Security Requirements and Security Solutions For Community Administrations

Natalia Koneva · NORA - Norwegian Open Research Archives · 2003

The Internet is slowly becoming a mirror of the society. Everything we do in the real world, we want to do out on the Net: conduct private conversations, keep personal papers, sign letters and contracts, shop, publish documents etc. All these things require security, but we go ahead using the net without asking too many questions. Today security issues are not a fundamental starting point. This also means that the limits of security are the limits of the Internet. There are several reasons behind that municipalities should enter the digital world. Firstly, they have to follow the trends citizens will expect them to offer these kinds of services when they meet them elsewhere in their daily life. Secondly, it is clearly more efficient if one could move from double bookkeeping (paper and electronic) to just using bits and bytes, which also will mean that public employees could have time to handle other issues. Thirdly, an electronic system is available 24 hours a day and 365 days a year, which means that you can interact with the Municipality whenever you have the time (also called 7/24-administration). Municipalities in Norway have recently started to use Internet connection as a mean of communication with their residents. There is a need of analysing vulnerable points in this connection in order to better protect the information stored in the municipality, especially if this information should be shared with the inhabitants. In this thesis we have studied threats to the electronic communication and their impact. We have set up requirements for secure communication, which became the basis for our end solution. The main requirement to electronic communication is the use of digital signatures. A digital signature is the main element that makes the electronic communication over Internet secure both for private persons and institutions. It confirms the identity of the other party; ensures that the contents of any document have not been changed in any way; verifies that the document has come from the claimed party and ensures that the original signing party cannot later claim not to have signed. Thus a digital signature provides such security services as authentication, integrity, authenticity and non- repudiation. Public Key Infrastructure (PKI) is the necessary infrastructure for digital signatures. PKI is an infrastructure for a distributed environment that centres on management and distribution of public keys and digital certificates. The main goal of PKI is to make authentication possible. PKI supports electronic signatures and secure communications by providing electronic certificates. A Public Key Certificate (PKC) is a digital document attesting to the identity of the certificate holder and can be used to sign documents electronically.

Read the paper · More papers on PaperTik