20150730 - Meeting minutes, Thursday, July 30th, 2015 - OpenNCP integration with eID
OpenNCP integration with eID
Estimated - 14:00 to 14:30 CEST
Performed - 13:00 to 14:30 CEST
AGENDA
a) Progress monitoring towards LARMS stable release;
b) Progress monitoring towards LARMS integration into OpenNCP bundle and release;
c) Early preparations for 2.3.0-RC1 (includes LARMS and other bug fixes - made since last release)
d) AOB: Scheduling f next meting, preferably during next week.
LOCATION
- Wiki+ WorkBench + AdobeConnect
Development Board: https://openncp.atlassian.net/secure/RapidBoard.jspa?rapidView=1
AdobeConnect:
http://ec-wacs.adobeconnect.com/openncp/
Room Passcode: ask @Rui Alves (Unlicensed) or @markus.kalliola
----------------
If you have never attended an Adobe Connect meeting before:
Test your connection: http://ec-wacs.adobeconnect.com/common/help/en/support/meeting_test.htm
Get a quick overview: http://www.adobe.com/products/adobeconnect.html
Adobe, the Adobe logo, Acrobat and Adobe Connect are either registered trademarks or trademarks of Adobe Systems Incorporated in the United States and/or other countries.
----------------
PARTICIPANTS
Today's Meeting Participants:
Alexandre Santos <alexandre.santos@spms.min-saude.pt>
João Gonçalves <joao.cunha@spms.min-saude.pt>
Jerome Subiger <jerome.subiger@ext.ec.europa.eu>
Michele Foucard <Michele.FOUCART@ext.ec.europa.eu>
Massimiliano Masi <massimiliano.masi@tiani-spirit.com>
Robert Scharinger <Robert.Scharinger@bmg.gv.at>
Sören Bittins <soeren.bittins@fokus.fraunhofer.de>
Invited Members List:
Tomé Vardasca <tome.vardasca@spms.min-saude.pt>
Ioannis Petrakis <petrakis@ics.forth.gr>
(Holidays) Rui Alves <rui.alves@spms.min-saude.pt>,
(Holidays) Licinio Mano <licinio.mano@spms.min-saude.pt>,
(Holidays) Stéphane Spahni <stephane.spahni@hcuge.ch>,
Kostas Karkaletsis <k.karkaletsis@gnomon.com.gr>,
Daniele Crespi <Daniele.Crespi@lispa.it>,
(Holidays) Markus Kalliola <markus.kalliola@ec.europa.eu>,
MEETING NOTES
0. Overview
1. Relevant Documentation (What's gathered so far)
The eID approach: The different levels
Level (Requirements) | Mode | Pilot | Action by Pat | Attributes |
|
|---|---|---|---|---|---|
Level 0 | Manual input in the portal. | epSOS | Minimum D3.6.2 |
|
|
Level 1 (disconnected mode possible) | LARMS | ?? (eSENS eHeath OpenNCP 2.3.0 – floting componento any portal | Pat gives card, does not type; | Surname given name gender unique (health) identifier; Varies with each country* | RISK: not 100% sure individual ID |
Level 3 (connection to internet and to Country A is needed/national PKIs via centraized service) | LAMb+Pat action |
| Patient confirms (mobile key; Pins of the card) |
| Allows “signed consent” Authetication is possible |
Level 4 (Does not use local functions of the card, uses online “information”; access to PEP) | DCA Distributed CrossB Authentication | Stork II | Patient confirms (mobile key; Pins of the card) in a PC at the PoCare) | (atributes in the “assertion are the key issue”) | Confirms with National PKI everything; Confirmes eIDAS. |
Level 5 | .Advanced Mobile APP solution (AMAPP) |
| Use their mobile phone for full autentication without card need |
|
|
According to @Soeren Bittins comment "Liferay workflow (WorkFlow Manager) and session handling will be a problem. As an example, the same TRC can be used several times because it is cached on the Liferay. Another example is the Liferay orchestration of the business which is a security problem also".
It can be configured / redeveloped this part of portal and a new TRC tp be created on each request and the last one used to be invalidated (deleted from session). On the other hand the trc by design has validity time duration and thus it could be used the same for several requests