26
Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Embed Size (px)

Citation preview

Page 1: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Establishing a Digital Identity

Martin Roe - Director of Technology, Royal Mail ViaCode

Page 2: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

What’s in a name?

Page 3: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Work Health Club

Family Member

Who am I?

Citizen

Page 4: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Work Health Club

Family Member

One Signature!

Who am I?

Citizen

Page 5: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

The Signature is mineBecause I signed it!

Note that the Signature is:Perpetual (All my life)Not affected by value of the transaction

This is clearly open to Fraud:Risk can be reduced by using NotariesChecks are increased if value rises

Signing a Contract

Page 6: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Digital ID’s

Page 7: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Digital signatures are ‘One Off’Associated with a single transaction

Signatures are validated against KeysKeys need to be under tight control

Private secure/Public readily availableIssuer must maintain history/audit

Oddly, less open to fraudProcesses are tighter

Digital Signatures

Page 8: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Both Specific or General UseOther uses achievableRestricted by liabilityRestricted by law (currently)

PKI Technology MatureExtending Storage MediumPC, Smart Cards, WAP DevicesHas a full revocation method

Needs a Trusted Issuing Party

Digital Signatures

Page 9: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Examples Travel Agents Insurance Brokers Insurance Assessors Auditors

Trusted Third Parties

Page 10: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

OK; I’ve got a Digital Signature.

The world knows who I am; ViaCode have validated me!

Now, what can I use it for?

Signing Documents Digitally

Page 11: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Level Cert.Strength

Meaning

0 No Authentication Required

1 Low On Balance of ProbabilityThey are who they say they are

2 Medium ID Established to a SubstantialDegree of Assurance

3 High Identity Established Beyond aReasonable Doubt

Legal Defintions (CITU/PIU)

Page 12: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Level Cert.Strength

Authentication Method

0 No Authentication Required

1 Low On Line with Checks

2 Medium On Line with Extensive Checks

3 High Face to Face

ViaCode: Citizen Authentication

Page 13: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Level Cert.Strength

Authentication Method

0 No Authentication Required

1 Low Trusted Organisation (Agents)

2 Medium Delegated Face to Face

3 High Face to Face

ViaCode: Business Authentication

Page 14: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

PKI provides: Content Confidentiality through Encryption Content Integrity Authentication of both Parties

ViaCode: Document Exchange

Page 15: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

PKI does NOT provide: Non Repudiation; inability to deny an event Backed by a Trusted Organisation Backed by Insurance/Liability protection Backed by Audit/Forensic Evidence

ViaCode: Document Exchange

Page 16: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Send eMail/Document to Royal Mail in an Encrypted Session

Receipt Acknowledgement

ViaCode: Document Exchange

Page 17: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Royal Mail re- transmits the Document but without ‘Keys’

Opening Requests ‘Keys’?

‘Keys’ are Returned

ViaCode: Document Exchange

Page 18: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

The Originator is informed that the transaction is complete

OR

ViaCode: Document Exchange

Page 19: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

The Originator is informed that the transaction is INCOMPLETE

X

ViaCode: Document Exchange

Page 20: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

State of the Art

Page 21: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Within the Post Office..

Secure track and trace facility for selected customers

Veronica - International Services can have secure communications with their Dutch division

ViaCode: State of the Art

Page 22: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Major Reseller partnership

300,000 potential certificate holders

Secure communications between European network

Export documentation process reduced from 3 days to 3 hours with ViaCode

ViaCode: State of the Art

Page 23: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

New Second Generation Portal Launch

Portal web site with trust a key feature of differentiation

Planning for over 2 million subscribers

ViaCode certificates will secure all transactions and communications

launching summer 2000

Corporate Solution involving Royal Mail, POCL & Parcelforce

ViaCode: State of the Art

Page 24: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Operating as a reseller of ViaCode in the Channel Islands

Targeting lucrative banking, legal and finance sectors

Applications such as on line contract signing money transfer requests and insurance quotes

ViaCode: State the Art

Page 25: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Government

The e-commerce minister Patricia Hewitt MP used a ViaCode certificate in the first ever digital signing of an agreement between two European Governments(Mar 2000)

Legal Sector

8 contracts secured in March 2000 alone

ViaCode: State the Art

Page 26: Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode

Establishing a Digital Identity

Martin Roe - Director of Technology, Royal Mail ViaCode