150 likes | 176 Views
Secure Identity Management – SIM Raiffeisen Informatik GmbH Adolf Formanek. Not another security issue more!!. More security = less convenience! More or less useless – always one step behind! Where are those useful applications??. What is e-Commerce??. Electronic Banking
E N D
Secure Identity Management – SIMRaiffeisen Informatik GmbHAdolf Formanek
Not another security issue more!! • More security = less convenience! • More or less useless – always one step behind! • Where are those useful applications??
What is e-Commerce?? • Electronic Banking • E-Procurement, e-Billing • Platforms • Portals • Webshops And what is e-Government…….
The Chellenge • How to guarantee services • Processes • Weak spots in the processes for the user and authorisation management • Insufficient level of automation (system breaks) • Storage and Archive • bad data quality • Sessionhandling • Impediment of adaptable and mobile solutions And above all: Security
Ausgangssituation • Existing security gaps in the system access , e.g.: • Use of „Team-Passwords“ • Use of redundant access to different applications (on an average 8-12 min.) • use of "pattern users" for the authorisation assignment for new employees without plausibility cheque are copied to "amassed" rights of existing employees
Lotus Notes Groupware Intranet Phone-System Admission authorisations HR-Management Secure Identity Management –a milestone! • Card and password allow the secure authorised access to all internal applications
Functionality of SIM • Identity-Management: All functions concerning to user management • Single-Sign-On: Functionality for automated registration in systems and applications • Public-Key-Infrastructure:The management of certificates Public Key Infrastructure Identity Management Single-Sign-On
SIM – advantages • unified efficient administration, standardised workflows • Simplified processes for user- administration (user- management, rights etc.) due to authorisation assignment based on roles • Improved data protection and raised data security • Functioning and simple documentation and archiving of legal assignment and completely written logfiles along the prozess-chain • Unified setup • Discharge of routine operations (e.g., password resetting), focus on core operations (efficiency increase) • Transactions are directly connected to authorised persons due to the use of hardwarebased certificates (no Dummy User) • Dataset is permanently cleared and settled which improves data quality with lasting effect
SIM – Advantages from user‘s view • Security is clearly improved combined with simplification (easy Login with card, two-factor authentication, 1 PIN) • The Digital Signature-Card is designed for multiple purpose (Legic Chip, Identity Card) • Easy Handling of integrated security components • Easy authorisation requirement and quick realization of legal assignment • Fast and easy user change - fast application access
Fast and easy user exchange … Konzept Für eine wunderbare Präsentation zum Thema SIM Aöewfnawef iwepfnöawfn öanefwfn
… rapid application access in different workplaces and different locations Konzept Für eine wunderbare Präsentation zum Thema SIM Aöewfnawef iwepfnöawfn öanefwfn
Summary Secury Identity Management • Easy access to all applications and systems for centrally authorised users • Tremendous reductions in administration • Encrease of security within the • More efficiency with enterprise-internal processes • Near to the customer requires more mobility • Customer-related processes will change further on • Competitiveness by trendsetting investments in IT security And: In fact security and convenience fit together!!
Adolf FormanekRaiffeisen Informatik GmbHadolf.formanek@r-it.athttp://www.r-it.at