European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group.

Slides:



Advertisements
Similar presentations
1 Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market (COM( final) {SWD(2012)
Advertisements

How eID and eSignatures work in a cross-border setting Wendy Carrara SPOCS Deputy Programme Director eID workshop Reaping the benefits of eID in different.
Taxpayers registration and e-services provided by the Estonian Tax and Customs Board Karin Aleksandrov Chief Expert Service Management Department.
Mr. Aivars Paegle, Legal manager at The Register of Enterprises of the Republic of Latvia, Juridical Division Workshop on Single Institution for Registration.
European Electronic Identity Practices Country Update of Finland Speaker: Päivi Pösö Date:
EGovernment Vision, Policies and Implementations in Austria Prof. Dr. Reinhard Posch CHIEF INFORMATION OFFICER.
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
The Austrian Governmental eDelivery System Technical Aspects Ankara, March 17th, 2015 Christian Maierhofer, EGIZ The E-Government Innovation Center is.
© Southampton City Council Sean Dawtry – Southampton City Council The Southampton Pathfinder for Smart Cards in public services.
Public Key Infrastructure (PKI) Hosting Services.
Setting Processes for Electronic Signature 1 The ”W-SPES Project” and the “Leuven Report on the Electronic Signatures Directive” – Putting the Project.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
European Electronic Identity Practices Country Update of …………… Speaker: Date:
European Electronic Identity Practices Country Update of Belgium Speaker: Maes F. Date: 25 May 2005.
Stork is an EU co-funded project INFSO-ICT-PSP Secure Identity Across Borders Linked Secure Electronic Identity Across Europe! STORK – 4 TH I NDUSTRY.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
ESign-Online Digital Signature Service February 2015 Controller of Certifying Authorities Department of Electronics and Information Technology Ministry.
August 2004 Providing Industry-wide Security and Identity Management Solutions.
Respecting Privacy in Global Networks/ Guernsey, Wednesday 11 th April, Paula Ortiz López Spanish Data Protection Agency.
U.S. Environmental Protection Agency Central Data Exchange EPA E-Authentication Pilot NOLA Network Node Workshop February 28, 2005.
European Electronic Identity Practices Country Update of Norway Speaker: Sverre Bauck Date:
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
Polytechnic University of Tirana Faculty of Information Technology Computer Engineering Department Identification of on-line users and Digital Signature.
Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict All rights.
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
Intra-ASEAN Secure Transactions Framework Project Progress Report
Stork is an EU co-funded project INFSO-ICT-PSP STORK PRESENTATION STORK Presentation Lithuania March 2010.
Civil Registry Agency of the Ministry of Justice, Georgia Georgian ID card Mikheil Kapanadze.
© Julia Wilk (FHÖV NRW) 1 Digital Signatures. © Julia Wilk (FHÖV NRW)2 Structure 1. Introduction 2. Basics 3. Elements of digital signatures 4. Realisation.
Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia.
ISA programme: Secure-related initiatives Miguel Alvarez Rodríguez.
European Electronic Identity Practices Country Update of Spain Date: 26 May 2005.
Country Update: Austria Herbert Leitold Secure Information Technology Center - Austria
COUNTRY XXX European Electronic Identity Practices Country Update of XXX Speaker: Date: 11 May 2006.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
Update on WS eAuthentication status Jan van Arkel Co-Chairman eEurope Smart Card Charter Ambassador CEN/ISSS WS eAuthentication.
Copyright 次世代 IC カードシステム研究会 C 1 Nagaaki OHYAMA Tokyo Institute of Technology Chair of NICSS National ID card in Japan May Provoo (Reykjavik,
EGov Interop'05 - Feb 23-24, Geneva (Switzerland) OBSERVATORY ON INTEROPERABLE eGOVERNMENT SERVICES eGov-Interop'05 Annual Conference February.
Synthesis of the Eurosmart’ Technical Day on eID interoperability Bruno Rouchouze, ID SG Convenor Porvoo 12, Grosseto - Italy.
Harmonisation of electronic Identities for the European Citizen Jan van Arkel, co- chair Porvoo group, May 11, 2006 Ljubljana.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
The lessons from European and Middle Eastern implementations of e-ID Michael Magrath, CSCIP Director, Business Development – Government & Healthcare Gemalto.
Slide 1 Smart Cards for eGovernment and Health Insurance - Status in Austria.
Slovenian Governmental Certification Authority Dr. Aleš Dobnikar Government Centre for informatics of the Republic of Slovenia 4th Business and Government.
EGovernment Services in Poland Today & in The Future Dariusz Bogucki Ph.D, IDA II, National Co-ordinator National Registers Department, Ministry of Internal.
U.S. General Services Administration Federal Technology Service November 9, 1999 Judith Spencer Director, Center for Governmentwide Security Office of.
Risks of data manipulation and theft Gateway Average route travelled by an sent via the Internet from A to B Washington DC A's provider Paris A.
Federal Electronic Commerce Program Office Tony Trenkle General Services Administration October 28, 1998.
The Porvoo Group Tapio Aaltonen Director, CA-services, co- chair Porvoo Group Population Register Centre Finland.
PKI and the U.S. Federal E- Authentication Architecture Peter Alterman, Ph.D. Assistant CIO for e-Authentication National Institutes of Health Internet2.
BEV The NMCA of Austria. 8 June 2006, ViennaBEV - NMCA of Austria EG/PCC G. Schennach Austria 8 Mio sqkm.
Data protection as an integral part of OOP implementations: The Austrian approach Peter Kustor.
The German eID and eIDAS
eIDAS: current state of play and the Luxembourgish approach
European Electronic Identity Practices
Estonian Online Services Raino Paron. ESTONIAN E-SERVICES (1/2) Electronic State Gazette – official source of Estonian law, also un-official English translations.
European Electronic Identity Practices Country Update of Estonia Speaker: Ivar Jung Date:
Presentation Overview eGovernment Coordination Big Picture / Standards Map Examples of change –eID – getting mobile –Large Scale Pilots –Cloud Positioning.
Bulding blocks of e- government Ingmar Pappel. Bulding blocks of e-government  Personal Code  Digital Identity  Digital signature  X-Road  Organizations.
The Federal E-Authentication Initiative David Temoshok Director, Identity Policy GSA Office of Governmentwide Policy February 12, 2004 The E-Authentication.
TAG Presentation 18th May 2004 Paul Butler
Smart Data infrastructure
Paperless & Cashless Poland Program overview
TAG Presentation 18th May 2004 Paul Butler
E-government Working Group
EDUCAUSE Fed/Higher ED PKI Coordination Meeting
Laur Mägi Department of Information Systems and Document Management
SCOOP4C: Societal Vision for Once Only Principle for Citizens
E-identities (and e-signatures)
Presentation transcript:

European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group

CA organisation Responsible CA organisation: A1, A-Trust, SV (no unique CA) The background of the organisation (private/public): Private (A1, A-Trust) and public (SV) Description of the existing CA infrastructure (e.g. registration authority, card factory etc): Different “representations” of citizen card

Status of National legislation on eID eID specific regulations enacted and in place 2004 eGovernment Act 2004 Administrative Signature Order 2005 Electronic Document Act

Status of National deployment of eID Name of the project: Bürgerkarte (”Citizen Card”) Plans, piloting or implementation? Operational Is the card obligatory? Yes/No No Starting date of issuance: 2004

Status of National deployment of eID Envisioned total number of cardholders: 8M Number of cards/certificates issued by : (some 25K QCs) Number of inhabitants: 8M Yearly growth rate (percentage): SV cards per week at moment Expected number of cards/eID certs by end of 2007: 13M

Status of national deployment of eID Bürgerkarte: Not an official ID document or European travel document Supports on-line access to e-Services and electronic signatures Valid for 3 years

Status of national deployment of eID Price of the cards: - to the citizen, depends on issuer (€0 up to 15) - to the card issuer: 0 (no special fee) - for the card reader and software: € 10 (Government subsidy to offset retail price) Various suppliers of end/user package – mobile phone, banks, civil service, social insurance

Basic ID function What cardholder data is electronically stored in the card: - national identifier: Yes - family name, given name: Yes - sex: No - date of birth: Yes - nationality: No - others No

Basic ID function Are these data elements in a dedicated data file? Yes - Is the file ’openly accessible’? depends on card - If not, how is the file protected? Querying national id requires an eGov certificate Name and date of birth may be freely accessible - Does the data file comply with the ICAO LDS? No Is the personal data (also) held in a certificate? No, only name

Basic Authentication function What Cardholder Verification mechanism is used: –PIN –Biometrics not envisioned Is there a PKI supported cardholder authentication mechanism? Yes Is there a mutual device authentication mechanism? Varies according to implementation

Basic Signing function PKI-supported signing mechanism (certificate and keypair) present for e-transaction services (non –repudiation)

eID based services What kind of services (include examples) are accessible to cardholders based on acceptance of the cards / eID Certificates: Various eGov services (e.g. tax declaration, municipality services), but open to eCommerce offers Total number of eID based services accessible by cardholders by : 100 Goal (in numbers/ percentage) of eID based services to be accessible to cardholders by the end of 2007: 80%

eAuthentication Business models; financial What are the Charging/Revenue mechanisms? Private CAs charge for certificates What charges are levied for use of the card? None (compared with paid non-eService charges) Is there a charge for checking certificates and if so who pays for this? None, prohibited by law Has a cost benefit analysis been compiled for the eID scheme? Yes, by private sector suppliers Is there a study report available? No

eAuthentication Business models; public/private partnership Are non government bodies allowed to use the IAS or other card functions in support of their services? Yes, in line with data-protection laws Is the card a multi-application smart card? Yes but depends on implenter/implementation –80-100% of the deployed card base is multi-application smart card enabled –Additional services (other than core IAS) loaded pre- issue

eAuthentication Business models; cross border usage Are there agreements with other national smart card issuers for mutual recognition of cards? (Status of Memorandum of Understanding (MOU) with other CAs) –No bilateral agreements; QCs are recognised under 1999/93/EC; prototype integration of IT and FI eIDs

Other Interoperability issues Level of Current Compliance: –CWA Secure Signature creation device: depends on issuer

Next plans Continued pilots on integration of foreign eIDs into national model Development of further server-side service modules Acting by proxy (“power of attorney”, for individuals and companies)

Lessons learned so far Need greater pan-European cooperation (especially on recognition of digitally signed and authenticated Austrian documents abroad) Possible limitations and liability questions arising from use of Bridge CAs

Porvoo Group cooperation issues Issue: need for an Interoperability Framework Action: –Survey of eID requirements –Map between different requirements and solutions –development of a ”Common Solutions and Services Centre” (see also Austrian proposal for en EU eGov “Virtual Competence Centre”)

More information Web-pages for the project/eID issues: