European Electronic Identity Practices Country Update of Finland Speaker: Päivi Pösö Date: 26.5.2005.

Slides:



Advertisements
Similar presentations
Universal Electronic Signatures Tarvi Martens ESTONIA.
Advertisements

1 Proposal for a Regulation on Electronic identification and trust services for electronic transactions in the internal market (COM( final) {SWD(2012)
Public Key Infrastructure and Applications
© fedict All rights reserved Legal aspects Belgian electronic identity card Samoera Jacobs – November 2008.
1 eGovernment Projects and Perspectives in the Bulgarian Public Administration Nedelcho Nedelchev Advisor to the Minister of State Administration and Administrative.
© ITU Telecommunication Development Bureau (BDT) – E-Strategy Unit.. Page - 1 Building Confidence in E-government Services ITU-T Workshop on.
© ITU Telecommunication Development Bureau (BDT) – E-Strategy Unit.. Page - 1 Seminar on Standardization and ICT Development for the Information.
1 ABCs of PKI TAG Presentation 18 th May 2004 Paul Butler.
Taxpayers registration and e-services provided by the Estonian Tax and Customs Board Karin Aleksandrov Chief Expert Service Management Department.
Mr. Aivars Paegle, Legal manager at The Register of Enterprises of the Republic of Latvia, Juridical Division Workshop on Single Institution for Registration.
Residents’ register service under the Ministry of the Interior
Gareth Ellis Senior Solutions Consultant Session 5a Key and PIN Management.
Launching Egyptian Root CA and Inaugurating E-Signature Dr. Sherif Hazem Nour El-Din Information Security Systems Consultant Root CA Manager, ITIDA.
Siemens IT Solutions and Services Porvoo 12 – Grosseto, October 2007 Update on EU Common Specifications.
EGovernment Vision, Policies and Implementations in Austria Prof. Dr. Reinhard Posch CHIEF INFORMATION OFFICER.
Digital Identity Group May GIXEL  GIXEL is the professional association of electronic component and system industries in France. It brings together.
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
Wireless PKI Shakeel Ahamad Shaik (Research Fellow) Under the supervision of Dr.V.N.Sastry, Associate Professor (IDRBT) & Dr.S.K.Udgata, Reader (UOH) Saturday,
© Southampton City Council Sean Dawtry – Southampton City Council The Southampton Pathfinder for Smart Cards in public services.
Setting Processes for Electronic Signature 1 The ”W-SPES Project” and the “Leuven Report on the Electronic Signatures Directive” – Putting the Project.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
European Electronic Identity Practices Country Update of …………… Speaker: Date:
European Electronic Identity Practices Country Update of Belgium Speaker: Maes F. Date: 25 May 2005.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
ESign-Online Digital Signature Service February 2015 Controller of Certifying Authorities Department of Electronics and Information Technology Ministry.
August 2004 Providing Industry-wide Security and Identity Management Solutions.
Respecting Privacy in Global Networks/ Guernsey, Wednesday 11 th April, Paula Ortiz López Spanish Data Protection Agency.
Page 1 Issues in and perspectives on electronic authentication of health professionals Pascal POITEVIN Marketing and Communication manager GIP-CPS e-Health.
The Leading Information Centre Conference on Interoperable European ID Haikko, Finland 3-5 April 2002.
European Electronic Identity Practices Country Update of Norway Speaker: Sverre Bauck Date:
Polytechnic University of Tirana Faculty of Information Technology Computer Engineering Department Identification of on-line users and Digital Signature.
Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict All rights.
Brooks Evans – CISSP-ISSEP, Security+ IT Security Officer Arkansas Department of Human Services.
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
Civil Registry Agency of the Ministry of Justice, Georgia Georgian ID card Mikheil Kapanadze.
P O L I C E D E P A R T M E N T  Biometric passport – Passport Act – Issuing a biometric passport – Development project  Biometric Passport To Biometric.
European Electronic Identity Practices Country Update of Spain Date: 26 May 2005.
Non-immigration Applications for Incorporation into the Smart ID Card Information Technology and Broadcasting Bureau 20 December 2001.
National Smartcard Project Work Package 8 – Security Issues Report.
COUNTRY XXX European Electronic Identity Practices Country Update of XXX Speaker: Date: 11 May 2006.
European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
Update on WS eAuthentication status Jan van Arkel Co-Chairman eEurope Smart Card Charter Ambassador CEN/ISSS WS eAuthentication.
PRESENTATION OF ETSI © ETSI All rights reserved Sophia Antipolis, 22 May 2014 Luis Jorge Romero Director General, ETSI.
Copyright 次世代 IC カードシステム研究会 C 1 Nagaaki OHYAMA Tokyo Institute of Technology Chair of NICSS National ID card in Japan May Provoo (Reykjavik,
Mike McCurry Health Market Development An Introduction to Monad in Healthcare.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
Slovenian Governmental Certification Authority Dr. Aleš Dobnikar Government Centre for informatics of the Republic of Slovenia 4th Business and Government.
Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode.
U.S. General Services Administration Federal Technology Service November 9, 1999 Judith Spencer Director, Center for Governmentwide Security Office of.
Risks of data manipulation and theft Gateway Average route travelled by an sent via the Internet from A to B Washington DC A's provider Paris A.
The Porvoo Group Tapio Aaltonen Director, CA-services, co- chair Porvoo Group Population Register Centre Finland.
PKI in the Swedish public sector Decentralised administration - each agency make their own decisions PKI in different situations: internally within an.
ELECTROINC COMMERCE TOOLS Chapter 6. Outline 6.0 Introduction 6.1 PUBLIC KEY INFRASTRUCTURE (PKI) AND CERTIFICATE AUTHORITIES (CAs) TRUST
European Electronic Identity Practices CEN TC224 WG15 European Citizen Card Standard Speaker: L. Gaston AXALTO Date: 26 May 05.
Belgian EID Card 15/12/2004 Derette Willy eID program manager.
European Electronic Identity Practices
/ 8 FEIDHE Electronic Identification in Finnish Higher Education Janne Kanner FEIDHE Electronic Identification in Finnish Higher Education.
European Electronic Identity Practices Country Update of Estonia Speaker: Ivar Jung Date:
Cross border electronic signature services Ingmar Vali Head of Court Registers Department Centre of Registers and Information Systems
Bulding blocks of e- government Ingmar Pappel. Bulding blocks of e-government  Personal Code  Digital Identity  Digital signature  X-Road  Organizations.
The Future Digital Identity Landscape in Europe Timothée Mangenot, chairman 14th of December, 2015 ACSIEL partners day.
TAG Presentation 18th May 2004 Paul Butler
Smart Data infrastructure
ESign Aashutosh.
TAG Presentation 18th May 2004 Paul Butler
E-Commerce for Developing Countries (EC-DC)
E-identities (and e-signatures)
Presentation transcript:

European Electronic Identity Practices Country Update of Finland Speaker: Päivi Pösö Date:

CA organisation Responsible CA organisation: Population Register Centre (PRC) The background of the organisation: PRC operates under Ministry of the Interior Description of the existing CA infrastructure: PRC is the CA in public sector. We have outsourced the ICT- technology.

Status of National legislation on eID The position of PRC as the CA is based on the Population Register Act PRC shall ensure that the parties of certified electronic transactions can be authenticated and that messages and document can be electronically signed and enciphered

Status of National legislation on eID In Finland the police issues the ID cards and PRC the citizen certificates in these PRC may issue citizen certificates also for other cards or technical means. Certificates are quality certificates based on the Act of Electronic Signatures

Status of National legislation on eID Are eID specific regulations enacted and in place? Yes - The Population Information Act and Decree (1993) -The Identity Card Act (1999) -Act on Electronic Services and Communication in the Public Sector (2003) -Directive on Electronic Signatures -Act on Electronic Signatures (2003)

Status of National deployment of eID Co-operation with telecommunication operators Citizen certificate in Sim-card Easy to use, no additional equipments

Status of National deployment of eID Is the card obligatory? No Starting date of issuance:

Status of National deployment of eID Number of citizen certificates issued by : issued, at the moment valid cards Number of inhabitants: Yearly growth rate (percentage): Expected number of cards/eID certs by end of 2007:

Status of national deployment of eID Basic functionalities of the eID card: - official ID document: Yes - European travel document: Yes - support of on-line access to e-Services: Yes - social security information on the card: Yes Validity period of the card/certificates: 5 years

Status of national deployment of eID Price in Euros of the cards: - for the citizen: 40 - for the card issuer: 40 - price for the card reader and software: 20 – 40 - any additional costs for the user/relying party: No additional costs From whom and how may the citizen obtain the end/user packages: PC-stores

Basic ID function What cardholder data is electronically stored in the card: - national identifier - family name, given name - (optional)

Basic ID function Are these data elements in a dedicated data file? No - Is the file openly accessible? No - If not, how is the file protected? PIN - Does the data file comply with the ICAO LDS? Yes Is the personal data (also) held in a certificate? Yes

Basic Authentication function What Cardholder Verification mechanism is used: - PIN? Yes - Biometrics?No - Is introduction of biometrics envisioned? Under survey, not active Is there a PKI supported cardholder authentication mechanism? Yes Is there a mutual device authentication mechanism? No

Basic Signing function Is a PKI supported signing mechanism (certificate and key pair) present for e- transaction services (non –repudiation)? Yes - The card holder´s authentication certificate - The card holder´s digital signature certificate - PRC´s CA certificate

eID based services What kind of services (include examples) are accessible to cardholders based on acceptance of the cards / eID Certificates:

eID based services Examples of Sevice provider using the Fineid Card Tax administration Several Cities Several Insurance Companies OKO Bank Social Insurance Institution Electronic Forms Finland – service The Finnish Defence Forces

eID based services Total number of eID based services accessible by cardholders by : Over 50 Goal (in numbers/ percentage) of eID based services to be accessible to cardholders by the end of 2007: At least 200

eAuthentication Business models; financial What are the Charging/Revenue mechanisms? eID card costs 40 What charges are levied for use of the card? Free of charge Is there a charge for checking certificates? No Has a cost benefit analysis been compiled for the eID scheme? This is the basic infrastructure in Finland Is there a study report available? No

eAuthentication Business models; public/private partnership Are non government bodies allowed to use the IAS or other card functions in support of their services? Yes Is the card a multi-application smart card? No –If No, are there any plans for this and in what timeframe? –Co-operation with cities and municipalities

eAuthentication Business models; public/private partnership What is the level of usage of supported services (number of transactions per card per year)? - No reliable studies of this What is the approach to and experience with card branding? There are information and logos of the Social Insurance Institute of Finland and cities/municipalities

eAuthentication Business models; cross border usage Are there agreements with other national smart card issuers for mutual recognition of cards? (Status of Memorandum of Understanding (MOU) with other CAs): MOU was made with Estonia in Co-operation is under preparation in TIFI- project with many countries.

Other Interoperability issues What is the level of Current Compliance with each of the following international standards or group activities (Full/Planned/None): –CWA eAuthentication (under development):planned –CWA Secure Signature creation device:planned –CEN 224 –15 European Citizen Card (under development):none –ISO/IEC JTC1 SC 37 biometric standards:none –ICAO recommendations: all

Current use and plans in Biometrics (if applicable) Technical solution(s): Type of project(s): Application areas: –Under survey, based on the experiences coming from the biometric passport.

Lessons learned so far Prerequisites for success easy to use social and health care services broad, cross-administrative co-operation co-operation with the private sector supporting and guiding service providers

Next plans Biometric passport in co-operation with the Ministry of Interior, Police Department Co-operation with teleoperators and banks to have the citizen certificates on there platforms – already with one bank and one operator 64k Java chips on the first of June 2005 Co-operation with cities and municipalities

Porvoo Group cooperation issues List of issues to be overcome: Open Source Card reader software? Could this be an easier way for pan European usage? The collision of the RSA algorithm at the moment. What will be the next step – elliptic curve cryptography? Should we try to study this more?

More information Web-pages eID issues: Thank You!