiatives e-Provisioning Group Frank Galligan Fed/Ed.
JVM Tehnologic Company profile & core business Founded: February 1992; –Core business: design and implementation of large software applications mainly.
Country Update: Austria Herbert Leitold Secure Information Technology Center - Austria
Non-immigration Applications for Incorporation into the Smart ID Card Information Technology and Broadcasting Bureau 20 December 2001.
National Smartcard Project Work Package 8 – Security Issues Report.
COUNTRY XXX European Electronic Identity Practices Country Update of XXX Speaker: Date: 11 May 2006.
European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
Update on WS eAuthentication status Jan van Arkel Co-Chairman eEurope Smart Card Charter Ambassador CEN/ISSS WS eAuthentication.
Copyright 次世代 IC カードシステム研究会 C 1 Nagaaki OHYAMA Tokyo Institute of Technology Chair of NICSS National ID card in Japan May Provoo (Reykjavik,
Synthesis of the Eurosmart’ Technical Day on eID interoperability Bruno Rouchouze, ID SG Convenor Porvoo 12, Grosseto - Italy.
Harmonisation of electronic Identities for the European Citizen Jan van Arkel, co- chair Porvoo group, May 11, 2006 Ljubljana.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
Special Publication : Interfaces for Personal Identity Verification Jim Dray NIST NPIVP Workshop March 3, 2006.
HEPKI-TAG UPDATE Jim Jokl University of Virginia
Gregorio Martínez Pérez University of Murcia PROVIDING SECURITY TO UNIVERSITY ENVIRONMENT COMMUNICATIONS.
Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode.
U.S. General Services Administration Federal Technology Service November 9, 1999 Judith Spencer Director, Center for Governmentwide Security Office of.
The Porvoo Group Tapio Aaltonen Director, CA-services, co- chair Porvoo Group Population Register Centre Finland.
Digital Signatures A Brief Overview by Tim Sigmon April, 2001.
1 7 th CACR Information Workshop Vulnerabilities of Multi- Application Systems April 25, 2001 MAXIMUS.
PKI in the Swedish public sector Decentralised administration - each agency make their own decisions PKI in different situations: internally within an.
28 th International Traffic Records Forum Biometrics/SmartCard Workshop 28 th International Traffic Records Forum August 4, 2002 Orlando, Florida.
ELECTROINC COMMERCE TOOLS Chapter 6. Outline 6.0 Introduction 6.1 PUBLIC KEY INFRASTRUCTURE (PKI) AND CERTIFICATE AUTHORITIES (CAs) TRUST
European Electronic Identity Practices CEN TC224 WG15 European Citizen Card Standard Speaker: L. Gaston AXALTO Date: 26 May 05.
LEFIS PKI LEFIS General Beja, Portugal October 2006 Leo Catalinas.
The German eID and eIDAS
European Electronic Identity Practices
/ 8 FEIDHE Electronic Identification in Finnish Higher Education Janne Kanner FEIDHE Electronic Identification in Finnish Higher Education.
European Electronic Identity Practices Country Update of Estonia Speaker: Ivar Jung Date:
Bulding blocks of e- government Ingmar Pappel. Bulding blocks of e-government  Personal Code  Digital Identity  Digital signature  X-Road  Organizations.
The Future Digital Identity Landscape in Europe Timothée Mangenot, chairman 14th of December, 2015 ACSIEL partners day.
TAG Presentation 18th May 2004 Paul Butler
TAG Presentation 18th May 2004 Paul Butler
Secure Enterprise Technology Initiatives e-Provisioning Group
European Citizens’ Initiative, Commission regulation proposal Focus on IT aspects Jérôme Stefanini DIGIT.B.2 05/06/2018.
E-identities (and e-signatures)
Presentation transcript:

European Electronic Identity Practices Country Update of Spain Date: 26 May 2005

CA organisation I Responsible CA organisation: National Spanish Police Department. (Ministry of Interior ). The background of the organisation (private/public): Public

CA organisation II Double CAs Infrastructure. Root CA technology A, and two SubCAs Technology A and B. We have 380 Police Station where all Spanish people can get their eID-card. The Card Factory is FNMT (Spanish Royal Mint).

Status of National legislation on eID I Are eID specific regulations enacted and in place? Yes –Directive 1999/93/CE. –Law 59/2003 of Electronic signature. –Directive 1995/46/CE, Directive 97/66/EC, Directive 2002/58/CE. Regulation (EC) 45/2001. About processing of personal data. –Organic Law 15/1999, of protection of data of personal character. –Organic Law 1/1992, of protection of city life –The Decree 196/1976 regulates the DNI (National Identity Card). –It has been partially modified by Royal Decree 1189/1978, 2002/1979, 2091/1982, 1245/1985. –Minister of Interior orders of July 12, 1990 and April 26, 1996 –Royal Decree 896/2003 regulates the Pasports.

Status of National deployment of eID Name of the project: DNI electrónico Plans, piloting or implementation? We should be starting and the end of 1Q of 2006 The eID card is mandatory for all >= 14 years Starting date of issuance: End of 1Q of 2006

Status of National deployment of eID Envisioned total number of cardholders: Number of inhabitants: Expected number of cards/eID certs by end of 2007: – eID-Cards. – Certificates.

Status of national deployment of eID Basic functionalities of the eID card: - official ID document: Yes - European travel document: Yes, but not ePasport - support of on-line access to e-Services: Yes Validity period of the card/certificates: –eID-card: 5 or 10 years depending the age of the cardholder. –Certificates: 30 months.

Status of national deployment of eID Price in Euros of the cards: - for the citizen: Tbd. - for the card issuer: Tbd - price for the card reader and software: Out of Scope - any additonal costs for the user/relying party: N one From whom and how may the citizen obtain the end/user packages: From Project and partners Website.

Basic ID function I Inside the eID-card we only stored: - Two Certificates (Autentication & No repudiation). - Personal National Identifier. - first & second family name, given name - date of birth - nationality - Fingerprint for MoC. - Application for MoC. - Hash personal data. Personal data is held only in the certificates, and printed in the Policarbonate (PC).

Basic ID function II We have two Certificates: –Autentication is free. –Signature (N R), is protected by PIN. Our project is out of the ICAO LDS scope. There is another project that we undertake in the near future.

Basic Authentication function What Cardholder Verification mechanism is used: - PIN? Yes - Biometrics? Yes, MoC, for Certificate update. Is there a PKI supported cardholder authentication mechanism? Yes. Is there a mutual device authentication mechanism? Yes for issue & update. No for USE

Basic Signing function Is a PKI supported signing mechanism (certificate and keypair) present for e- transaction services (non –repudiation)? Yes. And our eID CARD is: - CC EAL CWA – SSCD type 3. - CWA – 14890–1. Application Interface for smart cards used as Secure Signature Creation Devices. Part 1: Basic requirements.

eID based services What kind of services (include examples) are accessible to cardholders based on acceptance of the cards / eID Certificates: Law 59/2003 of Electronic signature, artº 16 “All public administration should used, if it is possible, the signing mechanism of spanish eID” - The “Agencia Estatal de Administración Tributaria” (for tax declaration) - The “Seguridad Social” (Social Security).

eAuthentication Business models; financial What are the Charging/Revenue mechanisms? –There are only charges for card expedition or update. The expedition and update of the certificates are free of charge. What charges are levied for use of the card? None. Is there a charge for checking certificates and if so who pays for this? NO Has a cost benefit analysis been compiled for the eID scheme? If yes what are the main conclusions? Out of scope

eAuthentication Business models; public/private partnership Are non government bodies allowed to use the IAS or other card functions in support of their services? YES, Only IAS. The CARD will never be used as health insurance card or bank card. Only as Id CARD & travel document. Is the card a multi-application smart card? Yes, Only Cryptographic & Match on Card

eAuthentication Business models; public/private partnership What is the level of usage of supported services (number of transactions per card per year)? Without limits

eAuthentication Business models; cross border usage Are there agreements with other national smart card issuers for mutual recognition of cards? (Status of Memorandum of Understanding (MOU) with other CAs) Not nowadays, but we are open to all type of Understanding.

Other Interoperability issues What is the level of Current Compliance with each of the following international standards or group activities (Full/Planned/None): –CWA eAuthentication (under development): Tbd –CWA Secure Signature creation device: FULL. –CWA – 1 : FULL –CEN 224 –15 European Citizen Card (under development): Tbd –ISO/IEC JTC1 SC 37 biometric standards: FULL. –ISO/IEC JTC1 SC 17 IS (under developmment): Tbd –ICAO recommendations: Planned, for 2007

Current use and plans in Biometrics (if applicable) Technical solution(s): We are working with Sagem and Siemens in the field of Match On Card. We store an Algoritm & template inside the CHIP. We use ISO/IEC , ISO/IEC , ISO/IEC 19785, ISO/IEC FDIS

Next plans We will aim to transform our eID in eID with ePasport funcionality. We will use Dual or Hybrid smart Card for this task.

Porvoo Group cooperation issues List of issues to be overcome and recommended Porvoo Group members actions that would support accelerated deployments: W e want to talk with Microsoft/SUN/Linux Comunnity to include our CSP/PKCS#11 and Root CA Public Key in their OS.

Environment... Client Application RTF, HTML, PDF XML Firma plugin / applet (PKCS#7 / XML) (S/MIME) Web (SSL) Logon (Kerberos) PC/SC Drivers Microsoft Resource Manager DNIe PKCS#11 Netscape Internal PKCS#11 Netscape Internal Services RSA Base CSP DNIe CSP CryptoAPI Authenticode

More information Web-pages for the project/eID issues: (under construction) Thank You!