government online copyright © 2007 credentica inc. all rights reserved. february 15th - 16th, 2007...

7
Government Online Copyright © 2007 Credentica Inc. All Rights Reserved. February 15th - 16th, 2007 Mobile Showcase

Upload: matthew-phillips

Post on 16-Jan-2016

212 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Government Online Copyright © 2007 Credentica Inc. All Rights Reserved. February 15th - 16th, 2007 Mobile Showcase

Government Online

Copyright © 2007 Credentica Inc. All Rights Reserved.

February 15th - 16th, 2007

Mobile Showcase

Page 2: Government Online Copyright © 2007 Credentica Inc. All Rights Reserved. February 15th - 16th, 2007 Mobile Showcase

2Copyright © 2007 Credentica Inc. All Rights Reserved.

Legacy Environment

Immigration Board

Treasury Board

File numberFull nameCreation dateCurrent status

UsernamePasswordFull nameAddress2003 Revenue

Page 3: Government Online Copyright © 2007 Credentica Inc. All Rights Reserved. February 15th - 16th, 2007 Mobile Showcase

3Copyright © 2007 Credentica Inc. All Rights Reserved.

GPRS

Moving to Government Online

GPRS

Treasury Board Issuing

Authority

Immigration Board

Page 4: Government Online Copyright © 2007 Credentica Inc. All Rights Reserved. February 15th - 16th, 2007 Mobile Showcase

4Copyright © 2007 Credentica Inc. All Rights Reserved.

One-Time Registration

GPRS

GPRS

Immigration Board

Treasury Board Issuing

Authority

Page 5: Government Online Copyright © 2007 Credentica Inc. All Rights Reserved. February 15th - 16th, 2007 Mobile Showcase

5Copyright © 2007 Credentica Inc. All Rights Reserved.

GPRS

Subsequent Access

GPRS

Immigration Board

Treasury Board Issuing

Authority

Page 6: Government Online Copyright © 2007 Credentica Inc. All Rights Reserved. February 15th - 16th, 2007 Mobile Showcase

6Copyright © 2007 Credentica Inc. All Rights Reserved.

Benefits to users and service providers

• SSO experience• Improved security

• No passwords / secrets over the wire• Secret keys can be stored in trusted user device

• Off-line sessions• Improved scalability and availability

• Privacy preservation• No identification at access time • No cross-linking powers

• User-authenticated audit trail• User digitally signs access requests

• No loss of autonomy/power to IdP

Page 7: Government Online Copyright © 2007 Credentica Inc. All Rights Reserved. February 15th - 16th, 2007 Mobile Showcase

7Copyright © 2007 Credentica Inc. All Rights Reserved.

Not yet implemented

• Data sharing between Service Providers• User-centric• Privacy preservation (modulo transferred attributes)

• Content signing following login• Using secret key of pseudonym used for access• Strongest protection against MITM phishing attacks

• Dual-chip enhancements• Trusted chip can handle any number of identity

assertions

• Fine-grained privilege & entitlement management

• Revoking access across Service Providers• Blacklist on basis of built-in User identifier• Blacklist even if built-in User identifier is unknown