eauthentication in Estonia and beyond Tarvi Martens SK



Similar documents
Embedding digital signature technology to other systems - Estonian practice. Urmo Keskel SK, DigiDoc Product Manager

e- Estonia - 10 years of experience

Digital Signatures in Reality. Tarvi Martens SK

IDENTITY ANYONE CAN TRUST

The Estonian ID Card and Digital Signature Concept

X-Road. egovernment interoperability framework

Global eid Developments. Detlef Eckert Chief Security Advisor Microsoft Europe, Middle East, and Africa

Interoperability Support systems Nationwide components (Estonia)

eid/authentication/digital signatures in Denmark

1. Lifecycle of a certificate

European Electronic Identity Practices

eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke

PROXKey Tool User Manual

TrustKey Tool User Manual

Study on Mutual Recognition of esignatures: update of Country Profiles Icelandic country profile

PKI - current and future

Egyptian Best Practices Securing E-Services

EDI legal aspects in Estonia

Sicherheitsaspekte des neuen deutschen Personalausweises

ROADMAP. A Pan-European framework for electronic identification, authentication and signature

Proposed Framework for an Interoperable Electronic Identity Management System

Guide to Obtaining Your Free WISeKey CertifyID Personal Digital Certificate (Personal eid) WISeKey 2010 / Alinghi 2010 Smartcards

trust and confidence "draw me a sheep" POLICY AND REGULATION FOR EUROPE

Statewatch Briefing ID Cards in the EU: Current state of play

A KIND OF IMPLEMENT ABOUT MOBILE SIGNATURE SERVICE BASED ON MOBILE TELEPHONE TERMINAL

esign Online Digital Signature Service

Guide for Securing With WISeKey CertifyID Personal Digital Certificate (Personal eid)

Page 1. Smart Card Applications. Lecture 7: Prof. Sead Muftic Matei Ciobanu Morogan. Lecture 7 : Lecture 7 : Smart Card Applications

Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market

Spanish initiative to encourage the use of eid & esignature technologies in egovernment Services. Ministry of Public Administrations

Part III-a. Universität Klagenfurt - IWAS Multimedia Kommunikation (VK) M. Euchner; Mai Siemens AG 2001, ICN M NT

Qualified mobile electronic signatures: Possible, but worth a try?

ISA Work Programme SECTION I

esign FAQ 1. What is the online esign Electronic Signature Service? 2. Where the esign Online Electronic Signature Service can be used?

EHR central system advantages and disadvantages, the case of Estonia. Estonian E-health Foundation Raul Mill

White Paper. Cloud Signing vs. Smartcard Signing

OECD workshop on digital identity management BELGIAN approach

COMMISSION OF THE EUROPEAN COMMUNITIES

Data Privacy in the Cloud E-Government Perspective

Log Analysis of Estonian Internet Voting

e-estonia Strategic decisions for success

Mobile OTPK Technology for Online Digital Signatures. Dec 15, 2015

Digital Signatures and Interoperability

Role Based Identity and Access Management Basic Infrastructure for New Citizen Services and Lean Internal Administration

FAQs Electronic residence permit

The Austrian Citizen Card

Norway Post s Electronic ID Case study on authentication. Oslo 17. June 1999 Terje Kolnes, Norway Post

Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market

Making Digital Signatures Work across National Borders

PrivateServer HSM Integration with Microsoft IIS

Identifying Obstacles in moving towards an Interoperable Electronic Identity Management System

e-signature as a Service

CERTIFICATION PRACTICE STATEMENT UPDATE

Certificate Policy for. SSL Client & S/MIME Certificates

Hungarian Electronic Public Administration Interoperability Framework (MEKIK) Technical Standards Catalogue

egovernment 2020 new media and technologies for better citizenship oriented communication and applications

MyKey is the digital signature software governed by Malaysia s Digital Signature Act 1997 & is accepted by the courts of law in Malaysia.

Finger Vein digital biometric signature: use cases

Serge Novaretti IDABC DIGIT European Commission

The Mobile Phone Signature in edemocracy and egovernment Applications.

How much do you pay for your PKI solution?

Controller of Certification Authorities of Mauritius

REGISTRATION AUTHORITY (RA) POLICY. Registration Authority (RA) Fulfillment Characteristics SECURITY DATA SEGURIDAD EN DATOS Y FIRMA DIGITAL, S.A.

Business Issues in the implementation of Digital signatures

Position Paper European Citizen Card: One Pillar of Interoperable eid Success

The identity card program in Belgium

Rich Furr Head, Global Regulatory Affairs and Chief Compliance Officer, SAFE-BioPharma Association. SAFE-BioPharma Association

TREADING THE PATH THE PORTUGUESE ADMINISTRATIVE MODERNIZATION EXPERIENCE

Commission s proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market

Number of relevant issues

Landscape of eid in Europe in 2013

Aloaha Sign! (English Version)

OB10 - Digital Signing and Verification

Secure Information Technology Center Signature verification and digital services

ONE SINGLE ADDRESS FOR ALL YOUR ONLINE PROCEDURES. as part of your professional activity. Business Portal

International Porvoo Group Seminar in Reykjavik, May 2005: DEVELOPING ELECTRONIC IDENTITY IS A PAN-EUROPEAN CHALLENGE

LEGAL FRAMEWORK FOR E-SIGNATURE IN LITHUANIA AND ENVISAGED CHANGES OF THE NEW EU REGULATION

SSLPost Electronic Document Signing

CERTIFICATES USER GUIDE

Web Application Entity Session Management using the eid Card Frank Cornelis 03/03/2010. Fedict All rights reserved

Department of Defense PKI Use Case/Experiences

The Austrian Citizen Card

ConCERTO Secure Solutions for Converged Systems

Study on Mutual Recognition of esignatures: update of Country Profiles Analysis & assessment report

2. Each server or domain controller requires its own server certificate, DoD Root Certificates and enterprise validator installed.

HKUST CA. Certification Practice Statement

A secure, economic infrastructure for signing of web based documents and financial affairs Overview of a server based, customer-friendly approach.

How to Configure Certificate Based Authentication for WorxMail and XenMobile 10

Server based signature service. Overview

Processo Civile Telematico (On-line Civil Trial)

NC CJIN Governing Board. 13 October, George A. White

The concept of biometric digital signatures based on Hitachi activities in Japan

Questions & Answers. on e-cohesion Policy in European Territorial Cooperation Programmes. (Updated version, May 2013)

PKI Smart Card Usage for Business-Partners Features and Requirements. Version 1.4 / August 2013

CONCEPT. International Comparison eid Means

Guide to Obtaining Your Free WISeKey CertifyID Personal Digital Certificate on Aladdin etoken (Personal eid)

Introducing etoken. What is etoken?

Brocade Engineering. PKI Tutorial. Jim Kleinsteiber. February 6, Page 1

These registration data can be used for the access to the wide range of services and their functions all around the world anytime:

French Justice Portal. Authentication methods and technologies. Page n 1

Transcription:

eauthentication in Estonia and beyond Tarvi Martens SK

E-stonia? Population: 1.35M Internet usage: 56% Internet banking: 88% Mobile penetration: >100% 1000+ Free Internet Access points PKI penetration: >80% Biggest national eid card roll-out in Europe!

Agenda Bank eid The ID-card Mobile-ID Computer Security 2009 On international eid interoperability

Bank eid Internet banking started in 1996 Everyone has a Internet bank account 5 (i-)banks covering 99% of the market Authentication options Password cards (>1Mio, usage 90%) PIN calculators (~50 000 in use) ID-card

Bank eid for third parties All banks are providing authentication services to 3rd parties: Doing taxes 86% online Citizen portal providing access to 70 databases and over 700 services E-school Telecom, utilities E-business E-business Overhelmingly used

ID-card Project Started in 1997 Law on personal identification documents: Feb, 1999 Digital Signature Act: March, 2000 Government accepted plan for launching ID-card: May, 2000 First card issued: Jan 28, 2002 October 2006: 1 000 000 th card issued

The Card Compulsory for all residents Contains: Personal data file Certificate for authentication (along with e-mail address Forename.Surname@eesti.ee) Certificate for digital signature

Card issuance TRÜB Baltic AS 3. Request for Certificates 4. Certificates 2. Request for Personalisation 5. ID Card with Private Keys and Certificates 6. PIN codes sent by courier CMB Regional Offices ( 18 sites ) Citizenship and Migration Board Ministry of Internal Affairs CA RA (bank office)... 7. Personalised ID Card with Certificates and PIN envelope handed over Public Directory RA Certification Centre Ltd

ID-starter packages Package 2003: card reader manual installation CD Price ca 20 EUR Package 2007: card reader https://installer.id.ee Price ca 6 EUR

ID-card as a ticket for public transportation Fixed-line Population Registry Mobile e-tickets Internet Cash Person must possess and show an ID-card when buying or verifying a ticket

Authentication: e-citizen portal log-in options Log-in with ID-card Log-in via web-bank

ID-card for secure e-mail The authentication certificate contains an e-mail address Surname.Lastname[.X]@eesti.ee All S/MIME mailers are usable The eesti.ee server runs a forwarding service Usable for secure C2C, B2C and G2C communication

Public sector is obliged to accept digitally signed documents Common Digital Signature System DigiDoc is used cross-sector, no alternatives around Highest security level (longtime validity) is provided Over 2 Mio signatures created in 4+ years Application Win32 Client COM-library DigiDoc portal WebService Digital Signature with IDcard Application DigiDoc-library (Win32/Unix/C/Java) Application CSP PKCS#11 XML ID card OCSP

Internet voting Happened first in October 2005 First pan-national binding occasion (municipal government elections) Parliament elections is 2007 (3x increase on i-voters turnout) ID-card as an enabling tool Encrypted vote E-voters Digital signature E-votes Results Public key Private key

Flip side of the coin 1,000,000 ID-cards 55,000 electronic users

Why won t they go E? Habits Strong tradition of banks-provided authentication service (based on passwords) Barriers Need for smart-card reader and software No awareness promotion ID-cards are perceived as merely physical documents Unawareness about security benefits

Who is driving? Public sector service Tax Declarations Private sector service Online banking Once in a year Once in a week

Computer Security 2009 Co-operation program between private and public sector Aims for safe information society in general Special target: ten-fold increase of eid users (400,000 in 2009)

Measures for CS09 Availability Alternative PKI-based tokens/methods Redundant service network Wide support and usability Support for alternative platforms (Mac,Linux,..) Awareness and training Pressure by banks Termination of authentication service to 3rd parties Reduction of transaction limits with passwords

id.ee

Mobile-ID PKI-capable SIM cards Requires replacement of SIM Instantly ready to use No specific software required Equal legal power and security with ID-card Launched: May 2007 Available from the major GSM operator (EMT 40%)

Estonia: conclusions Banks were not ready to go for full PKI before end of the ID-card roll-out PPP is crucial for pan-national cross-sector happiness C2G & G2C happens 1.4x/year! This is not driver to e People from street seldom sign something Not a e-driver either Start from major e-service providers!

How to Achieve International Interoperability in eauthentication few thoughts

On eid Interop Widely discussed topic One of main targets of EC i2010 program Technically repeatedly proven IDABC Bridge/Gateway European Bridge-CA (TeleTrust, Germany) Euro-PKI, GUIDE,... openvalidation.org We have organizational and legal issues!

Organizational issues Paper-ID interoperability works! Miracles happen in border points Organizational set-up of Paper-ID interop: ICAO sets standards Continuous information exhange by network of MoIA-s to the borderguards etc. Organizational set-up of eid interop??? Standards are not strict and not imposed Continuous information exhange is missing completely

Need for (foreign) eid info Collecting and managing eid/service info is a daily job, not project-based What info is needed? Certificate validity (reference) Certificate semantics Certificate quality (!!!) Hardware token vs. software certificate Quality of service provider & certificate Context of certificate issuance...

Desirable situation Service Provider What certificate is that? Certificate quality / semantics / validity Identity hub Certification & validation service providers foreign user

Who will run the Indentity Hub? EC does not have mandate (yet) Single MS cannot afford it (to cover all Europe/World) To tell the truth there is no actual demand (read: need covered with money) for this 99% of transactions occur domestically Uptake of national eid-s is still underway We need clear political agreement to create such a service in EU level In future we can envisage situation where every MS runs its own e-borderguard

Legal problems There is no eauthentication Directive National legislations hardly touch the subject SP: What if I will make wrong assessment on certificate inheritance/validity?

Bottom Line We need to create and distribute eid-s first Preferably PKI-based quality certs Then teach holders of eid-s to use them Estonian case: penetration usage But interop shall be addressed NOW Withouht vision, political wisdom and hard work there would never been such thing as EU

Additional Information ID-card issuance www.pass.ee PKI & CA www.sk.ee ID-card & Mobile-ID www.id.ee Digital signature software www.openxades.org Contact point: tarvi@sk.ee