Presentation is loading. Please wait.

Presentation is loading. Please wait.

9/19/2016 1 Latest developments in Estonian eID Ivar Jung CMB Estonia.

Similar presentations


Presentation on theme: "9/19/2016 1 Latest developments in Estonian eID Ivar Jung CMB Estonia."— Presentation transcript:

1 9/19/2016 1 Latest developments in Estonian eID Ivar Jung CMB Estonia

2 9/19/2016 2 Latest developments in Estonian eID Change of ID card chip Digital stamps m-ID Quick eIDs

3 9/19/2016 3 Change of ID card chip Old chip 16-Bit Security Controller with Memory Management and Protection Unit in 0.25 µm CMOS Technology 64-Kbytes ROM, 3004 bytes RAM, 16-Kbytes EEPROM 1100-Bit Advanced Crypto Engine 112-Bit / 192-Bit DDES-EC2 Accelerator New chip 8/16-Bit Security Controller with enhanced instruction set for large memories in 0.22 um CMOS Technology 246-Kbytes ROM, 7100 bytes RAM, 68-Kbytes EEPROM 1100-Bit Advanced Crypto Engine certified RSA 2048-bit library available Dual Key Triple DES Accelerator

4 9/19/2016 4 Change of ID card chip Reasons to change The old chip was not available anymore

5 9/19/2016 5 Change of ID card chip Services bound to ID card authentication internet banking state services at workplace digital signing Digidoc portal Digidoc utility all of them had lot of users

6 9/19/2016 6 Change of ID card chip The goal was: both chips should work with all services with no problems Solution: porting OS Micardo Public 2.1 to the new chip Problems It was noticed that some application developers didn't follow the specification of EstEID with respect to the ATR – they had to fix their work The goal was met

7 9/19/2016 7 Change of ID card chip There were 1,136,857 ID cards issued with old chip 7520 ID cards are issued with new chip (as of 01.10.2007) RSA key pair generation is a bit faster with new chip

8 9/19/2016 8 Digital stamps Rationale Organizations produce automatic documents for citizens for other organizations It is not reasoned to (digitally) sign this kind of documents by some employee with his personal certificate There may be reasons to stamp some kind of documents by person if he acts as a business or public unit

9 9/19/2016 9 Digital stamps We have an ongoing process of Digital Signature law amendment, to include digital stamps for organizations for persons There will be one stamp per stamp-owner, although technically there may be n stamps You will get more and better overview of digital stamps from Mr. Tarvi Martens

10 9/19/2016 10 m-ID Rationale To use ID cards, one needs: a smartcard reader software installed they are not always available A thing that nearly everybody has with them nowadays is a mobile phone There are SIM cards that conform with security requirements

11 9/19/2016 11 m-ID How does it work Mobile phone acts as card reader pinpad SIM card holds securely keys Certificates are somewhere on the net – actually at the service provider's

12 9/19/2016 12 m-ID It is possible to: authenticate with m-ID digitally sign with m-ID

13 9/19/2016 13 m-ID Authentication process Computer: login with m-ID Computer: control code C0 Mobile phone: control code C1 Must be condition C0==C1 Mobile phone: enter? Mobile phone: enter PIN code Computer: you are in

14 9/19/2016 14 m-ID m-ID was developed by: EMT – Estonian Mobile Telephone SK – Certification Center It has: 1219 activated users 329 not yet activated users

15 9/19/2016 15 m-ID Problems: issuing process issuer is a private company identification of the certificates recipient is considered to be not reliable activation of m-ID certificates is done by ID card

16 9/19/2016 16 Quick eIDs Rationale Loss of ID card Broken chip on ID card Any reason why ID card electronic part does not work Need to use e-identity in spite of reasons said

17 9/19/2016 17 Quick eIDs The period from application till receipt of ID card is 30 days by the regulations CMB has reduced this period to 5 days in our capital city This is not enough for people who use their ID cards in business (work) daily There may be same kind of needs in civil life also

18 9/19/2016 18 Quick eIDs CMB has started a process of developing new kind of quick eIDs not visually personalized smartards same certificates as on ID card citizen must have ID card issued to get quick eID issuance by one visit to CMB's office same electronic functionality as on ID cards

19 9/19/2016 19 The end Thank you Ivar Jung jung@mig.ee


Download ppt "9/19/2016 1 Latest developments in Estonian eID Ivar Jung CMB Estonia."

Similar presentations


Ads by Google