Interoperability academy 2024 - Day 3 - Ranchynska Presentation.pdf

SIGMA2013 397 views 30 slides Jun 28, 2024
Slide 1
Slide 1 of 30
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30

About This Presentation

Presentation given at the Cross-regional exchange and learning week on Interoperability and Digital Transformation in the Western Balkans and Eastern Partnership region that took place 24-28 June 2024 in Brussels.


Slide Content

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Liudmyla Rabchynska, former Deputy Minister at Ministry of Digital Transformation of Ukraine
26 June 2024
Cross-regional exchange between
Western Balkan and EaPcountries on
Mutual recognition of
trust services on the case
of Ukraine

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Agenda
1Outlook on Ukrainian Trust Services
2Transformation of Ukrainian eT rust Services
3Pilot for the International Compatibility
4Afterpilot Achievements

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
1
Outlook on Ukrainian Trust
Services

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Outlook on Ukrainian T rust Services
30
QualifiedeTSPsin 2023
20B
qualifiedtime stampsin 2023
27,5M
eSignaturequalifiedcertificates
generatedin 2023
491K
eSealqualifiedcertificates
generatedin 2023

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Outlook on Ukrainian T rust Services
8
QualifiedeTSPs
in 2022
TrustedList was setup
since2023
Ukrainiane-signaturesand
sealscanbeverifiedin EU
memberstates
since2022
Ukraine recognisedtheeTS
ofEU states

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Outlook on Ukrainian T rust Services
CADES
CADES -BES; -T; -C; -X Long
XADES
XADES B-B; B-T; B -LT; B-LTA
PADES
ASIC- e
PADES B-B; B-T; B -LT; B-
LTA

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
2
Transformation of
Ukrainian eT rust Services

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
2017
Law on Trust Services
implementation of eIDASwith partial retaining of Ukrainian previous specifics
2018-2019
Secondary legislation to implement the Law on Trust Services
a vast number of secondary legislation has been adopted to implement the Law on Trust
Services
2019
Ukrainian request to the EU on mutual recognition of electronic trust
servicesand signeddeclarationsofintentionswithLithuania and Estonia
The mutual recognition is foreseen in Article 14 eIDAS Regulation
2020
Joint Working Plan with the EU
сross-bordereSignaturevalidationtested
2020-2021
Cross-border eSignaturPilot
Armenia – Georgia – Ukraine – Estonia – Lithuania – Latvia – Moldova
2021
Self-assessment eIDASMRA CookBook
Legal and technical assessment based on eIDAS art.14 CheckList
2020-2022
Refininglegislation and infrastructure
Law revisions, Signature Portal upgrade and Trust List set-up

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
Main pillarsforcomparingPKI-basedtrustserviceschemes
Best Practice
Trust
Legal
Supervision
Trusted Lists
Supervision&Auditing
QTSP&QTS Legal/eIDAS
provisions
Practices&Standards
supportingtools and bilding
blocks

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
Cross- border eSignaturPilot
If both countries are satisfied with each other's legal, trust and
supervisory framework, then we can move on to technical
requirements:
define trust or identity services
test the cross-border technical interoperability:
•design a solution compatible with requirements which
includes timestamping, and certificate validation mechanisms
•test the readiness of national infrastructure for cross-border
interoperability by examining the technical ability of pilot
countries to validate a service created by another and vice-
versa
disseminate pilot results

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
Successful cross- border eSignatur Pilot examples:
July 2020 - March 2021
Ukraine –Moldova
July 2020 - March 2021
Ukraine –Estonia
October 2021 – February 2022
Armenia – Georgia – Ukraine – Estonia – Lithuania – Latvia
All cross-border eSignature Pilots led by EU -funded EU4Digital Facility and
were performed across the pilot countries

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
Illustration pilot results
Ukraine – Moldova
(*) eSignature Pilot Report, EU4Digital, April 2021 p.34

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
Testing for cross-border eSignature interoperability
Ukraine – Estonia
(*) eSignature Pilot Report, EU4Digital, April 2021 p.32

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
Testing for cross-border eSignature interoperability
Armenia – Georgia – Ukraine – Estonia – Lithuania – Latvia
(*) eSignature Pilot Report, EU4Digital, April 2022 p.11

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
The recognition of TSs is foreseen in Article 14 eIDAS Regulation and may only occur
under implementing acts or an agreement concluded between the Union and the
interested 3rd countries or international organisation in accordance with Article 218 TFEU
3rd country / international org TSP/TS must meet the eIDAS requirements applicable to EU
QTSP/QTS
So farno:
3rd country/ international orgTSs recognisedasquelifiedin EU

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
Typical eIDAS Art.14 MRA life-cycle process flow
(*) Pilot eSig BB internationalization - MRA Cook-book, p.13

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Transformation of Ukrainian eTrust Services
Typical eIDAS Art.14 MRA life-cycle process flow
(*) Pilot eSig BB internationalization - MRA Cook-book, p.13
Joint work
plan with
17
additional
steps

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
3
Pilot for the International
Compatibility

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Pilot for the International Compatibility
The pilot aims to illustrate how the mutual recognition between the EU and a 3rd
country of the QTSP and the QTSs they could be (technically) implemented under
Article 14 of eIDAS .
Before getting to the inclusion in the EC LOTL of such a pointer to the trusted list
of a 3rd country, the process of concluding an Art.14 MRA will include several
steps and potentially important piloting and negotiation phases.
The pilot simulates a test LOTL that
points to the trusted lists referred in
the current LOTL and also points to
a test 3rd country trusted list as a
result of the mutual recognition above
Provide documentation with a view to
supporting to technically validate
eSignatures and Seals supported by
certificates issued by TSP established in 3rd countries
as advanced
electronic signatures and seals, in the
context of eIDAS Art. 27 and 37

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Pilot for the International Compatibility
Website on Pilot CEF eSig BB
international compatibility
Documentation
Tools
MRA cookbook
eIDAS Article 14 Assessment Check-List
MRA element specification (and XML
Schema Definition)
MRA element usage
Browse the LOTL and trusted lists
Validate the trusted lists outputs
(signatures and certificates)
Pilot for the International
Compatibility of Trust Services
Documentation
Tools
MRA cookbook
eIDAS Article 14 Assessment Check-List
NexU – application required to sign
documents
Keystore / Private key
Sample document for validation

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Pilot for the International Compatibility

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Pilot for the International Compatibility
Publicationof3rd Country
AdESLOTL pointingtoUA
TrusedList
Member States were allowed:
download and authenticate the
3rd Country TL
validate UA-QES as eIDAS
AdES, using the MRA
elements

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Pilot for the International Compatibility
01
UA preparedtheMRA self-
assessmentchecklist
Regulatory and standardization
framework, List of QTSPs,
exaplesof signed certificates
and documents
02
Assessment the feasibility
of UA QES technical
recognition as EU AdES
03
UA TL preparation for publication
Specification otthe contant,
location and signing certificates,
notification
04
UA prepared the technical
recognition of UA
qualified certificates
Specification of the certificate
profile and interoperability with
EU
05
EC specified the content
of the MRA element in
the EU TC AdESLOTL
06
UA published a test UA TL
07
EC hosted a test EU UA AdESLOTL pointing to
the test UATL, and test recognition of UA QES
08
UA published the UA TL
09
EC included UA pointer in the EU TC dES LOTL
Technical processforinclusionin 3rd Country AdESLOTL

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Pilot for the International Compatibility
Publication of 3rd Country AdES LOTL and update of Digital Signature Service Library

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Pilot for the International Compatibility
Display 3
rd
Country AdES LOTL in the eIDAS Dashboard

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Pilot for the International Compatibility
Ukraine Trusted List in the eIDAS Dashboard

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
4Afterpilot Achievements

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Afterpilot Achievements
8 UA QSPs ensure that their QES can be signed and validated in the EU

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
Afterpilot Achievements
31.12.2023
thenewLaw on Electronic
Identificationand Electronic
Trust Services cameinto
force
05.2024
Ukraine hasjoineda pilotof
theEuropean Digital Identity
Wallet (EUDI)

A joint initiative of the OECD and the EU, principally financed by the EU.
Restricted Use - À usage restreint
And now it's time for your questions