The main purpose for the eIDAS is supporting business

27
The main purpose for the eIDAS is supporting business Michał Tabor, CISSP Trusted Information Consulting Ltd. ©Copyright 2015 Michał Tabor 1

Transcript of The main purpose for the eIDAS is supporting business

Page 1: The main purpose for the eIDAS is supporting business

©Copyright 2015 Michał Tabor 1

The main purpose for the eIDAS is supporting business

Michał Tabor, CISSPTrusted Information Consulting Ltd.

Page 2: The main purpose for the eIDAS is supporting business

Motivation

One slide presented on #CA-Day 9.06.2015 by Andrea Servida

What eIDAS is about?

Page 3: The main purpose for the eIDAS is supporting business

Slide from Andrea Servida presentation – 9.06.2015

Page 4: The main purpose for the eIDAS is supporting business

©Copyright 2015 Michał Tabor

How to support business?

Help to deliver convenient and usable services to customers

Page 5: The main purpose for the eIDAS is supporting business

©Copyright 2015, PIIT & Michał Tabor

52015-06-11

Page 6: The main purpose for the eIDAS is supporting business

6

#eIDAS Trust Service

Trust Service

creation

certification

verification

validation

preservation

delivery

combination of trust servies

provided for remuneration

©Copyright 2015 Michał Tabor

Page 7: The main purpose for the eIDAS is supporting business

Business process

Securing transactions

Employee - consultant

Employer

Need of contract

Trustworthy contract

1. eSignature

2. Registred

Delivery

6. Archive

placement

3. Bank a

ccount

confirm

ation

4. SMS

Authentication

5. Regis

tred

Delivery

Trust Service

©Copyright 2015 Michał Tabor

Page 8: The main purpose for the eIDAS is supporting business

Trustworthy document

Trust Service

EvidenceElectronic Identification

Evidence

Trust Service creates evidence

Page 9: The main purpose for the eIDAS is supporting business

ElectronicSignature

ElectronicSeal

Evidence Protection

Means

Page 10: The main purpose for the eIDAS is supporting business

eIDAS opportunity

Electronic Signature

Electronic Seal

Page 11: The main purpose for the eIDAS is supporting business

Electronic signature

Used to protect evidence created by humans

Page 12: The main purpose for the eIDAS is supporting business

Electronic signature

Evidence from systems is signed by the people to protect origin

Page 13: The main purpose for the eIDAS is supporting business

Electronic seal

Evidence from systems is sealed automatically to protect origin

Page 14: The main purpose for the eIDAS is supporting business

Electronic signature

Evidence from systems is signed by the people to protect origin

Page 15: The main purpose for the eIDAS is supporting business

Electronic seal

Evidence from systems is sealed automatically to protect origin

Page 17: The main purpose for the eIDAS is supporting business

Electronic seal protects evidence from trust services

EVIDENCE

Qualified Seal

QTScreation

QTSvalidation

QTSpreservation

QTSdelivery

Certification Sig or Seal

QTSverification

Page 18: The main purpose for the eIDAS is supporting business

18

Creator of an Electronic Seal

Legal person creates eSeal

Creator with eSeal guarantees authenticity of evidence

Seal proves integrity of sealed evidence

eSEAL creating data must remain under control of a creator

eIDAS doesn’t specify how controls should be implemented

Page 19: The main purpose for the eIDAS is supporting business

Seal creation data „sole control” models

• Sealing is on own site• Full control over sealing device

Creator of the seal owns sealing device

• Device secured for sealing• Policy determines what is sealed

Creator of the seal distributes his sealing device

Page 20: The main purpose for the eIDAS is supporting business

20

Device

Sealing Device

Evidence: What

Evidence: When

Evidence: Where

Document

Event

Evidence

Creator of a seal – takes responsibility for a evidence

prepared by device

ElectronicSeal created by manufacturer✔

Page 21: The main purpose for the eIDAS is supporting business

21

#insurance case

Captured photo

GPS Time

GPS Localization

Collecting evidence of an accident

TIMEPLACE

Page 22: The main purpose for the eIDAS is supporting business

22

Evidence – Handwritten

document

Time

Hand signature

Document

Handwritten signature

Handwritten signature secured with electronic seal

Page 23: The main purpose for the eIDAS is supporting business

Expected documentation

Trust Service

EvidenceElectronic Identification

Page 24: The main purpose for the eIDAS is supporting business

24

Electronic Sealprotects evidence

Page 25: The main purpose for the eIDAS is supporting business

Let’s accept in public services

electronic documents resulting from various trust services and secured by qualified electronic seal

Public service

Qualified Seal

Qualified Signature

Trust Service

Start

Page 26: The main purpose for the eIDAS is supporting business

©Copyright 2015, PIIT & Michał Tabor

262015-06-11

Trust Service

USER Service

Trust service is a gateway between user and service

(commercial or public)

BusinessSupport

Page 27: The main purpose for the eIDAS is supporting business

27

Michał Tabor

[email protected]: @michal_tabor

Trusted Information Consulting Ltd. is the member of Polish Chamber of Information Technology and Telecommunications

The main purpose for the eIDAS is supporting

business