Top Banner
SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue: SWEB Day in APV, Novi Sad Author(s): Dr. Milan Marković Organisations: MISANU Belgrade Date: 26/03/2009
12

SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

Jan 04, 2016

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEBSWEB Security and Privacy Technologies –

Implementation Aspects

Venue: SWEB Day in APV, Novi Sad

Author(s): Dr. Milan Marković

Organisations: MISANU Belgrade

Date: 26/03/2009

Page 2: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEBSWEB user types

JAVA mobile client

.NET mobile client

SELIS client

Civil Servant client

Page 3: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEBSecurity of communications between the client and SWEB platform

XML signature

Time Stamping

SAML token

WS-Security (WS-Encryption and/or WS-Signature)

Page 4: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEBUser authentication and authorization

Username/password to access the client application and

asymmetric private key

User’s digital certificate to be authenticated by the STS server

SAML token issued to the user for authentication to the particular

service

User profile (digital certificate) for user authorization to the platform

Page 5: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEBSecure communication between two SWEB platforms

Digital certificate for authentication to the STS server

SAML token for authentication to the service

User’s profile (digital certificate) for user authorization

Page 6: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEBIdentities of users

Digital certificates

PKI hierarchy

XKMS for certificate locating (LocateRequest) and

validating (ValidateRequest)

Page 7: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEB

Page 8: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEB

Page 9: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEB

The Residence Certification Service Cross-Border request scenario

Page 10: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEBSWEB Security Aspects Summary

X.509 certificate XML Digital Signatures and Encryption WS-security Time stamping Federation Identity - Security Token (SAML) XKMS Smart cards for Civil Servants Future upgrade include PKI SIM cards

Page 11: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEBFuture research directions

Implementing JAVA mobile application into the JAVA CDC 1.1 enabled mobile devices

Full implementation of advanced electronic signature formats (e.g. XAdeS)

Integration of PKI SIM technology in the Mobile Client application

Using SWEB-like system for other PKI based e/m-governmental services (strong user authentication to other e-gov web portals, signing documents prepared through some other communication channels, qualified signatures, etc.)

Page 12: SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.

SWEBSWEB

Thank You!!