European Electronic Identity Practices Country Update of Portugal



Similar documents
European Electronic Identity Practices

Landscape of eid in Europe in 2013

Statewatch Briefing ID Cards in the EU: Current state of play

eid Security Frank Cornelis Architect eid fedict All rights reserved

eidas as blueprint for future eid projects cryptovision mindshare 2015 HJP Consulting Holger Funke

International Porvoo Group Seminar in Reykjavik, May 2005: DEVELOPING ELECTRONIC IDENTITY IS A PAN-EUROPEAN CHALLENGE

Position Paper European Citizen Card: One Pillar of Interoperable eid Success

Full page passport/document reader Regula model 70X4M

A Guide to EMV. Version 1.0 May Copyright 2011 EMVCo, LLC. All rights reserved.

Spanish Certification Body. Challenges on Biometric Vulnerability Analysis on Fingerprint Devices. New. Technical Manager September 2008

MOBILE IDENTIFICATION:

I N F O R M A T I O N S E C U R I T Y

Entrust Smartcard & USB Authentication

I N F O R M A T I O N S E C U R I T Y

Combatting Counterfeit Identities: The Power of Pairing Physical & Digital IDs

Published International Standards Developed by ISO/IEC JTC 1/SC 37 - Biometrics

Smart Card Technology Capabilities

Preventing fraud in epassports and eids

Introducing etoken. What is etoken?

Biometrics for Public Sector Applications

Banking. Extending Value to Customers. KONA Banking product matrix. is leading the next generation of payment solutions.

Biometrics for public sector applications

Implementation of biometrics, issues to be solved

1. Product Overview 2. Product Features 3. Comparison Chart 4. Product Applications 5. Order Information 6. Q & A

RF-Enabled Applications and Technology: Comparing and Contrasting RFID and RF-Enabled Smart Cards

Security by Politics - Why it will never work. Lukas Grunwald DN-Systems GmbH Germany DefCon 15 Las Vegas USA

Discover Germany s Electronic Passport

Proposed Framework for an Interoperable Electronic Identity Management System

Biometrics for Payment Applications. The SPA Vision on Financial Match-on-Card

The security features which are not visible on a photocopy

FAQs Electronic residence permit

Smart Card. Smart Card applications

COMMISSION OF THE EUROPEAN COMMUNITIES

Modular biometric architecture with secunet biomiddle

PRIME IDENTITY MANAGEMENT CORE

Electronic Identity White Paper V 1.0. June eeurope Smart Cards / Trailblazer 1 Public Identity. Your reliable key to e-services

Description of the Technical Component:

Conformance test specification for BSI-TR Biometrics for public sector applications

Study on Mutual Recognition of esignatures: update of Country Profiles Icelandic country profile

NIST s FIPS 201: Personal Identity Verification (PIV) of Federal Employees and Contractors Masaryk University in Brno Faculty of Informatics

Facts about the new identity card

ON IDENTITY CARDS. Based on Article 65 (1) of the Constitution of the Republic of Kosovo, LAW ON IDENTITY CARDS CHAPTER I GENERAL PROVISIONS

Keep Out of My Passport: Access Control Mechanisms in E-passports

Secure web transactions system

esign Online Digital Signature Service

Digital Signatures and Interoperability

IDENTITY ANYONE CAN TRUST

Best Practices for the Use of RF-Enabled Technology in Identity Management. January Developed by: Smart Card Alliance Identity Council

IDENTITY SOLUTIONS END-TO-END SYSTEMS SOLUTIONS TO PROTECT IDENTITIES AND SECURE ACCESS FOR A MOBILITY WORLD

Supporting Smart Cards in UEFI

Security Issues in Cross-border Electronic Authentication

The ID card with eid function at a glance

Gemalto Mifare 1K Datasheet

Case Studies. National Identity Management Commission (NIMC), Nigeria eid Consulting for national ID system

How To Protect A Smart Card From Being Hacked

M2M For industrial and automotive

GOALS (2) The goal of this training module is to increase your awareness of HSPD-12 and the corresponding technical standard FIPS 201.

MACHINE READABLE TRAVEL DOCUMENTS

Optical Memory Cards in Federal Government

Advanced Security Mechanisms for Machine Readable Travel Documents and eidas Token

Electronic Citizen Identities and Strong Authentication

ROADMAP. A Pan-European framework for electronic identification, authentication and signature

RVS Seminar Deployment and Performance Analysis of JavaCards in a Heterogenous Environment. Carolin Latze University of Berne

What Merchants Need to Know About EMV

BiSPI Conformance Testing

Biometrics, Tokens, & Public Key Certificates

Global eid Developments. Detlef Eckert Chief Security Advisor Microsoft Europe, Middle East, and Africa

e-authentication guidelines for esign- Online Electronic Signature Service

Description of Biometric Data Interchange Format Standards

Personal Identity Verification Card

Page 1. Smart Card Applications. Lecture 7: Prof. Sead Muftic Matei Ciobanu Morogan. Lecture 7 : Lecture 7 : Smart Card Applications

A. Background. In this Communication we can read:

Extending EMV payment smart cards with biometric on-card verification

ECCA 2014 Conference Santander

addressed. Specifically, a multi-biometric cryptosystem based on the fuzzy commitment scheme, in which a crypto-biometric key is derived from

IDENTIFICATION Morpho Driver s license Solution for governments and road traffic authorities

A Guide to EMV Version 1.0 May 2011

Requirements for an EMVCo Common Contactless Application (CCA)

The identity card program in Belgium

Secure Remote Photo Identification With ID card

Contactless Smart Cards vs. EPC Gen 2 RFID Tags: Frequently Asked Questions. July, Developed by: Smart Card Alliance Identity Council

Smart Tiger STARCHIP SMART TIGER PAYMENT PRODUCT LINE. Payment. STiger SDA. STiger DDA. STiger DUAL

The Estonian ID Card and Digital Signature Concept

Biometric For Authentication, Do we need it? Christophe Rosenberger GREYC Research Lab - France

E-Passport Testing. Ensuring Global Acceptance. Jos Chehin Date: 17 November 2006 Location: ASML

Electronic Signature in the banks data/order exchanges within the small, medium-sized or large corporate and their banks in France

Smart Cards and Biometrics in Physical Access Control Systems

MACHINE READABLE TRAVEL DOCUMENTS

esign FAQ 1. What is the online esign Electronic Signature Service? 2. Where the esign Online Electronic Signature Service can be used?

The German eid-card. Jens Bender. Federal Office for Information Security Bundesamt für Sicherheit in der Informationstechnik

IAS2. ets Market analysis

SOLUTIONS FOR HEALTHCARE PROFESSIONALS AND GOVERNMENTS

Microsoft Identity Lifecycle Manager & Gemalto.NET Solutions. Jan 23 rd, 2007

Machine Readable Travel Documents

How to Use ISO/IEC with Arbitrary Smart Cards

Why do we need a new approach?

EUROPEAN CARD FOR e-services

Deploying Smart Cards in Your Enterprise

NOAA HSPD-12 PIV-II Implementation October 23, Who is responsible for implementation of HSPD-12 PIV-II?

Securing Card-Not-Present Transactions through EMV Authentication. Matthew Carter and Brienne Douglas December 18, 2015

Transcription:

European Electronic Identity Practices Country Update of Portugal Speaker: Anabela Pedroso anabela.pedroso@umic.pt Date: 3 November 2006

1. Status of National legislation on eid Are eid specific regulations enacted and in place? Almost! Currently the new Law for Portuguese Citizen Card is on Portuguese Parliament for discussion and approval

2. CA organisation Responsible CA organization: Ministry of Justice Information Technology Institute for Ministry of Justice (ITIJ) The background of the organization: Public Organization responsible for implementing and running IT in Ministry of Justice Card/ Certificate issuer: Ministry of Justice Portuguese Registration Centre for Citizens and Enterprises ( DGRN- Direcção-Geral de Registos e Notariado) No. of certificates stored on the eid chip: 2 certificates are available for the citizen (authentication and signature) What access mechanism is used for each private key: Private key is stored in the chip, in a high secure environment. The chip is in a EAL5+ certification process

3. Status of National deployment of eid Is the eid card obligatory: yes Number of inhabitants: 10 millions Number of eid cards issued as of October 2006: 0 Number of certificates activated: 0 Yearly growth rate (percentage): N/A The expected number of eidcards by the end of 2007: 200.000

3. Status on National deployment of eid Basic functionalities of the eid card: Official national ID document? Yes European travel document? Yes eservices? Authentication and signature Other? Authentication throw multiple channels (using one-time-password application) Match-on-the-card application Offline data transfer (some are PIN protected e.g., address) Validity period of the card/certificates: 5 years

3. Status of national deployment of eid The price of the card in euros: - for the citizen: In study - for the card issuer: In study - price for the card reader and software: In study - any additional costs for the user/relying party: In study From whom and how can the citizen obtain the end/user packages: In 2007: only the State will provide these packages (in Identification Registration Offices, Ministry of Justice) After 2007: these packages will be available in retail stores (e.g., supermarkets, )

3.1. Portuguese eid Citizen Card Substitutes 5 National Id Cards: Identity Card Tax Card Social Security Card Health Services User Card Voters Card

Citizen Card Front Phisical suport (ID-1 format) in policarbonate with several phisical security mechanisms (3 levels of control) The front of the Card olds specific information about the identification of the citizen Variable Optical Ink Micro Relive (Braille) Surname Chip Sex, High, Nationality Document Nº and Id Nº MLI (Multiple Laser Image) Signature Validity Date Given Name Date of Birth Photo DOVID (Elemento Difractivo Opticamente Variável)

The back olds specific information of the other sectorial id documents (Taxes, Social Security and Health). Machine Readable Zone (MRZ). Citizen Card Back Version Nº Tax Nº DOVID in Holographic Filet Parents Social Security Nº Health User Nº Machine Readable Zone

Citizen Card Chip Chip JavaCard, Philips, 72Kb EEPROM for applications and data. Several security mechanisms, in the algorithm and encriptation and in the protection against atacks (EAL5+ certification, based in International Common Criteria standard) EMV compliant (partnership with Banks in the distribuiton of commun readers to the citizens) JavaCard 2.2.1 16-bit RISC CPU Core 386Kb ROM 72Kb EEPROM 2Kb Crypto-RAM EMV Compliant True Random Number Generator Crypto-Engine: 3DES, AES, RSA, etc MD5, SHA-1, SHA-256 Atacks protection: Side-channel attacks (SPA/DFA) Invasive attacks Advanced fault attacks

4. Interoperability issues What is the level of Current Compliance with each of the following international standards or group activities (in Full / Planned / None): CWA 15264 (eauthentication): Compliant CWA 14890 (esign) : Compliant CEN/TS 15480 1,2 (European Citizen Card): Compliant ISO 19794 Biometric Data Interchange Format Part 2: Finger Minutiae Data: Compliant ISO 24727 1,2,3 (ICC programming interfaces): Compliant ICAO 9303 (travel documents): Compliant, where mandatory e.g., Portuguese Citizen Card does not have Radio Frequency interface

Besides ECC standards ECC, The Citizen Card follows the best practices in eid: Card: ISO/IEC 9798 (deviceauthentication/secure messaging); ISO 7810; ISO 7811; ISO 7811; ISO 7816; ISO 10373; ISO/IEC 10373; EN 742:1993; CECC 90000; MIL STD-883C; Pr CEN/TS 15480 1,2 (European Citizen Card - draft); ICAO 9303 (travel documents); 4. 1 Citizen Card Use of Standards Chip: ISO/IEC 7810 ISO 7816; ISO/IEC 14443; Java Card/GP (suporte de Java cards, ISO/IEC 7501-3 (ICAO)) CEN / TC 2254; CWA 15264; CWA 14890; ISO/IEC 19794-2: Finger Minutiae data; ISO/IEC 19794-4,5 : Finger Image data; ISO/IEC 19784 BioAPI; ISO/IEC 19785 CBEFF; ISO/IEC 24727 EMV Biometria: ISO/IEC/JTC 1 SC 37; ISO/IEC 7816-11; ISO/IEC FCD 19794-2 (fingerprint minutiae); ISO/IEC 19784-1 BioAPI; ISO/IEC 19785-1 Common Biometric Exchange formats (CBEFF) - Part 1: Data Element Specification. PKI, Certificados e Assinaturas Digitais: ISO/IEC 7816-15; CWA 14890 - CEN/ISSS Workshop on the electronic signature (Area K); CWA 15264 (eauthentication); CWA 14167 (Multipart); PKCS#1, PKCS#3, PKCS#7, PKCS#8, PKCS#10, PKCS#11, PKCS#12, PKCS#15.

5. eauthentication cross border usage and harmonisation Are there agreements with other national smart card issuers (either per country or bilateral) for mutual recognition of cards? Status and targets of these agreements and timetable how to proceed: Currently we are on informal contacts with several countries

6. Next steps in your country? January 2007: Pilot Phase of Portuguese Citizen Card (in Azores islands) Summer/Autumn 2007: Project Roll-out beginning in other municipalities 2007: PORVOO 11 in Portugal!!! During 2008: All country and portuguese consulates around the world

Cartão de Cidadão The Chip: Internal Applications and Data Principal resident applications: IAS Responsible for the operations of authentication and electronic signature EMV-CAP Responsible for the generation of one-time-passwords for alternative communications channels (e.g., telephone) Match-on-Card Responsible for the biometric verification of the finger tips Aplications Citizen Data IAS Legend: EMV-CAP Match-On-Card PIN Protection Public Access Not Accessible Biometric Template of Fingertip Photo Adress Identification data of the Citizen (the same as the visible data on the card) Area for personal use of the Citizen Digital Certificate for Signature Digital Certificate for Authentication

7. Future of eid What is expected of the eid in the future? Catalyst for the complete availability of e-services to the citizen and enterprises: Eg. in the near futur: - Change of address - Medical Doctor Appointment scheduling - Bank account subscription - Enterprise creation - Apply for the University

7. Future of eid What is expected from the Porvoo Group in the future? (Cooperation with groups, permanent workingroups within Porvoo Group etc.) Cooperation with Interoperability Groups Cooperation in Pan-European public services

8. More information Web-pages on eid issues: www.cartaodocidadao.pt www.ucma.gov.pt www.umic.pt email: anabela.pedroso@umic.pt Thank You!

Next Porvoo Meeting Portugal City of Coimbra Spring 2007

Coimbra, capital of portuguese knowledge. 3th ancient University in Europe

European Electronic Identity Practices Country Update of Portugal Speaker: Anabela Pedroso anabela.pedroso@umic.pt Date: 3 November 2006