<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Privacy and Capability Management for the European eIDM Framework</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Mario Reyes</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ignacio Alamillo</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Daniel Chavarri</string-name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Agència Catalana de Certificació</institution>
          ,
          <addr-line>Passatge de la Concepció, 11 08008 Barcelona</addr-line>
          ,
          <country country="ES">Spain</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>S21sec Labs, Parque empresarial La Muga</institution>
          ,
          <addr-line>No11, Planta 1, Oficinas 1 - 6, 31160 Orcoyen</addr-line>
          ,
          <country country="ES">Spain</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>The natural evolution of eGovernment is to go beyond the management of identities and therefore it is necessary to manage people, companies or organizations, and their capabilities to interact with Public Administrations. When developing an application based on an eID management system, this management issue must be tackled within each application (i.e. demonstrate the capability of one person to act, demonstrate the economical reliability, demonstrate his professional status, etc ...) and is normally based on the local jurisdiction. The objective of the present paper is to introduce a distributed system for the privacy-enhanced management of the capabilities associated to a person within the EU framework, independently from the origin and destination EU member state. The core of this system is the intelligence of the Capabilities Resolution Nodes (CRN) to cope with the complexity of the capability resolution and the capability sources discovery in the pan-European scenario. A European Capacity Resolution Network will be able to grow up the interoperability of the digital identities provided and valid in each member state and will answer the question “is this person, identified with this digital identity and who is described by those attributes, allowed to carry out this legal act in this country according to its law?”.</p>
      </abstract>
      <kwd-group>
        <kwd>privacy-enhanced tools</kwd>
        <kwd>attribute management</kwd>
        <kwd>legal roles</kwd>
        <kwd>ontologies</kwd>
        <kwd>semantic web</kwd>
        <kwd>electronic government</kwd>
        <kwd>identity management</kwd>
        <kwd>interoperability</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1 Introduction</title>
      <p>In today’s Europe citizens are free to work and re-locate within the Union. Enterprises
trade and carry out business across the Union. When citizens and enterprises do this
they frequently have to interact with national public administrations. Member States
are currently putting in place eGovernment1 strategies that will allow such
1 EGovernment seeks to use information and communications technologies to improve the
quality and accessibility of public services. It can reduce costs for businesses and
administrations alike, and facilitate transactions between administrators and citizens. It also
interactions to take place electronically. In parallel, they are frequently improving
their business processes and the way in which business with citizens and enterprises is
carried out. However, there is a risk that that the development of government
eservices may inadvertently result in the erection of barriers to the continued
development of the single market and the associated freedoms of movement. This
would happen if citizens and enterprises that need to interact electronically with a
national public administration other than their own were unable do so. For enterprises
it could mean a relative loss of competitiveness, and for citizens increased costs. For
Europe it could mean that the development of the single market and the associated
four freedoms is hampered or even blocked.</p>
      <p>Full-scale implementation of eGovernment raises difficult issues. These include:
• Safeguarding trust and confidence in on-line interaction with governments,
• Widespread access to on-line services so that no digital divide is created,
• Interoperability for information exchange across organizational and national
borders,
o organizational nature, which affect the processes and the collaboration
between the administrations;
o semantic nature, which is not limited to the interconnectivity of
information resources, but also extends to the area where information can
be interpretable by automatic and consequently re-usable forms of
software applications that did not take part in the information resources’
creation;
o technical nature, which is the most direct form of interconnection of
applications through diverse technological components; in particular, the
development and ubiquity of the Internet technologies, on the base of
standards and open specifications that are universally accepted have
allowed for a high degree of technical interoperability.
• Advancing pan-European services that support mobility in the Internal Market
and European Citizenship.</p>
      <p>In this context, privacy laws impose strict controls on the interchange of personal
information, an issue which is specially delicate when the information to interchange
is identity information or, in our case, capabilities information, such as authorizations,
delegations, powers of attorney and the representation of minors or incapables</p>
      <sec id="sec-1-1">
        <title>1.1 The current scenario for capabilities management</title>
        <p>When developing an application (business application, public procurement
application ...) based on an eID management system, each application must develop
the capability logics (i.e. demonstrate the capability of one person to act, demonstrate
the economical reliability, demonstrate his professional status, etc ...), logic which is
usually connected to legal theory in a concrete local jurisdiction. The present reality is
helps to make the public sector more open and transparent and governments more
understandable and accountable to citizens.
that we negotiate the connection with the information sources locally in personalized
scenarios and manage these “attributes” inside that application. Each change in the
applied philosophy or in regulations implies the re-development of the application to
adapt it to these new environmental conditions, even if the final logic of the
application has not changed at all.</p>
        <p>Moreover, when we are facing a pan-European or wider scenario, the complexity to
build an application intelligent enough to deal with other ID attributes and
information sources is enormous (who hosts that info? How can it be provided? How
to understand and manage the relevant information?,...). Furthermore there are
potential legal issues to be solved: roles and mandates are not homogeneous
throughout Europe, privacy laws must be respected in both member states and so
forth.</p>
        <p>As an example, in a current real e-procurement scenario, if a company want to access
a public procurement process in another member state, the representative will be able
to identify himself (with current Identity Management technology/infrastructure) but
his capability to act as a representative of that company has to be proved also ;…
perhaps he will be able to do it locally (in his member state identity), but when trying
to solve this for another member state he will be asked for registration of his
capability to act as a representative in the destination member ’s state system. …The
conclusion is that he will have to go through all the physical procedures in the
destination member state to be inscribed as a potential user of the system The normal
situation nowadays is that every company must be inscribed in on-line registers
(registration that must comply with national laws and thus must be done locally) in
every member state (27 times the same procedure).</p>
        <p>The actual research challenge should not be aimed towards the integration and
deployment of the identity management technologies that are currently in the
standardization process, but it should be a step further, focusing on the real-world
management of identity management contents (capabilities resolution) and the use of
people management contents.</p>
        <p>Moreover, it is of paramount importance to consider the privacy issue, as law requires
that personal identifiable information must be under control of its owner. Some of the
current proposed models of eGovernment initiatives do no consider the citizen as an
active actor of the system, but just as an object about which different Public
Administrations interchange data: these models present some potential deficiencies to
comply with the privacy laws, and as a consequence may not be fully applied to the
capabilities resolution domain.</p>
        <p>On the contrary, the model we propose do consider the citizen as the actor that
controls the capability information that she wants to share with one or more Public
Administrations, in her local jurisdictions or along the network.</p>
      </sec>
    </sec>
    <sec id="sec-2">
      <title>The proposed system</title>
      <p>The main objective of the research work is the creation of a distributed system for the
management of the capabilities associated to a person (a person is a set of one or more
identities) within the EU framework independently from the origin and destination
EU member state. This platform will integrate an intelligent system for arbitrating and
routing the process flow needed for the capabilities resolution.</p>
      <p>The solution is an intelligent system that releases the final application from the
complex logic associated with the capability management in a pan-European
framework. This simplifies the creation of the final application for businesses and
eGovernment applications and at the same time will allow end users (EU citizens) to
not only identify themselves in all member states (nowadays this is a fact) but also to
be able to act in other member states. Moreover, the system will be a key tool for the
citizen to be able to control the attributes and capabilities associated to his set of
identities, which is a sound strategy to comply with privacy regulations and to
generate user confidence.</p>
      <p>The platform will allow any EU citizen in any EU member state to perform private
and public procedures, whilst the capabilities resolution will take place in the
credentials’ origin country if the user has agreed to such a use of his identities. The
result will be a real teleprocessing of administrative procedures in the EU framework.
Moreover, the system will comply with the legislative framework in the field of
privacy of personal data in each EU member state, as the information will not flow
through the network without explicit user consent. Each origin member state will
resolve the capabilities of a user in the same member state. This approach will follow
the EC eGovernment Unit Roadmap design criteria, which state that the
panEuropean eIDM system must be 'federated in a policy sense'; in other words, this
means that administrations mutually trust each other's identification and
authentication methods, on the basis that they were considered acceptable by the
originating administration.</p>
      <p>At this stage of the research, the Catalan Certification Agency is leading the
development of a platform for the management of capabilities in Catalonia, called
Project PASSI, with the full set of functionality but limited in the scope to the Spanish
law. At the moment, the first set of connectors are being developed, to allow a citizen
to acquire and share her capabilities registered by Notaries (powers of voluntary
representation) with the Catalan Public Administrations adhered to the system, using
the interconnection infrastructure offered by the public administrations consortium
AOC.
2.1</p>
      <sec id="sec-2-1">
        <title>The proposed architecture</title>
        <p>The system proposed does not consist in the network itself (that will follow a
federated model and will be based on previous research work) but on the intelligence
of the Capabilities Resolution Nodes (CRN) to cope with the complexity of the
capability resolution and the capability sources discovery in the pan-European
scenario (figure 1).</p>
        <p>For this purpose the following modules are developed:
• A semantic model to provide the necessary knowledge for the resolution of
capabilities. The system should be capable of addressing the appropriate
capabilities provider for the resolution of a specific capability.
• An expert system that will learn how to resolve the capabilities for a specific
purpose, using machine learning technologies and intelligent agents.
• A conceptual taxonomy service able to map between roles and procedures in
different domains (European, national, regional, local).
• Interfaces for the management, administration and communication between
the platform providers, both service providers, identity providers and
capacity providers. Similarly they are had to include the interfaces necessary
to integrate the CRNs in the TESTA network.</p>
      </sec>
      <sec id="sec-2-2">
        <title>2.2 Standards and related work</title>
        <p>The Project relies on current Identity Management Technologies, most of which are in
the process of being standardized:
• The XACML standard for resources access control, modified in order to
include the capability resolution and to allow this resolution to be made in a
distributed way.
• The SAML standard as a base to request identity and attribute information
related to a given user.
• The Liberty Alliance standard, further analyzed to define the trust and security
model for the capabilities federation.
• The federation concept becomes crucial to the concepts of association of
identities and pan-European networks of identities. Only in this form is the
citizen able to efficiently manage his personal character data.
• The platform is SOA based. Research is needed in this field for the definition
and study of the workflows for the presented scenario, establishing a set of
recommendations in the web services development phases for the public
administrations.</p>
      </sec>
    </sec>
    <sec id="sec-3">
      <title>3 Conclusion</title>
      <p>The major contribution will not be Identity Management, but the capability and
content management associated to an identity in an EU framework.</p>
      <p>• Ontology and semantics are able to provide knowledge to the building blocks
of the distributed intelligent manager. This is the main research block as, on
the one hand it is mandatory to represent the semantic models of the member
states laws as well as the EU directives, and on the other hand these models
must represent the semantic relationship between all the EU legislation.
• The capability resolution intelligent manager will include the logic required to
increase its knowledge while it continues resolving the assigned tasks
(intelligent agents and machine learning). It must be capable of discovering
where to direct its consultation to, so that a certain capacity is resolved.
• Information security in every area: access, authorization, information flow,
personal data protection, citizen rights and audit. The recommendations
coming from this project will be valid for the small administration as well as
for large corporative administrations; different recommendation levels will
be used to address all relevant stakeholders.
• The resulting system is a privacy enhancing tool (PET) in which the end user
can manage his identities, his information, his personal character data,
knowing at any moment where these data are and who has access to them.
Furthermore, the provision of explicit access control to identity data by the
user. As a consequence, the end user is able to share and to control the use of
his attributes and consequently his capabilities.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <given-names>Ignacio</given-names>
            <surname>Alamillo</surname>
          </string-name>
          , Xavier Urios:
          <article-title>La Gestión de identidades y capacidades por las administraciones públicas</article-title>
          .
          <source>TECNIMAP</source>
          .
          <string-name>
            <surname>Sevilla</surname>
          </string-name>
          (
          <year>2006</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <given-names>Ignacio</given-names>
            <surname>Alamillo</surname>
          </string-name>
          :
          <article-title>Beyond identity management: capabilities management as a Public Administration simplification technique</article-title>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <article-title>Consultation document for a future policy paper on pan-European Government eServices</article-title>
          . http://ec.europa.eu/enterprise/consultations/government_e-services/
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>4. IDABC, European eGovernment Services. http://ec.europa.eu/idabc/</mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5. TESTA:
          <article-title>Trans European Services for Telematics between Administrations</article-title>
          . http://ec.europa.eu/idabc/en/document/2097/
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <given-names>Torsten</given-names>
            <surname>Priebe</surname>
          </string-name>
          , Wolfgang Dobmeier, Nora Kamprath:
          <article-title>Supporting Attribute-based Access Control with Ontologies</article-title>
          .
          <source>ARES</source>
          <year>2006</year>
          :
          <fpage>465</fpage>
          -
          <lpage>472</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <given-names>Kamelia</given-names>
            <surname>Stefanova</surname>
          </string-name>
          , Dorina Kabakchieva:
          <article-title>User involvement in identity management e-Government architecture Development</article-title>
          .
          <source>Proceedings from workshop on User Involvement in e-Government development projects. September</source>
          <volume>12</volume>
          , at Interact 2005 in Rome, Italy. http://www.effin.org/egov-workshop_proceedings.html
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Jena</surname>
          </string-name>
          (
          <year>2002</year>
          ).
          <article-title>The jena semantic web toolkit</article-title>
          , http://www.hpl.hp.com/semweb/ienatop.html, Hewlett-Packard Company.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Jena</surname>
          </string-name>
          (
          <year>2005</year>
          ).
          <article-title>Jena - A Semantic Web Framework for Java</article-title>
          , http://jena.sourceforge.net/
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>RDQL</surname>
          </string-name>
          (
          <year>2005</year>
          ).
          <source>Jena RDQL</source>
          , http://jena.sourceforge.net/RDOL/
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Protégé</surname>
          </string-name>
          (
          <year>2005</year>
          ). Protégé, Stanford Medical Informatics.
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Protégé-API</surname>
          </string-name>
          (
          <year>2006</year>
          ). The
          <string-name>
            <surname>Protégé-OWL API - Programmer's Guide</surname>
          </string-name>
          , http://protege.stanford.edu/plugins/owl/api/guide.html
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>13. Liberty Alliance Project. http://www.projectliberty.org/</mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>