Mon Service Public - Case study and Mapping to SAML/Liberty specifications. Gaël Gourmelen - France Telecom 23/04/2007



Documents pareils
DOCUMENTATION - FRANCAIS... 2

Application Form/ Formulaire de demande

MELTING POTES, LA SECTION INTERNATIONALE DU BELLASSO (Association étudiante de lʼensaparis-belleville) PRESENTE :

Editing and managing Systems engineering processes at Snecma

DOCUMENTATION - FRANCAIS... 2

Instructions Mozilla Thunderbird Page 1

calls.paris-neuroscience.fr Tutoriel pour Candidatures en ligne *** Online Applications Tutorial

How to Login to Career Page

France SMS+ MT Premium Description

Forthcoming Database

Instructions pour mettre à jour un HFFv2 v1.x.yy v2.0.00

Acce s aux applications informatiques Supply Chain Fournisseurs

DOCUMENTATION MODULE BLOCKCATEGORIESCUSTOM Module crée par Prestacrea - Version : 2.0

APPENDIX 2. Provisions to be included in the contract between the Provider and the. Holder

English Q&A #1 Braille Services Requirement PPTC Q1. Would you like our proposal to be shipped or do you prefer an electronic submission?

First Nations Assessment Inspection Regulations. Règlement sur l inspection aux fins d évaluation foncière des premières nations CONSOLIDATION

Gestion des autorisations / habilitations dans le SI:

DOSSIER DE CANDIDATURE APPLICATION FORM

La gestion de l'identité en ligne

LOI SUR LA RECONNAISSANCE DE L'ADOPTION SELON LES COUTUMES AUTOCHTONES ABORIGINAL CUSTOM ADOPTION RECOGNITION ACT

Compléter le formulaire «Demande de participation» et l envoyer aux bureaux de SGC* à l adresse suivante :

RAPID Prenez le contrôle sur vos données

Cheque Holding Policy Disclosure (Banks) Regulations. Règlement sur la communication de la politique de retenue de chèques (banques) CONSOLIDATION

UNIVERSITY OF MALTA FACULTY OF ARTS. French as Main Area in an ordinary Bachelor s Degree

FCM 2015 ANNUAL CONFERENCE AND TRADE SHOW Terms and Conditions for Delegates and Companions Shaw Convention Centre, Edmonton, AB June 5 8, 2015

1.The pronouns me, te, nous, and vous are object pronouns.

Once the installation is complete, you can delete the temporary Zip files..

0,3YDQGLWVVHFXULW\ FKDOOHQJHV 0$,1²0RELOLW\IRU$OO,31HWZRUNV²0RELOH,3 (XUHVFRP:RUNVKRS %HUOLQ$SULO

Règlement sur le télémarketing et les centres d'appel. Call Centres Telemarketing Sales Regulation

Formulaire d inscription (form also available in English) Mission commerciale en Floride. Coordonnées

English version Legal notice

Présentation par François Keller Fondateur et président de l Institut suisse de brainworking et M. Enga Luye, CEO Belair Biotech

RULE 5 - SERVICE OF DOCUMENTS RÈGLE 5 SIGNIFICATION DE DOCUMENTS. Rule 5 / Règle 5

Module Title: French 4

en SCÈNE RATIONAL Rational Démonstration SDP : automatisation de la chaîne de développement Samira BATAOUCHE sbataouche@fr.ibm.com

affichage en français Nom de l'employeur *: Lions Village of Greater Edmonton Society

AMENDMENT TO BILL 32 AMENDEMENT AU PROJET DE LOI 32

PIB : Définition : mesure de l activité économique réalisée à l échelle d une nation sur une période donnée.

Les Portfolios et Moodle Petit inventaire

Quatre axes au service de la performance et des mutations Four lines serve the performance and changes

CEPF FINAL PROJECT COMPLETION REPORT

Paxton. ins Net2 desktop reader USB

Gestion des prestations Volontaire

Improving the breakdown of the Central Credit Register data by category of enterprises

AIDE FINANCIÈRE POUR ATHLÈTES FINANCIAL ASSISTANCE FOR ATHLETES

Nouveautés printemps 2013

THÈSE. présentée à TÉLÉCOM PARISTECH. pour obtenir le grade de. DOCTEUR de TÉLÉCOM PARISTECH. Mention Informatique et Réseaux. par.

NOM ENTREPRISE. Document : Plan Qualité Spécifique du Projet / Project Specific Quality Plan

SERVEUR DÉDIÉ DOCUMENTATION

that the child(ren) was/were in need of protection under Part III of the Child and Family Services Act, and the court made an order on

Academic Project. B2- Web Development. Resit Project. Version 1.0 Last update: 24/05/2013 Use: Students Author: Samuel CUELLA

Form of Deeds Relating to Certain Successions of Cree and Naskapi Beneficiaries Regulations

Interest Rate for Customs Purposes Regulations. Règlement sur le taux d intérêt aux fins des douanes CONSOLIDATION CODIFICATION

Les technologies de gestion de l identité

Secrétaire générale Fédération Internationale du Vieillissement Secretary general International Federation on Ageing Margaret Gillis Canada

Credit Note and Debit Note Information (GST/ HST) Regulations

GEIDE MSS /IGSS. The electronic document management system shared by the Luxembourg

lundi 3 août 2009 Choose your language What is Document Connection for Mac? Communautés Numériques L informatique à la portée du Grand Public

Exercices sur SQL server 2000

TABLE DES MATIERES A OBJET PROCEDURE DE CONNEXION

Archived Content. Contenu archivé

de stabilisation financière

ETABLISSEMENT D ENSEIGNEMENT OU ORGANISME DE FORMATION / UNIVERSITY OR COLLEGE:

Comprehensive study on Internet related issues / Étude détaillée sur les questions relatives à l Internet. November/Novembre 2014

Cedric Dumoulin (C) The Java EE 7 Tutorial

22/09/2014 sur la base de 55,03 euros par action

IPSAS 32 «Service concession arrangements» (SCA) Marie-Pierre Cordier Baudouin Griton, IPSAS Board

Loi sur la Semaine nationale du don de sang. National Blood Donor Week Act CODIFICATION CONSOLIDATION. S.C. 2008, c. 4 L.C. 2008, ch.

This is a preview - click here to buy the full publication NORME INTERNATIONALE INTERNATIONAL STAN DARD. Telecontrol equipment and systems

Comprendre l impact de l utilisation des réseaux sociaux en entreprise SYNTHESE DES RESULTATS : EUROPE ET FRANCE

PeTEX Plateforme pour e-learning et expérimentation télémétrique

Quick Start Guide This guide is intended to get you started with Rational ClearCase or Rational ClearCase MultiSite.

Règlement relatif à l examen fait conformément à la Déclaration canadienne des droits. Canadian Bill of Rights Examination Regulations CODIFICATION

Integrated Music Education: Challenges for Teaching and Teacher Training Presentation of a Book Project

Practice Direction. Class Proceedings

UNIVERSITE DE YAOUNDE II

DOCUMENTATION - FRANCAIS... 2

Deadline(s): Assignment: in week 8 of block C Exam: in week 7 (oral exam) and in the exam week (written exam) of block D

Disclosure on Account Opening by Telephone Request (Trust and Loan Companies) Regulations

Rountable conference on the revision of meat inspection Presentation of the outcome of the Lyon conference

CURRENT UNIVERSITY EDUCATION SYSTEM IN SPAIN AND EUROPE

ONTARIO Court File Number. Form 17E: Trial Management Conference Brief. Date of trial management conference. Name of party filing this brief

3615 SELFIE. HOW-TO / GUIDE D'UTILISATION

Contrôle d'accès Access control. Notice technique / Technical Manual

setting the scene: 11dec 14 perspectives on global data and computing e-infrastructure challenges mark asch MENESR/DGRI/SSRI - France

COUNCIL OF THE EUROPEAN UNION. Brussels, 18 September 2008 (19.09) (OR. fr) 13156/08 LIMITE PI 53

et Active Directory Ajout, modification et suppression de comptes, extraction d adresses pour les listes de diffusion

AUDIT COMMITTEE: TERMS OF REFERENCE

Tammy: Something exceptional happened today. I met somebody legendary. Tex: Qui as-tu rencontré? Tex: Who did you meet?

Bill 69 Projet de loi 69

VTP. LAN Switching and Wireless Chapitre 4

Natixis Asset Management Response to the European Commission Green Paper on shadow banking

iqtool - Outil e-learning innovateur pour enseigner la Gestion de Qualité au niveau BAC+2

Innovation in Home Insurance: What Services are to be Developed and for what Trade Network?

Contents Windows

donor which means an individual person who makes a charitable contribution to The Playhouse or one of its Clients;

THE LAW SOCIETY OF UPPER CANADA BY-LAW 19 [HANDLING OF MONEY AND OTHER PROPERTY] MOTION TO BE MOVED AT THE MEETING OF CONVOCATION ON JANUARY 24, 2002

Logitech Tablet Keyboard for Windows 8, Windows RT and Android 3.0+ Setup Guide Guide d installation

POLICY: FREE MILK PROGRAM CODE: CS-4

Préconisations pour une gouvernance efficace de la Manche. Pathways for effective governance of the English Channel

Transcription:

Mon Service Public - Case study and Mapping to SAML/Liberty specifications Gaël Gourmelen - France Telecom 23/04/2007

Agenda Brief presentation of the "Mon Service Public" project (main features) Detailed use-cases : SSO and Federation Attribute sharing Liberty flows Focus on "Mon Service Public" specificities regarding Liberty Alliance specifications or implementations of these specifications (products)

1. Central Access Point A personalized portal mon.service-public.fr will enable every citizen to set up his or her own home page to access all the online public services of concern to him or her. Users will thus be able to access all their official paperwork.

Global Identity Management Solution based on Liberty Alliance specifications Identity Federation, no Unique Identifier 1. Central Access Point 2. Single Sign On One MSP account / several authentication ways (user / pwd, SMS challenge, certificates) smartcard) e-id means M DUPONT Other e-id MME DURAND Federation with different kinds of egov accounts MSP Account Dupont Account Durand Services provided by public sectors Health Care Refund Personal account M Dupont- N 85651 Job agency Researches Personnal account N 15646746 Tax administration Tax account Family account Durand - N 654832 Seamless adm Changement d adresse Procedure Id N 694125

1. Central Access Point 2. Single Sign On 3. Personal Data Storage and Exchange An e-safe / briefcase to store personal data and dematerialized official documents (diplomas, civil register certificates, etc ) which the user can obtain from the civil service and submit to the authorities to complete other procedures.

A Dashboard to give the end user a unified perception of his / her interactions with public services : messaging, documents, information... Mon EMPLOI travail Démarches Actualités Informations Accueil > Emploi Démarches ANPE Espace recherche d emploi Cpt Robert xx Actualités Handicap : semaine de l emploi du 13 au 19 novembre Insertion 8/11/2006 1. Central Access Point 2. Single Sign On 3. Personal Data Storage and Exchange 4. Focal Communication Center Offres emploi Mes démarches emploi Suivi des convocations ANPE Espace recherche d emploi Nouveau barème de calcul des indemnités ANPE Employeur ASSEDIC www.anpe.fr www.anpe.fr www.anpe.fr www.assedic.fr Instituts régionaux d administration : concours 2006 Recrutement 6/11/2006 Guide Information + toute l actualité emploi Recherche d emploi Assurance chômage Aide à la reprise d activité Formation des demandeurs d emploi Emploi, travail Formation Retraite Emploi et handicap + toute l information emploi Documents Texte présentant les types de documents (fiches de paie, attestation ASSEDIC,etc. ) Mes documents Mon état civil Mon adresse Mon bloc note >> Accéder à mes documents

Agenda Brief presentation of the "Mon Service Public" project (main features) Detailed use-cases : SSO and Federation Attribute sharing Liberty flows Focus on "Mon Service Public" specificities regarding Liberty Alliance specifications or implementations of these specifications (products)

Use-cases: SSO & Federation The SSO and Federation processes can be both initiated from "Mon Service Public" portal (dashboard) or from "partner site" : Mon EMPLOI travail Démarches Actualités Informations Accueil > Emploi Démarches ANPE Espace recherche d emploi Cpt Robert xx Actualités Handicap : semaine de l emploi du 13 au 19 novembre Insertion 8/11/2006 Offres emploi Mes démarches emploi Suivi des convocations ANPE Espace recherche d emploi Nouveau barème de calcul des indemnités ANPE Employeur www.anpe.fr www.anpe.fr Instituts régionaux d administration : concours 2006 Recrutement 6/11/2006 Guide Information + toute l actualité emploi Recherche d emploi Assurance chômage Aide à la reprise d activité Formation des demandeurs d emploi Emploi, travail Formation Retraite Emploi et handicap + toute l information emploi ASSEDIC www.anpe.fr www.assedic.fr Documents Texte présentant les types de documents (fiches de paie, attestation ASSEDIC,etc. ) Mes documents Mon état civil Mon adresse Mon bloc note >> Accéder à mes documents

Use-cases: SSO & Federation The kinematics are the same in both cases (if initiated from the dashboard, the user is first redirected to the "partner site" SP). Principal Portal/Dashboard IDP SP <lib:authnrequest> Initiate SSO or Federation Process (with requested authentication context) Authentication of the principal (if necessary) artifact <samlp:request> <samlp:response>

Use-cases: SSO & Federation Standard use of the Liberty Alliance ID-FF specifications (ID-FF 1.2) with however the following specificities: Requirement: One single account on the "Mon Service Public" portal (IDP) can be federated with multiple accounts on SP side. The Liberty Alliance ID-FF specifications do not prevent the implementation of this requirement but in that case the "link" between the multiple accounts at a same SP is established and maintained on SP side only (as according to ID-FF specifications, for one single account on the IDP, only one federation alias is associated to one SP). This was considered as not acceptable (mainly from privacy and user experience standpoints) The decision has been taken to instead support "multi-federation" on IDP side (and thus managing multiple federation aliases on IDP side for one single IDP account and one given SP)

Use-cases: SSO & Federation Démarches This has some impacts on: Management and storage of federations on IDP side. IDP bob@msp ANPE : Alias=123 Index=0 ANPE : Alias=456 Index=1 CAF : Alias=998 Index=0 ANPE Espace recherche d emploi Cpt Robert Offres d emploi 01/02/2007 confirmation inscription! 02/02/2007 Offre d emploi 02/02/2007 Offre d emploi Mes démarches emploi Suivi des convocations xx www.anpe.fr > Archiver cette démarche ANPE Espace recherche d emploi Cpt Sylvie Offres d emploi 01/03/2007 confirmation inscription! xx www.anpe.fr > Archiver cette démarche Mes démarches emploi 01/03/2007 confirmation inscription! Suivi des convocations > Archiver cette démarche SSO & Federation Interfaces exposed by "Mon Service Public" IDP. Specific processing rule associated with the parameter "NameIDPolicy=federated" of a <lib:authnrequest>. Introduction of a new parameter during SSO from the dashboard to enable the IDP to identify the right federation ("FederationIndex").

Use-cases: SSO & Federation SSO from the "Mon Service Public" portal/dashboard: Principal Portal/Dashboard IDP SP FederationIndex <lib:authnrequest> + FederationIndex Initiate SSO process (with requested authentication context) Authentication of the principal (if necessary) artifact <samlp:request> <samlp:response>

Use-cases: Attribute sharing The partner sites (SPs/WSCs) will rely on the Liberty Alliance ID-WSF framework to query the principal's e-safe / briefcase (SP/WSP) to provide the following features: Automatic form filling (and update) Retrieval of dematerialized documents that can be needed to complete the procedures at these partner sites

Use-cases: Attribute sharing Principal IDP DS WSP SP/WSC WSP The user wants to auto-fill the form or attach a document to the current procedure ID-FF one-time federation flows (redirection) if needed <disco:query> <idwsf:query> ID-WSF 1.1 Interaction Service <idwsf:query>

Use-cases: Attribute sharing Again, this is a standard use of the Liberty Alliance specifications (ID-WSF 1.1). Just wanted to highlight the two following points: The ID-WSF framework is not only used to exchange attributes or profile data but also documents (binary content). The interaction with the principal (through the "ID-WSF 1.1 Interaction Service" protocol) is not only used to collect consent but also to select the document to be exchanged.

Use-cases: Others Some other interesting use-cases exist, related to: Inter-COT (IDP to IDP federation with bi-directional SSO) People Service (contacts)

Thank you!