<?xml version="1.0" encoding="UTF-8"?><feed
xmlns="http://www.w3.org/2005/Atom"
xmlns:thr="http://purl.org/syndication/thread/1.0"
xml:lang="en"
xml:base="http://mysuisseid.net/blog/wp-atom.php"
><title
type="text">mySuisseID experience &#187;  | mySuisseID experience</title> <subtitle
type="text">know who you&#039;re dealing with... &#124; savoir à qui on a affaire... &#124; wissen mit wem mann zu tun hat...</subtitle><updated>2011-03-07T15:51:50Z</updated><link
rel="alternate" type="text/html" href="http://mysuisseid.net/blog" /> <id>http://mysuisseid.net/blog/feed/</id><link
rel="self" type="application/atom+xml" href="http://mysuisseid.net/blog/feed/" /><generator
uri="http://wordpress.org/" version="3.1">WordPress</generator> <entry> <author> <name>Tito Espinoza</name> </author><title
type="html"><![CDATA[Plan your SuisseID implementation carefully]]></title><link
rel="alternate" type="text/html" href="http://mysuisseid.net/blog/suisseid/organiser-deploiement-suisseid/" /> <id>http://mysuisseid.net/blog/?p=175</id> <updated>2011-02-21T21:15:11Z</updated> <published>2011-02-19T09:35:16Z</published> <category
scheme="http://mysuisseid.net/blog" term="Process" /><category
scheme="http://mysuisseid.net/blog" term="SuisseID" /> <summary
type="html"><![CDATA[<p><p><a
href="http://mysuisseid.net/blog">mySuisseID experience - know who you&#039;re dealing with... | savoir à qui on a affaire... | wissen mit wem mann zu tun hat...</a></p><p>Success factors for the implementation of SuisseID in an existing environment</p></p><p><a
href="http://mysuisseid.net/blog/suisseid/organiser-deploiement-suisseid/">Plan your SuisseID implementation carefully</a></p>]]></summary> <content
type="html" xml:base="http://mysuisseid.net/blog/suisseid/organiser-deploiement-suisseid/"><![CDATA[<p><a
href="http://mysuisseid.net/blog">mySuisseID experience - know who you&#039;re dealing with... | savoir à qui on a affaire... | wissen mit wem mann zu tun hat...</a></p><p>The  implementation of SuisseID in your existing infrastructure is not just a  technical challenge. It may also require thorough analysis and re-definition of your identity management and authentication processes. It&#8217;s an objective that calls for carefull reflection and thinking.  It  can be vital to overcome the psychological barrier of accepting a third party like &#8220;La Poste&#8221;, &#8220;Swisscom&#8221; or &#8220;QuoVadis&#8221; to take the role of trusted supplier;  any such change is worthy to be addressed from the outset in order to avoid any misunderstanding.</p><blockquote><p>&#8220;The implementation of SuisseID in your infrastructure is not just a technical challenge. The fundamental changes are worthy to be addressed from the outset in order to avoid any misunderstanding!&#8221;</p></blockquote><h1>Process</h1><p>The pivot of the SuisseID process is the proper identification and  authentification of the &#8220;to-be&#8221; holder of the certificate by a <a
title="Certificate Authority on Wikipedia" href="http://en.wikipedia.org/wiki/Certificate_authority" target="_blank">Certificate Authority (CA)</a>.</p><div
id="attachment_207" class="wp-caption alignleft" style="width: 220px"><a
href="http://mysuisseid.net/blog/wp-content/uploads/2011/02/SuisseID-chip.jpg"><img
class="size-full wp-image-207 " title="SuisseID-chip" src="http://mysuisseid.net/blog/wp-content/uploads/2011/02/SuisseID-chip.jpg" alt="" width="210" height="207" /></a><p
class="wp-caption-text">SuisseID - Card with chip</p></div><p>In the case of the Swiss Post (&#8220;La Poste&#8221;) the CA is their daughter company <a
title="X509 Certificate - (Certificate Authorities)" href="https://www.globaltrustpoint.com/x509/x509trustcenter_list.jsp#52" target="_blank">SwissSign</a>. They rely on two elements to be able to issue a certificate.</p><p>One the one hand is the employee at your local post office that checks the presented ID for validity, verifies the match with the person in front (photo) and makes a copy  thus certifying the authenticity (and therefore trustworthiness) of the copy. This service is know as their <a
title="Link to the Yellow ID product as offer by the Swiss Post" href="http://www.post.ch/en/post-startseite/post-privatkunden/post-einkaufen/post-spezialangebote/post-gelbeid/post-leitfaden-gelbeid.htm">&#8220;yellow ID&#8221;</a> product.  Other parties that can certify authenticity of a proof of identity are notaries or local councils. Alternatively you can have one or several employees trained and certified for this role within your organisation (<a
title="Documentation as found in an offer from the Swiss Post" href="http://mysuisseid.net/blog/wp-content/uploads/2011/02/Post-SuisseID-Identifikationsprozess-DE.pdf" target="_blank">ID @ Office</a>, point 3.2.2.3 (only available in German). Once this identification has been carried out, the user&#8217;s documentation will allow them to submit their forms and apply for a SuisseID.</p><p>One the other hand we see the SwissSign employee that receives and treats each request in combination with the authenticated ID copy.  A subset of the personal data from the identification document (e.g. a passport) is stored in the identity provider service (IDP) operated by the Certificate Authority. The only way to retrieve that data is by <a
href="http://en.wikipedia.org/wiki/Strong_authentication">strong authentication</a> with the IDP using the appropriate SuisseID authentication certificate; They make sure that only trusted (i.e. attributes that are present on the ID) are registered as <a
title="Link to posting on attributes" href="http://mysuisseid.net/blog/2011/02/suisseid-une-etape-en-avant#tab1" target="_self">attributes</a> of the client. In the end a client receives a card with a chip and a (USB or external) card reader.</p><p>With the SuisseID standard this chip contains two certificates; one certificate for the purpose of authentication and one certificate for the use signing electronically. Both certificates only contain the bare minimum of personal information on the chip, but all  information that is available through the IDP will be based strictly on the information from the Passport or Identity card.</p><blockquote><p>&#8220;SuisseID for your access management is like integrating an electronic passport in your authentification processes.&#8221;</p></blockquote><p>Implementation of SuisseID in your corporate environment is like integrating an electronic passport in your authentication procedure. This passport is issued and guaranteed by a third party who can vouch for the validity of the information contained therein. Hence the importance of accepting this third party as a trusted body.</p><p>In the case of &#8220;La Poste&#8221; the  yellow identification with its certified copy lies at the heart of the trusted third party principle, by which many different atributes like names, surname and date of birth are validated and  integrated into the database of the SuisseID IDP.</p><h1>Some more about technical principles</h1><p>From  a technical standpoint, the <a
title="If you want to implement SuisseID for logon for your staff in your business systems? Here you will find a document (white paper) describing how to integrate the SuisseID in a Microsoft Active Directory." href="http://www.suisseid.ch/unternehmen/technik/unterstuetzung/index.html?lang=fr&amp;download=NHzLpZeg7t,lnp6I0NTU042l2Z6ln1ae2IZn4Z2qZpnO2Yuq2Z6gpJCDdIJ8f2ym162epYbg2c_JjKbNoKSn6A--" target="_blank">implementation of SuisseID in the company infrastructure</a> uses the application programming interfaces (APIs) by which it is possible to connect <a
title="The SuisseID SDK/Java offers an easy to use API for securely integrating applications with the SuisseID core infrastructure. This document will to get you started with the usage of the SDK/Java." href="http://www.e-service.admin.ch/wiki/display/suisseid/Users+Guide" target="_blank">programmatically</a>. These  APIs are documented, and architects can specify the requests  needed to be made to the Identity Providers (IDP), in order to technically implement the SuisseID in the identity management and authentication mechanisms of the company.</p><p>But  although technical aspects define constraints and a framework within which identity management and authentication must take place,  the level of usability should be prioritized. Particularly  in the context of a company having its own identity repository (eg.  centralized directory), it will be necessary to define the levels of  integration between the existing identities repository and the external IDPs, to specify access to various IT-resources or programs as linked to each identity.</p><p>This is why in the analysis phase it is important to anticipate on some of the following processes:</p><ul><li>Set the necessary attributes of your digital identity &#8211; the SuisseID proposes <a
href="http://mysuisseid.net/blog/suisseid/suisseid-une-etape-en-avant/#tab1">15 attributes</a> as a &#8220;standard&#8221; set.</li><li>Define the process for the creation of an identity with SuisseID.</li><li>If you have existing electronic identities, it might be worthwhile to define the process of linking the existing authentication with the SuisseID authentication. This is the case of a company that already offers online services and has defined its own identity management processes.</li><li>In the case of SuisseID connection with existing identities, it might also be worth to define a process for unlinking a SuisseID authentication in order to  allow authentication mechanisms as initially implemented without SuisseID.</li><li>Define the various user authentication mechanisms to access online  services: uniquely SuisseID or maintain multiple mechanisms &#8211; as  SuisseID is currently not yet sufficiently widespread, the company might focus  instead on maintaining several authentication mechanisms.</li><li>Establish a process for releasing the SuisseID &#8211; it is possible to use the process defined by the IDP.</li><li>Define an identity process and association rules in relation to existing business repositories.</li><li>Manage the exceptions to identities association rules.</li></ul><p>As  can be seen from the not exhaustive list of processes above, the analysis will require  a great deal of attention, especially since SuisseID is still a young  solution providing significant potential for organizational  simplification. It does also still leaves open many  questions without  clear answers from the IDP;  it allows room for interpretation and provides options for each implementator to create its own solution related to its  own needs.</p><blockquote><p>Liked this post? <a
href="http://feeds.feedburner.com/MysuisseidExperience">Subscribe to our RSS feed</a> and get loads more!</p></blockquote><p><a
href="http://mysuisseid.net/blog/suisseid/organiser-deploiement-suisseid/">Plan your SuisseID implementation carefully</a></p>]]></content><link
rel="replies" type="text/html" href="http://mysuisseid.net/blog/suisseid/organiser-deploiement-suisseid/#comments" thr:count="0"/><link
rel="replies" type="application/atom+xml" href="http://mysuisseid.net/blog/suisseid/organiser-deploiement-suisseid/feed/" thr:count="0"/> <thr:total>0</thr:total> </entry> <entry> <author> <name>Jan-Paul Theunissen</name> </author><title
type="html"><![CDATA[SuisseID, one step at a time]]></title><link
rel="alternate" type="text/html" href="http://mysuisseid.net/blog/suisseid/suisseid-une-etape-en-avant/" /> <id>http://mysuisseid.net/blog/?p=10</id> <updated>2011-03-07T15:49:45Z</updated> <published>2011-02-03T22:13:12Z</published> <category
scheme="http://mysuisseid.net/blog" term="Customer attributes" /><category
scheme="http://mysuisseid.net/blog" term="Electronic Identity" /><category
scheme="http://mysuisseid.net/blog" term="Electronic Signature" /><category
scheme="http://mysuisseid.net/blog" term="PKI" /><category
scheme="http://mysuisseid.net/blog" term="SuisseID" /><category
scheme="http://mysuisseid.net/blog" term="X.509" /> <summary
type="html"><![CDATA[<p><p><a
href="http://mysuisseid.net/blog">mySuisseID experience - know who you&#039;re dealing with... | savoir à qui on a affaire... | wissen mit wem mann zu tun hat...</a></p><p>In this article we discuss how SuisseID can help using a standard authentification process over the Internet for bespoke needs. The common attributes as well as organisation specific attributes are discussed and an idea is launched for using SuisseID in a medical process.</p></p><p><a
href="http://mysuisseid.net/blog/suisseid/suisseid-une-etape-en-avant/">SuisseID, one step at a time</a></p>]]></summary> <content
type="html" xml:base="http://mysuisseid.net/blog/suisseid/suisseid-une-etape-en-avant/"><![CDATA[<p><a
href="http://mysuisseid.net/blog">mySuisseID experience - know who you&#039;re dealing with... | savoir à qui on a affaire... | wissen mit wem mann zu tun hat...</a></p><p><strong>A journey of a thousand miles begins with a single step.</strong> <a
href="http://www.suisseid.ch/">SuisseID</a> &#8211; the recently defined Swiss standard for electronic identities could well be amongst one of the first steps on the long journey to make the Internet a place where one can &#8220;wheel and deal&#8221; in confidence and safety.</p><p>By integrating SuisseID as a means of authentication it&#8217;s now quite easily possible for any online service to establish a relationship based on trusted and guaranteed customer attributes. If the customer so agrees of course, that is! No longer is it necessary to develop, use or upkeep a bespoke identification process.</p><div
id="attachment_207" class="wp-caption alignleft" style="width: 380px"><a
href="http://mysuisseid.net/blog/wp-content/uploads/2011/02/USB-Stick_S1.jpg"><img
class="size-full wp-image-207 " title="SuisseID USB card reader" src="http://mysuisseid.net/blog/wp-content/uploads/2011/02/USB-Stick_S1.jpg" alt="" width="370" height="185" /></a><p
class="wp-caption-text">SuisseID - USB Reader from Swiss Post</p></div><h2>Personal data available on the fly</h2><p>With 15 personal attributes available on the fly (<a
href="#tab1">see Table-1</a>) from which 5 another can be deducted (<a
href="#tab2">see Table-2</a>) Internet users who have and use a SuisseID can just as easily order a new mobile phone subscription (currently requires a visit to the shop for identification and proof of address) or a bunch of flowers on account (granted, if the flowershop allows). That&#8217;s all in all a great first step!</p><p>In a recent project for a government body we were able to reduce the complexity of an existing authentication and enrollment process drastically by completely eliminating registered letters as part of the process. Not only did this greatly improve the through-time and user-friendliness for the customer, at the same time it increased conversion and reduced our clients&#8217; costs. But what to do if in a next step would one requires information that&#8217;s simply not provided by this &#8220;standard&#8221;?<br
/> <a
href="#medical"></a></p><h1>An example; prescription medication</h1><p>When my wife recently came back with a doctor&#8217;s prescription I was wondering how it&#8217;s possible that in today&#8217;s day and age pharmacies are still allowed to hand out prescription medication on the basis of a piece of paper with some print, poor handwriting and a signature. How do they know if a doctor is really a doctor -with a degree and all- and not some charlatan? How can they be sure the patient didn&#8217;t slip in another drug? If the first issue could be dealt with by the use of some (electronic) directory, I am not equally convinced if the second issue can be dealt with at all. The question has remained unanswered so far but I&#8217;d be interested if anyone here can give me his opinion and feedback.</p><p>Linking back to the story of electronic identity, in a scenario such as with the prescription, SuisseID could provide an answer and next step. Imagine that the association of medics in Switzerland were to decide to make their paper subscription notebook &#8220;abuse-proof&#8221;. In that case an improved and paperless process is easy to imagine.</p><p>Let&#8217;s first assume that each doctor is registered by the association. Secondly that this same association is willing to maintain this registry in an electronic (yet secured) format that is accessible with the SuisseID standard. In this form such a registry could be considered a Claim Assertion Service [<a
title="Read more about CAS (in french, german or italian)" href="http://www.suisseid.ch/unternehmen/technik/bestaetigungsdienst/index.html?lang=fr" target="_blank">CAS</a> info only available in FR | DE | IT].</p><p>Now whenever a patient requires prescription medication, the doctor creates an entry for this order in a central database. To get access to this database she needs to authentificate herself. Using her SuisseID and the Association&#8217;s Claim Assertion Infrastructure this acces is granted thus acknowledging that she is registered as a doctor with them. The medication is added to a record with a unique ID number (order number) which is printed and given to the patient. The patient can now go to the pharmacy with this number where they retrieve the corresponding line items and prepare the order. When the transaction is finished this information is automatically passed on to the insurance company of the patient to make sure the payment is processed.</p><h1>Who dares&#8230;?</h1><p>Clearly there are many other possibilities to use the Claim Assertion Service [<a
title="Read more about CAS (in french, german or italian)" href="http://www.suisseid.ch/unternehmen/technik/bestaetigungsdienst/index.html?lang=fr" target="_blank">CAS</a> info only available in FR | DE | IT]. The question really is which organisations, companies and other bodies are interested to join us on our thousand mile journey. Whatever your journey is, we&#8217;d like to hear from you.</p><h2>Appendix</h2><p><a
name="tab1"></a></p><table
border="0" cellspacing="0" cellpadding="0" width="450"><colgroup
span="1"><col
class="xl3227307" span="1" width="150"></col><col
span="1" width="300"></col></colgroup><tbody><tr><td
class="xl2927307"><strong>Friendly Name</strong></td><td
class="xl2627307"><strong>Description</strong></td></tr><tr><td
class="xl3027307">Given names</td><td
class="xl2427307">Given names</td></tr><tr><td
class="xl3127307">First Name</td><td
class="xl2527307">Preferred name or first name of a Subject.<br
/> Every IdP/CAS MUST use the first name appearing in givenNames for this purpose.</td></tr><tr><td
class="xl3027307">Last Name</td><td
class="xl2427307">Surname, Family name</td></tr><tr><td
class="xl3127307">Date of Birth</td><td
class="xl2527307">If the date is only partially known, this attribute MUST NOT be returned.</td></tr><tr><td
class="xl3027307">Date of Birth</td><td
class="xl2427307">May be returned in any ofthe following formats:YYYY or YYYY-MM orYYYY-MM-DD</td></tr><tr><td
class="xl3127307">Place of Birth</td><td
class="xl2527307">Place of birth according to an official identification document.<br
/> This attribute is not applicable for a Swiss citizen.</td></tr><tr><td
class="xl3027307">Origin</td><td
class="xl2427307">Place of origin according to Swiss ID card or passport.<br
/> Not applicable for foreigners.</td></tr><tr><td
class="xl3127307">Gender</td><td
class="xl2827307">0:unspecified 1:male 2: female</td></tr><tr><td
class="xl3027307">Nationality</td><td
class="xl2427307">ISO 3166-1 alpha-3 codes with modifications<br
/> (use 000 for stateless persons, use RKS for Kosovars)</td></tr><tr><td
class="xl3127307">Identification Number</td><td
class="xl2527307">Number of the identification document, limited to 9 characters, in accordance to<br
/> the machine readable zone MRZ as defined in [22] (trailing filler characters must be removed).</td></tr><tr><td
class="xl3027307">Identification Kind</td><td
class="xl2727307">0: Passport 1: ID 2: Stateless</td></tr><tr><td
class="xl3127307">Issuing Country</td><td
class="xl2527307">Issuing country for the identification document (see Nationality except for 000)</td></tr><tr><td
class="xl3027307">Issuing Office</td><td
class="xl2427307">Issuing Office</td></tr><tr><td
class="xl3127307">Identification Issued On</td><td
class="xl2527307">Issuance date of the identification document</td></tr><tr><td
class="xl3027307">Identification Valid Until</td><td
class="xl2427307">Valid-through date of the identification document</td></tr></tbody></table><p><strong>Table-1:</strong> SuisseID Plain Core Assertion Attributes (<a
href="http://www.suisseid.ch/unternehmen/technik/index.html?lang=fr&amp;download=NHzLpZeg7t,lnp6I0NTU042l2Z6ln1ae2IZn4Z2qZpnO2Yuq2Z6gpJCDdIJ9e2ym162epYbg2c_JjKbNoKSn6A--" target="_blank">source:  SuisseID Specification</a> &#8211; page 30)</p><p><a
name="tab2"></a></p><table
border="0" cellspacing="0" cellpadding="0" width="500"><colgroup
span="1"><col
class="xl3227307" span="1" width="150"></col><col
span="1" width="200"></col><col
span="1" width="150"></col></colgroup><tbody><tr><td
class="xl2927307"><strong>Friendly Name</strong></td><td
class="xl2627307"><strong>Derived from</strong></td><td
class="xl2627307"><strong>Type</strong></td></tr><tr><td
class="xl3127307">Age (derived)</td><td
class="xl2527307"></td><td
class="xl2527307">xs:unsignedInt</td></tr><tr><td
class="xl3027307">Over 16 year (derived)</td><td
class="xl2427307">(return true, iff Age &gt;= 16)</td><td
class="xl2427307">xs:boolean</td></tr><tr><td
class="xl2527307">Over 18 year (derived)</td><td
class="xl2527307">(return true, iff Age &gt;= 18)</td><td
class="xl2527307">xs:boolean</td></tr><tr><td
class="xl3027307">Is mature (derived)</td><td
class="xl2427307">(return true, iff Age &gt;= 18)<br
/> 0 = False<br
/> 1 = True<br
/> 2 = Unknown</td><td
class="xl2427307">xs:token</td></tr><tr><td
class="xl3127307">Is Swiss Citizen (derived)</td><td
class="xl2527307">(return true, iff nationality == “CHE”)</td><td
class="xl2527307">xs:boolean</td></tr></tbody></table><p><strong>Table-2:</strong> SuisseID Derived Core Assertion Attributes (<a
href="http://www.suisseid.ch/unternehmen/technik/index.html?lang=fr&amp;download=NHzLpZeg7t,lnp6I0NTU042l2Z6ln1ae2IZn4Z2qZpnO2Yuq2Z6gpJCDdIJ9e2ym162epYbg2c_JjKbNoKSn6A--" target="_blank">source:  SuisseID Specification</a> &#8211; page 36)</p><blockquote><p>Liked this post? Subscribe to my RSS feed and get loads more!</p></blockquote><p><a
href="http://mysuisseid.net/blog/suisseid/suisseid-une-etape-en-avant/">SuisseID, one step at a time</a></p>]]></content><link
rel="replies" type="text/html" href="http://mysuisseid.net/blog/suisseid/suisseid-une-etape-en-avant/#comments" thr:count="0"/><link
rel="replies" type="application/atom+xml" href="http://mysuisseid.net/blog/suisseid/suisseid-une-etape-en-avant/feed/" thr:count="0"/> <thr:total>0</thr:total> </entry> </feed>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk
Page Caching using disk (enhanced)
Database Caching using disk
Object Caching 749/766 objects using disk

Served from: mysuisseid.net @ 2012-12-17 18:37:13 -->