new opportunities for trust services in eu #eidas

26
New opportunities for Trust Services in EU Michał Tabor, CISSP Expert of PIIT in the identification, authentication and electronic signature 05.06.2014 © 2014, PIIT & TICons 1

Upload: michal-tabor

Post on 28-Nov-2014

863 views

Category:

Technology


2 download

DESCRIPTION

New eIDAS regulation opens discussion about Trust Services

TRANSCRIPT

Page 1: New opportunities for Trust Services in EU #eIDAS

New opportunities for Trust Services in EU

Michał Tabor, CISSP

Expert of PIIT in the identification, authentication and electronic signature

05.06.2014 © 2014, PIIT & TICons

1

Page 2: New opportunities for Trust Services in EU #eIDAS

05.06.2014 © 2014, PIIT & TICons

2

Electronic identification and trust services for electronic transactions in the internal market

European Parliament legislative resolution of 3 April 2014 on the proposal for a regulation of the European Parliament and of the Council on electronic identification and trust services for electronic transactions in the internal market (COM(2012)0238 – C7-0133/2012 – 2012/0146(COD))

Page 3: New opportunities for Trust Services in EU #eIDAS

eIDAS means

05.06.2014 © 2014, PIIT & TICons

3

electronic identification

electronic signature

electronic seal

trust service electronic time

stamp

electronic registered delivery

service

qualified certificate for

website authentication

Page 4: New opportunities for Trust Services in EU #eIDAS

eIDAS Services

05.06.2014 © 2014, PIIT & TICons

4

electronic identification

electronic signature

• Creation

• Verification

• Validation

• Certificate services

electronic seal

• Creation

• Verification

• Validation

• Certificate services

trust service

electronic time stamp

• Creation

• Verification

• Validation

• Certificate services

electronic registered delivery service

qualified certificate for website authentication

• Creation

• Verification

• Validation

Page 5: New opportunities for Trust Services in EU #eIDAS

Trust Service definition

(16) 'trust service' means an electronic service normally provided for remuneration which consists in:

a) the creation, verification, and validation of electronic signatures, electronic seals or electronic time stamps, electronic registered delivery services and certificates related to these services or

b) the creation, verification and validation of certificates for website authentication or

c) the preservation of electronic signatures, seals or certificates related to these services;'

05.06.2014 © 2014, PIIT & TICons

5

Page 6: New opportunities for Trust Services in EU #eIDAS

#eIDAS Trust Service

Trust Service

creation

certification

verification validation

preservation

delivery

05.06.2014 © 2014, PIIT & TICons

6

provided for remuneration

Page 7: New opportunities for Trust Services in EU #eIDAS

Defining trust services

• (25) Member States should remain free to define other types of trust services in addition to those making part of the closed list of trust services provided for in this Regulation, for the purpose of recognition at national level as qualified trust services

05.06.2014 © 2014, PIIT & TICons

7

Page 8: New opportunities for Trust Services in EU #eIDAS

#eIDAS Trust Service

Trust Service

creation

certification

verification

validation

preservation

delivery

combination of trust servies

05.06.2014 © 2014, PIIT & TICons

8

provided for remuneration

Page 9: New opportunities for Trust Services in EU #eIDAS

Business process

Securing transactions

Employee - consultant

Employer

Need of contract

Trustworthy contract Trust Service

Page 10: New opportunities for Trust Services in EU #eIDAS

Cloud of Trust

Evidence

Risk mitigation

User Commitment

Verification Authorization Confirmation

User Authentication

eSignature

Trust

Security

Workflows User needs

Page 11: New opportunities for Trust Services in EU #eIDAS

Cloud of Trust

Evidence

Risk mitigation

User Commitment

Verification Authorization Confirmation

User Authentication

eSignature

Trust

Security

Workflows User needs

TRUST SERVICE

WORKFLOW

SIGNATURE SERVICE

TRUSTED REPOSITORY

CONTROLS SERVICE

ATTRIBUTE SERVICES

CERTIFICATE AUTHORITY

Page 12: New opportunities for Trust Services in EU #eIDAS

Trust service

05.06.2014 © 2014, PIIT & TICons

12

WORKFLOW

creation

certification

verification

validation

preservation

delivery

Identification

Authentication

Authorization

Atributes

Information

PROOF OF TRUST

SEAL

Page 13: New opportunities for Trust Services in EU #eIDAS

05.06.2014 © 2014, PIIT & TICons

13

certification

verification

validation

preservation

delivery

EVIDENCE

EVIDENCE

EVIDENCE

EVIDENCE

EVIDENCE

EVIDENCE

EVIDENCE

WORKFLOW

creation

Trust service Evidence gathering

Page 14: New opportunities for Trust Services in EU #eIDAS

TRUST SERVICES

05.06.2014 © 2014, PIIT & TICons

14

Page 16: New opportunities for Trust Services in EU #eIDAS

Signature on demand

Identification

Authentication

Attributes

• Time

• External confirmations Signed document

05.06.2014 © 2014, PIIT & TICons

16

Bank account

Cell phone

Corporate systems

Insurance …

WORKFLOW

creation

certification

verification

validation

preservation

delivery

Page 18: New opportunities for Trust Services in EU #eIDAS

Synchronised signature

Document Synchronization Dissemination

05.06.2014 © 2014, PIIT & TICons

18

Signatory A

Signatory B

WORKFLOW

creation

certification

verification

validation

preservation

delivery

Page 20: New opportunities for Trust Services in EU #eIDAS

Business contracts trust service

05.06.2014 © 2014, PIIT & TICons

20

DOCUMENT

Sign

Final contract version

EVIDENCE

SEAL

Contract version…

Contract version…

Contract version…

Contract version…

WORKFLOW

creation

certification

verification

validation

preservation

delivery

Page 22: New opportunities for Trust Services in EU #eIDAS

Smart Paper

05.06.2014 © 2014, PIIT & TICons

22

DOCUMENT

Sign

VISUALIZATION

SEAL

WORKFLOW

creation

certification

verification

validation

preservation

delivery REPOSITORY Preservation

Delivery

Page 26: New opportunities for Trust Services in EU #eIDAS

26

Q&A

Michał Tabor

Trusted Information Consulting Ltd.

[email protected]

www.ticons.pl

Twitter: @michal_tabor

05.06.2014 © 2014, PIIT & TICons

Trusted Information Consulting Ltd. is the member of Polish Chamber of Information Technology and Telecommunications