Ministry of Public Administration

Slides:



Advertisements
Similar presentations
1 eGovernment Projects and Perspectives in the Bulgarian Public Administration Nedelcho Nedelchev Advisor to the Minister of State Administration and Administrative.
Advertisements

1 ABCs of PKI TAG Presentation 18 th May 2004 Paul Butler.
Mr. Aivars Paegle, Legal manager at The Register of Enterprises of the Republic of Latvia, Juridical Division Workshop on Single Institution for Registration.
Launching Egyptian Root CA and Inaugurating E-Signature Dr. Sherif Hazem Nour El-Din Information Security Systems Consultant Root CA Manager, ITIDA.
Public Key Infrastructure A Quick Look Inside PKI Technology Investigation Center 3/27/2002.
© Southampton City Council Sean Dawtry – Southampton City Council The Southampton Pathfinder for Smart Cards in public services.
Grid Computing, B. Wilkinson, 20045a.1 Security Continued.
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
ESign-Online Digital Signature Service February 2015 Controller of Certifying Authorities Department of Electronics and Information Technology Ministry.
Host of the 13 th ECRF Annual Conference - Budapest 2010.
Respecting Privacy in Global Networks/ Guernsey, Wednesday 11 th April, Paula Ortiz López Spanish Data Protection Agency.
Public Key Infrastructure (PKI) Providing secure communications and authentication over an open network.
PKI Activities at Virginia January 2004 CSG Meeting Jim Jokl.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
DIGITAL SIGNATURE AND ELECTRONIC DOCUMENTS IN ITALY Prof. Pierluigi Ridolfi AIPA Authority for Information Technology in the Public Administration V. Solferino,
Introduction to PKI Seminar What is PKI? Robert Brentrup July 13, 2004.
Summer School Certificates Diego Romano & Gilda Team.
CN1276 Server Kemtis Kunanuraksapong MSIS with Distinction MCTS, MCDST, MCP, A+
E-Government Security and necessary Infrastructures Dimitrios Lekkas Dept. of Systems and Products Design Engineering University of the Aegean
Workshop Ankara, –  Introduction  Legal background in Slovenia  Usage areas  Accreditations and supervision  REM service.
Workshop on registered electronic mail policies and implementation Ankara, March 2015 Davide Mula REM country practice in legal infrastructure,
TrustPort Public Key Infrastructure. Keep It Secure Table of contents  Security of electronic communications  Using asymmetric cryptography.
Civil Registry Agency of the Ministry of Justice, Georgia Georgian ID card Mikheil Kapanadze.
P O L I C E D E P A R T M E N T  Biometric passport – Passport Act – Issuing a biometric passport – Development project  Biometric Passport To Biometric.
Digital Signature Xiaoyan Guo/ Xiaohang Luo/
INTRODUCTION Why Signatures? A uthenticates who created a document Adds formality and finality In many cases, required by law or rule Digital Signatures.
Virginia Tech Overview of Tech Secure Enterprise Technology Initiatives e-Provisioning Group Frank Galligan Fed/Ed.
European Electronic Identity Practices Country Update of Austria Peter F Brown Office of the CIO, Austrian Federal Chancellery Chair, CEN eGov Focus Group.
E-government and e-services Portal Strategy of e-commerce Action plan e-government gallery.
Copyright © 2008, CIBER Norge AS 1 Using eID and PKI – Status from Norway Nina Ingvaldsen and Mona Naomi Lintvedt 22 nd October 2008.
E-Gov SLO 1 of 29 A to Z of the Slovenian e-Government Boštjan Tovornik, M.Sc Ministry of public administration.
F. Guilleux, O. Salaün - CRU Middleware activities in French Higher Education.
Copyright 次世代 IC カードシステム研究会 C 1 Nagaaki OHYAMA Tokyo Institute of Technology Chair of NICSS National ID card in Japan May Provoo (Reykjavik,
THE ROLE OF CIVIL REGISTRY TO ACTIVATE THE ELECTRONIC AUTHENTICATION
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
IT in the Swedish public sector Britta Johansson
NECTEC-GOC CA APGrid PMA face-to-face meeting. October, Sornthep Vannarat National Electronics and Computer Technology Center, Thailand.
E-Commerce Security Technologies : Theft of credit card numbers Denial of service attacks (System not availability ) Consumer privacy (Confidentiality.
Slovenian Governmental Certification Authority Dr. Aleš Dobnikar Government Centre for informatics of the Republic of Slovenia 4th Business and Government.
EGovernment Services in Poland Today & in The Future Dariusz Bogucki Ph.D, IDA II, National Co-ordinator National Registers Department, Ministry of Internal.
Chapter 9: Using and Managing Keys Security+ Guide to Network Security Fundamentals Second Edition.
Cryptography Encryption/Decryption Franci Tajnik CISA Franci Tajnik.
Unit 1: Protection and Security for Grid Computing Part 2
Configuring Directory Certificate Services Lesson 13.
Risks of data manipulation and theft Gateway Average route travelled by an sent via the Internet from A to B Washington DC A's provider Paris A.
Certificate-Based Operations. Module Objectives By the end of this module participants will be able to: Define how cryptography is used to secure information.
Digital Signatures A Brief Overview by Tim Sigmon April, 2001.
CERTIFICATES. What is a Digital Certificate? Electronic counterpart to a drive licenses or a passport. Enable individuals and organizations to secure.
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
Public Key Infrastructure (X509 PKI) Presented by : Ali Fanian
DIGITAL SIGNATURE. GOOD OLD DAYS VS. NOW GOOD OLD DAYS FILE WHATEVER YOU WANT – PUT ‘NA’ OR ‘-’ OR SCRATCH OUT FILE BACK DATED, FILE BLANK FORMS, FILE.
PKI and the U.S. Federal E- Authentication Architecture Peter Alterman, Ph.D. Assistant CIO for e-Authentication National Institutes of Health Internet2.
ELECTROINC COMMERCE TOOLS Chapter 6. Outline 6.0 Introduction 6.1 PUBLIC KEY INFRASTRUCTURE (PKI) AND CERTIFICATE AUTHORITIES (CAs) TRUST
Belgian EID Card 15/12/2004 Derette Willy eID program manager.
PKI Future Directions 29 November 2001 Russ Housley RSA Laboratories CS – Class of 1981.
Module 2: Introducing Windows 2000 Security. Overview Introducing Security Features in Active Directory Authenticating User Accounts Securing Access to.
National Information Communication Technologies Strategy Vasif Khalafov “National strategy” working group - Web -
NECTEC-GOC CA The 3 rd APGrid PMA face-to-face meeting. June, Suriya U-ruekolan National Electronics and Computer Technology Center, Thailand.
European Electronic Identity Practices Country Update of Estonia Speaker: Ivar Jung Date:
Bulding blocks of e- government Ingmar Pappel. Bulding blocks of e-government  Personal Code  Digital Identity  Digital signature  X-Road  Organizations.
GRID-FR French CA Alice de Bignicourt.
QuoVadis Group Roman Brunner, Group CEO Update for EUGridPMA – May 12, 2009.
TAG Presentation 18th May 2004 Paul Butler
ESign Aashutosh.
TAG Presentation 18th May 2004 Paul Butler
کاربرد گواهی الکترونیکی در سیستمهای کاربردی (امضای دیجیتال)
Chronological presentation
Year
PKI (Public Key Infrastructure)
National Trust Platform
Presentation transcript:

Ministry of Public Administration www.mju.gov.si, e: gp.mju@gov.si Tržaška cesta 21, 1000 Ljubljana t: 01 478 83 30, f: 01 478 83 31 Republic of Slovenia Certification service and electronic identification – PKI in Slovenian government Aleš Pelan, M.Sc. Directorate for e-Government and Administrative Processes Ministry of Public Administration

Digital Certificate Digital Certificate = Presents a modern alternative to old fashioned forms of identification Content: Name and surname of the holder Unique number Public key E-mail address ...... Certified by the certificate authority DN: cn=Ales Pelan, ou=certificates, o=state-institutions,c=si Serial #: 8391037 Start: 15/7/2008 14:20 End: 15/7/2013 14:50 E-mail: Ales.Pelan@gov.si Key: CA DN: ou=SIGOV-CA, c=SI

Legal Bases for Digital Certificates Electronic Commerce and Electronic Signature Act (2001, novel in 2004) Decree on Conditions for Electronic Commerce and Electronic Signing Personal Data Protection Act Secret Data Protection Act CA Policy (public and internal part of rules)

Register of CSP’s (Certificate Service Providers) Regulated in ECESA (electronic, digitaly signed form) Managed by Ministry of Higher Education, Science and Technology Basis for Certificate-based e-services in Slovenia (instead of cross-certification) 5 CSP’s issuing qualified certificates: SI*CA (CA at MPA) HALCOM CA AC NLB POŠTA CA SI-MoD-CA

SI*CA Slovenian Governmental Certification Authority Slovenian General

SI*CA Slovenian Time Stamping Authority Country Signing Certification Authority Slovenia

Types of digital certificates Enterprise certificates Web certificates Encryption/decryption Digital signature Authentication Secure delete Web communication e-mail Web communication (SSL, TLS) e-mail (S/MIME) Usage private public Validity of keys 3 years en./de., signature 5 years authentication Characteristics Valid for 5 years No automatic extension of validity Automatic extension of validity Keeping of decryption keys

Types of digital certificates Public administration Natural and legal persons Enterprise certificates: employees organizational units servers TSA systems Enterprise certificates : employees organizational units servers Web certificates : employees organizational units servers code signers OCSP responders Web certificates: employees organizational units servers code signers citizens

o=state-institutions SIGEN-CA public directory (digital certificates & CRL) c=si X500.gov.si (LDAP, HTTP access) o=state-institutions ou=sigen-ca firma1 ou=companies firma2 firma3 … ou=companies-web firma1 firma2 firma3 … ou=individuals

Data of certificate holders and legal persons serial number of digital certificate holder’s ID number holder’s tax number ID number of legal person tax number of legal person Connectional table Access for services: legal basis agreement Levels of access: data acquisition data validation 2345680712012 1103986715158 95962158 5874483000 28232801 2345680812017 1903969500853 32542186 5874483000 28232801 2345680912011 0104971500476 89159659 1358561000 33714789 2345681012014 0504953500645 16186575 1358561000 33714789 2345681112019 5119645002051 98783653 1358561000 33714789 2345681212013 2307976500283 11745889 5874424000 40016803 2345681312018 1403966500019 25978977 5874424000 40016803 …

Registration authority SI*CA Policy Application Registration authority SIGOV-CA SIGEN-CA Applicant Reference number Authorization code DC holder

Registration authority SI*CA Public Admini- stration MPA Administrative units (68) Citizens Embassies & Consulates (45) Legal persons Tax offices (24)

SI*CA certificates in e-services e-Government (e-SPA, OSS, e-taxes, Intrastat, e-notary, e-reporting, e-geodetic data, e-farm …) e-banking (Abanet, e-Banka Celje, DBS NET, Bank@Net, Dh-Plus, E-LON, KaD.Net …) e-businesses (SiOL, Elektro Ljubljana, Mobitel, miniMAX, EBA …) other (e-student, M servis …)

SI-TSA (Slovenian Time-Stamp Authority) Trusted time stamp is an electronically signed certificate from a certifying authority that confirms data content at the stated time. SI-TSA Issuing trusted time stamps for applications; Intended for public administration institutions and bussinesses (agreement); Interface: Web service (SOAP) and RFC 3161 ASN.1 service.

CSCA-SI (Country Signing Certification Authority - Slovenia) EU Member States must issue passports with Biometric identifiers (facial image) after 28 August 2006 - Council Regulation No 2252/2004 of 13 December 2004; Countries in Visa waiver Permanent Program had to fulfill the same requirement till 26 October 2006; Biometric data stored on a contactless radio chip and digitaly signed; CSCA-SI issues digital certificates for Document Signers in Slovenia; Operational since June 2006.

Bussiness issues PKI – one of infrastructural services at MPA availability of services: free services for government and citizens paylable services for legal persons (16.000 contracts,300.000 EUR of yearly income) maintanance costs: usually as a percentage of purchase price monthly cost per CA approx. 5.000 EUR (covering HW and SW for core CA and RA services; no costs for business premises, common infrastructure and employees included)

Critical success factors suitable internal organization compulsory policy documents (CP, CPS…) pre-defined standard procedures strict division of responsibilities/roles min two employees per role trained stuff (min 9 persons for 8 roles to be correctly covered) integration of certificates in e-services: test PKI environment tool for creating dig. signatures (XML/PDF) CA certificates in web browsers (IE,FF…)

And the future? web RA autoregistration identification by Post m-PKI certificates on mobile phones CVCA-SI e-passports with fingerprints CVCA -> DV -> IS e-ID e-gov functionality (digital certificates) project currently on-hold

Any further questions: Ales.Pelan@gov.si Additional information: http://www.gov.si/ca/eng/index.htm sigov-ca@gov.si