13
E-estonia Prof. Dr. Dr. Robert Krimmer 29 May 2019 1

Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

  • Upload
    others

  • View
    0

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

E-estonia

Prof. Dr. Dr. Robert Krimmer

29 May 2019 1

Page 2: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

Digital Economy & Society Index 2018

29 May 2019 2

Page 3: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

Information Society Indicators

• 100% of schools and government organisations ICT equipped

• Entire country is covered with a broadband connection

• Broadband a reality (500 Mbit/s synchronous FTTH)• 99% of bank transfers electronical within minutes• 95% of income tax declarations made via the e-Tax

Board• 31% of votes were cast over

the internet in 2017

29 May 2019 3

Page 4: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

E-estoniaDrechsler 201429 May 2019 4

Page 5: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

Estonian Prime Minister votes „e-“

29 May 2019 5

Page 6: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

Internet Voting Website www.valimised.ee

Page 7: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

29 May 2019 7

E-residency

Page 8: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

Digital Currency

29 May 2019 8

Page 9: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

Internet

?InternetX-Road

There are various databases and information systems in different platforms with need to co-operate...

Population Register(Progress)

Business Register(Oracle)

Land Register(MSSQL)

Motor Vehicle Register(Oracle)

Citizen Portal

Information System of Company A

Citizen

Officers

more than 100 Databases...

Information System of Company B Officers

more than 1000 Information Systems...

SecurityServer

SecurityServer

SecurityServer

SecurityServer

Security Server

SecurityServer

SecurityServer SOAP

client

SOAPclient

SOAPclient

SOAPserver

SOAPserver

SOAPserver

SOAPserver

Extra interface from every database to every information system would have been expensive...

X-Road is a platform-independent secure standard interface between databases and information systems

Database is adapted to X-Road by setting up Adapter Server, which contains:

SOAP or XMLRPC server + X-Road rules

Information systems need:SOAP or XMLRPC client + understanding of X-Road rules

To secure the system, each party accesses X-Road via it’s Security Server

X-Road Security Server is a standard software solution that encrypts/decrypts outgoing/ingoing messages, filters ingoing messages

as a firewall, and logs messages it receives

CA

Traffic between Security Servers is encrypted with PKI. Security Servers have to be certified by X-Road Certification AuthorityCertificates are available for verification from X-Road Central Servers.

Central Servers are duplicated

Central Servers

No redundant centralization:Security Servers create connections directly to each other

Data from Central Servers is cached in Security Servers by use of DNSSEC

29 May 2019 9

Page 10: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

FinEst link?

29 May 2019 10Soe 2017

Page 11: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

The pan-European OOP landscape

29 May 2019 11

Page 12: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

Key success factors

n Digital first – or ’all digital’n Different approach to data protection:

transparency and accountability keyn People are signing digitally in real lifen Different approach to innovation: “public beta”, “it is

possible”n Thinking in feedback loops:

Cooperation between Public and Private n Cutting the middle-man: e-invoice & real-time economyn Data exchange layer is in active use (x-road)n Branding a nation …

29 May 2019 12

Key success factors

n Digital first – or ’all digital’

n Different approach to data protection:

transparency and accountability key

n People are signing digitally in real life

n Different approach to innovation: “public beta”, “it is

possible”

n Thinking in feedback loops:

Cooperation between Public and Private

n Cutting the middle-man: e-invoice & real-time economy

n Data exchange layer is in active use (x-road)

n Branding a nation …

1 Jun 2018 11

Key success factors

n Digital first – or ’all digital’

n Different approach to data protection:

transparency and accountability key

n People are signing digitally in real life

n Different approach to innovation: “public beta”, “it is

possible”

n Thinking in feedback loops:

Cooperation between Public and Private

n Cutting the middle-man: e-invoice & real-time economy

n Data exchange layer is in active use (x-road)

n Branding a nation …

1 Jun 2018 11

Page 13: Krimmer E-estonia Brasil 20190529€¦ · Security Servers have to be certified by X-Road Certification Authority Certificates are available for verification from X-Road Central Servers

29 May 2019

Contact

Tallinn University of Technology

Prof. DDr. Robert KrimmerProfessor of e-Governance

Akadeemia tee 312618 Tallinn, Estonia

E-mail: [email protected]

13