Future of Identity in the Information Society Summary
Total Page:16
File Type:pdf, Size:1020Kb
FIDIS Future of Identity in the Information Society Title: “D16.1: Conceptual Framework for Identity Management in eGovernment” Author: WP16 Editors: J.C. Buitelaar (Tilburg University, The Netherlands), M. Meints (Unabhängiges Landeszentrum für Datenschutz, Kiel, Germany) and B. van Alsenoy (K.U. Leuven, Belgium) Reviewers: J. Vyskoc (VaF, Slovakia) and M. Gasson (Reading University, U.K.) Identifier: D16.1 Type: Deliverable Version: 1.03 Date: 18th November 2008 Status: [Final] Class: [Public] File: 2008_11_18_D16.1_Framework_IDM_in_eGov_Final[2] Summary The main goal of deliverable D16.1 is to find an agreement within the different disciplines represented in the FIDIS NoE on the basic building blocks needed to allow dialoguing on the very specific research field of privacy-friendly identity management in eGovernment. Concretely, this means that the conceptual framework explores the basic concepts of (1) privacy and data protection, (2) identity management and (2) eGovernment, and brings them together in a conceptual framework. This framework will, in the next phase, be used to define the requirements for privacy friendly IDM in a multi-level eGovernment context. Copyright © 2004-09 by the FIDIS consortium - EC Contract No. 507512 The FIDIS NoE receives research funding from the Community’s Sixth Framework Program FIDIS D16.1 Future of Identity in the Information Society (No. 507512) Copyright Notice: This document may not be copied, reproduced, or modified in whole or in part for any purpose without written permission from the FIDIS Consortium. In addition to such written permission to copy, reproduce, or modify this document in whole or part, an acknowledgement of the authors of the document and all applicable portions of the copyright notice must be clearly referenced. The circulation of this document is restricted to the staff of the FIDIS partner organisations and the European Commission. All information contained in this document is strictly confidential and may not be divulged to third parties without the express permission of the partners. All rights reserved. PLEASE NOTE: This document may change without notice – Updated versions of this document can be found at the FIDIS NoE website at www.fidis.net. [Final], Version: 1.03 Page 2 File: 2009_04_16_D16.1_Framework_IDM_in_eGov_Final[2].doc FIDIS D16.1 Future of Identity in the Information Society (No. 507512) Members of the FIDIS consortium 1. Goethe University Frankfurt Germany 2. Joint Research Centre (JRC) Spain 3. Vrije Universiteit Brussel Belgium 4. Unabhängiges Landeszentrum für Datenschutz (ICPP) Germany 5. Institut Europeen D'Administration Des Affaires (INSEAD) France 6. University of Reading United Kingdom 7. Katholieke Universiteit Leuven Belgium 8. Tilburg University1 Netherlands 9. Karlstads University Sweden 10. Technische Universität Berlin Germany 11. Technische Universität Dresden Germany 12. Albert-Ludwig-University Freiburg Germany 13. Masarykova universita v Brne (MU) Czech Republic 14. VaF Bratislava Slovakia 15. London School of Economics and Political Science (LSE) United Kingdom 16. Budapest University of Technology and Economics (ISTRI) Hungary 17. IBM Research GmbH Switzerland 18. Centre Technique de la Gendarmerie Nationale (CTGN) France 19. Netherlands Forensic Institute (NFI)2 Netherlands 20. Virtual Identity and Privacy Research Center (VIP)3 Switzerland 21. Europäisches Microsoft Innovations Center GmbH (EMIC) Germany 22. Institute of Communication and Computer Systems (ICCS) Greece 23. AXSionics AG Switzerland 24. SIRRIX AG Security Technologies Germany 1 Legal name: Stichting Katholieke Universiteit Brabant 2 Legal name: Ministerie van Justitie 3 Legal name: Berner Fachhochschule [Final], Version: 1.03 Page 3 File: 2009_04_16_D16.1_Framework_IDM_in_eGov_Final[2].doc FIDIS D16.1 Future of Identity in the Information Society (No. 507512) Versions Version Date Description (Editor) 0.1 March 29th, Initial release (all authors and Brendan van 2008 Alsenoy, Hans Buitelaar, Martin Meints) 0.2 May 2008 Hans Buitelaar, Martin Meints, editors 0.3 October 2008 Hans Buitelaar, Martin Meints, editors of version ready for reviewers 1.01 October 29th , Comments Mark Gasson, Jozef Vyscok and 2008 executive summary included (HB) 1.02 November 6th Final version (HB) , 2008 [Final], Version: 1.03 Page 4 File: 2009_04_16_D16.1_Framework_IDM_in_eGov_Final[2].doc FIDIS D16.1 Future of Identity in the Information Society (No. 507512) Foreword FIDIS partners from various disciplines have contributed as authors to this document. The following list names the main contributors for the chapters of this document: Chapter Contributor(s) 1 Executve Summary Hans Buitelaar (TILT) 2 Introduction Hans Buitelaar (TILT) 3 Identity Martin Meints (ICPP) and Brendan van Alsenoy (ICRI) Management in eGovernment 4 Privacy-friendly 4.1 Data Protection principles for IDM in eGovernment: Brendan identity management van Alsenoy (ICRI) and Hans Buitelaar (TILT) in eGovernment 4.2 Identity Management Evolution: Bart Priem and Martin Pekarek (TILT); Martin Meints (ICPP) 5 Summary and Martin Meints (ICPP) conclusions 6 The EU perspctive Brendan van Alsenoy (ICRI) and Bart Priem (TILT) on eGovernment 7 Switzerland Eric Dubuis (VIP) 8 United Kingdom Ruth Halperin (LSE) 9 Netherlands Hans Buitelaar, Marleen Knapen and Karolina Owczynik (TILT) 10 Belgium Jacqueline v.d. Velden (ICRI) 11 Germany Martin Meints (ICPP) and Suad Cehajic (TILT) 12 Austria Martin Meints (ICPP) and Suad Cehajic (TILT) 13 Summary and Martin Meints (ICPP) conclusions [Final], Version: 1.03 Page 5 File: 2009_04_16_D16.1_Framework_IDM_in_eGov_Final[2].doc FIDIS D16.1 Future of Identity in the Information Society (No. 507512) Table of Contents Terminology definitions.........................................................................................................10 1 Executive Summary ....................................................................................................... 12 PART I - IDM in eGovernment: an approach for a theoretical framework.................... 16 2 Introduction ....................................................................................................................17 3 Identity Management in eGovernment ........................................................................ 19 3.1 Identity Management Systems ................................................................................. 19 3.2 IMS in eGovernment – what are they used for?....................................................... 20 3.2.1 Identification and authentication............................................................................. 20 3.2.2 Authorization........................................................................................................... 21 3.2.3 Digital and electronic signatures............................................................................. 22 3.3 eGovernment IMS – How are they run? ................................................................. 23 3.3.1 Life-cycles of the IMS............................................................................................. 23 3.3.2 The identity life cycle.............................................................................................. 24 3.3.3 Registration ............................................................................................................. 26 3.3.4 User management.................................................................................................... 26 3.3.5 IT Operations and IT Service Management ............................................................ 29 3.3.6 Quality and security management........................................................................... 30 4 Privacy-friendly identity management in eGovernment ............................................ 34 4.1 Data protection principles for IDM for eGovernment ............................................. 34 4.1.1 Privacy in IDM design ............................................................................................ 34 4.1.2 Making data processing legitimate.......................................................................... 36 4.1.3 Finality principle vs. ‘maximal’ re-use of personal data......................................... 37 4.1.4 Data quality ............................................................................................................. 39 4.1.5 Transparency in eGovernment? .............................................................................. 40 4.2 Identity Management Evolution............................................................................... 40 4.2.1 IDM models: from IDM silos to user-centric IDM................................................. 41 4.2.2 Central vs. decentral IDM approaches in Member States....................................... 43 4.2.3 General Organizational measures............................................................................ 46 4.2.4 Transparency enhancement – the state perspective................................................. 47 4.2.5 Opacity enhancement – the state perspective.......................................................... 49 4.2.6 Transparency enhancement – the citizen’s perspective .......................................... 50 4.2.7 Opacity enhancement – the citizen’s perspective ................................................... 51 4.2.8 Conclusions ............................................................................................................