EAuthentication in Estonia and beyond Tarvi Martens SK.

Slides:



Advertisements
Similar presentations
Universal Electronic Signatures Tarvi Martens ESTONIA.
Advertisements

1 Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market (COM( final) {SWD(2012)
Estonia – The Country With Identification Infrastructure Tarvi Martens SK.
1 eGovernment Projects and Perspectives in the Bulgarian Public Administration Nedelcho Nedelchev Advisor to the Minister of State Administration and Administrative.
Taxpayers registration and e-services provided by the Estonian Tax and Customs Board Karin Aleksandrov Chief Expert Service Management Department.
Digital Certificate Installation & User Guide For Class-2 Certificates.
European Electronic Identity Practices Country Update of Finland Speaker: Päivi Pösö Date:
Digital Certificate Installation & User Guide For Class-2 Certificates.
Digital Certificate Installation & User Guide For Class-2 Certificates.
Internet Voting in Estonia Tarvi Martens Project Manager National Electoral Committee.
Setting Processes for Electronic Signature 1 The ”W-SPES Project” and the “Leuven Report on the Electronic Signatures Directive” – Putting the Project.
European Electronic Identity Practices Country Update of …………… Speaker: Date:
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
ESign-Online Digital Signature Service February 2015 Controller of Certifying Authorities Department of Electronics and Information Technology Ministry.
Mobile identity you really trust
August 2004 Providing Industry-wide Security and Identity Management Solutions.
1 Pertemuan 12 Authentication, Encryption, Digital Payments, and Digital Money Matakuliah: M0284/Teknologi & Infrastruktur E-Business Tahun: 2005 Versi:
Civil Registry Agency of the Ministry of Justice, Georgia Digital Signature Services in Georgia Mikheil Kapanadze.
Mar 12, 2002Mårten Trolin1 This lecture Diffie-Hellman key agreement Authentication Certificates Certificate Authorities SSL/TLS.
E-Procurement: Digital Signatures and Role of Certifying Authorities Jagdeep S. Kochar CEO, (n)Code Solutions.
ID-Card and Mobile-ID Computer Security 2009 world Foundation.
Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict All rights.
ID card – vision in action Tarvi Martens SK, Estonia.
Estonia e(m)-ID and e-services Towards cross-border services Seth Lackman, ITL.
Financial Transactions on Internet Financial transactions require the cooperation of more than two parties. Transaction must be very low cost so that small.
Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia.
Estonia 2005 the first practice of Internet voting Epp Maaten Councillor of the Elections Department Chancellery of the Riigikogu Strasbourg, 23 November.
Arvo Ott & Hannes Astok e-Governance Academy, Estonia
E-services for business: convenience that counts Anna Hrapovitskaja Estonian ICT Demo Center.
Internet voting in Estonia Epp Maaten Councillor of the Elections Department Chancellery of the Riigikogu.
COUNTRY XXX European Electronic Identity Practices Country Update of XXX Speaker: Date: 11 May 2006.
European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group.
Mobile Identity and Mobile Authentication (mobile e-signature) Valdis Janovs Sales Director Lattelecom Technology SIA.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
EGov Interop'05 - Feb 23-24, Geneva (Switzerland) OBSERVATORY ON INTEROPERABLE eGOVERNMENT SERVICES eGov-Interop'05 Annual Conference February.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
The lessons from European and Middle Eastern implementations of e-ID Michael Magrath, CSCIP Director, Business Development – Government & Healthcare Gemalto.
IT in the Swedish public sector Britta Johansson
Vizija in praksa estonske e-vlade Marten Kokk Ministrstvo za zunanje zadeve, Estonija 21. marca 2007 Ljubljana.
EGovernment in Estonia – organization, policies, frameworks Arvo Ott, PhD, e-Governance Academy Vinnytsia
1 World Intellectual Property Organization PCT-SAFE Preparing PCT Applications Electronically South Africa, February 5-9, 2007.
Architecture Models to Support Accessible eGovernment Services for All Karl Wessbrandt, the Swedish Administrative Development Agency 19 April 2007.
EGovernment Services in Poland Today & in The Future Dariusz Bogucki Ph.D, IDA II, National Co-ordinator National Registers Department, Ministry of Internal.
1 Using EMV cards for Single Sign-On 26 th June st European PKI Workshop Andreas Pashalidis and Chris J. Mitchell.
Results of audit “Quality of public services in the information society” Markko Kard Alo Lääne The 9th Annual Meeting of the Representatives of the Baltic,
E-state Estonia. What is e-state? e-state means public official databases and collection of legal acts in Internet It creates quick and diverse forum.
PKI in the Swedish public sector Decentralised administration - each agency make their own decisions PKI in different situations: internally within an.
Belgian EID Card 15/12/2004 Derette Willy eID program manager.
Estonian Online Services Raino Paron. ESTONIAN E-SERVICES (1/2) Electronic State Gazette – official source of Estonian law, also un-official English translations.
/ 8 FEIDHE Electronic Identification in Finnish Higher Education Janne Kanner FEIDHE Electronic Identification in Finnish Higher Education.
The Estonian eID - concept and applications Signe Ratso Deputy Secretary General Gothenburg, November 14, 2005.
European Electronic Identity Practices Country Update of Estonia Speaker: Ivar Jung Date:
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
LEARNING AREA 1 : INFORMATION AND COMMUNICATION TECHNOLOGY PRIVACY AUTHENTICATION VERIFICATION.
Cross border electronic signature services Ingmar Vali Head of Court Registers Department Centre of Registers and Information Systems
Bulding blocks of e- government Ingmar Pappel. Bulding blocks of e-government  Personal Code  Digital Identity  Digital signature  X-Road  Organizations.
The Future Digital Identity Landscape in Europe Timothée Mangenot, chairman 14th of December, 2015 ACSIEL partners day.
9/19/ Latest developments in Estonian eID Ivar Jung CMB Estonia.
Digital Certificates Presented by: Matt Weaver. What is a digital certificate? Trusted ID cards in electronic format that bind to a public key; ex. Drivers.
Estonian ICT October, 2009.
ESign Aashutosh.
Paperless & Cashless Poland Program overview
Installation & User Guide
European Citizens’ Initiative, Commission regulation proposal Focus on IT aspects Jérôme Stefanini DIGIT.B.2 05/06/2018.
Digital Signatures and Forms
E-cert (Digital Certificate)
Installation & User Guide
E-Lock ProSigner ProSigner means “Professional Signer” signifying the software that can apply legally enforceable Advanced electronic signatures to electronic.
Laur Mägi Department of Information Systems and Document Management
E-identities (and e-signatures)
Presentation transcript:

eAuthentication in Estonia and beyond Tarvi Martens SK

E-stonia ? Population: 1.35M Internet usage: 56% Internet banking: 88% Mobile penetration: >100% Free Internet Access points PKI penetration: >80% Biggest national eID card roll-out in Europe !

Agenda Bank eID The ID-card Mobile-ID Computer Security 2009 On international eID interoperability

Bank eID Internet banking started in 1996 “Everyone” has a Internet bank account 5 (i-)banks covering 99% of the market Authentication options  Password cards (>1Mio, usage – 90%)  PIN calculators (~ in use)  ID-card

Bank eID for third parties All banks are providing authentication services to 3rd parties:  Doing taxes – 86% online  Citizen portal providing access to 70 databases and over 700 services  E-school  Telecom, utilities  E-business Overhelmingly used

ID-card Project Started in 1997 Law on personal identification documents: Feb, 1999 Digital Signature Act: March, 2000 Government accepted plan for launching ID-card: May, 2000 First card issued: Jan 28, 2002 October 2006: th card issued

The Card “Compulsory” for all residents Contains:  Personal data file  Certificate for authentication (along with address  Certificate for digital signature

Card issuance CMB Regional Offices ( 18 sites ) CA RA RA (bank office) Certification Centre Ltd Public Directory 6. PIN codes sent by courier 2. Request for Personalisation 5. ID Card with Private Keys and Certificates 7. Personalised ID Card with Certificates and PIN envelope handed over 4. Certificates... TRÜB Baltic AS 3. Request for Certificates Citizenship and Migration Board Ministry of Internal Affairs

“ID-starter” packages Package 2003: card reader manual installation CD Price ca 20 EUR Package 2007: card reader Price ca 6 EUR

ID-card as a ticket for public transportation e-Tickets Population Registry Mobile Internet Cash Person must possess and show an ID-card when buying or verifying a ticket Fixed-line

Authentication: e-Citizen portal log-in options Log-in with ID-card Log-in via web-bank

ID-card for secure The authentication certificate contains an address All S/MIME mailers are usable The eesti.ee server runs a forwarding service Usable for secure C2C, B2C and G2C communication

Digital Signature with ID- card Public sector is obliged to accept digitally signed documents Common Digital Signature System “DigiDoc” is used cross-sector, no alternatives around Highest security level (long- time validity) is provided Over 2 Mio signatures created in 4+ years DigiDoc-library (Win32/Unix/C/Java) CSP PKCS#11 OCSP XML ID card Win32 Client DigiDoc portal Application COM-libraryWebService Application

Internet voting Happened first in October 2005  First pan-national binding occasion (municipal government elections) Parliament elections is 2007 (3x increase on i-voters turnout) ID-card as an enabling tool Encrypted vote Digital signature E-voters E-votes Results Private key Public key

Flip side of the coin 1,000,000 ID-cards 55,000 electronic users

Why won’t they go E? Habits  Strong tradition of banks-provided authentication service (based on passwords) Barriers  Need for smart-card reader and software No awareness promotion  ID-cards are perceived as merely physical documents  Unawareness about security benefits

Who is driving ? Tax Declarations Public sector service Once in a yearOnce in a week Online banking Private sector service

“Computer Security 2009” Co-operation program between private and public sector Aims for safe information society in general Special target: ten-fold increase of eID users (400,000 in 2009)

Measures for CS09 Availability  Alternative PKI-based tokens/methods  Redundant service network Wide support and usability  Support for alternative platforms (Mac,Linux,..) Awareness and training Pressure by banks  Termination of authentication service to 3rd parties  Reduction of transaction limits with passwords

id.ee

Mobile-ID PKI-capable SIM cards  Requires replacement of SIM Instantly ready to use  No specific software required Equal legal power and security with ID-card Launched: May 2007 Available from the major GSM operator (EMT – 40%)

Estonia: conclusions Banks were not ready to go for full PKI before end of the ID-card roll-out PPP is crucial for pan-national cross-sector happiness C2G & G2C happens 1.4x/year !  This is not driver to e “People from street” seldom sign something  Not a e-driver either Start from major e-service providers!

How to Achieve International Interoperability in eAuthentication few thoughts

On eID Interop Widely discussed topic  One of main targets of EC i2010 program Technically repeatedly proven  IDABC Bridge/Gateway  European Bridge-CA (TeleTrust, Germany)  Euro-PKI, GUIDE,...  openvalidation.org We have organizational and legal issues!

Organizational issues Paper-ID interoperability works!  Miracles happen in border points Organizational set-up of Paper-ID interop:  ICAO sets standards  Continuous information exhange by network of MoIA-s to the borderguards etc. Organizational set-up of eID interop ???  Standards are not strict and not imposed  Continuous information exhange is missing completely

Need for (foreign) eID info Collecting and managing eID/service info is a daily job, not project-based What info is needed ?  Certificate validity (reference)  Certificate semantics  Certificate quality (!!!) Hardware token vs. software certificate Quality of service provider & certificate Context of certificate issuance......

Desirable situation Certification & validation service providers “Identity hub” Certificate quality / semantics / validity Service Provider “What certificate is that?” foreign user

Who will run the Indentity Hub ? EC does not have mandate (yet) Single MS cannot afford it (to cover all Europe/World)  To tell the truth – there is no actual demand (read: need covered with money) for this  99% of transactions occur domestically  Uptake of national eID-s is still underway We need clear political agreement to create such a service in EU level In future we can envisage situation where every MS runs its own “e-borderguard”

Legal problems There is no eAuthentication Directive National legislations hardly touch the subject SP: “What if I will make wrong assessment on certificate inheritance/validity ?”

Bottom Line We need to create and distribute eID-s first  Preferably PKI-based quality certs Then teach holders of eID-s to use them  Estonian case: penetration ≠ usage But interop shall be addressed NOW  Withouht vision, political wisdom and hard work there would never been such thing as EU

Additional Information ID-card issuancewww.pass.eewww.pass.ee PKI & CAwww.sk.eewww.sk.ee ID-card & Mobile-ID Digital signature softwarewww.openxades.orgwww.openxades.org Contact point: