NETWORKED EUROPEAN SOFTWARE & SERVICES INITIATIVE NESSI: delivering building blocks for the Internet of Services New Architectures for Future Internet,

Slides:



Advertisements
Similar presentations
Session 3: Safer Services in a Digital Society Security with RFID Gérald Santucci European Commission Head of Unit DG INFSO/D4.
Advertisements

What Does it Mean to be a Strategic NESSI Project?
Overview of NESSI Projects Portfolio Stefano De Panfilis Engineering Ingegneria Informatica S.p.A.
Support for the coordination of activities TECHNOLOGY PLATFORMS Context, Rationale and State of Play Presentation by Julie Sors European Commission Rotterdam,
A strategy for a Secure Information Society –
ETSI Workshop – 24-Oct-06 NESSI From R&D to Competitiveness in Services Frederic Gittler HP Labs Vice-Chairman NESSI Steering Committee.
Towards Open Embbeded Systems, Architectures, Standards & Open Source Dominique Potier, THALES / Chair ARTEMIS WG Innovation Environment Alexander Roth,
Nokia - European R&D collaboration Juha Saarnio Head of Industrial Initiatives Nokia Research Center Juha Saarnio Head of Industrial Initiatives Nokia.
19/02/2006 The NESSI European Technology Platform 2nd Workshop – Shanghai Feb 2006 Stefano De Panfilis R&D Laboratories Engineering Ingegneria.
1 From Grids to Service-Oriented Knowledge Utilities research challenges Thierry Priol.
Road to Prague and Beyond Nov 2008 Introductory panel discussions in the FI of Services networking Lyon Dec 2008 Panel discussions during FIA.
The role of NESSI in the Future Internet Frédéric Gittler, HP Labs NESSI SC Chairman NEXOF-RA Chief Architect.
Multi-level SLA Management for Service-Oriented Infrastructures Wolfgang Theilmann, Ramin Yahyapour, Joe Butler, Patrik Spiess consortium / SAP.
Life Science Services and Solutions
Support for the coordination of activities Joint Technology Initiatives: Background and Current State of Play Presentation to the Meeting of High-Level.
First create and sign up for a blue host account Through the help of Blue Host create a WordPress website for the business After you created WordPress.
Jose Jimenez Director. International Programmes Telefónica Digital.
Digital Agenda Unleashing the Potential of Cloud Computing in Europe Ken Ducatel Head of Unit Software and Services, Cloud European Commission (Directorate.
NEXOF-RA Standardisation Support Franz Kudorfer, Siemens AG NEXOF-RA.
Integrating SSA&I projects into the Future Internet activities Limitations of the current Internet.
CEF Building Blocks Joao RODRIGUES FRADE
FP7 Preparations ISTC meeting 31 March Content FP7 preparation approach and timetable Context for FP7 and for ICT in FP7 Research in New Financial.
1 ICT R&D&Innovation in Europe A market of more than 660 Billion Euro –Largest market world wide, (~34%) EU produces 23% of the world ICT value added –ICT,
European Innovation for Active and Healthy Ageing
Strategy 2022: A Holistic View Tony Hayes International President ISACA © 2012, ISACA. All rights reserved.
Digital public services and innovation
Stakeholder meeting on the SHIFT²RAIL Strategic Master Plan Manuel Pereira, IST Lisbon ERRAC Vice Chairman 20 th June 2014, Brussels 1.
Towards trustworthy ICT service infrastructures Yves PAINDAVEINE Directorate General Information Society and Media Unit F5 Security European Commission.
- 1 Agenda Introduction Overview of NESSI NESSI’s roadmap for FP7 NESSI – a value proposition for vertical areas Debate and input from the audience Conclusion.
Jj/mm/yyyy An introduction to NESSI Frédéric Gittler HP Labs NESSI Steering Committee Vice-Chairman.
ICT 7: Advanced cloud infrastructures and services ICT 8: Boosting public sector productivity and innovation through cloud computing services Jorge GASOS.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
Objective 1.2 Cloud Computing, Internet of Services and Advanced Software Engineering Arian Zwegers European Commission Information Society and Media Directorate.
EGI-Engage EGI-Engage Engaging the EGI Community towards an Open Science Commons Project Overview 9/14/2015 EGI-Engage: a project.
WHO–ITU National eHealth Strategy Toolkit An effective approach to national Strategy Development and Implementation Clayton Hamilton WHO Regional Office.
ICT policies and the Lisbon Agenda Baltic IT&T 2005 Riga, 7 April 2005 Frans de Bruïne Director “Lisbon Strategy and Policies for the Information Society”
IST 2006 – 22/11/2006 Aljosa Pasic Atos Origin Security, Dependability and Trust in Service Infrastructures.
WISTP workshop Aljosa Pasic Atos Origin Trust, Security and Dependability in ICT – FP7.
András Siegler - ERTRAC National Platforms Workshop, Budapest, 5/9/2008 The role of Technology Platforms in European Research ERTRAC National Platforms.
An Integrated Control Framework & Control Objectives for Information Technology – An IT Governance Framework COSO and COBIT 4.0.
“The NESSI Strategy: The Way Ahead” BCI´07 Jose M. Cavanillas Vice-chairman NESSI Steering Committee Director Atos Origin – Research & Innovation.
IST Call 5 Preparatory Workshop on “Collaborative Working Environments” Nuria de Lama Las ideas no duran mucho. Hay que hacer algo con ellas.
JOINING UP GOVERNMENTS EUROPEAN COMMISSION Establishing a European Union Location Framework.
ISPLC 2001 PLC in the IST Programme Thierry Devars DG INFSO/E1
NETWORKED EUROPEAN SOFTWARE & SERVICES INITIATIVE Future research challenges in dependability - an industrial perspective from NESSI Aljosa Pasic Atos.
Paulo Lopes Counsellor for Information Society and Media European Union Delegation in Brazil The European Union Approach to the Interoperability of e-Government.
Catawba County Board of Commissioners Retreat June 11, 2007 It is a great time to be an innovator 2007 Technology Strategic Plan *
NESSI at a glance Josep Martrat ATOS ORIGIN EGEE 1st Industry Day. Paris, 27 th April 2006.
Challenge 6: Mobility, Environmental sustainability and energy efficiency Includes as driving objective: “Sustainable growth and environmental sustainability”
The European Union R&D Landscape The Israel-Europe R&D Directorate For EU FP6 Rehovot, July 2006.
The EU framework programme for research and innovation.
Jacques Bus Head of Unit, DG INFSO-F5 “Security” European Commission FP7 launch in the New Member States Regional on-line conference 22 January 2007 Objective.
NCP Info DAY, Brussels, 23 June 2010 NCP Information Day: ICT WP Call 7 - Objective 1.3 Internet-connected Objects Alain Jaume, Deputy Head of Unit.
Chapter © 2012 Pearson Education, Inc. Publishing as Prentice Hall.
Technology-enhanced Learning: EU research and its role in current and future ICT based learning environments Pat Manson Head of Unit Technology Enhanced.
19-20 October 2010 IT Directors’ Group meeting 1 Item 6 of the agenda ISA programme Pascal JACQUES Unit B2 - Methodology/Research Local Informatics Security.
“From GRID research to GRID business” Francesco Giglio
Cultural Heritage in Tomorrow ’s Knowledge Society Cultural Heritage in Tomorrow ’s Knowledge Society Claude Poliart Project Officer Cultural Heritage.
FROM PRINCIPLE TO PRACTICE: Implementing the Principles for Digital Development Perspectives and Recommendations from the Practitioner Community.
Aligning Policy Agendas The case of personalised care and cure for healthy and active ageing Setting the scene for the DG Regio and Flanders Smart Specialisation.
IoT R&I on IoT integration and platforms INTERNET OF THINGS
Information Society Technologies European olicies for Information ociety European Policies for Information Society European Commission DG Information Society.
EUB Brazil: IoT Pilots HORIZON 2020 WP EUB Brazil: IoT Pilots DG CONNECT European Commission.
NESSI OPEN SERVICE FRAMEWORK – REFERENCE ARCHITECTURE NEXOF-RA V October 2008 Mike Fisher, BT Innovate.
Evaluation and Impact Assessment of European FP for R&D :
“Self-Sustaining Innovation Ecosystems for European Leadership”
inclusive Information Society
Standards for success in city IT and construction projects
The Single European Sky Implementation Programme: SESAME
EXPLORING GLOBAL COOPERATION OPPORTUNITIES
Presentation transcript:

NETWORKED EUROPEAN SOFTWARE & SERVICES INITIATIVE NESSI: delivering building blocks for the Internet of Services New Architectures for Future Internet, Campinas, Aljosa Pasic, Atos Origin

Agenda The story of NESSI Future Internet (of services) Building blocks for IoS Closer look at security for IoS Conclusions

The story of NESSI The context - European Technology Platform Private-public partnership Industrial leadership Uniting all stakeholders Around a key, strategic area Strategic? Europes future growth Europes competitiveness Link? Requires major research and technological advances In the medium to long term NESSI aims to provide a unified view for European research in Services Architectures and Software Infrastructures Today, NESSI partners represent 1.7 Million strong workforce and 490 B in revenues NESSI has presented an initial Strategic Research Agenda that represents a global investment of 2.5 B

NESSIs governance 4 NESSI partners Coordinating NESSI members Actively Contributing to NEXOF to the SRA Staying Aware Committees Board Steering Committee Working Group Committees NESSI Office Research Projects NewslettersEvents Mailings

NESSI partners Coordinating NESSI members Actively Contributing to NEXOF to the SRA Staying Aware 400 members 12 working groups 6 NESSI Strategic Projects 5 NESSI Compliant Projects NESSIs constituency

ETP or JTI? ETP – European Technology Platform JTI – Joint Technology Initiative Over 30 ETPs – 6 JTIs Innovative Medicines Initiative (IMI) Embedded Computing Systems (ARTEMIS) Aeronautics and Air Transport (Clean Sky) Nanoelectronics Technologies 2020 (ENIAC) Fuel Cells and Hydrogen (FCH) Global Monitoring for Environment and Security (GMES) 6 ETPs JTI

NESSI at a glance

Agenda The story of NESSI Future Internet (of services) Building blocks for IoS Closer look at security for IoS Conclusions

NESSI in Future Internet Internet of things Internet of Users Internet of Contents Internet of Services Services Data & Contents Things & sensors Users & Knowledge AMBIENT NETWORKS & PERVASIVE COMPUTING REAL VIRTUAL Tomorrow the Internet will be strategic because of services

Future Internet Assembly 10 European Commission

NESSI Framework NESSI Landscape NESSI Adoption Holistic Model Core Services Business Services EU Economy NESSI Adoption

NESSI Framework NESSI Landscape NESSI Adoption Holistic Model Core Services Business Services EU Economy NESSI Adoption Define and implement Practices & Usages Architecture & Engineering Regulatory Governance

Agenda The story of NESSI Future Internet (of services) Building blocks for IoS Closer look at security for IoS Conclusions

The tools of NESSI The first tool of an ETP is its Strategic Research Agenda Moving from vision to definition Frame the context Refine the Technological scope

The tools of NESSI The first tool of an ETP is its Strategic Research Agenda Moving from vision to definition Frame the context Refine the Technological scope Enhance definition of NEXOF – the NESSI Open Service Framework Build it together

Contributing to NEXOF Contributing key components to NEXOF Compliant to NEXOF or Contributing to NEXOF - Open to all - Participative selection process Contributing to NEXOF – a world-wide process

Contributing to NEXOF Contributing to NEXOF – a world-wide process

System Platform Consumer Adaptation Service consumers Infrastructure Service Composition BPM view Service Platform Monitoring Service Communication Service Discovery Mediation SLA Negotiation Service Coordination Integration Services Reasoning Service Execution Lifecycle Management Service Registration Infrastructure and Data Abstraction Data Management Resources Management Business Process Execution SVN Lifecycle Management Information Services Interaction Services End user Interface Context Handling Mapping users perspectives to business/Integration Native Services External Services Knowledge Modelling Service Modelling SVN Modeling Infrastructure Modelling SBS/SBA Modelling Context Modelling Business Process Modeling Engineering tools Requirements Capture offered as services

System Platform Consumer Adaptation Service consumers Infrastructure Service Composition BPM view Service Platform Monitoring Service Communication Service Discovery Mediation SLA Negotiation Service Coordination Integration Services Reasoning Service Execution Lifecycle Management Service Registration Infrastructure and Data Abstraction Data Management Resources Management Business Process Execution SVN Lifecycle Management Information Services Interaction Services End user Interface Context Handling Mapping users perspectives to business/Integration Native Services External Services Knowledge Modelling Service Modelling SVN Modeling Infrastructure Modelling SBS/SBA Modelling Context Modelling Business Process Modeling Engineering tools SOA4ALL MASTER EzWeb RESERVOIR

Agenda – The story of NESSI – Future Internet (of services) – Building blocks for IoS – Closer look at security for IoS – Conclusions

Service Oriented World Applications will need to utilise shared and co-owned services out of different domains of control that require to obey separate security policies and ask for diverse security and dependability qualities

Challenges A trustworthy Internet with services that you trust The technical base that makes the Internet a safer place Address long-term research and industry vision on trust, security and dependability in software and services

Coming problems For industry: Demand for Secure software is much higher than available security expertise For research/technology: New complex scenarios (e.g. ambient intelligence) introduce security issues not addressed by conventional engineering processes For market consultants: Security properties difficult to measure and it is also difficult to evaluate their compositional effects For users: Security segmentation and market definitions are blurring: service infrastructure covers network infrastructure, perimeter, desktop, server and application security For auditors and lawyers: Who is accountable and liable for what? For society: Trust becomes a key enabler for service provision and use For everyone: How much should we spend on security?

Some Research Topics Security Technologies Embedded in Services Services at the component level of the Service-Oriented Architecture Specialised Security Services and Properties Access control architecture and its implementation System-wide Security Characteristics Holistic implementation of the secure service eco-system. Dependability and Availability. Human/Societal/Technical Trust elements The human & machine perception of System Trustworthiness. Privacy, digital rights… Governmental and Societal Context Policy, Regulation, Certification, Awareness, Security Stakeholders Mapping…

TSD grey context boundaries If computing sky is getting cloudy…TSD will depend on weather conditions… Infrastructure view: Expanding boundary (include remote access PC) and/or Contracting boundary (exclude outsourcing staff PC, external B2B server…) Trust view: trust zones where a level of trust can be established and security controls can be enforced E2E Security or Dependability levels: closed, semi-open or open servicenets ?

Security Dimensions in Service Infrastructures Secure Services Securing Services Security as a service

What should it be? Dynamic Adaptable Composable Measurable Predictive Scalable Persuasive Open Trustworthy Interoperable Approaches, properties and research challenges In TSD engineering and modelling In TSD control and management In TSD level assurance

…which brings many trade-off issues… AvailabilityData integrity Privacy Accountability ScalabilityAssurance

Metrics for Trust, Security & Dependability a)b)c)

Biometrics Network Privacy, identity Services Secure Implementation Trusted Computing FP6FP7 Coordination Action SecurIST ESFORS THINK-TRUSTFORWARD PARSIFALAMBER

More on trust and trustworthiness… In a service-centric Internet: Use and adoption of services depends highly on TRUST and TRUSTWORTHINESS The trust model relies on complete requirements that include business, technical, legal, regulatory, and societal requirements PrimeLife

We need more than technology : an example Risk management failure; a trader (Jerome Kerviel) was able to turn off the monitoring controls which should have alerted the organization to a magnitude of risk which put the organization in danger. Governance failure; when the French Banking Commission detected Kerviel's activity and warned Societe Generale (SocGen) that its risk management regime was not working properly, SocGen management apparently failed to take effective action to fix the problem. Identifying in time both failures and who in the organization is responsible for addressing each failure is a lesson learnt for other companies which might face in the future similar problems.

MASTER approach: align and manage GRC tool structure should have roundtrip processes. Management at all levels should have effective tools for understanding the information and reports it receives, including the ability to drill down into information to see the details provided by staff at all levels. Compliance Management solution, such as MASTER can help implement roundtrip processes. Different interfaces for different people. Conceptual Model Methodology MASTER Architecture Online Enforcement Run-time Monitoring and Signalling Design-Time Workbench Assessement Cockpit

34 Outsource people, processes, resources... Regulators Standards Bodies Best practices Offshore Outsourcing

35 Compliance Management in MASTER Designing Methods and tools for selecting and integrating controls Monitoring Collecting evidence for the measurement of operation and effectiveness of controls. Assessment Evaluation of status of compliance Enforcement Ensuring controls are applied Reacting when controls fail MASTER integrated project (Feb 2008-Feb 2011) Industry Atos Origin (ES), SAP AG (DE), Engineering (IT), British Telecom (UK), IBM (CH), ANECT (CZ), Deloitte (FR) Academia Lero (IE), University of Trento (IT), ETH (CH), University of Stuttgart (DE), SINTEF ICT (NO) End user CESCE (ES), Hospital San Raffaele (IT) OrganizationOrganization Service Provision = Control process

Decompose compliance/control objectives Control Objectives Can be decomposed Means-end analysis Risk-assessment Control Activities Can be decomposed Process/temporal constructs Enforcement and auditing language constructs Control service Description of step-by-step control mechanisms Target/Value Goals Can be decomposed Business process engineering This is outside the MASTER process. Target Activities (business process) Can be decomposed Again outside MASTER Impact of control steps over value steps must be considered Target service Controls

Business Process Control Process Event going into control process Event coming out of control process Event not modified by control process

BP step Control step In SOA world… BP step Control step BP step Control step

KSI (correctness) 7, Event going into control process Event coming out of control process Event not modified by control process Compliant event (trace) Non-compliant event (trace)

Standardization and reusability PRM A CO 4 PRM B PRM C Control Objectives: security goals need to be satisfied to be compliant CO M CO 4 CO 8 CO 9 CO 2 CO N CO 1 Possibility to leverage on existing PRMs and re-using existing ones (or part of) in defining new PRMs Protection Model: is a set of controls whose enforcement, monitoring and assessment guarantees an experimentally and/or formally assessed level of compliance Control activities and steps: Derived from a set of required COs From specification of high level COs to operational policies

Key building block for FI: Identity STORK is a large scale pilot in the ICT-PSP (ICT Policy Support Programme), under the CIP (Competitiveness and Innovation Programme), and co-funded by EU. It aims at implementing an EU wide interoperable system for recognition of eID and authentication that will enable businesses, citizens and government employees to use their national electronic identities in any Member State. It will also pilot transborder eGovernment identity services and learn from practice on how to roll out such services, and to experience what benefits and challenges an EU wide interoperability system for recognition of eID will bring. The STORK interoperable solution for electronic identity (eID) is based on a distributed architecture that will pave the way towards full integration of EU e- services while taking into account specifications and infrastructures currently existing in EU Member States. The solution provided is intended to be robust, transparent, safe to use and scalable, and should be implemented in such a way that it is sustainable beyond the life of the pilot.

Agenda The story of NESSI Future Internet (of services) Building blocks for IoS Closer look at security for IoS Conclusions

The importance of the global collaboration Future Internet – an opportunity for collaboration Similar initiatives exist in several countries end-to-end location-ind. services the best of all communities optimise resources No single domain delivers end-to-end user scenarios Global convergence is only implemented by a common approach and shared process Many companies are present worldwide Many countries have specific excellence Multiple disciplines and knowledge domains are needed Validate the best competitive applications and usage scenarios worldwide Avoid reinventing the wheel ETPs

Conclusions We need to invest in research GLOBALLY in order to ensure continued trust by users as society increases its dependency on software services Software security engineering, in its road to maturity, could & should use lessons learned from the software engineering and from the system security, but also other disciplines and research communities

Thank you FACING TECHNOLOGICAL CHALLENGES TOGETHER Aljosa Pasic (Atos Origin)