A database of up to 50 million fingerprints can now be housed in a new Automatic Fingerprint Identification System (AFIS) recently deployed by Public Safety Authority in China’s Anhui Province to help reduce its criminal investigations. In partnership with NEC Corporations, the AFIS, the largest of its kind in China can help increase the hit rate on latent fingerprint inquiries by tenfold.
Rabu, 06 Juni 2012
Vietnam conducts comprehensive assessment of govt websites
On 25 May, Workshop on Information Security Policies towards Developing of E-Governance was hosted by Vietnam Information Security Association (VNISA) and Vietnam Computer Emergency Response Team (VNCERT), to implement Prime Minister’s Instruction and the Guidelines of Ministry of Information and Communications (MIC) on the protection of websites.
Labels:
ASEAN,
Cybersecurity,
ICT,
Keamanan Publik dan Negara,
Smart City
Sabtu, 10 Maret 2012
Brunei climbs 14 places to 54 on UN e-Gov't ranking
BRUNEI's e-Government structure has climbed up 14 notches to 54 out of 193 countries this year, according to the "United Nations E-Government Survey 2012 - E-Government for the People".
Commenting on Brunei's previous ranking at 68th place two years ago, the Minister of Energy at the Prime Minister's Office Pehin Datu Singamanteri Colonel (Rtd) Dato Seri Setia (Dr) Hj Mohd Yasmin Hj Umar, said this is "good news" for the country.
He added that among ASEAN countries, the Sultanate is third behind Singapore and Malaysia.
"This is because of the way the e-Government project has been implemented and this is good news. Moving up 14 steps is quite a good sign and improvement," he told The Brunei Times in a telephone interview yesterday evening.
The minister also commended the team at the E-Government National Centre (EGNC) for the hard work they have been putting in, noting their efforts are appreciated. Brunei's current e-Government ranking, however, did not take into account EGNC's eDarussalam, a single online portal integrating all e-government services, he said. "Next year if we look at eDarussalam and the completion of the Fibre-to-the-Home (FTH) project, that will definitely improve our standing a lot," Pehin Dato Hj Mohd Yasmin said. Pehin Dato Hj Mohd Yasmin said the EGNC will continue to work hard, and aims for Brunei to be ranked top 40, if not 30, in the next survey.
"This is because of the way the e-Government project has been implemented and this is good news. Moving up 14 steps is quite a good sign and improvement," he told The Brunei Times in a telephone interview yesterday evening.
The minister also commended the team at the E-Government National Centre (EGNC) for the hard work they have been putting in, noting their efforts are appreciated. Brunei's current e-Government ranking, however, did not take into account EGNC's eDarussalam, a single online portal integrating all e-government services, he said. "Next year if we look at eDarussalam and the completion of the Fibre-to-the-Home (FTH) project, that will definitely improve our standing a lot," Pehin Dato Hj Mohd Yasmin said. Pehin Dato Hj Mohd Yasmin said the EGNC will continue to work hard, and aims for Brunei to be ranked top 40, if not 30, in the next survey.
In the United Nations survey assessment of progress, it is stated that eGovernment is increasingly being viewed among countries in the vanguard as going beyond service delivery towards a framework for a smart, inclusive and sustainable growth for future generations.
Its website added the overall conclusion that emerges from the 2012 Survey in today's recessionary world climate is that while it is important to continue with service delivery, governments must increasingly begin to rethink in terms of e-Government and e-Governance.
By placing greater emphasis on institutional linkages between and among the tiered government structures, synergy can be created for inclusive sustainable development. In a foreward message, Sha Zukang, Under-Secretary-General for Economic and Social Affairs and Secretary-General of the United Nations Conference on Sustainable Development said, "The increasing role of e-Government in promoting inclusive and participatory development has gone hand-in-hand with the growing demands for transparency and accountability in all regions of the world."
"This report shows that with the right institutional framework, policies and capacity-building efforts, progress in enhancing the contributions of e-government to sustainable development is within reach," he added.
The Brunei Times
Labels:
ASEAN,
eGov Readiness Ranking,
Government Management
Senin, 05 Maret 2012
Indonesia Hosts Clean Power Asia To Embrace Cleaner and Renewable Energy
Asian Countries Increase Spend More on Renewable and Clean Power Than Other Developed Nations
“Asian countries are overtaking developed ones in terms of spending on renewable and cleaner fossil power projects,” said Daria La Valle, the conference manager of Clean Power Asia. This is clearly illustrated by the 27 case studies of recent and upcoming clean power projects in the Asian region which will be presented at Clean Power Asia 2012 which is taking place in Bali, Indonesia in May.
The annual conference and exhibition will gather some 600 leading Asian renewable and cleaner fossil power experts, utilities, energy ministries, regulators, investors and technology and service providers to discuss the latest renewable and cleaner fossil power developments in the region as well as the main challenges that utilities face to adopt greener power sources.
Future of renewable energy in developing world
The future of renewable and clean energy is now in the developing world” says Daria La Valle, “and new government policies have made it more palatable for foreign investors to finance clean power projects here in Asia through various financial instruments and clearer regulatory frameworks.”
The Clean Power Asia conference manager continues: “Indonesia has announced a master plan for the development of renewable energy resources and set a target for renewables to represent 25% of total energy consumption in 2025. Malaysia is hoping that the recently launched National Renewable Energy Policy Plan will help the country hit its targets and the new feed-in-tariffs that recently came into effect will certainly help achieving those targets. Thailand launched its 15-year Renewable Energy Development plan last year and aims to increase renewable energy from 6.4% to 20% in 2022.”
Indonesia the next regional powerhouse
Clean Power Asia’s Daria La Valle says Indonesia in particular has huge potential to be a leading power player in the region: “Indonesia is actually the country with the biggest potential for both renewable as well as cleaner fossil power generation in Southeast Asia. The country sits on the largest geothermal energy resources in the world and has great bioenergy, solar and hydropower potential. Combine this with extensive coal resources and a low electrification rate, and you can see the potential of Indonesia to be the powerhouse of the region.” ===
In addition, she notes, the fall in equipment costs and growing appetite for clean technology has resulted in increased policy support measures and increased investment in cleaner fossil power investments. She adds: “Thailand is involved in clean coal pilot projects, Indonesia is building its first ultra supercritical coal fired power plant. TNB Malaysia has increased its operational efficiency by upgrading 6 existing plants. Successful CO2 sequestration achievements are made and much effort is being made in power plant optimisation and efficiency increase resulting in tremendous CO2 emission reduction results.”
Clean Power Asia’s conference programme will feature more than 80 experts, including:
Future of renewable energy in developing world
The future of renewable and clean energy is now in the developing world” says Daria La Valle, “and new government policies have made it more palatable for foreign investors to finance clean power projects here in Asia through various financial instruments and clearer regulatory frameworks.”
The Clean Power Asia conference manager continues: “Indonesia has announced a master plan for the development of renewable energy resources and set a target for renewables to represent 25% of total energy consumption in 2025. Malaysia is hoping that the recently launched National Renewable Energy Policy Plan will help the country hit its targets and the new feed-in-tariffs that recently came into effect will certainly help achieving those targets. Thailand launched its 15-year Renewable Energy Development plan last year and aims to increase renewable energy from 6.4% to 20% in 2022.”
Indonesia the next regional powerhouse
Clean Power Asia’s Daria La Valle says Indonesia in particular has huge potential to be a leading power player in the region: “Indonesia is actually the country with the biggest potential for both renewable as well as cleaner fossil power generation in Southeast Asia. The country sits on the largest geothermal energy resources in the world and has great bioenergy, solar and hydropower potential. Combine this with extensive coal resources and a low electrification rate, and you can see the potential of Indonesia to be the powerhouse of the region.” ===
In addition, she notes, the fall in equipment costs and growing appetite for clean technology has resulted in increased policy support measures and increased investment in cleaner fossil power investments. She adds: “Thailand is involved in clean coal pilot projects, Indonesia is building its first ultra supercritical coal fired power plant. TNB Malaysia has increased its operational efficiency by upgrading 6 existing plants. Successful CO2 sequestration achievements are made and much effort is being made in power plant optimisation and efficiency increase resulting in tremendous CO2 emission reduction results.”
Clean Power Asia’s conference programme will feature more than 80 experts, including:
- Datuk Loo Took Gee, Secretary General, Ministry of Energy, Green Technology and Water, Malaysia
- Dr. Songpope Polachan, Director General, Department of Mineral Fuels, Ministry of Energy, Thailand
- Hatsady Sysoulath, Director General of Institute of Renewable Energy Promotion, Ministry of Energy and Mines, Lao PDR
- Dr Direk Lavansiri, Chairman, Energy Regulatory Commission, Thailand
- Dr Kardaya Warnika, Director General of New, Renewable Energy and Energy Conservation Ministry of Energy and Mineral Resources, Indonesia
- Nu Pamudji, President Director, PT PLN (Persero), Indonesia -Shinta W. Kamdani, Vice Chairwoman in KADIN Indonesia (Indonesian Chamber of Commerce and Industry), Owner and Managing Director of Sintesa Group, and Steering Committee of IBCSD (Indonesian Business Council for Sustainable Development)
- Y. Bhg. Dato’ Mohd Nazri Shahruddin, VP of Power Generation, Tenaga Nasional Berhad (TNB), Malaysia
- Yokihiro Hirabayashi, Department Deputy Director, International Business Development Dept., J-POWER, Japan
- Dr. Nattakit Parkpoom, Specialist System Power Planning, Generation Division, EGAT, Thailand -Heru Dewanto, Commissioner, PT Cirebon Electric Power, Indonesia
- Anupam Datta, General Manager, Calcutta Electric Supply Corporation (CESC Ltd), India
Event dates and location:
14 - 16 May 2012
Bali International Convention Centre, Bali,
Indonesia
Jumat, 02 Maret 2012
CARTES in Asia to Showcase Government Identity Technology
The convergence of biometrics, global operational standards and the integration of public and private services are forging government identity technology ahead in the Asia Pacific region. Identity technology developers and government decision makers at CARTES in Asia conference and exhibition on 28 and 29 March will be able to see and hear about new developments in this sector. On the second day of the exhibition, there will be a full day dedicated to ID Management and e-Government covering innovations, privacy and security issues.
With a population that reaches nearly four billion, the biometric identity industry has been going from strength to strength in Asia Pacific. In the last couple of years countries in South East Asia such as Brunei, Cambodia, Indonesia, Malaysia, Myanmar, Philippines, Singapore, Thailand and Vietnam have embraced technologies such as ePassports, eIDs and eVisas in a bid to communicate with their people and protect their identities. Vietnam is due to issue its first electronic passport by the end of this year and by 2014 the Philippines is expected to be the world’s sixth-largest issuer of ePassports, behind India, the US, Brazil, and Britain.
With a population that reaches nearly four billion, the biometric identity industry has been going from strength to strength in Asia Pacific. In the last couple of years countries in South East Asia such as Brunei, Cambodia, Indonesia, Malaysia, Myanmar, Philippines, Singapore, Thailand and Vietnam have embraced technologies such as ePassports, eIDs and eVisas in a bid to communicate with their people and protect their identities. Vietnam is due to issue its first electronic passport by the end of this year and by 2014 the Philippines is expected to be the world’s sixth-largest issuer of ePassports, behind India, the US, Brazil, and Britain.
In order to facilitate interoperability across countries, the ICAO (International Civil Aviation Organization) has introduced e-passport standards: Basic Access Control (BAC) and then Supplemental Access Control (SAC). These new security standards are designed to help countries migrate from traditional paper-based travel documents and protect the passport’s data confidentiality, integrity and anti-cloning.
Isabelle Alfano, Director of CARTES events, Comexposium, said: “A new era of government biometric technology is upon us here in Asia Pacific and across the world. The concept is also changing with more functions being incorporated including social security information, driving licenses, healthcare, banking and transportation applications. And standardization is making the technology more secure and interoperable across different countries. Visitors and exhibitors to CARTES in Asia will be able to find out about all of this and much, much more at CARTES in Asia next month.”
Present in more than 70 countriesworldwide, Oberthur Technologies is one of the key players in identity sector, providing secure documents and issuance systems for more than 60 government programs.
“Oberthur Technologies participates in identity document programs in Asian countries including national electronic ID cards in Cambodia, electronic Driving Licenses for Bangladesh and Passports or electronic Passports in Thailand, Philippines, Taiwan and Nepal” said Mr Cheong Chung Chin, Vice president ID division Asia Pacific. “Oberthur Technologies is glad to take part in the third session of CARTES IN ASIA exhibition to meet our customers and show our latest innovations, products and solutions expertise at our booth”.
On March 28 CARTES in Asia will also provide an insight into major trends shaping ID Management and eGovernment at their conference. The ID Management and eGovernment all-day session will include speakers from Datacard, Gemalto, Global Platform, HID Global, JDSU, Keynectis, Komsco, Natural Security and Oberthur Technologies. The two day conference, which will bring together more than 300 high level conference attendees and over 70 keynote speakers will also cover Mobile Payment, NFC Applications, e-Transaction/e-Banking, Prepaid & Loyalty Programmes, IT Security & Internet of Things.
About CARTES in Asia
Date: 28-29 March 2012
Opening times: 9.30am to 5.30pm
Place: Hong Kong – AsiaWorld-Expo
Organizer: Comexposium
Website: www.cartes-asia.com
koreaittimes.co.id
Labels:
ASEAN,
Cybersecurity,
Government Management,
ICT,
KTP NIK Nasional,
Smart City
Selasa, 28 Februari 2012
Authenticating users: Going beyond the password
Passwords are the most common way users confirm their identities so they can be granted access to a given system. However, passwords are also considered a weak form of authentication, so alternative or complementary methods are being used to verify the identity of the user.
In this post, I will describe the factors that are most commonly used along with their strengths and weaknesses in order to provide the foundation for a discussion of a multi-factor authentication strategy.
What is authentication?
Authentication is basically the process to confirm that a person (or user) is who they say they are. There are three classic "factors" that can be used to confirm a users' identity:
What is authentication?
Authentication is basically the process to confirm that a person (or user) is who they say they are. There are three classic "factors" that can be used to confirm a users' identity:
- Using something only the user knows
- Using something unique the user has
- Using something that only the user is
Other factors that can sometimes be used are based on time and location. For example, you could limit valid logon hours to a particular user given their work schedule or limit the locations from where a user can attempt to log in, using geo-location information. These factors tend to be used only in very specific scenarios so they are mostly relegated to complement the classic authentication factors. Let's take a closer look at each of the classic authentication factors.
Something you know
Authentication through something only the user knows (most commonly a password) is the most widely used of all the classic factors. Passwords provide a simple and mostly inexpensive way to perform authentication. Passwords can range from simple 4-digit PIN numbers to complex alphanumeric passphrases.
Due to their prevalence, the use of passwords has been subject to intense scrutiny and is generally considered to be a weak form of authentication. Their biggest weakness is that users tend to have some bad habits when it comes to choosing their passwords, basing them on information that can be easily guessed or not making them complex enough to withstand a brute force attack. Sometimes however, bad password policy has something to do with it. Some of these weaknesses can be addressed with education and training (for both users and the IT staff).
Something you have
This factor is also in widespread use, most commonly in the form of ATM cards. The basic principle is that the "something you have" is a unique item possessed only by a certain person and the system will accept it as proof of identity of an authorized user.
There are many ways this factor can be implemented in computer systems, using items ranging from smartcards, USB tokens, wireless tokens/cards and more recently, using mobile phones as tokens (via SMS text or downloaded apps). There are several issues to consider when evaluating the use these types of solutions, including deployment costs, hardware/software requirements, usability, user acceptance, item durability, etc.
Stealing the item is the first way an attacker could attempt to compromise this type of system. In this scenario, the attacker has a limited window of opportunity before the owner reports the loss and the stolen item rendered invalid. Copying the item may be more effective, though some items include copy-protection mechanisms to prevent the success of such an attack. Man-in-the-middle attacks may be more complex to execute in some cases, but they can be far stealthier and effective. Take for example the recent compromise of RSA tokens. Another example is the rise of mobile malware, where the compromise of the mobile phone also leads to the compromise of the authentication factor.
Something you are
Using something you are as an authentication factor is essentially using a biometric reading from the user (via a fingerprint, voiceprint or iris scan) and comparing it to an archived recording for that user.
Biometric readings are usually stored as a hash resulting from a mathematical algorithm applied to the reading. The comparison is then made between two hashes and if they have enough similarities, it will be accepted as good enough and the user granted access. Biometric devices therefore can result in a false reading being accepted as true (false positive) or a valid reading being rejected (false negative).
Manufacturers measure these errors using the False Acceptance Rate (FAR) for the percentage of false positives and the False Rejection Rate (FRR) for the percentage of false negatives. To better compare the accuracy between two readers however, the Equal Error Rate (EER, the rate at which both types of errors are equal) should be used. A device with a lower EER is usually more accurate. This type of authentication also presents other challenges in its implementation, including higher costs, user resistance and hardware requirements. Also of consideration is the process of capturing the initial reading of the user ("enrollment") into the biometric system.
Some biometric readers are also vulnerable to man-in-the-middle attacks, where an attacker can capture the reading, record it as it is being sent and replayed at will. Also, biometric readings can be copied or faked (duplicating a fingerprint with a gelatin fake or capturing a voice recording for instance) and are more difficult to change. A user can change a compromised password or receive a new smartcard, but a user cannot easily change their voiceprint for instance.
Another aspect that has sometimes been linked to biometrics category is "how you behave". This aspect is usually used as a way to corroborate an already established identity, rather than provide the initial verification. The best-known example is when a credit card transaction breaks known usage patterns and casts doubt on its validity. Currently, DARPA is looking for new ways to authenticate users through their behavior without interrupting their normal activities.
Here, we examined the different authentication factors available and some of their individual strengths and weaknesses. Next time, we will take a look at what true multi-factor authentication is and what to look for when considering the use of a multi-factor strategy.
Alfonso is a technology specialist with experience in multiple IT roles with the latest one being in information security.
zdnetasia.com
Langganan:
Postingan (Atom)