Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington -...

32
Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th , 2010 Frank LEYMAN © fedict 2010. All rights reserved
  • date post

    19-Dec-2015
  • Category

    Documents

  • view

    216
  • download

    1

Transcript of Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington -...

Page 1: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience

Washington - September 27th, 2010

Frank LEYMAN

© fedict 2010. All rights reserved

Page 2: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Citizen CentricityCOMM

ON BACK-OFFICE

COMMON

PROCESS FLOW

COMMON KEY

MODULES

E-APPLICATIONS

TOOLS

MandatesAt

tribu

tes

Deleg

atio

n

Roles

© fedict 2010. All rights reserved

Page 3: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

ONE COMMON BACK-OFFICE

© fedict 2010. All rights reserved

Page 4: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

SECURITY LAYER

…Ministr

yA

MinistryB

MinistryC

MinistryZ

FEDMANFederal Service Bus

National Portal Website

Building Blocks

© fedict 2010. All rights reserved

Page 5: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

ONE UNIQUE ELECTRONIC KEY: THE BELGIAN eID

© fedict 2010. All rights reserved

Page 6: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Electronic identity card (eID)

Children <12 years old

Foreign residents

Belgian citizens >12 years old

© fedict 2010. All rights reserved

Page 7: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

eID Security

© fedict 2010. All rights reserved

Page 8: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

eID Digital Information

Use without PIN

IDID ADDRESSADDRESS

RRN SIGN

RRN SIGN

RRN SIGN

RRN SIGN

IDENTITY“PIN

protected”

authentication

digital signature

PKI

privatepublic

privatepublic

© fedict 2010. All rights reserved

Page 9: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

LOTS OF e-APPLICATIONS

© fedict 2010. All rights reserved

Page 10: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Lots of applications of the eID card

student cards

Healthcare

e-commerce

Driver’s license

Proof of membership

SSO, etc.

Home banking

© fedict 2010. All rights reserved

Page 11: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Vending machines

No alcohol under 18 year...

© fedict 2010. All rights reserved

Page 12: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Lots of TOOLS at your disposal

© fedict 2010. All rights reserved

Page 13: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Quick Install

1. Install the eID software

2. Connect the card reader to the computer

3. Consult your data

© fedict 2010. All rights reserved

Page 14: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

http://www.belgium.be

© fedict 2010. All rights reserved

Page 15: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

05/05/2009 | Bruxelles

Direct access to more than70 on-line transactions

Page 16: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

eID Middleware Reading of the data – Certificates - Card & PIN

© fedict 2010. All rights reserved

Page 17: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

https://mondossier.rrn.fgov.be

© fedict 2010. All rights reserved

Page 18: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

www.checkdoc.be A website to verify whether Belgian identity documents are valid or

not: passport identity card residence permit with chip

Registration the first time

Sources authentiques

© fedict 2010. All rights reserved

Page 19: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Fiscality

© fedict 2010. All rights reserved

Page 20: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

More Information?

>www.eid.belgium.be

© fedict 2010. All rights reserved

Page 21: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

http://map.eid.belgium.be

© fedict 2010. All rights reserved

Page 22: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Lots of MODULES at your disposal

© fedict 2010. All rights reserved

Page 23: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

MODULES FAS:

Federal Authentication Service via eID

e-LOKET: Tool to allow municipalities to offer electronic services to its citizen in a secure way

e-DEPOT: Service to allow notaries to faster register acts

PersonService: Webservice to allow fast query about physical persons in the public registers

DIGIFLOW: User interface the Public Sector uses to get access to the FSB

IAM: Identity and Access Management

MAGMA: Delegation of powers between two legal entities in order to allow the second to operate

on-line transactions in the name of the first (accountants, social reprenstatives, ...)

e-PAYMENT: Service package to allow public authorities to introduce electronic transactions

© fedict 2010. All rights reserved

Page 24: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Standard usageStandard Process Flows

© fedict 2010. All rights reserved

Page 25: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Standard approach

WEB

FSB

FEDMAN network

Authentic Sources

© fedict 2010. All rights reserved

Page 26: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Example1: citizen files a complaint “theft”

e-FORM

FAS

FSB

Police

Ticket #

Push

e-LOKET

© fedict 2010. All rights reserved

Page 27: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Future developments

© fedict 2010. All rights reserved

Page 28: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Identity and Access Management

IDENTITY

NAME

DATE of BIRTH

PLACE of BIRTH

GENDER

ADDRESS

NATIONALITY

FAMILY STATUS

CEO of COMPANY

LAWYER

FATHER

MEMBER OF SERVICE CLUB

ACCOUNTANT

MEMBER of BOARD

SOCIAL SECURITY

DRIVING LICENSE

© fedict 2010. All rights reserved

Page 29: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

This is for Belgium, but what about the rest of Europe?

© fedict 2010. All rights reserved

Page 30: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

SECURITY LAYER

FEDMANFederal Service Bus

National Portal Website

…MinistryA

MinistryB

MinistryC

MinistryZ

Gateway to EU

Region A

Region B

Region C

Region Z

Municipality A

Municipality B

Municipality C

Municipality Z

……

Country1

Country2

Country3

CountryX

© fedict 2010. All rights reserved

Page 31: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Room for improvement...

Communication & Education

Card readers

Prices of internet

Prices of PC’s

# of Applications

http://welcome-to-e-belgium.be/en/

© fedict 2010. All rights reserved

Page 32: Designing and Implementing Secure ID Management Systems: BELGIUM’s Experience Washington - September 27 th, 2010 Frank LEYMAN © fedict 2010. All rights.

Th@nk you!

FRANK LEYMANManager International Relations

Maria-Theresiastraat 1/3Bruxelles 1000 Brussel

TEL +32 2 212 96 24FAX +32 2 212 96 99

[email protected]

www.belgium.be/fedict

© fedict 2010. All rights reserved