20150219 - Meeting minutes, Thursday February 19th, 2015 - OpenNCP Community: Dev meeting
OpenNCP Community: Weekly meeting
19th February 13:30 to 14:00 CET
AGENDA
a) Non-Repudiation BB development progress;
b) Non-Repudiation BB integration with OpenNCP;
c) Non-Repudiation BB test plans.
LOCATION
- Wiki+ WorkBench + GoToMeeting
Support Board: https://openncp.atlassian.net/secure/RapidBoard.jspa?rapidView=2e
Development Board: https://openncp.atlassian.net/secure/RapidBoard.jspa?rapidView=1
GoToMeeting:
PARTICIPANTS
Today's Meeting Participants:
@Licinio Kustra Mano <licinio.mano@spms.min-saude.pt>,
@Rui Alves (Unlicensed) <rui.alves@spms.min-saude.pt>,
Markus Kalliola <markus.kalliola@ec.europa.eu>,
@Kostas Karkaletsis <k.karkaletsis@gnomon.com.gr>,
@Massimiliano Masi <massimiliano.masi@tiani-spirit.com>,
Heiko Zimmermann <Heiko.Zimmermann@agence-esante.lu>,
Stéphane Spahni <stephane.spahni@hcuge.ch>,
Konstantin Hypponen <konstantin.hypponen@kela.fi>,
(not able to attend) @Marko Peric <marko.peric@hzzo.hr>,
(not able to attend) @Isabel Cruz <isabel.cruz@iuz.pt>,
Invited Members List:
@Rui Pinto (Unlicensed) <rui.pinto@spms.min-saude.pt>,
Ioannis Petrakis <petrakis@ics.forth.gr>,
Ljubi Igor <Igor.Ljubi@hzzo.hr>,
Alen Vrecko <Alen.Vrecko@nijz.si>,
Alexander Berler <a.berler@gnomon.com.gr>,
Marcello Melgara <Marcello.Melgara@cnt.lispa.it>,
Gwenaelle Quivy <Gwenaelle.QUIVY@ext.ec.europa.eu>
Marcelo Fonseca <marcelo.fonseca@iuz.pt>,
Michele Foucard <Michele.FOUCART@ext.ec.europa.eu>,
Gottfried Heider <gottfried.heider@ehealthcon.at>,
Ivo Pinheiro <ivo.pinheiro@iuz.pt>,
Juergen Wehnert <juergen.wehnert@gematik.de>,
Dimitrios G. Katehakis <katehaki@ics.forth.gr>,
Olaf Rode <olaf.rode@fokus.fraunhofer.de>,
Thomas Fleischmann <thomas.fleischmann@bmg.gv.at>,
Robert Scharinger' <Robert.Scharinger@bmg.gv.at>,
Agius Muscat Hugo at MEH-IMU-Health <hugo.agius-muscat@gov.mt>,
Kenn Schultz Nielsen <KSN@ssi.dk>,
Sören Bittins <soeren.bittins@fokus.fraunhofer.de>,
Gareth Woodham <Gareth.Woodham@ehalsomyndigheten.se>,
Fredrik Linden <fredriklinden1@gmail.com>,
Karima Bourquard <karima.bourquard@ihe-europe.net>,
Samuel Danhardt <Samuel.Danhardt@agence-esante.lu>,
Giorgio Cangioli <giorgio.cangioli@gmail.com>,
Jussi Lemmetty <jussi.lemmetty@kela.fi>
Aarne Roosi <Aarne.Roosi@affecto.com>,
Arnaud Gaudinat <arnaud.gaudinat@hesge.ch>,
Belani Hrvoje <Hrvoje.Belani@hzzo.hr>,
Gergely Heja <heja.gergely@eski.hu>,
Oskari Kettinen <oskari.kettinen@kela.fi>,
Maarten Festen <maarten.festen@ihe-europe.net>
Mate Beštek <mate.bestek@gmail.com>,
Norbert Repas <norbert.repas@elga.gv.at>,
Patrick Ruch <Patrick.Ruch@unige.ch>,
Tomaz Cebular <Tomaz.Cebular@ivz-rs.si>,
Steen Manniche <steen@manniche.net>,
Catherine Chronaki<chronaki@gmail.com>,
Matic Meglic<matic.meglic@nijz.si>,
Mate Beštek <matebestekpro@gmail.com>,
Merik Seven <seven@nictiz.nl>,
João Francisco Marques <joaof.marques@spms.min-saude.pt>,
Gwenaelle Quivy <Gwenaelle.QUIVY@ext.ec.europa.eu>,
Philippe Loopuyt <Philippe.Loopuyt@ec.europa.eu>,
EXPAND Wp5 <expand-wp5@spms.min-saude.pt>
MEETING NOTES
a) BB development progress
The ATNA are the current specifications. The REM ...
eSENS final Specifications:
ABB - Non Repudiation
SBB - for Health Domain, non repudiation for XCA and XCF transactions audit trail
What are we trying to achieve in order to provide all the evidence:
Witch are the potencial disputes?
Non Repudiation of Origin (NRO), of Receipt (NRR), of Delivery (NRD), and of Submission (NRS)??
Th possible scenario where NCP-A message is forged by and XML writer....
What do we need to protect?
The health care professional data
All the data exchanged
Number of medicines -
Allergies were missing
Witch are the evidences that be collected?
The full request MSG and full response MSG???
What would be the proper solution for storing this data..
Which kind o f content is retrieved by NCP A
The patient signs the assertion on the request message
http://wiki.ds.unipi.gr/display/ESENS/Whitepaper+-+Non+Repudiation
EIDAS
http://ec.europa.eu/digital-agenda/en/trust-services-and-eid
b) Non-Repudiation BB integration with OpenNCP
Extend the audit message, go for full message????
Then, we find a way for NCPs to sign the message....
c) Non-Repudiation BB test plans
ACTIONS NEEDED
today meeting actions
previously identified actions - keep track