Baltimore Technologies Jack Nagle



Similar documents
ROS Background IRELAND

Entrust Secure Web Portal Solution. Livio Merlo Security Consultant September 25th, 2003

February Are You Ready for E-invoicing?

White Paper Delivering Web Services Security: The Entrust Secure Transaction Platform

Role Based Identity and Access Management Basic Infrastructure for New Citizen Services and Lean Internal Administration

Baltimore UniCERT. the world s leading PKI. global e security

Automation for Electronic Forms, Documents and Business Records (NA)

ELECTRONIC PRESENTATION AND E-SIGNATURE FOR ELECTRONIC FORMS, DOCUMENTS AND BUSINESS RECORDS ALPHATRUST PRONTO ENTERPRISE PLATFORM

IBM Tivoli Access Manager and VeriSign Managed Strong Authentication Services. Combine resources for one complete online business security solution.

AlphaTrust PRONTO Enterprise Platform Product Overview

Class 3 Registration Authority Charter

CoSign by ARX for PIV Cards

White paper. Implications of digital certificates on trusted e-business.

Extending the Benefits of SOA beyond the Enterprise

Evaluate the Usability of Security Audits in Electronic Commerce

Understanding Digital Certificates & Secure Sockets Layer (SSL): A Fundamental Requirement for Internet Transactions

Norway Post s Electronic ID Case study on authentication. Oslo 17. June 1999 Terje Kolnes, Norway Post

U. S. Department of Justice Information Technology Strategic Plan. Appendix E. Public Key Infrastructure at the Department of Justice.

Enabling Secure, Diverse Communications for B2B and B2C Organizations

Internet Part 2. CS/MIS Department

White Paper. Cloud Signing vs. Smartcard Signing

Variorum, Multi- Disciplinary e-research Journal Vol.-01, Issue-IV, May 2011

E-government Bulgaria Brussels,

Module 6. e-business and e- Commerce

POLICY ISSUES IN E-COMMERCE APPLICATIONS: ELECTRONIC RECORD AND SIGNATURE COMPLIANCE FDA 21 CFR 11 ALPHATRUST PRONTO ENTERPRISE PLATFORM

XML Trust Services. White Paper

GOVERNMENT. Helping governments transform public service delivery with efficient, citizen-centric solutions

AITSF Position Paper. PKI Governance in Australia

Lexmark Enterprise Software. Transforming customer engagement

Microsoft Identity Lifecycle Manager & Gemalto.NET Solutions. Jan 23 rd, 2007

Business opportunities for the IT industry with LSP solutions The IT industry perspective

SSLPost Electronic Document Signing

Protection. Code of Practice. of Personal Data RPC001147_EN_D_19

Protection. Code of Practice. of Personal Data RPC001147_EN_WB_L_1

Business Intelligence

Albany epay. Intelli gent Payments Management

PKI Deployment Business Issues

Understanding Digital Certificates & Secure Sockets Layer A Fundamental Requirement for Internet Transactions

Product overview. CA SiteMinder lets you manage and deploy secure web applications to: Increase new business opportunities

E-commerce. A promising future. Anacom conference

Optimizing Your Accounting Process with Electronic Invoicing. A GXS White Paper for the Active Business

LexisOne. LexisOne. Powered by Microsoft Dynamics AX EnterpriseSolutions

Successful Real-World Implementations of Identity and Access Management

Capacity Building Workshop on Cross-border Paperless Trade Facilitation: Lessons from Ongoing Initiatives and Way Forward.

Consumer Goods. itouch Vision s CRM for

Simplify SSL Certificate Management Across the Enterprise

FTP-Stream Data Sheet

Managing SSL Security in Multi-Server Environments

Advanced Knowledge Acquisition System

How To Get Smart Cards From Atos

AUSTIN COMMUNITY COLLEGE CONTINUING EDUCATION. Marketing on The World Wide Web. (18 hours) ITNW 6023 COURSE SYLLABUS

1) A complete SCM solution includes customers, service providers and partners. Answer: TRUE Diff: 2 Page Ref: 304

How To Run An E-Government Website In Hong Kong

The E-NTRY Web-based E-commerce Platform: an advanced infrastructure supporting Tendering, Bidding and Contract Negotiation

AS2 AND EDI OVER THE INTERNET FAQ

PRACTICE NOTE 1013 ELECTRONIC COMMERCE - EFFECT ON THE AUDIT OF FINANCIAL STATEMENTS

secure user IDs and business processes Identity and Access Management solutions Your business technologists. Powering progress

TOURISM INNOVATIVE PAYMENT SOLUTIONS. Efficient, flexible, worldwide and secure

How can Identity and Access Management help me to improve compliance and drive business performance?

e-business Process Automation

Nordic Practice and Experience on e-invoicing. Erkki Poutiainen 20 November 2007

1.Because e-commerce is ubiquitous it reduces A. marketspace. B. transaction costs. C. dynamic pricing. D. price discrimination.

Digital Signatures in the Legal Market:

IDaaS: Managed Credentials for Local & State Emergency Responders

Strong Authentication for Secure VPN Access

Community Development and Training Centre Semester IT 245 Management Information Systems Chapter 3 Internetwork E-Business Electronic Business

Mobile OTPK Technology for Online Digital Signatures. Dec 15, 2015

Enterprise Integration Architectures for the Financial Services and Insurance Industries

Knowledge-Based Authentication Challenge Response System

User-side Payment Settlement

What is multichannel How to Protect communications?

The Continuous Delivery Tool Chain: So Many Choices!

Extranet Access Management Web Access Control for New Business Services

Mobility, Security and Trusted Identities: It s Right In The Palm of Your Hands. Ian Wills Country Manager, Entrust Datacard

White Paper. What is an Identity Provider, and Why Should My Organization Become One?

Glossary of Key Terms

CS 356 Lecture 28 Internet Authentication. Spring 2013

Company presentation SHARES - CENKOS Innovators & Investors FORUM 29 January globoplc.com

Key & Data Storage on Mobile Devices

W3C Web Payment IG. Payment Service Providers. Alibaba Zephyr Tuan

Integrating Hitachi ID Suite with WebSSO Systems

X-Road. egovernment interoperability framework

E-commerce refers to paperless exchange of business information using following ways.

Document control for sensitive company information and large complex projects.

Enterprise SSL FEATURES & BENEFITS

A secure, economic infrastructure for signing of web based documents and financial affairs Overview of a server based, customer-friendly approach.

The Bank of New York Mellon is Open For Business.

3rd Party Assurance & Information Governance outlook IIA Ireland Annual Conference Straightforward Security and Compliance

Meeting the FDA s Requirements for Electronic Records and Electronic Signatures (21 CFR Part 11)

G-CLOUD FRAMEWORK RM1557-vi 5DRIVE PROFESSIONAL STORAGE (PRO)

Cloud Procurement Discussion Paper. For Comment

Understanding E-Signatures: A Beginner s Guide

Applying best practices for secure, automated electronic invoicing

E-invoices. What they are. Different types. Best practices for implementation. R E A D S O F T W H I T E P A P E R

E-procurement marketing efforts with the help of customer relationship management philosophy

Managing a Global Business

Response to the European Commission consultation on. European Data Protection Legal Framework

Efficient Key Management for Oracle Database 11g Release 2 Using Hardware Security Modules

The e-payment Systems

EUROPEAN ECONOMIC AREA JOINT PARLIAMENTARY COMMITTEE. REPORT on E-Commerce and EEA legislation

Transcription:

Baltimore Technologies Jack Nagle

E-Government! Relationship between E-Business & E- Government growth! Government as a Leader for Change! Security Requirements! An Irish Example Revenue On-Line

E-Security! Real E-Business! Needs real E- Security! Conducted with Integrity! In an Infosphere involving multiple stakeholders including Government! Without which!real progress will be retarded! Islands of T rust will persist

Next-Generation Boundaries! A foundation assumption: economic transition The world is in transition from the industrial economy of the past to the digital economy of the future The network is no longer just a tool for doing business; it s the medium in which we do business Organizations resist this change at their peril The shift is self-perpetuating: The emerging capabilities of the network are driving dramatic change in business models The dramatic change in business models is having a substantial effect on enterprise network infrastructure

Next-Generation Boundaries! The business web The twentieth century enterprise is giving way to the business-web, driven by the disaggregation and reaggregation of the firm. Don Tapscott David Ticoll Alex Lowy Digital Capital, citing Ronald Coase

E-Busines s Drivers Leverage the Internet to. Deliver better customer service Enable customer self-service Improve operational efficiency Increase productivity Automate processes Create customer loyalty Service customers Create new sales channels Develop new business partners Develop new markets and business models Lower costs Improve business agility Respond to competitive challenges Increase revenues Create new products and services Integrate supply chains

Next-Generation Boundaries! The Virtual Enterprise Network Suppliers Partners Employees Internal Systems & Data Virtual enterprise? Virtual network? It s both. Employees Partners Customers

The Integrated Enterprise Database Mainframe Packages Enterprise Application Integration Custom Applications Web Application Integration emarket Integration XML Integrated Organization B2B Services Infrastructure Physical Delivery B2C Services Infrastructure Secure Collaboration Space Specialist Networks Internet Dynamic Trading Partners Corporate Firewall Client

E-Government! What it it G2B: corporation TAX, VAT returns.. G2C: Personal TAX, housing benefits, Motor TAX G2E: Government to Employee! What are the Drivers behind this External effectiveness Increased accessibility to the authorities through e- services One stop shop: single point of entry EU directives Internal effectiveness Increase efficiencies of work flow process Cost reduction is the main driver

E -Governmentreflects E - Business Growth Moving from! Information Searching/Providing -Websites, D/B s, Forms! Interaction - Transaction engines, Secure Communications! Interoperability Front and Back Office Integration, Workflow, XML joined up government needs joined up information systems

Waves ofe -Government Value of Service Information WebBased Guide to Services Electronic Leaflets Transaction Primarily one-way Single Agency Little backend integration Interaction 2 way transactions Multiple Agencies Single point of entry Backend integration Interoperability On-line transparent Government e-voting Cross boarder Electronic Passports Complexity

Barriersto fulldeployment ofe- Business/Government! Organisational Change process / budgetary! Legal Framework Digital Signature Data Protection On-line transactions! Security Confidentiality Strong Authentication of Citizen / Organization Strong Authentication to ensure accurate provisioning! Acceptance by users non-intrusive security measures acceptance of technology

Government Leadership! Legislation Development of e-commerce and e-government services relies on clear legal frameworks which also help in building public confidence in electronic transactions.(hong Kong experience) Governments must ensure that the protection of fundamental rights meets the needs of the digital age (Netherlands experience)! Provide Infrastructure E-commerce in Australia will be simplified by allowing businesses to use one digital certificate to carry out online transactions with banks, trading partners and government agencies. (Australian experience) Government can play an important role in driving the development of the Public Key Infrastructure. (Hong

E-Government Leadership contd..! Promotion Promotion of on-line transactions, standards, interoperability (governments.)..don t underestimate the effort required to develop and grow user contacts, promote awareness of standards, attend relevant user groups and to manage business requirements. (UK experience)! By Example

Security Challenges! Establishing identity! Providing access to the right resources! Conducting e-busines s with integrity! Making security; Easy to deploy Readily available Simple to use Authentication Authorization Digital Signatures Receipts Timestamps E-payments Delivering real business benefit

How Much Authentication? Sensitivity of Data Treasury etrading Military Passwords Closed User Group CRM Access Supply Chain Intranet Corporate Mail Social Site Instant Messaging epharma Pension ebanking Tax Returns Web Mail Micropayments Web surfing CD Retail Open User Group Easily broken Easily forgotten Must be protected by SSL Suitable for low value applications Scales to large numbers of users Low cost Not suitable for high value applications No audit trail

How Much Authentication? Sensitivity of Data Closed User Group CRM Access Supply Chain Intranet Corporate Mail Treasury Military etrading Social Site Instant Messaging epharma Pension ebanking Tax Returns CD Retail Web Mail Web surfing Open User Group Dynamic Passwords Too expensive for low value apps Only suitable for closed user groups No signed audit trail Proprietary Difficult to recover from lost token Good security

How Much Authentication? Sensitivity of Data Closed User Group CRM Access Supply Chain Intranet Corporate Mail Treasury Military etrading Social Site Instant Messaging epharma Pension ebanking Tax Returns CD Retail Web Mail Web surfing Open User Group Biometrics Can never be forgotten! Adds extra security factor of something you are to broad authentication mechanisms like PKI Uptake hindered by immaturity of technology and cost & availability of devices now changing Suitable for closed user groups Socially difficult

How Much Authentication? Sensitivity of Data Closed User Group CRM Access Supply Chain Intranet Corporate Mail Treasury Military etrading Social Site Instant Messaging epharma Pension ebanking Tax Returns CD Retail Web Mail Web surfing Open User Group PKI Worldwide standard system for digital certificates (like passports) and digital signatures Bedrock of Internet security; easily combined with other mechanisms like smartcards & biometrics Signed Audit Trail for dispute resolution/nonrepudiation Legacy integration can be expensive; web services making it easier

SecurityFramework Employees Partners Suppliers Customers Identity Proved Authorization Granted Transaction Signed Portals Applications Systems Any Device, any Platform, any Network Provisioning Identity and Entitlements Managing Identity and Entitlements Enforcing Identity and Entitlements Security Services Platform

Irish E-Government! Legislation Data Protection Act: registration of use of data has implications for e-government 1988 Electronic Signature Directive 2000 E-Commerce Act 2000: recognition of on-line transactions Electronic Commerce Directive einvoicing Directive! Leadership REACH initiative ROS : E-Government in action

National IT & E-SecuritySum mit 21 March 2002 Revenue On-Line Service

Revenue On-Line Service " Introduction " Colm Bermingham, ROS Project Manager " Today s Presentation RFT to Reality " Background to ROS " Business considerations for the Service " Revenue s security solution (PKI) " Sample Functionality " Conclusions

ROS -Background! Revenue one of the largest processors of information in Ireland! Bulk of processing paper based! Resource intensive! Revenue also provides information to taxpayers and agents! Paper mountain contributes to costs, delays, frustration

R O S Drivers DRIVERS! Revenue Board Statement of Strategy 1997-1999 50% of all business returns filed electronically by 2005 Position ROS as the preferred method by which customers interact with Revenue egovernment Initiative Information Society Commission National ebroker projects for Corporations & Citizens European Union Benchmarking

Government Achievements! Electronic Commerce Act 2000! Investment - Broadband Infrastructure! International Connectivity Project! Action Plan for the Information Society

What is ROS?! A facility to file returns over the Internet! Access over the Internet to specified tax information! A facility to send information and correspondence to RO S users over the Internet! Enhancement of payment options available to customers

Strategic Objectives of ROS! Increase voluntary compliance by making it easier and cheaper to comply! Improve Revenue s Customer service! Address our obligations under the Government s Information Society Strategy! Eliminate routine processing and paper handling to create a more effective and efficient organisation

ROS Facilities " Filing Tax Returns Employer s Tax, VAT Income Tax & Corporation Tax " Making Payments ROS Debit Instruction Laser Card " Access to Tax Information Own Revenue data " Access Control System Agents and Companies

R O S - Develop ment History! Business team - September 1998! Vision documented - November 1998! Corporate commitment - March 1999! Procurement process completed - Dec. 1999! Contractors appointed Accenture, January 2000 Baltimore, April 2000! ROS Live 29 th September 2000

R OS Procurement - Application! Detailed RF T is sued July 99 - to cover design, build and possibly support of ROS! Eighteen responses to RF T! Rigorous analysis and selection process! Nine contractors selected for in depth evaluation! Accenture selected! ROS implementation commenced January 5

R OS Procurement- Security! Detailed RF T issued Feb 2000 - to cover PKI, product integration, Certification Authority! Eight responses to RFT! Rigorous analysis and selection process! Baltimore Technologies selected! ROS implementation commenced April 2000 Hosting facility commissioned August 2000

ROS -Approach! Senior management support and sponsorship! Short snappy phases! Committed team! Funding & Resources

R OS - Approach Effective and ongoing consultation is key to success Internal Consultation! New Partnership Structure! Management! Staff! Unions External Consultation! Accounting/Professional Representative Groups! Tax Agents! Software/Payroll Companies! Customer Panels! Individual Customers

ROS -Security " Business considerations " Confidentiality " Authentication " Integrity " Non-Repudiation " Other factors " Public Key Infrastructure " Customer Service vs Technology " Security

ROS -Security " Foreign Experience " Certification Authority " Customer Focus " Digital Certificate link to Revenue Records " Documentation

ROS -Security " Policy Approval Authority (PAA) " Certificate Policy Statement (CPS) " Certificate Policy (CP) " Terms and Conditions " Independent PKI audit

ROS -Security! Confidentiality 128 bit SSL Verisign Global certification Single session key generation! Easy to implement once the U S strong Encryption export restrictions lifted! ROS infrastructure security

ROS -Security Strong authentication digital certificates Web Server Security Application Security Application Server and Database encrypted data Internet Web Server Firewall " Taxpayer " Agent Cryptographic Services Multiple Firewalls Firewalls Certification Authority

R OS - Technical! Open systems approach! Front end developed using mixture of standard HTML, JAVA applets, JAVA servlets! Interface DTD specifications are for XML! Compatible and tested with Screen Reader technology

R OS Registration Process " Step 1 " Application for a ROS Acces s Number (RAN) " Step 2 " Application for a Digital Certificate " Step 3 " Retrieve the Digital Certificate

ROS Registration Process

ROS Sign & Submit

ROS Usage to Date! 5,960 Digital Certificates issued! 57,256 on-line access requests to customer details! 56,344 Returns filed! 2.59 Bn collected in Business Taxes! 170m repayments

What s Next for ROS?! Enhanced Services for Customers! Returns from Financial Institutions! Environmental Levy! Vehicle Registration Tax! Capital Acquisitions Tax Returns! Payments using On-line Banking! More seamles s integration with 3 rd party software

ROS PKI -Summary " PKI " Satisfies Revenue business requirements " Revenue is own CA Baltimore hosting " Documentation overhead " Still needs security infrastructure " Can be customer friendly

Ho w did we get here? Su m mary! Board and Top Management Commitment! Planning! Consultation! Legislation! Outsourced the Development! Outsourced the Security! Flexible and Nimble approach to Project Management! Funding

Conclusions! ROS is a success elabel award Nov 2001! ROS is having a dramatic impact! ebroker will streamline Public Service delivery! egovernment not edepartment! The public are trusting secure Internet sites

ROS Contactinfo Colm Bermingham cberming@revenue.ie Revenue - ROS www.revenue.ie - www.ros.ie

Conclusion! There is a close relationship between adoption of E- Government and of E-Business! Governments play a strong role in the growth the E- Economy! Ireland is positioned well for this growth! ROS provides an excelent example of how E- Government can be implemented

!Jack Nagle! jnagle@baltimore.com