20
Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Embed Size (px)

Citation preview

Page 1: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Evolution in cross-border interoperability

of eSignatures and eID

Tarvi MartensSK, Estonia

Page 2: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Let’s read the title again!

• “Evolution in cross-border interoperability of eSignatures and eID”

• Prerequisites:• eID

• eSignature• Evolution• Cross-border interoperability

Page 3: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

European eID

landscape

Page 4: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

eSignature landscape

Page 5: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Summary of current situation

• eID deployment:• Some countries are leading• Some countries have “odd” solutions and/or are

stalled• Number of countries have plans• Number of countries do not even have a plan• Deployment: 5-10 years

• eSignature practice:• Used mostly in closed systems• No common understanding of “free-flowing

digitally signed file”

Page 6: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Use of eID & eSignature in Estonia

• ID-card launched 6 years ago• Rollout “completed”, 1M+ cards out• Common system for eSignatures, widely accepted and

deployed for 5+ years• All major e-services support ID-card• Internet voting deployed...• ~80 000 users

Page 7: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Cross-border interoperability

• eID uptake low• Even worse with eSignatures• <1% of transactions cross-border

Cross-border interoperability ???

Page 8: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Manchester declaration

• By 2010 European citizens and businesses shall be able to benefit from secure means of electronic identification that maximise user convenience while respecting data protection regulations.

• By 2010 Member States will have agreed a framework for reference to and where appropriate the use of authenticated electronic documents across the EU, as appropriate in terms of necessity and applicable law

Page 9: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

The road to Nirvana i2010

Page 10: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Drivers behind interop

• Political• eProcurement• Service Directive

• Business• eBanking etc.

• General• Common understanding of digital signature• Standardization in industry (cards, tools etc.)

Page 11: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Evolution: yes!

• Technically repeatedly piloted• IDABC Bridge/Gateway v.1.• European Bridge-CA (TeleTrust, Germany)• Euro-PKI, GUIDE, ...• openvalidation.org

• Initatives to be observed today• De Norske Veritas e-notary service• Spanish eGov Validation Gateway• eApostille• Upcoming IDABC Bridge/Gateway v.2.• Upcoming eID Large Scale Project

Page 12: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Organizational issues

• Paper-ID interoperability works!• Miracles happen in border points

• Organizational set-up of Paper-ID interop:• ICAO sets standards• Continuous information exhange by network of MoIA-

s to the borderguards etc.• Organizational set-up of eID interop ???

• Standards are not strict and not imposed• Continuous information exhange is missing

completely

Page 13: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Need for (foreign) eID info

• Collecting and managing eID/service info is a daily job, not project-based

• What info is needed ?• Certificate validity (reference)• Certificate semantics• Certificate quality (!!!)

• Hardware token vs. software certificate• Quality of service provider & certificate• Context of certificate issuance• ......

Page 14: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Handling foreign eID

Certification & validation service providers

“Identity hub”

Certificate quality /semantics / validity

ServiceProvider

“What certificateis that?”

foreign user

Page 15: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

eSignature handling

Certification & validation service providers

“Identity hub”

Certificate quality /semantics / validity

“E-notary”“What certificate

is that?”

Digital signingsoftware providers

“translation” and assessment

“What documentis that?”

Page 16: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Who will run the Indentity Hub ?

• EC does not have mandate (yet)• Single MS cannot afford it (to cover all Europe/World)

• No actual demand (read: need covered with money)• Low volume of international transactions• Uptake of national eID-s is still underway

• We need clear political agreement to create such a service in EU level

• In future we can envisage situation where every MS runs its own “e-borderguard”

Page 17: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

The Other Direction - Harmonization

• Standardization• European Citizen Card (ECC)• Common middleware

• OpenSC• Windows Vista plug-and-play for smartcards

• Various approaches and initiatives to solve differences in middleware layer

Page 18: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Legal problems

• There is no eAuthentication Directive• National legislations hardly touch the subject

• SP: “Who to sue if I will make wrong assessment on certificate inheritance/validity ?”

Page 19: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Bottom Line

• We need to create and distribute eID-s first• Preferably PKI-based qualified certificates

• Then teach holders of eID-s to use them• Estonian case: penetration ≠ usage

• But interop shall be addressed NOW• Withouht vision, political will and hard work there

would never been such thing as EU

Page 20: Evolution in cross-border interoperability of eSignatures and eID Tarvi Martens SK, Estonia

Thank You!

[email protected]