sweb security and privacy technologies – implementation aspects

12
SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue: SWEB Day in APV, Novi Sad Author(s): Dr. Milan Marković Organisations: MISANU Belgrade Date: 26/03/2009

Upload: lydia-landry

Post on 01-Jan-2016

30 views

Category:

Documents


4 download

DESCRIPTION

SWEB Security and Privacy Technologies – Implementation Aspects. Venue: SWEB Day in APV, Novi Sad Author(s): Dr. Milan Marković Organisations: MISANU Belgrade Date: 26 /0 3 / 20 0 9. SWEB user types. JAVA mobile client .NET mobile client SELIS client Civil Servant client. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEBSWEB Security and Privacy Technologies –

Implementation Aspects

Venue: SWEB Day in APV, Novi Sad

Author(s): Dr. Milan Marković

Organisations: MISANU Belgrade

Date: 26/03/2009

Page 2: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEBSWEB user types

JAVA mobile client

.NET mobile client

SELIS client

Civil Servant client

Page 3: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEBSecurity of communications between the client and SWEB platform

XML signature

Time Stamping

SAML token

WS-Security (WS-Encryption and/or WS-Signature)

Page 4: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEBUser authentication and authorization

Username/password to access the client application and

asymmetric private key

User’s digital certificate to be authenticated by the STS server

SAML token issued to the user for authentication to the particular

service

User profile (digital certificate) for user authorization to the platform

Page 5: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEBSecure communication between two SWEB platforms

Digital certificate for authentication to the STS server

SAML token for authentication to the service

User’s profile (digital certificate) for user authorization

Page 6: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEBIdentities of users

Digital certificates

PKI hierarchy

XKMS for certificate locating (LocateRequest) and

validating (ValidateRequest)

Page 7: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEB

Page 8: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEB

Page 9: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEB

The Residence Certification Service Cross-Border request scenario

Page 10: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEBSWEB Security Aspects Summary

X.509 certificate XML Digital Signatures and Encryption WS-security Time stamping Federation Identity - Security Token (SAML) XKMS Smart cards for Civil Servants Future upgrade include PKI SIM cards

Page 11: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEBFuture research directions

Implementing JAVA mobile application into the JAVA CDC 1.1 enabled mobile devices

Full implementation of advanced electronic signature formats (e.g. XAdeS)

Integration of PKI SIM technology in the Mobile Client application

Using SWEB-like system for other PKI based e/m-governmental services (strong user authentication to other e-gov web portals, signing documents prepared through some other communication channels, qualified signatures, etc.)

Page 12: SWEB Security and Privacy  Technologies – Implementation Aspects

SWEBSWEB

Thank You!!