<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Maarten Wegdam&#039;s Blog</title>
	<atom:link href="http://maarten.wegdam.name/feed/" rel="self" type="application/rss+xml" />
	<link>http://maarten.wegdam.name</link>
	<description>A blog on identity, mobile, privacy, innovation, trust, middleware and more</description>
	<lastBuildDate>Thu, 26 Apr 2012 15:13:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='maarten.wegdam.name' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/919cf8ecf6f35b50e61434a17113f7ee?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Maarten Wegdam&#039;s Blog</title>
		<link>http://maarten.wegdam.name</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://maarten.wegdam.name/osd.xml" title="Maarten Wegdam&#039;s Blog" />
	<atom:link rel='hub' href='http://maarten.wegdam.name/?pushpress=hub'/>
		<item>
		<title>Context-enhanced authorization: usefulness and feasibility for the banking sector</title>
		<link>http://maarten.wegdam.name/2012/04/26/context-enhanced-authorization-usefulness-and-feasibility-for-the-banking-sector/</link>
		<comments>http://maarten.wegdam.name/2012/04/26/context-enhanced-authorization-usefulness-and-feasibility-for-the-banking-sector/#comments</comments>
		<pubDate>Thu, 26 Apr 2012 15:13:19 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[authorization]]></category>
		<category><![CDATA[context]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=425</guid>
		<description><![CDATA[We did a very interesting  project for a large Dutch bank (Rabobank) and IBM to determine the usefulness and feasibility of Context-enhanced Authorization in the banking sector. We focussed here on employees, and taking their context (location, used device etc) into account for authorization decisions. This would allow the authorization to become more dynamic, and address new [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=425&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://maartenwegdam.files.wordpress.com/2012/04/picture1.png"><img class="aligncenter size-medium wp-image-426" title="CeA" src="http://maartenwegdam.files.wordpress.com/2012/04/picture1.png?w=300&#038;h=212" alt="" width="300" height="212" /></a></p>
<p>We did a very interesting  <a href="http://www.novay.nl/okb/projects/context-enhanced-authorization/12435">project</a> for a large Dutch bank (Rabobank) and IBM to determine the usefulness and feasibility of Context-enhanced Authorization in the banking sector. We focussed here on employees, and taking their context (location, used device etc) into account for authorization decisions. This would allow the authorization to become more dynamic, and address new trends such as nomadic working (<em>Dutch: Het Nieuwe Werken</em>) and Bring Your Own Device.  An important technology in this project was XACML, for which we used IBM’s tooling (Tivoli Security Policy Manager).  In short the outcome was yes it is useful and yes it is feasible.</p>
<p>Today I presented the project at a <a href="http://xacml.eventbrite.com/">XACML seminar</a>, organized by PIMN, CSA, PvIB and SURFnet. I repeat the key take-aways here:</p>
<p><span id="more-425"></span></p>
<ul>
<li>Centralization &#8211; take authorization out of the application (cf authentication)</li>
<li>Use attributes (ABAC), XACML is the standard to do this multi-vendor and across domains</li>
<li>Our pilot: use dynamic attributes (i.e., context)</li>
<li>Yes it is useful, yes it is feasible</li>
<li>But w.r.t. context: authenticity, quality &amp; privacy</li>
<li>But w.r.t. dynamic attributes / XACML: complexity of policies &amp; scalability/performance</li>
</ul>
<p>More information can be found in my presentation. We also described (most of) the project in a <a href="http://www.novay.nl/okb/publications/feasibility-of-context-enhanced-authorization-in-the-banking-sector/67049">public whitepaper,</a> and even made <a href="http://www.youtube.com/watch?v=lGUprbxJNvE">small video</a> (2:39’, credits go to my <a href="http://www.ruudkosman.nl/blog/">colleague Ruud Kosman</a>).  I also copied the management summary of the whitepaper below for convenience.</p>
<iframe src='http://www.slideshare.net/slideshow/embed_code/12701596' width='450' height='369'></iframe>
<h3>Management Summary</h3>
<p>Context-enhanced authorization is about knowing when and where users are, what they are doing, which device they are using etcetera, and using this information as a parameter in authorization decisions. A sector which could benefit from this is the banking sector. There is an increasing need for banks to be deal with security in a more flexible way, for instance in order to enable nomadic working and the usage of less secure devices (tablets, smart phones, bring-your-own-device). Banking employees need to be able to perform transactions with a high security risk from different locations (home, office, at a customer etc.), at different times of the day, and from different devices. This brings with it new risks that may be mitigated by context-enhanced authorization. The promise of context-enhanced authorization is that by making this context explicit in authorization rules the flexibility increases without reducing security. Implementing context-enhanced authorization is also facilitated by the wide-spread introduction of mobile devices, which makes more context information available, and the adoption of (logically) centralized authorization systems.</p>
<p>This whitepaper provides the outcome of a feasibility study of implementing context-enhanced authorization for bank employees. An important part of this study was a demonstrator based on the XACML policy language, which enables centralized authorization policies. The whitepaper also provides a context model, criteria for usefulness of context for authorization and use cases for context-enhanced authorization for bank employees.</p>
<p>The main conclusion of the feasibility study is that context has indeed the potential to make authorization more flexible, and that it is possible to use XACML tooling to implement this. Relevant and practical context types, for now, are location, time, and information that can be derived from context. There are however non-trivial issues that have to be dealt with, especially:</p>
<ul>
<li>Authenticity of context – Depending on the context source, context can easily be falsified, e.g., when the context owner is the potential attacker. Context should be from trusted context sources if possible. In all cases, when designing context-enhanced policies, the authenticity of the context has to be carefully taken into account. For example, location information from an employer-owned WiFi network is typically more useful than location information originating from a smartphone.</li>
<li>Quality of context – Context is known with a certain amount of “vagueness”, this is called Quality of Context, due to technical limitation of context sensors. For example, an employee is never a 100% certain at home, but may be 95% certain within a 50 meter radius at his or her home. This vagueness further adds to the complexity of context-enhanced policies.</li>
<li>Privacy &#8211; Context information is often privacy sensitive information, e.g., location. The privacy risks have to outweigh the benefits of context-enhanced authorization. An issue for, among others, using context-enhanced authorization for banking employees is that they benefits may be more with the employer, and the privacy risks with the employee. There is also no generic answer if the benefits outweigh the privacy risks, this basically depends on the used context (how privacy sensitive is it), and what the actual benefits are in a specific case. The privacy implications were not explored in any detail within the scope of this study, but should be in potential follow-ups, This should include both legal aspects (e.g., role of works council, can informed consent play a role), technical (e.g. privacy-by-design) and user acceptance (e.g., do employees see benefits, what context information is sensitive).</li>
<li>Complexity of context-aware policies – Adding context parameters to policies makes them more complex. The use cases and demonstrator show that fine-grained policies are possible, but this finer level of granularity also means that it may become harder to ensure that the produced policies are complete, safe, and conflict-free.</li>
</ul>
<p>Scalability and performance – Context information is different from the usual static information on which today’s access policies are based (the identity of the user, the role of the user within the organization): context information is only relevant when processed in (near) real-time, and there is much more context information (in terms of amounts of data). This requires careful design of the collection of context, and puts much more stress on policy evaluation engines.</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/authorization/'>authorization</a>, <a href='http://maarten.wegdam.name/tag/context/'>context</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/425/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/425/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/425/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/425/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/425/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/425/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/425/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/425/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/425/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/425/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/425/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/425/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/425/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/425/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=425&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2012/04/26/context-enhanced-authorization-usefulness-and-feasibility-for-the-banking-sector/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2012/04/picture1.png?w=300" medium="image">
			<media:title type="html">CeA</media:title>
		</media:content>
	</item>
		<item>
		<title>Internet banking fraud in the Netherlands: 3.5 times more damage in 2011 (phishing)</title>
		<link>http://maarten.wegdam.name/2012/03/27/internet-banking-fraud-in-the-netherlands-three-times-more-damage-in-2011-phishing/</link>
		<comments>http://maarten.wegdam.name/2012/03/27/internet-banking-fraud-in-the-netherlands-three-times-more-damage-in-2011-phishing/#comments</comments>
		<pubDate>Tue, 27 Mar 2012 07:05:54 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=373</guid>
		<description><![CDATA[The Dutch Banking Association (NVB) published new internet banking fraud numbers yesterday. Compared to their numbers about half a year ago, there is a very significant increase in amount of damage. Previous numbers indicated a factor of two for 2011 compared to 2010, but apparently the fraud further increased in the second half of 2011, resulting in a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=373&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://maartenwegdam.files.wordpress.com/2010/10/phishing1.png"><img class="aligncenter size-medium wp-image-167" title="phishing" src="http://maartenwegdam.files.wordpress.com/2010/10/phishing1.png?w=300&#038;h=132" alt="" width="300" height="132" /></a></p>
<p>The Dutch Banking Association (NVB) published<a href="http://www.nvb.nl/home-nederlands/nieuws/nieuwsberichten/betalingsverkeer-veilig-ondanks-toename-fraude.html"> new internet banking fraud numbers yesterday</a>. Compared to <a href="http://maarten.wegdam.name/2011/11/15/internet-bankingfraud-in-the-netherlands-three-time-more-incidents-twice-the-damage/">their numbers about half a year ago</a>, there is a very significant increase in amount of damage. Previous numbers indicated a factor of two for 2011 compared to 2010, but apparently the fraud further increased in the second half of 2011, resulting in a factor of 3.5 increase. The total damage is now also adding up to €35M. Although NVB is correct is stating this is relatively not a lot (0.001% of total internetbanking volume), €35M is still €35M. Note that this amount is what they reimbursed to customers that were a victim of internet banking fraud (i.e. phishing). Costs associated with prevention, detection etc are not part of this amount.</p>
<p>What worries me most is the relative increase of these numbers, from <a href="http://maarten.wegdam.name/2011/03/15/updated-numbers-on-internet-banking-fraud-in-the-netherlands-5-fold-increase-in-2010/">2009 to 2010 the damages increased fivefold</a>, and from 2010 to 2011 they increased by a factor of 3.5. Playing with these numbers, damages in 2012 could be €70M (if the banks manage to slow down the increase to a factor of 2) or €122M if it stays a factor of 3.5. Banks, of course together with police, (Electronic Crimes Taskforce etc), will need to slow down this growth.</p>
<p><a href="http://maartenwegdam.files.wordpress.com/2012/03/nvb-phishing-2009-2011.png"><img class="aligncenter size-full wp-image-374" title="nvb-phishing-2009-2011" src="http://maartenwegdam.files.wordpress.com/2012/03/nvb-phishing-2009-2011.png?w=450&#038;h=265" alt="" width="450" height="265" /></a></p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/authentication/'>authentication</a>, <a href='http://maarten.wegdam.name/tag/phishing/'>phishing</a>, <a href='http://maarten.wegdam.name/tag/security/'>security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/373/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/373/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/373/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/373/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/373/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/373/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/373/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/373/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/373/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/373/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/373/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/373/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/373/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/373/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=373&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2012/03/27/internet-banking-fraud-in-the-netherlands-three-times-more-damage-in-2011-phishing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2010/10/phishing1.png?w=300" medium="image">
			<media:title type="html">phishing</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2012/03/nvb-phishing-2009-2011.png" medium="image">
			<media:title type="html">nvb-phishing-2009-2011</media:title>
		</media:content>
	</item>
		<item>
		<title>Guide to classifying e-services to Levels of Assurance: a good first step</title>
		<link>http://maarten.wegdam.name/2012/02/09/guide-to-classifying-e-services-to-levels-of-assurance-a-good-first-step/</link>
		<comments>http://maarten.wegdam.name/2012/02/09/guide-to-classifying-e-services-to-levels-of-assurance-a-good-first-step/#comments</comments>
		<pubDate>Thu, 09 Feb 2012 19:30:09 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[Levels of Assurance]]></category>
		<category><![CDATA[trust framework]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=358</guid>
		<description><![CDATA[A Dutch government body responsible for establishing open standards for elektronic exchange (Forum Standaardisatie) published a guide for government service providers to help them classify e-services to Levels of Assurance. They use the EU STORK Quality Authentication Assurance levels for this, which classify authentication solutions in four levels. Since Novay was responsible for defining these levels in the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=358&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:justify;">A Dutch government body responsible for establishing open standards for elektronic exchange (<a href="http://www.forumstandaardisatie.nl/english-page/">Forum Standaardisatie</a>) published a guide for government service providers to help them classify e-services to Levels of Assurance. They use the EU STORK Quality Authentication Assurance levels for this, which classify authentication solutions in four levels. Since Novay was responsible for defining these levels in the EU STORK project, and we&#8217;ve helped several clients in applying STORK levels, we read this guide with great interest. In the below text we discuss the Levels of Assurance concept, and give our opinion on the guide.</p>
<p style="text-align:justify;"><span id="more-358"></span></p>
<p style="text-align:justify;">The shortest summary is the same as the title of this blog post: we consider this guide a first good step to establish a best practice for classifying e-service to Levels of Assurance. We however also discuss some limitation and possible extentions.</p>
<p style="text-align:justify;">This blog post was written jointly with my colleague (and editor of the STORK deliverable that defines the STORK levels) Bob Hulsebosch. It is also <a href="http://www.novay.nl/onze-mensen/bob-hulsebosch/handreiking-betrouwbaarheidsniveaus-voor-overheidsdiensten-een-nuttige-eerste-stap/67061">posted at the Novay website</a>. For non-Dutch speakers, <a href="http://translate.google.com/translate?sl=nl&amp;tl=en&amp;js=n&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=2&amp;eotf=1&amp;u=http%3A%2F%2Fmaarten.wegdam.name%2F2012%2F02%2F09%2Fguide-to-classifying-e-services-to-levels-of-assurance-a-good-first-step%2F">try Google translate</a>.</p>
<h2>Handreiking betrouwbaarheidsniveaus voor overheidsdiensten: een nuttige eerste stap</h2>
<p>Door Bob Hulsebosch en Maarten Wegdam</p>
<p>Het <a href="http://www.open-standaarden.nl/">Forum Standaardisatie</a>, i.s.m. <a href="http://www.eherkenning.nl/">eHerkenning</a>, is eind vorig jaar gekomen met een<a href="http://www.forumstandaardisatie.nl/fileadmin/os/publicaties/Handreiking_Betrouwbaarheidsniveaus_def_tesktversie.pdf"><em>handreiking betrouwbaarheidsniveaus voor elektronische overheidsdiensten</em></a>. Het gaat hierom om de betrouwbaarheid van de authenticatie waarmee iemand toegang krijgt tot die diensten. Het gaat meestal om vier niveaus, en wordt in Nederland onder meer gebruikt door eHerkenning (business-2-government afsprakelstelsel). In Europa gebruikt men vaak de in het Europese STORK project gedefinieerde<a href="https://www.eid-stork.eu/dmdocuments/public/D2.3_final._1.pdf"> Quality Authentication Assurance levels</a>. Deze zijn, met <a href="http://www.novay.nl/okb/projects/stork/4561">Novay als auteur</a> namens MinBZK, in 2009 vastgelegd en zijn gebaseerd op de Levels of Assurance standaard van NIST (<a href="http://csrc.nist.gov/publications/nistpubs/800-63-1/SP-800-63-1.pdf">SP 800-63</a>). Bovenstaande standaarden leggen vast hoe een authenticatie-oplossing te classificeren op een betrouwbaarheidsniveau. Echter hoe te bepalen welke betrouwbaarheidsniveau nodig is voor een dienst bleef onderbelicht. Bovengenoemde handreiking voor betrouwbaarheidsniveaus moet juist hierin voorzien, en dus e-dienstverleners in de overheidssector helpen om te bepalen welk betrouwbaarheidsniveau nodig is voor hun dienst. In deze blogpost geven we ons beeld over deze materie.</p>
<p><strong>Introductie betrouwbaarheidsniveaus</strong></p>
<p>Om de betrouwbaarheid van een authenticatie-oplossing en daarmee de identiteit van de gebruiker te bepalen worden zowel technische (bv smartcard is veiliger dan gebruikersnaam/wachtwoord) als organisatorische (bv online aanvragen van het middel of fysiek komen afhalen) aspecten meegenomen.</p>
<p>Het concept van betrouwbaarheidsniveaus wint de laatste jaren sterk aan populariteit omdat het hergebruik van identiteiten van andere partijen kan faciliteren. Als een dienstverlener een identiteit wil hergebruiken die een gebruiker heeft gekregen van een andere partij (de identity provider), is het immers wel nodig op een gestandaardiseerde manier de benodigde betrouwbaarheid aan te geven (interoperabiliteit), zeker als er potentieel vele externe identity providers zijn (schaalbaarheid). Een dienstverlener moet kunnen specificeren welk betrouwbaarheidsniveau nodig is, en moet dit kunnen doen zonder allerlei implementatiedetails te verschaffen.</p>
<p>Kortom, gestandaardiseerde betrouwbaarheidsniveaus dragen bij aan interoperabiliteit en schaalbaarheid bij met name hergebruik van identiteiten. Dit standaardiseren is overigens niet triviaal, immers technologie ontwikkelt zich en er zitten altijd grijze zones in het classificeren van een specifieke oplossing. Bijvoorbeeld, de interpretaties verschillen of <em>DigiD basis</em>overeenkomt met STORK niveau 1 of 2. Andere beperkingen zijn dat het indelen een (typisch) vier discrete niveaus ten kosten gaat van een stuk nuance, en dat het onduidelijk kan zijn of externe identity providers wel conform het betrouwbaarheidsniveau handelen (audits zijn niet zaligmakend, zoals het <a href="http://www.novay.nl/our-people/maarten-wegdam/hacks-will-happen-but-the-damage-can-be-less-diginotar/12359">DigiNotar drama</a> ons weer geleerd heeft). Ook gaat een afweging welke authenticatie-oplossing te gebruiken verder dan de betrouwbaarheid; met name kosten en gebruikersvriendelijkheid zijn aspecten die ook meegenomen dienen te worden.</p>
<p><strong>Wat voegt de handreiking toe?</strong></p>
<p>Voor een dienstverlener die externe identiteiten wil gaan afnemen helpen de bovenstaande criteria eigenlijk weinig bij de afweging welk niveau vereist is voor een specifieke dienst. De handreiking vult hier de NIST/STORK standaarden aan, door risicogevoelige criteria te bieden voor overheidsdiensten om te bepalen welk niveau nodig is: rechtsgevoeligheid, formele vereisten, opgeven van persoonsgegevens, tonen van persoonsgegevens, verwerking van BSN, juistheid van de gegevens, economisch belang en publiek belang. Je zou het kunnen zien als een menukaart voor een snelle risico-inschatting van een specifieke dienst. Neem bijvoorbeeld het criterium economisch belang: bij een gering belang (~€1000) dan voldoet niveau 2, bij gemiddeld belang (~€10.000) voldoet niveau 3 en bij groot belang (&gt; €10.000) is niveau 4 nodig. Eventuele compenserende maatregelen (correctie factoren)  worden beschreven om een keuze voor een lager (of hoger) betrouwbaarheidsniveau te verantwoorden, bijvoorbeeld als er terugkoppeling plaatsvindt door middel van een bevestigingsbrief kan een lager niveau volstaan.</p>
<p><a href="http://maartenwegdam.files.wordpress.com/2012/02/201202-loas1.png" target="_blank"><img class="wp-image-360 alignleft" title="201202 - LoAs" src="http://maartenwegdam.files.wordpress.com/2012/02/201202-loas1.png?w=400" alt="" width="400" /></a></p>
<p>Aangezien wij vergelijkbare inschattingen hebben gemaakt de afgelopen tijd bij diverse klanten (geen overheidspartijen overigens), en gezien ons STORK verleden, hebben wij de handreiking met belangstelling gelezen. Het gaat te ver voor een blog post om op details op de criteria in te gaan, maar we kunnen wel zeggen dat we geen &#8216;rare dingen’ zagen. De risicogevoelige criteria komen ook redelijk overeen met de door de Amerikaanse overheid geadviseerde criteria (uit 2003! <a href="http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy04/m04-04.pdf">hier</a>, en met een <a href="http://www.nist.gov/manuscript-publication-search.cfm?pub_id=910388">recente revisie</a>). De Amerikanen beschouwen het toekennen van betrouwbaarheidsniveaus in een breder, procesmatig geheel waarbij, naast een risico-analyse en mapping op betrouwbaarheidsniveaus, ook oog is voor de evaluatie hiervan en het selecteren van een authenticatie-oplossing. Een dergelijke procesmatige aanpak is van meerwaarde voor de e-dienstverlener.</p>
<p>Hieronder wat andere kanttekeningen en aanvullingen op de handreiking, op hoog niveau:</p>
<ul>
<li><strong>E-Overheid specifiek</strong> – de criteria zijn opgesteld voor (Nederlandse) overheidsdienstverleners, en zijn voor een significant deel niet van toepassing voor private dienstverleners. Voor het stimuleren van business-2-business eHerkenning lijkt ons een aanpaste versie van de handreiking nodig. Bijvoorbeeld de criteria “verwerking van BSN” en “publiek belang”.</li>
<li><strong>Motivatie</strong> – een expliciete motivatie voor de criteria ontbreekt, en sommige keuzes zou je ook anders kunnen maken. Mogelijk reflecteert het consensus van een brede groep experts uit het overheidsdomein, dat is ons niet helder. Nuancering hierbij is dat in de praktijk zal blijken dat een dienst voor verschillende criteria op verschillende niveaus uitkomt, het blijft dan zoals de titel ook zegt een handreiking.</li>
<li><strong>Machtigingen en machine-2-machine</strong> – deze zijn out-of-scope voor de handreiking maar wel erg relevant naar onze mening zijn hoe met betrouwbaarheidsniveaus om te gaan bij machtigingen en machine-2-machine interacties.</li>
<li><strong>Risico en kans</strong> – de handreiking gaat grotendeels voorbij aan de voor een risicoanalyse veel gebruikte methode waarbij nader benoemde risico&#8217;s worden gekwantificeerd door het bepalen van de kans dat een dreiging zich voordoet en de gevolgen daarvan: Risico = Kans x Gevolg. Eigenlijk wordt alleen met het gevolg rekening gehouden.</li>
<li><strong>Kosten en eHerkenning specifiek</strong> – de handreiking gaat niet in op kosten en gebruikersaspecten. Dit is in de context van eHerkenning ook mogelijk minder relevant, immers een overheidsdienstverlener heeft hier toch geen directe verantwoordelijkheid voor, en draagt de kosten ook niet. Wel is het belangrijk te realiseren dat de keuze voor een (te) hoog niveau ten koste kan gaan van het gebruik van de dienst – niet iedere gebruiker zal de kosten willen dragen voor een sterk authenticatiemiddel en gebrek aan gebruiksgemak zal leiden tot minder gebruik van de dienst.</li>
</ul>
<p><strong>Conclusie</strong></p>
<p>De handreiking is een goede eerste stap om tot een <em>best practice</em> te komen hoe overheidsdienstverleners hun dienst kunnen indelen naar betrouwbaarheidsniveaus. Ook uit eigen ervaring weten we dat er behoefte is aan meer houvast hierin. De volgende stap lijkt ons om het door middel van cases te gaan beproeven, en ervaringen en ontwikkelingen terug te voeren naar de criteria. Verder zou het interessant zijn een analyse te doen hoe buitenlandse overheden hiermee om gaan, en waar de verschillen zitten.</p>
<p>UPDATE 23 feb 2012: de handreiking is verschenen in een &#8216;<a href="http://www.logius.nl/fileadmin/logius/product/Samenwerkende_Catalogi/HR_Betrouwbaarheidsniveaus_WEB.pdf">mooiere&#8217; versie</a>.</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/authentication/'>authentication</a>, <a href='http://maarten.wegdam.name/tag/levels-of-assurance/'>Levels of Assurance</a>, <a href='http://maarten.wegdam.name/tag/trust-framework/'>trust framework</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/358/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/358/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/358/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=358&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2012/02/09/guide-to-classifying-e-services-to-levels-of-assurance-a-good-first-step/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2012/02/201202-loas1.png" medium="image">
			<media:title type="html">201202 - LoAs</media:title>
		</media:content>
	</item>
		<item>
		<title>Looking back at 2011: what was new, and what could have been (IDentity.Next newsletter)</title>
		<link>http://maarten.wegdam.name/2011/12/21/looking-back-at-2011-what-was-new-and-what-could-have-been-identity-next-newsletter/</link>
		<comments>http://maarten.wegdam.name/2011/12/21/looking-back-at-2011-what-was-new-and-what-could-have-been-identity-next-newsletter/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 10:06:18 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[trust framework]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=324</guid>
		<description><![CDATA[I wrote an article for the IDentity.Next newsletter that came out today (21 December 2011). It is here, and for convenience, also copied below. Looking back at 2011: what was new, and what could have been 18-12-2011 With 2011 almost over, the question IDentity.News had for me was to look back to 2011 what were new developments [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=324&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I wrote an article for the IDentity.Next newsletter that came out today (21 December 2011). It is <a href="http://www.identitynext.nl/news.php?id=39">here</a>, and for convenience, also copied below.</p>
<p><a href="http://maartenwegdam.files.wordpress.com/2011/12/1324209834_2011.jpg"><img class="aligncenter size-full wp-image-325" title="1324209834_2011" src="http://maartenwegdam.files.wordpress.com/2011/12/1324209834_2011.jpg?w=450" alt=""   /></a></p>
<h3>Looking back at 2011: what was new, and what could have been</h3>
<div><strong>18-12-2011</strong></div>
<p>With 2011 almost over, the question IDentity.News had for me was to look back to 2011 what were new developments in the area of digital identity. Since I&#8217;m in the business of innovation, looking forward is more in my DNA than looking back. And so a little out of my comfort zone, below three major new developments of 2011, and, also, three developments that did not happen in 2011.</p>
<p><strong>1. Trust frameworks</strong>- in the US (e.g. NSTIC, OIX), in NL (e.g. eHerkenning) and elsewhere trust frameworks as a way to ensure a fair and trusted ecosystem to provide identity-related services are catching on. Experience with large scale deployment is still limited though. I guess we just have to do and learn. And the alternative for trust frameworks (i.e. government issued identities) also stays popular (e.g., the new German ID card, the Dutch DigiD/eNIK).</p>
<p><strong>2. Cloud and identity-as-a-service</strong>– it seems impossible for a self-respecting event in the area of identity not to spend significant time on the combination of cloud and identity. And something similar seems to apply to identity experts J. There is also progress here; especially commercial offerings of identity-as-a-service have been progressing. On making the cloud identity-enabled, things have developed slower than I would have expected a year ago. Although I guess everyone (?) agrees that companies want to have centralized authentication, authorization and provisioning (efficiency, control etc), adoption of standards is still too limited, which is at least part of the reason this is going slow.</p>
<p><strong>3. DigiNotar </strong>(and other security fiasco&#8217;s in the identity area) – while a disaster for DigiNotar and potentially a huge disaster for an unknown number of Iranians, there is actually a bright side. It resulted in more attention at &#8216;higher levels in organizations&#8217; for information security and identity. And I&#8217;m sure many security consultants had sufficient work in second half of 2011. The downside of this attention is that I rather have digital identity associated with ‘enabling online services’ than with security risks.</p>
<p>There are also three developments that did not happen, but could have. I stay close to home for these.</p>
<p>What first comes to mind is that there is still no clarity on introduction of a Dutch electronic identity card (eNIK), although the responsible Minister of Internal Affairs promised parliament a proposal before the end of the year (still two weeks to go!).</p>
<p>What also did not happen in the Netherlands is the Dutch national electronic health record, instead the Dutch senate seems to prefer faxes, or maybe smoke signals. Not that the proposed law they stopped did not have its flaws from a privacy and authorization perspective. But the proposal could have been improved upon, and current practise is much worse in my opinion. Hopefully the Dutch national health record will continue in another form, there are signs it might.</p>
<p>The third development that did not happen is a breakthrough in a re-usable consumer identity solution on Dutch national or, even better, European or worldwide scale: we still have the same long list of username/passwords for every website that offers personalization.</p>
<p><em><strong>Maarten Wegdam </strong>(principal consultant Novay &#8211; IDentity.Next member panel)</em></p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity/'>identity</a>, <a href='http://maarten.wegdam.name/tag/trust-framework/'>trust framework</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/324/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/324/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/324/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=324&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/12/21/looking-back-at-2011-what-was-new-and-what-could-have-been-identity-next-newsletter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2011/12/1324209834_2011.jpg" medium="image">
			<media:title type="html">1324209834_2011</media:title>
		</media:content>
	</item>
		<item>
		<title>Do&#8217;s and don&#8217;t&#039;s for DigiD</title>
		<link>http://maarten.wegdam.name/2011/12/20/dos-and-donts-for-digid/</link>
		<comments>http://maarten.wegdam.name/2011/12/20/dos-and-donts-for-digid/#comments</comments>
		<pubDate>Mon, 19 Dec 2011 22:43:39 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[identity federation]]></category>

		<guid isPermaLink="false">http://maartenwegdam.wordpress.com/?p=316</guid>
		<description><![CDATA[DigiD is the Dutch national digital identity solution for citizin-2-government. Although not the most secure solution around, it is one of the more succesful ones with respect to actual usage. DigiD is actually not only for e-government services, but also for online services in healthcare and pensions (since they can use the Dutch social security number). For such a [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=316&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.novay.nl/img/content/1579/1579_blogpost.png" alt="Nieuwe logo DigiD" width="163" height="175" /></p>
<p>DigiD is the Dutch national digital identity solution for citizin-2-government. Although not the most secure solution around, it is one of the more succesful ones with respect to actual usage. DigiD is actually not only for e-government services, but also for online services in healthcare and pensions (since they can use the Dutch social security number). For such a &#8216;lucky&#8217; company, which is going to use DigiD next to an own identity solution for consumers, we did a series of interviews to determine the do&#8217;s and don&#8217;t's of implementing DigiD. My colleague Wouter Bokhove was in the lead for this, and published a blog post summarizing some of the main finding. It is in Dutch, and be be found <a href="http://www.novay.nl/onze-mensen/wouter-bokhove/digid-een-goede-voorbereiding-is-het-halve-werk/12504">here </a>or for your convenience copied below. Amongst others we advised on using the new SAMLv2 interfaces or the &#8216;old&#8217; A-Select interfaces, and on how to use te Levels of Assurances concept.</p>
<p>&nbsp;</p>
<h3>DigiD: een goede voorbereiding is het halve werk!</h3>
<p>Stel: je hebt als organisatie in de pensioen- of zorgsector een Mijn-omgeving waar je online zaken kunt regelen. Een deel van je gebruikers heeft een account tot deze Mijn-omgeving op basis van een gebruikersnaam en wachtwoord (met alle nadelen en beperkingen van dien), maar je bent op zoek naar een goedkoper, veiliger en/of gebruikersvriendelijker alternatief.</p>
<p>Is DigiD dan het antwoord? Wanneer is het nuttig om DigiD te implemeteren? Waarom zou ik nog een eigen gebruikersnaam/wachtwoord-combinatie aanbieden? Wat is belangrijk bij het implementeren van een DigiD koppeling? DigiD heeft verschillende koppelvlakken, welke moet ik kiezen? Wat gaat er met DigiD 4.0 veranderen, welke ontwikkelingen zijn nog meer relevant en welke impact zullen deze veranderingen en ontwikkelingen kunnen hebben op de keuzes die ik nu maak? Hoe zorg ik voor een toekomstvaste identiteitsarchitectuur die hiermee om kan gaan?</p>
<p><a href="http://www.novay.nl/" target="_blank">Novay</a> heeft voor een grote Nederlandse financiële dienstverlener een aantal adviezen geformuleerd die op deze vragen een antwoord geven. Hiervoor is niet alleen gekeken naar de huidige situatie van deze klant en de publiek beschikbare informatie over DigiD, maar is ook uitgebreid gesproken met ervaringsdeskundigen uit de zorgsector, system integrators en met <a href="http://www.logius.nl/" target="_blank">Logius</a>. In deze blogpost schrijf ik kort een paar van de aanbevelingen die interessant zijn voor een breder publiek:</p>
<ul>
<li>Er kunnen verschillende redenen zijn om gebruik te willen maken van DigiD:
<ul>
<li>het wordt mogelijk om diensten aan te bieden waarvoor een hoger zekerheidsniveau nodig is (t.o.v. een eigen gebruikersnaam en wachtwoord);</li>
<li>het gebruik van <a href="http://www.zorgvisie.nl/ICT/Achtergronden-1/08357/DigiD-Veilige-toegang-en-algemeen-geaccepteerd.htm" target="_blank">DigiD verlaagt de drempel</a> voor klanten om gebruik te maken van de Mijn-omgeving; hierdoor zullen meer klanten gebruiken van dit (typisch goedkopere) kanaal;</li>
<li>er zal minder gebruik gemaakt worden van het eigen authenticatiemiddel, waardoor nieuwe identiteiten uitgegeven hoeven te worden en er minder belasting zal zijn voor de helpdesk (bv. voor het resetten van vergeten wachtwoorden);</li>
<li>het is eventueel niet langer noodzakelijk om een eigen authenticatiemiddel aan te bieden (dit is o.a. afhankelijk van het feit of alle klanten wel een DigiD kunnen aanvragen).</li>
</ul>
</li>
<li>Er moet gekozen worden tussen koppelen met het &#8216;oude&#8217; A-Select koppelvlak of met het &#8216;nieuwe&#8217; SAML v2 koppelvlak. Het gebruik van SAML v2 is aan te bevelen omdat dit meer toekomstvast is (SAML v2 is een OASIS standaard). SAML v2 wordt vanaf <a href="http://www.logius.nl/producten/toegang/digid/ontwikkeling/" target="_blank">DigiD 4.0</a> ondersteund (SAML v2 is nu ook al beschikbaar bij DigiD Eenmalig Inloggen). De release hiervan is echter <a href="http://www.logius.nl/actueel/item/titel/planning-digid-40-gewijzigd/" target="_blank">uitgesteld</a> van 1 oktober 2011 tot na 1 april 2012.</li>
<li>Ondanks het feit dat het gebruik van DigiD en de begeleiding bij de implementatie van DigiD door Logius momenteel nog <a href="http://www.logius.nl/actueel/item/titel/logius-heeft-officiele-status-van-baten-lastendienst/" target="_blank">gratis</a> is, is het verstandig om rekening te houden met het feit dat dit op termijn anders zal worden. Het is op dit moment niet te voorspellen hoe duur dit zal zijn, en of dit zal verschillen per zekerheidsniveau.</li>
<li>Doe een risico-inventarisatie van de huidige en geplande diensten voor de Mijn-omgeving en bepaal welke zekerheidsniveaus hiervoor nodig zijn. In verband met de toekomstvastheid is het verstandig hierbij gebruik te maken van de zekerheidsniveaus zoals deze gedefinieerd zijn in het Europese <a href="http://www.novay.nl/projecten/stork/4338" target="_blank">STORK</a> project (<a href="https://www.eid-stork.eu/dmdocuments/public/D2.3_final._1.pdf" target="_blank">D2.3</a>, geschreven door Novay in opdracht van het ministerie van BZK).</li>
<li>Logius is zeer streng met betrekking tot de communicatie-eisen en het blijkt dat Logius freuent (pre-)productie-omgevingen afkeurt als deze niet voldoen aan deze eisen. Dit betekent dat een aansluitende partij zich geen enkele vrijheid kan veroorloven ten aanzien van de voorgeschreven teksten en het gebruik van het DigiD logo.</li>
</ul>
<p>Bovenstaande adviezen zijn opgesteld in de periode voor &#8216;<a href="http://webwereld.nl/tags/lektober-2011.html" target="_blank">Lektober</a>&#8216;. Naar aanleiding van de DigiD-gerelateerde recente veiligheidsproblemen bij o.a. gemeentes die hieruit naar voren zijn gekomen, kan er nog een advies worden toegevoegd:</p>
<ul>
<li>Het is de bedoeling van minister Donner dat binnenkort alle organisaties die op DigiD zijn aangesloten een <a href="http://www.logius.nl/actueel/item/titel/intensief-contact-gemeenten-over-aansluiten-digid/" target="_blank">jaarlijks ICT-beveiligingsassessment</a> moeten uitvoeren. Anticipeer hier alvast op door ervoor te zorgen dat de beveiliging voldoet aan de &#8220;<a href="http://www.govcert.nl/dienstverlening/Kennis+en+publicaties/factsheets/checklist-webapplicatie-beveiliging.html" target="_blank">Checklist beveiliging webapplicaties</a>&#8221; zoals opgesteld door GOVCERT.</li>
</ul>
<p>&nbsp;</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity/'>identity</a>, <a href='http://maarten.wegdam.name/tag/identity-federation/'>identity federation</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/316/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/316/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/316/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=316&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/12/20/dos-and-donts-for-digid/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://www.novay.nl/img/content/1579/1579_blogpost.png" medium="image">
			<media:title type="html">Nieuwe logo DigiD</media:title>
		</media:content>
	</item>
		<item>
		<title>Internet banking fraud in the Netherlands: three time more incidents, twice the damage</title>
		<link>http://maarten.wegdam.name/2011/11/15/internet-bankingfraud-in-the-netherlands-three-time-more-incidents-twice-the-damage/</link>
		<comments>http://maarten.wegdam.name/2011/11/15/internet-bankingfraud-in-the-netherlands-three-time-more-incidents-twice-the-damage/#comments</comments>
		<pubDate>Tue, 15 Nov 2011 09:46:09 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity theft]]></category>
		<category><![CDATA[phishing]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=304</guid>
		<description><![CDATA[The Dutch Banking Association (NVB) in the Netherlands provides numbers of internet banking fraud, I think twice a year (see also my last post on this). Yesterday the announced new numbers, together with a new awareness campaign for the public. The numbers they announced yesterday about the first half of 2011: amount of incidents is [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=304&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://maartenwegdam.files.wordpress.com/2010/10/phishing1.png"><img class="aligncenter size-full wp-image-167" title="phishing" src="http://maartenwegdam.files.wordpress.com/2010/10/phishing1.png?w=450&#038;h=199" alt="" width="450" height="199" /></a></p>
<p>The Dutch Banking Association (NVB) in the Netherlands provides numbers of internet banking fraud, I think twice a year (see also my <a href="http://maarten.wegdam.name/2011/03/15/updated-numbers-on-internet-banking-fraud-in-the-netherlands-5-fold-increase-in-2010/">last post on this</a>). Yesterday the announced <a href="http://www.nvb.nl/index.php?p=918684">new numbers</a>, together with a new awareness campaign for the public. The numbers they announced yesterday about the first half of 2011: amount of incidents is 2400 and the damage is €11.2M.</p>
<p>I extrapolated these numbers for the whole of 2011 by simply multiplying them by two (which is probably optimistic) and compared them to the 2009 and 2010 numbers.  The bottom-line is is that internet banking fraud still increases a lot with more than twice the damage in 2011 than in 2010. The relative increase is however less dramatic than from 2009 to 2010, when it increased with a factor of five. The amount of incidents increased with a factor of about 3.5, and thus there is also good news: the amount of damage per incident decreased (to an average of ~€4.500 per incident). I guess this is because the Dutch banks improved their detection of internet fraud, and are more effective in quickly stopping money mules.</p>
<p>Non-technical countermeasures such as continuing awareness campaigns and the Electronic Crimes Taskforce (which hunts cybercrimes) are needed, but really preventing internet banking fraud also depends on better authentication means and other more technical measures. What I found somewhat remarkable is that the NVB press release and also e.g. the article in the Volkskrant (a Dutch national newspaper) talked about &#8216;old fashioned&#8217; phishing emails a being a big part of the problem, while I&#8217;m personally more worried about malware on the consumers devices (laptop, smartphone, tablet etc). An anecdote is a colleague of mine that was very recently the subject of an attack involving advanced malware that infected his PC irrespective of up-to-date patches and virus scanners. The malware then waited till my colleague made a transfer, and added a transfer to empty his acoount to a money mule in Portugal. Such malware is undetectable for &#8216;normal people&#8217;, including the browser indicating a valid website certificate. He however noticed this right after the transfer because the browser was acting strangely, and was able to stop the transfer by calling his bank. I&#8217;, however sure that for someone less &#8216;nerdy&#8217; the browser&#8217;s strange behavior would have been too suble to notice.</p>
<p>The below graphs show the fraud numbers for 2009, 2010 and (extrapolated for) 2011.</p>
<p style="text-align:center;"><a href="http://maartenwegdam.files.wordpress.com/2011/11/2011-internet-banking-fraud-nl-in-euros.png"><img class="size-full wp-image-305 aligncenter" title="2011-internet-banking-fraud-NL-in-euros" src="http://maartenwegdam.files.wordpress.com/2011/11/2011-internet-banking-fraud-nl-in-euros.png?w=450" alt=""   /></a></p>
<p style="text-align:center;"><a href="http://maartenwegdam.files.wordpress.com/2011/11/2011-internet-banking-fraud-nl-in-amount-of-incidents.png"><img class="aligncenter size-full wp-image-306" title="2011-internet-banking-fraud-NL-in-amount-of-incidents" src="http://maartenwegdam.files.wordpress.com/2011/11/2011-internet-banking-fraud-nl-in-amount-of-incidents.png?w=450" alt=""   /></a></p>
<p style="text-align:center;"><a href="http://maartenwegdam.files.wordpress.com/2011/11/2011-internet-banking-fraud-nl-in-euros1.png"><img class="aligncenter size-full wp-image-307" title="2011-internet-banking-fraud-NL-in-euros" src="http://maartenwegdam.files.wordpress.com/2011/11/2011-internet-banking-fraud-nl-in-euros1.png?w=450" alt=""   /></a></p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity-theft/'>identity theft</a>, <a href='http://maarten.wegdam.name/tag/phishing/'>phishing</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/304/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=304&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/11/15/internet-bankingfraud-in-the-netherlands-three-time-more-incidents-twice-the-damage/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2010/10/phishing1.png" medium="image">
			<media:title type="html">phishing</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2011/11/2011-internet-banking-fraud-nl-in-euros.png" medium="image">
			<media:title type="html">2011-internet-banking-fraud-NL-in-euros</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2011/11/2011-internet-banking-fraud-nl-in-amount-of-incidents.png" medium="image">
			<media:title type="html">2011-internet-banking-fraud-NL-in-amount-of-incidents</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2011/11/2011-internet-banking-fraud-nl-in-euros1.png" medium="image">
			<media:title type="html">2011-internet-banking-fraud-NL-in-euros</media:title>
		</media:content>
	</item>
		<item>
		<title>Edentiti wins Novay Digital Identity Award!</title>
		<link>http://maarten.wegdam.name/2011/11/10/edentiti-wins-novay-digital-identity-award/</link>
		<comments>http://maarten.wegdam.name/2011/11/10/edentiti-wins-novay-digital-identity-award/#comments</comments>
		<pubDate>Thu, 10 Nov 2011 09:30:52 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=299</guid>
		<description><![CDATA[Yesterday was the second edition of the IDentity.Next (un)conference, and also the second time Novay putted an innovation in the area of digital identity in the spotlight by awarding it with the Novay Digital Identity Award. Congratulations to Edentiti, and its founder Kevin Cox!!! Edentiti is an Australian started-up that does online identity verification. What I [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=299&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://maartenwegdam.files.wordpress.com/2011/11/novay-digital-identiti-award-2011.png"><img class="aligncenter size-full wp-image-300" title="Novay-Digital-Identiti-Award-2011" src="http://maartenwegdam.files.wordpress.com/2011/11/novay-digital-identiti-award-2011.png?w=450" alt=""   /></a></p>
<p>Yesterday was the second edition of the <a href="http://www.identitynext.eu">IDentity.Next </a>(un)conference, and also the second time Novay putted an innovation in the area of digital identity in the spotlight by awarding it with the Novay Digital Identity Award. Congratulations to <a href="http://www.edentiti.com">Edentiti</a>, and its founder Kevin Cox!!!</p>
<p>Edentiti is an Australian started-up that does online identity verification. What I personally like most about Edentiti is that they have a very pragmatic approach to identity verification which exploits a range of existing online databases and previously established identities. They provide increasing levels of trustworthiness of the identity verification, with increase in trust means more hassle for the user (and probably more cost for the service provider) but for many online services a lower level of trustworthiness is already good enough. And it all cases, the service provider doesn’t have to do the identity verification himself, and the user is in control how his identity is verified. A ‘trick’ they use is that users can verify their identity by proving that they have existing relationships with organizations. For more details, check out<a href="http://www.greenid.com.au/howitworks/index.html"> this webpage </a>from the greenID verification service that they provide together with a partner.</p>
<p>The photo with this  blog post is the award itself. The artist is Alexandra Veneman (from Ommen in NL, same of the 2010 award). The wave pattern symbolizes that identity if off all times and all areas. The I and the D of course stand for identity. She used the color purple from the Novay logo.</p>
<p>I copied the <a href="http://www.novay.nl/news/edentiti-wins-novay-digital-identity-award/12489">official announcement </a>of the award below.</p>
<h2><span style="color:#ff6600;"><strong>Edentiti wins Novay Digital Identity Award! </strong></span></h2>
<p><strong>The Hague, November 9, 2011 &#8211; At the Identity.Next’11 conference today, the Australian Edentiti has won the Novay Digital Identity Award for the best new concept or product in the field of digital identity. Edentiti provides online identity verification by checking information from various online data sources, and does so under the control of the end user.</strong></p>
<p>Identity verification is the process of verifying if someone is who he or she claims to be. It can be used to prevent identity theft, for age verification where the purchase of alcohol or gambling is concerned and for several other reasons. What the jury found particularly appealing about Edentiti is the efficient and innovative manner in which they rely on existing online identities that a user has, and use these as a basis for identity proofing for new online services. In the system Edentiti offers, individuals can verify their identity by proving they have existing relationships with organizations. Proof is obtained by the individual using the Privacy Principle that says that individuals can ask any organization that might hold personal information on them “Do you have any information about me? Yes or No?”. The number and quality of the “Yes” relationships determine the trust in the verification. Edentiti is also provided through Deloitte Digital under the brand name greenID, addressing Anti-Money Laundering/Counter-Terrorism Financing (AML/CTF) legislation.</p>
<p>Hermen van der Lugt, director of research institute Novay and chairman of the jury: “It is easier for end-users and less expensive for online businesses than traditional face-to-face identity verification approaches. Additionally, Edentiti lets the individual control the whole process of identity verification, which is a big plus, considering the privacy sensitivity.” Edentiti has an approach and business model that allows for incremental growth: in number of users, in number of customers and in the level of trustworthiness of the identity verification. The jury believes that their approach has the potential to be expanded to other countries through partnerships. Organizations which use the system, include Australia Post, the Australian Superannuation Fund and the National Australia Bank. More on Edentiti’s approach can be found at <a href="http://www.edentiti.com">www.edentiti.com</a>.</p>
<p>Apart from Edentiti, three more organizations were nominated for the award. Qiy (<a href="http://www.qiy.com">www.qiy.com</a>) is a Dutch personal data store initiative that provides a secure environment in which a user controls which companies can access his or her information. WAYF (<a href="http://www.wayf.dk">www.wayf.dk</a>), a Danish identity federation, connects over 90 service providers with over 130 identity providers in education, libraries, health care and government (including the NewLog-in national authentication system). WAYF pioneered and contributed to open source with, amongst others, a user consent module, real-time calculation of economic benefits of the federation and a federation administration interface. tiQR (<a href="http://www.tiqr.org">www.tiqr.org</a>) is an open-source and standards-based authentication solution from SURFnet. It uses a mobile phone to scan a QR code that is presented by a webpage, thereby implementing two-factor authentication that is very user friendly.</p>
<p>The award is part of the IDentity.Next’11 conference in The Hague, organized by the IDentity.Next foundation that focuses on developments in digital identity. With the award, IDentity.Next and research based ICT consultancy Novay want to recognize and support new developments and innovations that are shaping the future of digital identity. Co-organizer of the conference is EEMA, Europe&#8217;s leading independent, non-profit e-Identity &amp; Security Association. The conference brings together experts, professionals and industrial parties to discuss the latest developments in the field of digital identity. More information about the award and the jury is available at <a href="http://www.identitynext.eu">www.identitynext.eu</a>.</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity/'>identity</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/299/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/299/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/299/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=299&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/11/10/edentiti-wins-novay-digital-identity-award/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2011/11/novay-digital-identiti-award-2011.png" medium="image">
			<media:title type="html">Novay-Digital-Identiti-Award-2011</media:title>
		</media:content>
	</item>
		<item>
		<title>Nominees Novay Digital Identity Award announced</title>
		<link>http://maarten.wegdam.name/2011/10/26/nominees-novay-digital-identity-award-announced/</link>
		<comments>http://maarten.wegdam.name/2011/10/26/nominees-novay-digital-identity-award-announced/#comments</comments>
		<pubDate>Wed, 26 Oct 2011 15:40:46 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[identity]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=297</guid>
		<description><![CDATA[The submission were quite diverse, and from more different countries than last year. Since it was difficult to narrow it down to intended maximum of three nominees, the jury decided to select four My congratulations to edentiti, Qiy, WAYF and tiQR!! The jury is not done though, the winner still has to be selected among the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=297&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>The submission were quite diverse, and from more different countries than last year. Since it was difficult to narrow it down to intended maximum of three nominees, the jury decided to select four <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  My congratulations to edentiti, Qiy, WAYF and tiQR!! The jury is not done though, the winner still has to be selected among the nominees.</p>
<p>Below the<a href="http://www.novay.nl/news/nominees-novay-digital-identity-award-2011/12476"> &#8216;official&#8217; press release, copied from the Novay website</a></p>
<p><strong>On November 9, one of  four nominees will be granted the Novay Digital Identity Award at the IDentity.Next’11. The nominees for the best new concept or product in the field of digital identity are: the Australian edentiti, the Danish WAYF and the Dutch Qiy and tiQR.</strong></p>
<p>Edentiti (<a href="http://www.edentiti.com/"><span style="text-decoration:underline;">http://www.edentiti.com</span></a>) is an Australian identity proofing system that provides online identity verification by checking information from various online data sources, and does so under control of the user. Qiy (<a href="http://www.qiy.com/"><span style="text-decoration:underline;">http://www.qiy.com</span></a>) is a Dutch personal data store initiative that provides a secure environment in which a user controls which companies can access his or her information.<strong> </strong>WAYF (<a href="http://www.wayf.dk/"><span style="text-decoration:underline;">http://www.wayf.dk</span></a>), a Danish identity federation, connects over 90 service providers with over 130 identity providers in education. WAYF pioneered and contributed to open source with, amongst others, a user consent module, real-time calculation of economic benefits of the federation and a federation administration interface.<strong> </strong>tiQR (<a href="http://tiqr.org/"><span style="text-decoration:underline;">http://tiqr.org</span></a>) is an<br />
open-source and standards-based authentication solution from SURFnet. It uses a mobile phone to scan a QR code that is presented by a webpage, thereby implementing two-factor authentication that is very user friendly.<strong></strong></p>
<p>Most people have one or more digital identities. As we use more online services, this number increases and the question of who knows what about whom becomes increasingly complex. And then there&#8217;s the digital keychain, which yields more annoyance than convenience.  With this award &#8211; IDentity.Next and ICT research institute Novay recognize and support new developments will shape the future of digital identities. The jury is chaired by Herman van der Lugt, Director of Novay. The jury also includes<br />
Ziggur, last year’s winner. Ziggur provides a service that gives users control over what happens to their online identity after their death.</p>
<p>The award is part of the IDentity.Next conference in The Hague, organized by the Identity.Next foundation that focuses on<br />
developments in digital identity. Co-organizer is EEMA, Europe&#8217;s leading independent, non-profit e-Identity &amp; Security Association. The conference brings together experts, professionals and industrial parties to discuss the latest developments in the field of digital identity. More information about the award and the program is available at <a href="http://www.identitynext.eu/"><span style="text-decoration:underline;">www.identitynext.eu</span></a> .</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/identity/'>identity</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/297/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/297/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/297/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=297&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/10/26/nominees-novay-digital-identity-award-announced/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>
	</item>
		<item>
		<title>SIM augmented authentication as alternative for SIM based?</title>
		<link>http://maarten.wegdam.name/2011/10/20/sim-augmented-authentication-as-alternative-for-sim-based/</link>
		<comments>http://maarten.wegdam.name/2011/10/20/sim-augmented-authentication-as-alternative-for-sim-based/#comments</comments>
		<pubDate>Thu, 20 Oct 2011 19:17:07 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[mobile-centric identity]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=282</guid>
		<description><![CDATA[We recently did an assessment of a so-called SIM augmented authentication token, or VASCO&#8217;s new DigiPass Nano product to be more specific. We did this for SURFnet, for which we previously also did an assessment of Mobile PKI. We liked Mobile PKI, but it has a big disadvantage: you depend on your mobile network operator to be able [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=282&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://maartenwegdam.files.wordpress.com/2011/10/dp-nano.jpg"><img class="aligncenter size-full wp-image-285" title="dp-nano" src="http://maartenwegdam.files.wordpress.com/2011/10/dp-nano.jpg?w=450&#038;h=244" alt="" width="450" height="244" /></a></p>
<p>We recently did an assessment of a so-called <em>SIM augmented authentication token,</em> or VASCO&#8217;s new DigiPass Nano product to be more specific. We did this for SURFnet, for which we previously also did<a href="http://maarten.wegdam.name/2010/01/08/mobile-pki-and-mobile-centric-identity/"> an assessment of Mobile PKI</a>. We liked Mobile PKI, but it has a big disadvantage: you depend on your mobile network operator to be able to use it (and in the Netherlands they are not deploying this any time soon). This disadvantage is the main motivation to look at SIM augmented tokens. These are, as the term suggests, added to in stead on being &#8216;inside&#8217; the SIM card.</p>
<p>So what is a <em>SIM augmented</em> authentication token? Physically it is a sticker with an embedded chip that you stick on your SIM card and sits between the SIM card and the mobile phone. The chip stores a secret used for authentication, which is more secure than storing the secret in a &#8216;normal&#8217; mobile app. This secret is used by an authentication application that is also runs from this chip. This application, from the perspective of the mobile phone, appears to be a normal <em><a href="http://en.wikipedia.org/wiki/SIM_Application_Toolkit" target="_blank">SIM application</a></em>, and can work on basically any phone (smart of dumb). The only SIM augmented authentication token that I&#8217;m aware of is the above mentioned  DigiPass Nano from VASCO (let me know if you know of others?). The DigiPass Nano implements an event-based one-time-password functionality, i.e., it generated a new code every time the user asks for it.</p>
<p>We did an assessment of the usability, security and business model aspects. Below I copied the conclusions, but the bottom-line is that we believe from a security perspective this is a good alternative to other one-time-password solutions, and it more secure than solutions implemented as a mobile app. The main benefit is that it works on basically any phone (also non-smartphones), and you you can deploy it without needing help (and investments) from your mobile operator. The main disadvantage is the user experience. We did some limited testing with putting the sticker on, which was ok, but the user experience of getting a one-time-password can be troublesome. It requires the user to find SIM applications on their mobile phone, which are often hidden somewhere deep in the menu&#8217;s. My estimate is that this usability limitation will need to be addressed for this technology to get acceptance beyond specific enterprise use-cases. Or to put it differently, I&#8217;d do very carefull usability optimizations/testing before deploying this to millions of consumers.</p>
<p>This assessment was joint work with my colleague Martijn Oostdijk, see his <a href="http://martijno.blogspot.com/2011/07/digipass-nano.html">blog</a> for more details on especially the security aspect. The full<a href="http://www.surfnet.nl/Documents/rapport_201105_evaluation_vasco_DP_Nano_1_0_0.pdf" target="_blank"> report </a>of our assessment is available via the SURFnet website. If you&#8217;re looking for a wider perspective on the combination of mobile and digital identity, see this previous blog post on our<a href="http://maarten.wegdam.name/2011/04/05/mobile-centric-identity-in-the-identity-next-newsletter/"> mobile-centric identity vision</a>.</p>
<blockquote><p><strong>6 Conclusions</strong></p>
<p>The Digipass Nano uses a form factor that is relatively unique in the authentication token market. It is a SIM augmented token, a thin patch/sticker including an embedded chip that sits between the SIM and the user’s mobile phone. The key advantages of this form factor are:</p>
<ul>
<li>secure storage of credentials under a &#8220;security domain&#8221; that is distinct from the other stake holders (e.g. mobile operators, handset vendors),</li>
<li>while at the same time the ability to use the user-interface of the user’s existing GSM handset,</li>
<li><span style="font-family:Verdana,Verdana;font-size:small;"><span style="font-family:Verdana,Verdana;font-size:small;">and, potentially, the use of the mobile phone’s GSM or 3G network. </span></span></li>
</ul>
<p>As most users will always carry their mobile phone with them, this means that the token will be present during transactions in many different contexts.</p>
<p>The technology underlying SIM augmentation is based on standards that have existed for a long time, are present in billions of GSM handsets around the world, and have proven to be relatively secure given the threat landscape thus far. The DP Nano does not use all features offered by this technology (it only uses the user interface features, not, e.g., the network features present in GSM 11.14). However, a number of variations of the DP Nano exist (see [10], apparently targeting different markets) which do utilise the networking capabilities of the GSM SIM, and which appear to more strongly bind the token to either handset (&#8220;IMEI lock&#8221;) or SIM (&#8220;IMSI lock&#8221;).</p>
<p>On paper, from a technological and security perspective, SIM augmented tokens compare well to other mobile and possession based tokens such as SMS OTP, OTP tokens, mobile soft tokens, and smart cards. As to the security, threats from malware on the handset are minimal as long as the SIM toolkit API interface is properly implemented on the handset.</p>
<p>The user experience may cause some problems for certain groups of users, depending on the issuance and installation process (e.g. whether users are required to install the token themselves). The DP Nano requires the user to navigate through unfamiliar text based menus in order to start up the application when asked by the SP to provide an OTP. This is the most prominent drawback when compared to e.g. the Mobile PKI experience (as described in [8]) where the authentication application on the handset it triggered over the air.</p>
<p>From a business model perspective SIM augmented tokens are interesting as they separate the role of SIM based authentication provider from the role of MNO. Obviously, being the first of its kind and relying on a server side licensing model and proprietary implementation, whether a choice for the DP Nano provides a positive business case when compared to MNO provided SIM based authentication remains to be seen.</p>
<p>Interesting features to add could be:</p>
<ul>
<li>Lock the token to IMSI or IMEI (possible, according to [10])</li>
<li>Use the network to initiate authentication transactions (drawback: implies sending service SMS messages to the token, which may mean cooperation of a MNO or at least per-transaction costs)</li>
<li>Use the network as an OOB channel during an authentication session (e.g. to display transaction details, similar drawback as above)</li>
<li>Use the network to &#8220;blacklist&#8221; a token when a token is reported stolen</li>
<li>Combine SIM augmented solution with a handset resident application to provide a better user experience (may be dependent on operating system and handset to provide installed apps with an API for communication with SIM)</li>
</ul>
<p>The latter option is particularly attractive as a way to enhance the security of SURFnet’s tiqr solution (see [11]) and other mobile app solutions.</p>
<p>Since a one-size-fits-all solution to authentication does not exist, in the end SIM augmented solutions will likely find a market alongside authentication tokens with different form factors.</p></blockquote>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/authentication/'>authentication</a>, <a href='http://maarten.wegdam.name/tag/mobile-centric-identity/'>mobile-centric identity</a>, <a href='http://maarten.wegdam.name/tag/security/'>security</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/282/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/282/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/282/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=282&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/10/20/sim-augmented-authentication-as-alternative-for-sim-based/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>

		<media:content url="http://maartenwegdam.files.wordpress.com/2011/10/dp-nano.jpg" medium="image">
			<media:title type="html">dp-nano</media:title>
		</media:content>
	</item>
		<item>
		<title>Digital identity in the Netherlands: DigiD for consumer-2-business?</title>
		<link>http://maarten.wegdam.name/2011/10/05/digital-identity-in-the-netherlands-digid-for-consumer-2-business/</link>
		<comments>http://maarten.wegdam.name/2011/10/05/digital-identity-in-the-netherlands-digid-for-consumer-2-business/#comments</comments>
		<pubDate>Wed, 05 Oct 2011 18:01:47 +0000</pubDate>
		<dc:creator>Maarten Wegdam</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[business model]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[mobile-centric identity]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[trust framework]]></category>

		<guid isPermaLink="false">http://maarten.wegdam.name/?p=279</guid>
		<description><![CDATA[On Tuesday 4 October we organised a Novay networking event called Tuesday Update, with digital identities as the subject. The main subject of discussion was the need for re-usable identities, and especially who should be the identity provider: government or private parties. This is a hot subject in the Netherlands, also because of the recent [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=279&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>On Tuesday 4 October we organised a Novay networking event called Tuesday Update, with digital identities as the subject. The main subject of discussion was the need for re-usable identities, and especially who should be the identity provider: government or private parties. This is a hot subject in the Netherlands, also because of the recent security incidents (<a href="http://maarten.wegdam.name/2011/09/06/hacks-will-happen-but-the-damage-can-be-less-diginotar/">DigiNotar</a>). Hein Aanstoot, director at <a href="http://www.sivi.org/">SIVI</a>, argued very well that the insurance sector increasingly needs a consumer-2-business identity solution, and would they be allowed to use the national citizin-2-government solution DigiD then this would help insurance companies a lot. This is however not allowed in the Netherlands, and Kees Keuzenkamp from the ministry of Internal Affairs explained the policy developments in this area (NL and EU), including the planned Dutch eID smartcard (called eNIK, <em>elektronische Nederlandse Identiteits Kaart</em>). Bottom-line (in my wording) is that the decision on eNIK will be taken end of this year (after which it goes to parlement) and that it is very unlikely that DigiD/eNIK can be used as a generic consumer-2-business identity solution. Hein Aanstoot also gave some insight into a new initiative with several large insurance companies to create a breakthrough in a re-usable identity for the insurance sector, I think it is good for these insurance companies that they do not make themselves (too) dependent on the government or others (banks). I also presented, and gave my perspectives on consumer-2-business identities, why this is so difficult (privacy, trust etc), the outcomes of our cidSafe project, my views on DigiD (and eHerkenning) and what the role of government should be (especially: solve it or be very clear you&#8217;re not going to do so). I also presented three innovations we are working on that we believe will increasingly become important: user control over their data, mobile-centric identity and context-enhanced authentication/authorization. My presentation is on <a href="http://www.slideshare.net/wegdam/digitale-identiteiten-vertrouwen-identity-providers-en-de-toekomst-novay-tuesday-update-4-oktober-2011">slideshare</a> (dutch!).</p>
<p>&nbsp;</p>
<br />Filed under: <a href='http://maarten.wegdam.name/category/uncategorized/'>Uncategorized</a> Tagged: <a href='http://maarten.wegdam.name/tag/business-model/'>business model</a>, <a href='http://maarten.wegdam.name/tag/identity/'>identity</a>, <a href='http://maarten.wegdam.name/tag/mobile-centric-identity/'>mobile-centric identity</a>, <a href='http://maarten.wegdam.name/tag/privacy/'>privacy</a>, <a href='http://maarten.wegdam.name/tag/trust-framework/'>trust framework</a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/maartenwegdam.wordpress.com/279/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/maartenwegdam.wordpress.com/279/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/maartenwegdam.wordpress.com/279/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=maarten.wegdam.name&amp;blog=9638950&amp;post=279&amp;subd=maartenwegdam&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://maarten.wegdam.name/2011/10/05/digital-identity-in-the-netherlands-digid-for-consumer-2-business/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/14ddd460c4b636c6fda72af4f17206a4?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">maarten</media:title>
		</media:content>
	</item>
	</channel>
</rss>
