Introduc)on to STORK2.0 project



Similar documents
DS : Trust eservices. The policy context: eidas Regulation

COMMISSION OF THE EUROPEAN COMMUNITIES

ROADMAP. A Pan-European framework for electronic identification, authentication and signature

Agenda. The Digital Agenda for Europe Instruments to implement the vision EC actions to promote ehealth interoperability

esignature building block Introduction to the Connecting Europe Facility DIGIT Directorate-General for Informatics

CEF Building blocks. Informatics. Joao Rodrigues Frade DIGIT.B4. CEF Project and Architecture Office Directorate-General for Informatics

Digital signature and e-government: legal framework and opportunities. Raúl Rubio Baker & McKenzie

ISA Work Programme SECTION I

Commission s proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market

Quality Authenticator Scheme

Submitted to the EC on 03/06/2012. COMPETITIVENESS AND INNOVATION FRAMEWORK PROGRAMME ICT Policy Support Programme (ICT PSP) e-codex

A7-0365/133

Security framework. Guidelines for trust services providers Part 1. Version 1.0 December 2013

Electronic public procurement in the EU

Building the PEPPOL community OpenPEPPOL

Proposed Framework for an Interoperable Electronic Identity Management System

Rolling out eidas Regulation (EU) 910/2014. Boosting trust & security in the Digital Single Market

Study on Mutual Recognition of esignatures: update of Country Profiles Analysis & assessment report

Trusted e-id Infrastructures and services in EU

Implementation: Single European Market for eidentity

The Open PEPPOL e-id & e-signature

LEGAL FRAMEWORK FOR E-SIGNATURE IN LITHUANIA AND ENVISAGED CHANGES OF THE NEW EU REGULATION

Concerning: Norwegian Nurses Organisation s input to the Green Paper on Modernising the Professional Qualifications Directive

Questions & Answers. on e-cohesion Policy in European Territorial Cooperation Programmes. (Updated version, May 2013)

Mapping security services to authentication levels. Reflecting on STORK QAA levels

ehealth in support of safety, quality and continuity of care within and across borders

Towards an EXPAND Assessment Model for ehealth Interoperability Assets. Dipak Kalra on behalf of the EXPAND Consortium

JA to support the ehealth Network

eid/authentication/digital signatures in Denmark

E-Signatures and E-Procurement

PKI - current and future

Having regard to the Treaty on the Functioning of the European Union, and in particular Article 114 thereof,

eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke

Cartão de Cidadão: Autenticação de Papéis do Cidadão

January 2015 Copyright 2015 GSM Association

Rules for the Public Administration

Pan European Proxy Service och Autentisering av identitet

European Electronic Identity Practices

Serge Novaretti IDABC DIGIT European Commission

Smart Open Services for European Patients Open ehealth initiative for a European large scale pilot of patient summary and electronic prescription

STANDARDISIERUNG FÜR EIDAS IM MANDATE/460

Landscape of eid in Europe in 2013

E-Signature Issues in Cross-Border Single Window: A comparative analysis of Australia, the UK and China

Service Description. 3SKey. Connectivity

UNCITRAL United Nations Commission on International Trade Law Introduction to the law of electronic signatures

EUROPEAN PARLIAMENT AND COUNCIL DIRECTIVE. on a common framework for electronic signatures

VOPaaS Virtual Organisation Platform as a Service

Cyber Security Test-bed TDL Download Corner. Achieving The Trust Paradigm Shift ATTPS. Arthur Leijtens, Daan Velthausz, Bicore, April, Brussel

EUROPEAN COMMISSION Enterprise and Industry DG

WORK PROGRAMME NOVEMBER 2012

COMMUNICATION FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT, THE COUNCIL, THE EUROPEAN ECONOMIC AND SOCIAL COMMITTEE AND THE COMMITTEE OF THE REGIONS

ENISA What s On? ENISA as facilitator for enhanced Network and Information Security in Europe. CENTR General Assembly, Brussels October 4, 2012

NIST-Workshop 10 & 11 April 2013

Best prac*ces in Cer*fying and Signing PDFs

Rich Furr Head, Global Regulatory Affairs and Chief Compliance Officer, SAFE-BioPharma Association. SAFE-BioPharma Association

Horizon 2020 Secure Societies

Standardisation Efforts in Electronic Invoicing

COMMISSION OF THE EUROPEAN COMMUNITIES COMMISSION STAFF WORKING DOCUMENT. ANNEX I to the

Smart Open Services for European Patients

9360/15 FMA/AFG/cb 1 DG G 3 C

... Chair of Mobile Business & Multilateral Security. Privacy vs. Data: Business Models in the digital, mobile Economy

e-invoicing PwC November 2010 João Rodrigues Frade, Global e-invoicing and e-archiving Network November 2010 PricewaterhouseCoopers

Building the foundation for European wide eprocurement

Widespread Deployment of Telemedicine Services in Europe

ICT PSP Call 4 How to make a proposal and partnership

Under European law teleradiology is both a health service and an information society service.

View from a European Trust Service Provider Server Signing: Return of experience and certification strategy

Your door to future governance solutions

Security Issues in Cross-border Electronic Authentication

Transcription:

Introduc)on to STORK2.0 project AAI Workshop Brussels, April 2014

EUROPEAN EID CONTEXT FOR EGOVERNMENT

NaKonal online services today with eid CENTRAL GOVERNMENT ONLINE SERVICES LOCAL GOVERNMENT ONLINE SERVICES CITIZEN BUSINESS ONLINE SERVICES NON- PROFIT ORGANISATION ONLINE SERVICES

All MS have their own eid infrastructure CITIZEN CITIZEN CITIZEN CITIZEN CITIZEN

Borders will open & NaKonal online services will improve CITIZEN OpportuniKes for public and private sector CITIZEN CITIZEN CITIZEN CITIZEN

Large Scale Pilot - STORK Results 2008-2011 17 countries PEPS/VIDP- Enabled all over Europe More than 30 services running More than 40 different credenkals supported 6

STORK CredenKals

Cross Border Authentication for electronic services Safer Chat Student Mobility Electronic Delivery Change of Address ECAS Integration

STORK 2.0 PROJECT

Overview 3 year project 2012 to 2015 19 countries involved 58 partners

STORK structure IdP IdenKty providers (for basic idenkty a_ributes, generally are public bodies or CA that offer their services to general public) SP Service providers connected to the infrastructure (in the academic pilot in STORK2.0, most of them are universikes) PEPS/V- IDP interconnected proxies that integrate STORK common infrastructure (Kpically, one per country and run by a public administrakon or on behalf of it) AP A_ribute providers (for business a_ributes, specific a_ributes related to different sectors of ackvity such as educakon, banking, health...)

STORK 2.0 Pilots elearning and ACADEMIC QUALIFICATIONS ebanking PUBLIC SERVICES for BUSINESSES elearning: cross- border academic services. Academic Qualifica)ons: use of academic informa)on ()tles, registers, qualifica)ons) by governmental and private ins)tu)ons. Online banking services suppor)ng na)onal eids. Enable companies to open bank accounts and consult their daily procedures electronically and remotely. Enable legal en))es to use online public services in other Member States, with already exis)ng procedures and applica)ons. BUSINESS- ORIENTED ehealth Secure online access to medical data. The pa)ents rights to access to their personal medical data in cross- border health services.

CollaboraKon with LSPs Interac)on with the other LSPs building on gained experience and lessons learned. Close liaisons foreseen with: ecodex for legal aspects around eid for legal persons epsos for integrakng STORK 2.0 solukons for eid- based authenkcakon with its ehealth infrastructure esens for an infrastructure for cross- border public services delivery in support of the Digital Single Market

PLATFORM DEVELOPMENT

Enhancements to STORK 1 It encompasses eid for secure electronic authenkcakon of both legal and natural persons. It includes facilikes for mandates, widely useable across the EU, providing strong data proteckon and secure ways of transferring a_ributes, all under user control. Its allows the use of STORK not only to private sector but also public sectors, in the first place banks. This increases the requirements on availability, security, and reliability.

User Consent Plaform built around the user centric approach. No data is being sent abroad unless the user allows the administrakon to do so. The user can give his consent in various different ways: Implicitly: By introducing his credenkal, he implicitly allows the data to be transferred to its desknakon SP. Explicitly for data types: Allows users to exclude a_ributes to be sent. Explicitly with data values: Eliminates data to be sent to SP. As data is signed, user may not exclude any item.

Business Processes Authen)ca)on on behalf of: Allow access to an applicakon with data of another legal/natural person. Powers (for digital signature) (as part of a contract, commercial proposal, etc.), and representakon powers of signatory should be verified. Powers as stored by a service provider need to be updated / validated periodically.

Business Processes User Basic Id A_ributes Name Address Date of Birth Specific Business A_ributes Extended Id A_ributes Degrees Profession CerKficaKons Languages Official permits Academic Life Financial Life Health Life Public Services 18

IdP PEPS PEPS b TADS IMMD a 9 1 8 2 3 7 5 4 6

Business Processes Business Acributes A_ributes proceeding from a certain business sector, oken with a meaning limited to this sector, are to be retrieved from various A_ribute providers Need from pilots to interchange extended personal data (hasdegreewith diplomasupplement, ishealthcareprofessional, etc.) As standardised as possible (for cross- border use) MulK- country a_ribute colleckon

Other Processes in STORK 2.0 Signatures AdopKon of a common solukon for creakon and validakon of signatures Based on exiskng open source sokware (e.g. PEPPOL) Covering standards adopted by the EC, especially PAdES and XAdES with most common versions IntegraKon, packaging, examples, and revision of documentakon Version control Control of sokware and configurakon versions Procedure for automakc inclusion of renewed cerkficate AutomaKc inclusion of new MS Anonymity For anonymous esurveys, evokng, etc.

Plans Feb 2014 Common development and test Node integrakon and test Pilot integrakon and test Mar 2014 Mar 2015 Pilot running and evaluakon Maintenance, bug fixes Packaging

E- SIGNATURE

esignature AuthenKcaKon is not sufficient AuthorisaKon is a step Signature may be mandatory, e.g. in Banking Based on LSP PEPPOL signature service

SECURITY - QAA

A_ributes - QAA / AQAA As authenkcakon levels for a given applicakon may differ across Member States, the project defined acribute quality authen)ca)on assurance levels (AQAA) at a European scale to: Measure the quality of different acribute provider procedures. Ensure interoperability between the different acribute standards that exist in Europe.

QAA level framework STORK QAA level Descrip)on 1 Minimal assurance 2 Low assurance 3 SubstanKal assurance 4 High assurance Allows for mapping nakonal eid solukons to STORK QAA levels. Provides a means for mapping different member states levels onto each other. Similar to the IDABC authenkcakon levels report. CompaKble with the Liberty IdenKty Assurance Framework.

QAA AccreditaKon Body STORK2.0 will analyse the need and possible mechanisms to set up a neutral accredita)on body, verify compliance to the STORK QAA framework, take care of the contractual aspects regarding trusted eid interoperability. The requirements of such a body will be idenkfied, its feasibility will be examined, and a business as well as a governance concept will be designed. AlternaKves, like mutual recognikon, are included in the analysis. Stork 2.0 is an EU co- funded project INFSO- ICT- PSP- 297263

Visit STORK 2.0 website www.eid- stork2.eu! Subscribe to STORK 2.0 Newslecer! HOW TO GET INVOLVED ParKcipate & like Stork eid Facebook page! Follow us on Twi_er @StorkEid! Connect to Stork 2.0 EID LinkedIn page! Register in STORK 2.0 online groups! Contact us at info@eid- stork2.eu!

DemonstraKon of the funckonality Visit the pilot: www.eid- stork.eu/pilots/pilot3.htm

Thank you for your a,en.on! www.eid- stork2.eu