The State as a Platform and France Connect



Similar documents
Declaration of Internet Rights Preamble

A. Trusted Exchange Platform (e-trustexchange)

Improving Agility at PHMSA through Service-Oriented Architecture (SOA)

E-HEALTH PLATFORMS AND ARCHITECTURES

Panel 1. Greater Regulation of Special Threats to Privacy. Data Protection in the 21st Century

Connect Renfrewshire

The Eight Dimensions of Customer Experience for Financial Services

RECOMMENDED CHARTER FOR THE IDENTITY ECOSYSTEM STEERING GROUP

How To Use Ncr Aptra Clear

PLANNING COMMITTEE REPORT JUNE COMITÉ DE L URBANISME RAPPORT 31 LE 13 JUIN 2012

Speaking Notes for. Liseanne Forand. President, Shared Services Canada. At GTEC

Evaluation of different Open Source Identity management Systems

Transform Your Bank in Measurable Steps

CGI Payments360. Moving money with greater agility and confidence. Experience the commitment

TrustedX: eidas Platform

Towards a Cloud of Public Services

An Oracle White Paper Dec Oracle Access Management Security Token Service

How To Improve The Finnish Public Sector Information Resources

COMMISSION OF THE EUROPEAN COMMUNITIES

SOFTWARE, STRATEGIES, & SERVICES

XACML and Access Management. A Business Case for Fine-Grained Authorization and Centralized Policy Management

Cloud-based web hosting consolidation with an IBM Drupal solution

josh Archive! the software for archiving documents

IBM Solution for Pharmaceutical Track & Trace

Picasso Recommendation

Written Contribution of the National Association of Statutory Health Insurance Funds of

an EU perspective Interoperability Solutions for European Public Administrations

Solving data residency and privacy compliance challenges Delivering business agility, regulatory compliance and risk reduction

Realizing business flexibility through integrated SOA policy management.

ELECTRONIC DOCUMENT LAW

Get More from Microsoft SharePoint with Oracle Fusion Middleware. An Oracle White Paper January 2008

Concurrent Technologies Corporation (CTC) is an independent, nonprofit, applied scientific research and development professional services

California Enterprise Architecture Framework

Mutual legal recognition of electronic communications and electronic signatures and paperless trade facilitation: challenges and opportunities

Synapse Privacy Policy

Clinical Knowledge Manager. Product Description 2012 MAKING HEALTH COMPUTE

Combining the power of content and process with the right content management solution. IBM Information Management software

Entrust Secure Web Portal Solution. Livio Merlo Security Consultant September 25th, 2003

Whitepaper Data Governance Roadmap for IT Executives Valeh Nazemoff

TELSTRA RSS CA Subscriber Agreement (SA)

Information Technology Strategic Plan

Highmark Unifies Identity Data With Oracle Virtual Directory. An Oracle White Paper January 2009

Bank Account Management

API Architecture. for the Data Interoperability at OSU initiative

Integrating Single Sign-on Across the Cloud By David Strom

An Oracle White Paper August Oracle Service Cloud Integration with Oracle Siebel Service

SOA IN THE TELCO SECTOR

Service Oriented Enterprise Architecture

MISYS BANKFUSION UNIVERSAL BANKING WELCOME TO THE FUTURE OF BANKING

Healthcare Coalition on Data Protection

Can CA Information Governance help us protect and manage our information throughout its life cycle and reduce our risk exposure?

A Privacy Officer s Guide to Providing Enterprise De-Identification Services. Phase I

Internet Technical Advisory Committee to the OECD - Charter -

How To Improve The Eu'S Digital Vision

BMC Software Inc. Technical Disclosure Publication Document Enterprise Service Bus (ESB) Insulation Service. Author. Vincent J.

White Paper. An Introduction to Informatica s Approach to Enterprise Architecture and the Business Transformation Toolkit

SOA REFERENCE ARCHITECTURE: WEB TIER

POLICY CONCERNING SUBMISSION OF IDEAS AND OTHER MATERIALS

Understanding Digital Certificates & Secure Sockets Layer (SSL): A Fundamental Requirement for Internet Transactions

An Oracle White Paper February Centralized vs. Distributed SIP Trunking: Making an Informed Decision

FOR A PAPERLESS FUTURE. Petr DOLEJŠÍ Senior Solution Consultant SEFIRA Czech Republic

Shifting The Ticketing Paradigm

ISA Work Programme SECTION I

How to bridge the gap between business, IT and networks

The Art of Architecture Transformation. Copyright 2012, Oracle and/or its affiliates. All rights reserved.

International Open Data Charter

Oracle Forms and SOA: Software development approach for advanced flexibility An Oracle Forms Community White Paper

Certified Identity Management Professional (CIMP) Overview & Curriculum

Information Technology Services. Roadmap

How To Become A Member Of Europol

Data Management Value Proposition

Seminar E3 Developing an Effective Leadership Culture to Support Business Change

Innovative Approach to Enterprise Modernization Getting it Right with Data

An Oracle White Paper October Oracle Data Integrator 12c New Features Overview

SOLUTION BRIEF SEPTEMBER Healthcare Security Solutions: Protecting your Organization, Patients, and Information

End-to-End E-Clinical Coverage with Oracle Health Sciences InForm GTM

Transcription:

The State as a Platform and France Connect or, a new approach to the design of digital public services https://references.modernisation.gouv.fr/appel-public-%c3%a0-commentaires-epfc Service Architecture & Urbanisation de la Synthèse courte du 23 avril 2015 (V4.22 projet)

State as a Platform and France Connect 1. A platform strategy 2. Some key architectural principles 3. An ecosystem of federated APIs 4. Summary

State as a Platform and France Connect 1. A platform strategy

A platform strategy Key objectives 1. Design public services with a central focus on the needs and circumstances of end users. 2. Open up data, but give end users control over how personal information is exchanged. 3. Foster the growth of a self-regulated ecosystem of digital public services open to actors from the public, non-profit and private sectors. 4. Provide a framework of guidelines to choose among highly diverse technical and architectural options. 5. Lead the charge for a paradigm shift in project management practice. 6. Align with a number of similar initiatives in other countries and internationally.

A platform strategy Key objectives (1) Design public services with a central focus on the needs and circumstances of end users, with their active participation and across many channels (i.e. web, mobile, counter services, voice calls ), providing a consistent public face for government agencies and masking their internal complexity. This allows for the rapid deployment of legislative measures for simplification, such as «Dîtes-le-nous-une-fois» («Tell Us Once») or «Déclaration Sociale Nominative» (single salary expense declaration). Accueil

A platform strategy Key objectives (2) Open up data for exchange between agencies, but give end users control over how information of a confidential nature is exchanged, such as personal data. which implies a reliable mechanism for user identification, backed where necessary by appropriate authentication, and allowing the circulation of data beyond the public sphere, under the control of end users so as to forestall abuses. Create public trust through robust and secure systems

A platform strategy Key objectives (3) Foster the growth of a self-regulated ecosystem of digital public services open to actors from the public, non-profit and private sectors : by opening up for collaboration throughout the public sphere, for enhancing the public services offered by central administrations, agencies, particularly social services, local and regional authorities, and open to : private industry, business innovators, non-profit operators, giving a central role to end users on a par with public servants. For a more collaborative state.

A platform strategy Key objectives (4) Provide a framework of guidelines to choose among highly diverse technical and architectural options, converging quickly on shared invariants enjoying a high degree of legitimacy : a repository of interoperability guidelines, a common architectural framework, proven Web standards, a shared co-creation platform open to all actors, while acknowledging for a period of transition the choices embodied in legacy systems, and defining a migration path.

A platform strategy Key objectives (5) Lead the charge for a paradigm shift in project management practice, and a transformation in the State s information systems: Start with the pain points most direly felt by end users, Invest gradually in accordance with the priorities set for modernizing and enhancing public policy (simplification, streamlining, quality of service, reducing redundancy and waste in public expense, etc.) Champion development initiatives aligned with agile approaches, Promote share and reuse policies, Turn failure into an option rather than a stigma when trialling services, Accept that investment priorities require more frequent and regular review. For a more Agile government

A platform strategy Key objectives (6) Align with a number of similar initiatives in other countries and internationally: eidas* (EU regulation) : Electronic Identification and Signature PSI* : Public Sector Information, ISA* : Interoperability Solutions for European Public Administrations, Others relating with opening up and sharing public data, trust and confidence in public electronic transactions. collaborating closely with other agencies with overlapping responsibilities, such as ANSSI (National Agency for Information Systems Security) Respecting security contraints for information systems and the needs for protection of individuals, but with a mandate to redraw the lines * cf. annexes pour détail

State as a Platform and France Connect 2. Some key architectural principles 2.1. Major data flows

Some key architectural principles Major data flows: Opening up data Having all relevant data at hand (or being able to query for them) brings about radical change in the design of our systems, provided a clear distinction between : data that constitues a public good, managed by a public body obligated or willing to share it with all actors: statistical data bases, directories and repositories, etc., and data of a confidential or sensitive nature pertaining to a physical or legal person, which may be freely exchanged between agencies with a legitimate interest in such data, so long as the end user may control these exchanges, or is at the least informed that they take place. «Data is the new code», «code is the law»* and «architecture is politics» * Lawrence Lessig janvier 2000 Harvard Magazine

API API API Some key architectural principles Major data flows: Automated, paperless workflows Direct data exchange between Service and Data Providers Data providers 1 Service providers API Civil servant who certifies source data End user collects certified, electronic copy of records from digital workspace 2 End user transmits records to service provider Civil servant who handles inquiries or guides end users End user API Digital Workspace providers End users: persons acting on their own behalf as private individuals, or on behalf of other private individuals, or on behalf of legal entities

State as a Platform and France Connect 2. Some key architectural principles 2.2. Identification and Authentication France Connect

Some key architectural principles France Connect Identification and authentication of end users (1/2) We aim to make life simpler for end users, in particular allowing all to identify and authenticate, when necessary*, through a federated identity system to which all actors in the State as Platform are parties: France Connect. In this way, anyone can pick whichever digital identity is most convenient for them, to gain access to all digital public services. In order to guarantee the security of digital public services, to ensure services process and exchange the right data about the right person, and to ensure confidentiality while keeping the end user in control to a significant degree end users must be able to provide unambiguous forms of identification, and authenticate their identity to the degree warranted by the service being provided or data being accessed. These will be aligned with EU regulations and specifically eidas Levels of Assurance (low, substantial, high). * many formalities are also available anonymously, without requiring identification.

Some key architectural principles France Connect Target populations Three distinct variations on France Connect are envisioned, for each of : Private individuals, Representatives of legal entities (firms, non-profits, sole proprietorships, Les représentants de personnes morales (entreprises, associations, indépendants, members of regulated professions, ), Agents of the three branches of civil service, elected officials (TBC). France Connect provides a mechanism for identification and authentication, but is not concerned with and does not manage roles and permissions; these are under the purview of Service Providers.

API API API API Some key architectural principles France Connect Federated identity management Data providers Service providers API A Accueil Agent qui «certifie» une identité API Digital workspace providers End user provides authenticated identity to Service and Digital Workspace Providers Identity and Authentication providers France Connect allows end users to provide authenticated identification through whichever I&A provider they prefer

Some key architectural principles France Connect Federated identity management (SSO) Authentication Identity and authentication Provider A FranceConnect eidas level of insurance requested by service provider Login page of service provider End user

Some key architectural principles France Connect Trusted Third Party - Privacy by Design B FranceConnect eidas level of insurance requested by Data provider Data provider Workflow at service provider End user http://guichet-parisien.demo.dev-franceconnect.fr/ http://guichet-lyonnais.demo.dev-franceconnect.fr/ http://doc.integ01.dev-franceconnect.fr/ http://franceconnect.jamespot.pro/

State as a Platform and France Connect 3. An ecosystem of federated APIs

An ecosystem of federated APIs The State as Platform is intended as an «API First Strategy»!

State as a Platform and France Connect 6. Summary

State as a Platform and France Connect With some key initiatives now underway The State as a Platform strategy will succeed insofar as its general principles are translated into each of the major domains of public responsibility: education, health, social protection, employment, finances and accounting, local authorities, etc. It is therefore the responsibility of each of us to translate the concepts and principles into concrete action to bring about «Public services as a platform»

Experimentations Appropriation into specific domains State as a Platform and France Connect Our roadmap Strategic framework Architectural framework France Connect API Scaling out through addressing new needs and uses Agile approaches The State as a Platform and France Connect provide a consistent architectural framework supporting the design of new practices aligned with strategies for modernising and simplifying public policies.