Building a portal for citizens in Norway with secure authentication and single sign on. Dag Efjestad



Similar documents
Building a portal for citizens in Norway with secure authentication and single sign on. Dag Efjestad

PortWise Access Management Suite

nexus Hybrid Access Gateway

From centralized to single sign on

Government Service Bus

Securing WebFOCUS A Primer. Bob Hoffman Information Builders

OIO Web SSO Profile V2.0.5

ELM Manages Identities of 4 Million Government Program Users with. Identity Server

USER MANUAL Online Faxing Anywhere, Anytime Paperless Secure Faxing Anytime, Anywhere

ELECTRONIC SIGNATURES AT BANK REPUBLIC SEARCHING THE ORIGINAL COPY OF ELECTRONICALLY SIGNED DOCUMENT CARE FOR THE ENVIRONMENT

Access to Webmail services via a Non Trust Computer

Siebel CRM On Demand Single Sign-On. An Oracle White Paper December 2006

Operating Level Agreement for NYU Login Service

SSL User Authentication with the HTTP Security Server

Using etoken for Securing s Using Outlook and Outlook Express

INTEGRATION GUIDE. IDENTIKEY Federation Server for Juniper SSL-VPN

The Role of Federation in Identity Management

Liberty Alliance. CSRF Review. .NET Passport Review. Kerberos Review. CPSC 328 Spring 2009

Biometric Single Sign-on using SAML Architecture & Design Strategies

Entrust IdentityGuard Comprehensive

Safewhere*Identify 3.4. Release Notes

Mobility, Security and Trusted Identities: It s Right In The Palm of Your Hands. Ian Wills Country Manager, Entrust Datacard

OpenAM All-In-One solution to securely manage access to digital enterprise and customer services, anytime and anywhere.

HOL9449 Access Management: Secure web, mobile and cloud access

Synchronization Agent Configuration Guide

PortWise Access Management Suite

External Authentication with WebCT. What We ll Discuss

OpenAM. 1 open source 1 community experience distilled. Single Sign-On (SSO) tool for securing your web. applications in a fast and easy way

Agenda. How to configure

Getting Started with AD/LDAP SSO

NOTE: New directions for accessing the Parent Portal using Single Sign On

SAML SSO Configuration

Processo Civile Telematico (On-line Civil Trial)

New Single Sign-on Options for IBM Lotus Notes & Domino IBM Corporation

OpenSSO: Simplify Your Single-Sign-On Needs. Sang Shin Java Technology Architect Sun Microsystems, inc. javapassion.com

Configuring Single Sign-on for WebVPN

BlackShield ID Agent for Remote Web Workplace

CA Single Sign-On r12.x (CA SiteMinder) Implementation Proven Professional Exam

Implementation Guide SAP NetWeaver Identity Management Identity Provider

Biometric Single Sign-on using SAML

CA SiteMinder. SAML Affiliate Agent Guide. 6.x QMR 6

STRONGER AUTHENTICATION for CA SiteMinder

Interoperable Provisioning in a Distributed World

Entrust Managed Services PKI. Getting an end-user Entrust certificate using Entrust Authority Administration Services. Document issue: 2.

Web Services Security: OpenSSO and Access Management for SOA. Sang Shin Java Technology Evangelist Sun Microsystems, Inc. javapassion.

An SAML Based SSO Architecture for Secure Data Exchange between User and OSS

NetIQ Identity Manager Identity Reporting Module Guide

RSA Secured Implementation Guide for VPN Products

Crawl Proxy Installation and Configuration Guide

Chapter 7 Managing Users, Authentication, and Certificates

SAML Authentication Quick Start Guide

Server based signature service. Overview

Oracle Identity Management Concepts and Architecture. An Oracle White Paper December 2003

Allidm.com. SSO Introduction. Discovering IAM Solutions. Leading the IAM facebook/allidm

Revised edition. OIO Web SSO Profile V2.0.9 (also known as OIOSAML 2.0.9) Includes errata and minor clarifications

NetIQ Identity Manager Setup Guide

Adding Stronger Authentication to your Portal and Cloud Apps

COLT Portal User Guide

Integrating EJBCA and OpenSSO

Ensuring the Security of Your Company s Data & Identities. a best practices guide

Perceptive Experience Single Sign-On Solutions

Novell Access Manager

Authentication Integration

Administering Jive Mobile Apps

This release bulletin relates to Version build 2701 of the Swivel Authentication Platform and other new capabilities.

Securely Managing and Exposing Web Services & Applications

Building Secure Applications. James Tedrick

SalesForce SSO with Active Directory Federated Services (ADFS) v2.0 Authenticating Users Using SecurAccess Server by SecurEnvoy

PRIVACY, SECURITY AND THE VOLLY SERVICE

Configuring. SugarCRM. Chapter 121

PostFiles. The file sharing and synchronization solution dedicated to professionals.

APIS IT d.o.o. Fiscalization technical aspects

SAML Security Option White Paper

Integrating Apex into Federated Environment using SAML 2.0. Jon Tupman Portalsoft Solutions Ltd

This chapter describes how to use the Junos Pulse Secure Access Service in a SAML single sign-on deployment. It includes the following sections:

Revised edition. OIO Web SSO Profile V2.0.8 (also known as OIOSAML 2.0.8) Includes errata and minor clarifications

Session Code*: 0310 Demystifying Authentication and SSO Options in Business Intelligence. Greg Wcislo

SAML:The Cross-Domain SSO Use Case

Using Voltage Secur

Using SAML for Single Sign-On in the SOA Software Platform

CA Adapter. Installation and Configuration Guide for Windows. r2.2.9

Google Apps Deployment Guide

Cloud Authentication. Getting Started Guide. Version

Security Guide. BlackBerry Enterprise Service 12. for ios, Android, and Windows Phone. Version 12.0

BoardNox. Secure file sharing solution for Executive Committees and Boards of Directors.

An Oracle White Paper August Oracle OpenSSO Fedlet

Access Gateway Guide Access Manager 4.0 SP1

Web Work Module User s Guide

September 9 11, 2013 Anaheim, California 507 Demystifying Authentication and SSO Options in Business Intelligence

Connected Data. Connected Data requirements for SSO

NetworkingPS Federated Identity Solution Solutions Overview

Configuring. SuccessFactors. Chapter 67

Transcription:

Building a portal for citizens in Norway with secure authentication and single sign on Dag Efjestad

Norway 4.600.000 citizens Everyone has an unique id 75 % has a pc and 60% use it every day 60 % has Internet access at home 50 % has access to xdsl

Public sector in Norway About 1800 different organizations Three main levels IT Local Region Central Variations is size/complex/advanced Often very independent institutions Some common portals Altinn/Region portals

Strategy documents - egov

enorway2005 focus areas Make a good framework for enorway Modernization of public sector Accessibility and security Attractive contents Skill for change Creating value in industry

Modernization of public sector User orientated digital services Coordination of the use of IT in the public sector Simplified reporting

enorway2009 focus areas The individual in the digital Norway Innovation and growth in Norwegian business and industry A coordinated and user-adapted public sector

The individual in the digital Norway All relevant public services shall be digital. Enable the vision of the digital citizen From 2007 shall everyone be able to choose how to communicate with the public sector All services from the public sector shall be based on open standards

A coordinated and user-adapted public sector Interaction in the public sector shall be digital Public sectors shall use open standards Public sector shall use the security portal with a shared pki http://odin.dep.no/filarkiv/254956/enorway_2009.pdf

Before MyPage. Many services are already established and many more is under development The organization of the services is product orientated not customer focused You need to know public sector to find the service Lack of services where the citizen can get information from public sector No infrastructure for sending information No infrastructure for signature and crypt.

Before MyPage Different passwords and authentication solutions Great variation of solutions and quality IT in public sector - separated in silos No common framework for interoperability and corporation Lack of coordination Marketing for e-services

Before MyPage. Industry Citizen Altinn.no security Public institutions security Local authorities security Services Services Services

After MyPage Industry Citizen Altinn.no Other Portals MyPage Public security portal Services from public sector

MyPage makes the day for the citizen For citizens: Common portal don t need to know public sector. Don t have to deal with different authentication mechanism Can get information abut themselves that are registered in public sector For public sector: Get more digital services in public sector and easier marketing against the public. Establish common architecture and standards for public sector.

Services on MyPage Access to information like: My Vehicles, My properties Access to services like: apply for health card, apply for child support, apply for driver license. Information about my community Messages from public sector Important dates

Service types on MyPage Transaction service Url to a service on another site with SSO. Data retrieval service Webservice which retreive data of the citizen Message service A citizens mail box on Internet for public sector Calendar service. Pubilc and personal events

CA/ and autentiseringsmyndigheter and CA authenticationsauthorities Security portal MyPage profil database Maildb WebService URL to service Messages Service providers Tax Dep Local adm Work adm Poilce State loan Sosial security Defence Road adm

MyPage software Sun JES 2005Q1 Portal server Access manager WebProxy med SSL Application Server Mail server Calendar server Directory server Fatwire Spark Web Content management

Web service Standardized web service call. WS-I Basic Profile 1.1 Secured by VPN Next version Liberty ID-WSF? Not secured by VPN but WS-S WS-I Basic Security profile 1.0 Also transactions Common registry UDDI/ebXML Use of a common tool and repository for creating schemas

Messages Based on ordinary e-mail Secured by VPN May use SSL for transport SMS and e-mail alerts Future: web service based? Secure enough for sensitive data

Transaction service Url to another web site Must use the security portal Language support WAI requirements Future: Transaction services with webserices From schemas to web based transaction services Combination of messages/calendar and transaction services.

Security portal Established as a service exclusive for public sector. User based or transaction based pricing Not only for MyPage Altinn Education Portals for Local authorities/administrations Gambling Need to have at least 5 million authentications pr year to succeed.

Security Portal Site A SecurityServer WebServer SAML integration Module Policy Server Site B Front end WebServer SAML 1.0/1.1 Compliant product SecurityModule AuthProviders

Security Portal Site A etrust SAML Affiliate Agent from CA SecurityServer etrust SiteMinder from CA WebServer SAML integration Module Policy Server Site B Front end efactory Security Server from SPAMA WebServer SAML 1.0/1.1 Compliant product SecurityModule AuthProviders

Authentication providers Certificate based authentication Certificate shall also be used for signatures Use existing certificates and authentication providers. From Bank sector. Almost everyone with Internet access use banking solutions on Internet. From public game company. Soft certificates that you can download for free. Certificate types: Person standard Person high Company All Authentication providers are qualified by a independent control institution.

Browser/artifact mypage.norway.no Protected site 5 Security portal 9 www.brukerstedb.no Protected site Access conrol Front end SAML Affiliate Agent 8 1 2 4 3 7 6 Citizen (browser)

Session maintenance etrust siteminder expose to web services 1. Session validation (every 20 sec) 2. Session notification. Keep-a-live No push to the Service providers Not an option for non-affliate agent sites. Common idle and session timeout

Singel logout No notification from Security portal Confusing for the user: What happens when I close a window? What happens if I do a logout from site X? What is the difference between local and global logout? User has to close all browser windows to kill all sessions

Cookies and sessions

Solution Affility agent sites use shared session Global logout page with frames with individual logout pages for the others like MyPage Plan for upgrade to SAML 2.0 and Liberty ID- FF v 1.2 is in progress.

Questions