27.5.2016 1 Ivo Rosol, OKsystem Middleware.

Slides:



Advertisements
Similar presentations
Eclipse, M2M and the Internet of Things
Advertisements

Eclipse, M2M and the Internet of Things
© Copyrights 1998 Algorithmic Research Ltd. All rights Reserved D a t a S e c u r i t y A c r o s s t h e E n t e r p r i s e Algorithmic Research a company.
Mobile Devices in the DoD
Practical Digital Signature Issues. Paving the way and new opportunities. Juan Carlos Cruellas – DSS-X co-chair Stefan Drees - DSS-X.
Jose Jimenez Director. International Programmes Telefónica Digital.
Digital Identity Group May GIXEL  GIXEL is the professional association of electronic component and system industries in France. It brings together.
European Electronic Identity Practices Country Update of …………… Speaker: Date:
The fastest e-passport of the world – SESAMES 2013 winner for new generation eletronic documents Matthias Bruestle from MaskTech GmbH
BioSec Biometrics & Security IST © 2005 BIOSEC Consortium 1February 2005 BioSec Biometrics & Security Orestes SanchezBioSec Coordinator Telefónica.
Network Management Overview IACT 918 July 2004 Gene Awyzio SITACS University of Wollongong.
Identity and Access IDGo Secure (ISE) for Android Didier Bonnet April 2015.
FIT3105 Smart card based authentication and identity management Lecture 4.
UPnP Device Management Andre Bottaro France Telecom Group UPnP DM co-chairman End User Device Management panel Sunday, January 11th, 2009 CCNC'09.
Secure Element Access from a Web browser W3C Workshop on Authentication, Hardware Tokens and Beyond 11 September Oberthur Technologies – Identity.
InterSwyft Technology presentation. Introduction InterSwyft brings secured encrypted transmission of SMS messages for internal and external devices such.
©Ian Sommerville 2004Software Engineering, 7th edition. Chapter 18 Slide 1 Software Reuse 2.
.NET, and Service Gateways Group members: Andre Tran, Priyanka Gangishetty, Irena Mao, Wileen Chiu.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
LEVERAGING UICC WITH OPEN MOBILE API FOR SECURE APPLICATIONS AND SERVICES Ran Zhou 1 9/3/2015.
Leveraging UICC with Open Mobile API for Secure Applications and Services Ran Zhou.
PRESENTATION OF ETSI © ETSI All rights reserved Sophia Antipolis, 22 May 2014 Luis Jorge Romero Director General, ETSI.
TEC Automobile WG. Joint Work Group Meeting.
UICC UICC is a smart card used in mobile terminals in GSM and UMTS networks It provides the authentication with the networks secure storage crypto algorithms.
Synthesis of the Eurosmart’ Technical Day on eID interoperability Bruno Rouchouze, ID SG Convenor Porvoo 12, Grosseto - Italy.
KTC, November On services and apps in IoT Mobile apps – the key interface for IoT solutions The value of IoT devices increase with the functionality.
ITEA Easy Wireless project (EW-VTT) Milla Huusko
© Copyright 2010 ecsec GmbH, All Rights Reserved. © 2013 Open eCard Team An extensible client platform for eID, signatures and more Tobias Wich, Moritz.
Registration Processing for the Wireless Internet Ian Gordon Director, Market Development Entrust Technologies.
Brussels, 1 June 2005 WP Strategic Objective Embedded Systems Tom Bo Clausen.
THE EASY WAY TO STAGE ZEBRA’S ANDROID MOBILE COMPUTERS
Supplementary to Presentation on Kiosk Services ATM System Overview TrigMax Enterprise Solutions Mason Liu, Ph.D.
1 1 Update: ISO/IEC Identification Cards - Integrated circuit cards programming interfaces Teresa Schwarzhoff, U.S. Department of Commerce Porvoo-12:
XMPP Concrete Implementation Updates: 1. Why XMPP 2 »XMPP protocol provides capabilities that allows realization of the NHIN Direct. Simple – Built on.
Near Field Communication Systems Patras, July 2006.
Leveraging UICC with Open Mobile API for Secure Applications and Services.
PC/SC Overview Christophe Colas Chairman PC/SC Technical Workgroup CTST’ 2000 Miami.
Microelectronic Systems Institute Leandro Soares Indrusiak Manfred Glesner Ricardo Reis Lookup-based Remote Laboratory for FPGA Digital Design Prototyping.
1 / Name / Date IDA Interface for Distributed Automation The journey toward Distributed Intelligence.
European Electronic Identity Practices CEN TC224 WG15 European Citizen Card Standard Speaker: L. Gaston AXALTO Date: 26 May 05.
International Automation Congress th -31 st October, 2014 The Arrowhead Framework - Future of Cooperative Automation Zsolt Szepessy, Gábor Singler,
Demonstrators and Pan-European Services Laboratory WP5 session.
Enhanced Storage Architecture
June 5 – Orlando "Writing RFID Tags" Bob Brennan Technical Evangelist Integrated Manufacturing Systems, Inc.
Michael Milgramm, CEO/CTO Donald Kovalevich, President John Fricke, VP Business Development IdentaZone, Inc © Copyright 2012 IdentaZone provides a multi-layer.
StageNow The easy way to stage Android mobile computers from Zebra Technologies.
ECOGEM Cooperative Advanced Driver Assistance System for Green Cars Burak ONUR Project Coordinator R&D Support Executive
EUCISE 2020 EUCISE 2020 has received funding from the European Union’s seventh framework programme under grant agreement no: Participating Countries:
6. Protocol Standardization for IoT 1.  TCP/IP  HTML and HTTP  The difference between the Internet and the World Wide Web The Internet is the term.
The German eID and eIDAS
IST project ePerSpace N° IST integrated project ePerSpace Contract N°: Ádám Kapovits, Eurescom 8/11/2004.
Payment and Wireless Technologies. Engineering Services. July 2015.
© 2013, published by Flat World Knowledge Chapter 10 Understanding Software: A Primer for Managers 10-1.
Internet of Things. IoT Novel paradigm – Rapidly gaining ground in the wireless scenario Basic idea – Pervasive presence around us a variety of things.
GRID ANATOMY Advanced Computing Concepts – Dr. Emmanuel Pilli.
1 © NOKIA WWRF-Reference-Framework.PPT/ 26 June 2002 / Kimmo Raatikainen WWRF Reference Framework Nokia’s Perspective WWRF WG2 Meeting 26 June 2002 Kimmo.
GP Confidential GlobalPlatform’s Modular Approach to its Compliance and certification.
Spojujeme software, technologie a služby Company Profile OKsystem Ivo Rosol Development Director
Umm… What does this anagram mean ???. N EAR F IELD C OMMUNICATION (NFC)
OUTCOMES OBJECTIVES FUNCTIONS ACTIONS TERRITORIES LOCATIONS MARKET SEGMENTS TIME LINESCHALLENGE IMPACT RESOURCESACTIVITIESCHANNELS RELATIONS PARTNERS CUSTOMERS.
EMI is partially funded by the European Commission under Grant Agreement RI Common Authentication Library Daniel Kouril, for the CaNL PT EGI CF.
HP Network and Service Provider Business Unit Sebastiano Tevarotto February 2003.
Discussion on oneM2M and OSGi Interworking Group Name: ARC Source: Jessie, Huawei, Meeting Date: Agenda Item:
ARTEMIS Industry Association Title Presentation - 1 UR:BS eUropean Renaissance: Beyond Smart cities José J. De las Heras/Miguel Peñate.
IoT R&I on IoT integration and platforms INTERNET OF THINGS
The Future Digital Identity Landscape in Europe Timothée Mangenot, chairman 14th of December, 2015 ACSIEL partners day.
© The InfoCitizen Consortium Project Presentation Agent based negotiation for inter- and intra-enterprise coordination employing a European Information.
Common Transport Rafael Schloming. Objectives Scaling Engineering Time ● N experts in protocol & language -> 1 protocol expert & N language experts ●
Preparing for the Windows 8. 1 MCSA Module 6: Securing Windows 8
Presentation transcript:

Ivo Rosol, OKsystem Middleware

Medea+ project European Smartcard Platform for Citizenship and Mobile Multimedia Applications Project Strategic Objectives: Develop complete HW/SW smart-card platform and a framework enabling the European Governments to issue interoperable documents (Citizen Card, Electronic Identity, Visas or Passport documents) for electronic identification, authentication and for access to e-Services

Consortium Manpower: 305 MY, number of partners: 17 The consortium incorporates key players from the European smart-card industry: smart-card manufacturers (Axalto, Gemplus, Oberthur CS) silicon founders (STMicroelectronics, Philips Semiconductors) electronic design companies (ID3 semiconductors) biometrics specialists (Precise Biometrics) software and services companies (OKsystem, Esterel Technologies, CompuWorx) security laboratories (CEA-Leti) consumer electronics laboratories (Innovation Lab of Philips CE).

Project Organisation Project start: April 1st, 2005, end: December 2007 Workpackage structure WP1: project management and dissemination WP2: Market and system requirements, interaction with standards, related use cases WP3: architecture and specification, determination of interoperability features WP4: technical studies WP5: infrastructure & embedded interfaces WP6: biometrics architecture & interfaces WP7: platform development WP8: Tools & methodology WP9: demonstrators

Middleware definition Middleware is key interoperability element, connecting cards, card services, card accepting devices (readers), networks and applications.

Basic design requirements Interoperability: well established standards are key drivers of interoperability. We need standards on both edges of middleware block – app side and card services edge. Easy to use: high level API for software developers, to free their hands from the dirty work with complex low level card protocols Security: end-to-end security between application and card Extensibility: Open design, 3rd party shoud be able to add support to new cards and CAD

Interoperability decisions  middleware implementation is based on the ISO emerging standard, mainly on the application interface represented by ISO  CEN TC224/WG15 ECC-2 compatible smart card is enabled to provide IAS services required by a Client Application laid on ISO Part 3 interface.

General architecture Three basic layers SAL layer based on ISO CIL internal layer for APDU generation CTL extensible card transport layer

Key features Network communication Achieved through extensible CTL layer End-to-end security architecture Application does not share encryption keys with middleware Modular CAD support Achieved by IFD implementation for secure biometric readers, VHDR contactless readers Extensible card support Feasible API implementation instead of generic APDU mapping

Service Access Layer SAL implements high level interfaces for applications (both server and local), masking complexity of lower layers – card diversity, APDUs, readers and transport mechanisms SAL API brings all selected card services to applications, including end to end security between card and application

SAL card app discovery

Card Instruction Layer CIL defines generic card API interfaces. By implementing those interfaces, any 3rd party can easily add new card into the portfolio. Implementation of API is much easier task in comparison to APDU mapping (ISO GCAL concept)

End-to end security architecture Encryption keys stay in secure HSM module and application does not share them with middleware Application need not operate on APDU level APDUs are secured before transmitting to unsecured environment

Card Transport Layer CTL define interfaces (and implements some important technologies) with respect to the transport path from the middleware to the reader and (ECC compliant) card. Implementing those interfaces, any 3rd party can easily add new transport technology and/or new reader/CAD

Card Transport Layer modules CTL uses plug-in IFD modules Built-in PC/SC module Additional modules can be implemented by 3 rd party Secure biometric reader support Contact-less reader support (NFC, VHDR...) Network reader- remote communication support

Network Stack implementation Proxy IFD module communicates with CTL Broker CTL Broker retransmits CTL calls Protocol between IFD Proxy and CTL Broker is up to the implementator

ECC-3 Annex C (normative) CENCommon.XSD CENIFD.XSD CENIFD.WSDL ECC-3 Annex B (informative) IFD-API ECC-3 Annex D (normative) IFD-API C-Language Binding - Data types definition - Status code values - C prototype of each API - utility macros Inputs to ECC-3

Inputs to ISO: IFD-API Extension of PC/SC IFD-API incorporated in ISO/IEC Networking : remote IFD-handler Management of terminals equipped with biometric sensors, accoustic unit, optical unit, display User verification Multi-slot device management

Middleware main achievements Middleware implementation follows and also provide feedback inputs to CEN TS (ECC) and ISO development Open design – 3rd party standard can easily add new cards, new readers and transport technologies Brings proof of the concept and pioneer the middleware market, based on proposed European and international standards

middleware Thank you! Ivo Rosol Development Director OKsystem