The goal of the paper is to describe the main results of a European research project, namely CYSM, (The authors serve as technical managers of the CYSM project.) which is oriented to address the security and safety requirements of the commercial ports' Critical Information Infrastructures (CII). It aims to introduce an integrated security management system (for port operators) enabling asset modelling, risk analysis, anticipation/management of attacks, as well as stakeholders' collaboration. The proposed system helps port to identify, assess and treat their security and safety problems in an efficient, harmonized and unified manner.
This book constitutes the refereed conference proceedings of the 12th IFIP WG 6.11 Conference on e-Business, e-Services and e-Society, I3E 2013, held in Athens, Greece, in April 2013. The 25 revised papers presented together with a keynote speech were carefully reviewed and selected from numerous submissions. They are organized in the following topical sections: trust and privacy; security, access control and legal requirements in cloud systems; protocols, regulation and social networking; adoption issues in e/m-services; new services adoption and ecological behavior; knowledge management and business processes; and management, policies and technologies in e/m-services.
The maritime sector is critical in terms of economic activities and commercial impact not only for the European society but more importantly for the Mediterranean EU Member States, especially under the current economic turmoil. Commercial ports are the main gateways and face increased requirements, responsibilities and needs in view of a secure and sustainable maritime digital environment. Therefore, they have to rely on complicated and advanced facilities, ICT infrastructure and trustworthy e-maritime services in order to optimize their operations. This paper aims at alleviating this gap on the basis of a holistic approach that addresses the security of the dual nature of ports' Critical Information Infrastructures (CIIs). In particular, it introduces a collaborative security management system (CYSM system), which enables ports' operators to: (a) model physical and cyber assets and interdependencies; (b) analyse and manage internal / external / interdependent physical and cyber threats / vulnerabilities; and (c) evaluate / manage physical and cyber risks against the requirements specified in the ISPS Code and ISO27001.
Keywords: transformational government (t-Gov); interoperability; privacy; trust; SOA; SaaS; business process management; t-Gov adoption and diffusion; public administration; enterprise integration; content management; web 2.0.
?he transformational role of e-government can be achieved through engagement of the citizens in the e-government rollout and subsequent adoption. The present study integrates constructs from the Technology Acceptance Model, Diffusions of Innovation Theory and Trust Models in order to propose a research model to guide future e-government initiatives. The critical acceptance factors, namely: trust, security, and regulation are analyzed for the citizens’ adoption process. The citizen’s perceptions of electronic services adoption are analyzed based on the case study of the National Governmental Portal.
Information and knowledge management has obviously acquired immense value in business analysis and strategic planning. Targeting towards this direction, the role of collaborative systems and collective knowledge tools becomes highly important in supporting the exploitation of business knowledge and the harnessing of collective intelligence. Although existing technological advancement appears today more mature than ever in providing a stable technology framework, the use of which can lead to innovative knowledge management techniques and mechanisms, architects still struggle to define fundamental principles, strategies and integration approaches in designing and implementing successful collaborative information and knowledge management environments. This article aims at identifying all critical operational and technical requirements posed by such demanding enterprise solutions, and presents an overall system architecture that demonstrates all their indispensable characteristics. In addition, it proposes effective integration practices for achieving a greater level of maturity and predictability when building modern collaborative information and knowledge management environments.
Exploiting the advantages of Web 2.0 technologies and collaborative applications and tools such as wikis, blogs, forums, real-time text editors and other groupware systems, modern services and Information Systems have evolved towards collaborative and social environments where user-generated content is a common task. In this paper we will identify the additional privacy and trust requirements posed by collaborative knowledge tools and suggest a number of guidelines for the development of privacy-aware Identity and Access Management systems that are capable to ensure trust in the context of collaborative workspaces.
Migration for employment is acknowledged to have direct consequences on National economies, as well as the overall economic situation of the European Union (EU). Migration policy and decision-makers need to systematically collaborate towards sophisticated approaches that facilitate legal immigrants to be effectively integrated in labour markets and public administration processes. Latest ICT developments, which integrate Web 2.0 technologies, collaborative knowledge management systems, and semantic analysis technologies, allow participatory governance and citizen-generated policy making. This paper presents a collaborative migration policy-modelling centre, techniques, solutions and overall services for collaborative development of immigration policies, as well as for supporting related decisions.
Identity and Access Management (IAM) systems are considered as one of the core elements of any sound security electronic framework for electronic business processes. Their ability to quickly and reliably verify who is trying to access what service, and what they are authorized to do, is both a business enabler and a core requirement for meeting regulatory demands. However, IAM systems are difficult to implement since they touch virtually every end-user, numerous business processes, as well as every IT application and infrastructure component of an enterprise, and therefore most of the times IAM implementations fall short of expectations. This chapter proposes an effective way of approaching, designing, and implementing a constructive, user-centric, standards-based, centralized, and federated IAM system, with which a trust relationship among the involved entities is established in a secure and interoperable way, enabling end-users to easily gain electronic and/or mobile (e/m) access to advanced business services, and Service Providers (SPs) to effectively enhance their infrastructures by easily adopting it in their systems. In addition, a collective knowledge of IAM systems’ implementation best practices is presented.
Electronic services have become a critical force in service oriented economies introducing new paradigms like connected governance, ubiquitous and ambient public services, knowledge-based administration, and participatory budgeting. The success of e-Government integration requires the modernization of current governmental processes and services under three different perspectives, namely governmental business processes reengineering, legal framework reformation and technical solution effectiveness. The study proposes a knowledge guide for approaching, analyzing and defining government-wide architectural practices when building large scale enterprise governmental frameworks. A set of fundamental design and implementation principles are specified for increasing government organizations' agility and ensuring that end-users perceive the quality of the provided services.
The engineering world appears today more mature than ever in providing stable technology premises in order to build large scale, real interoperable and secure enterprise information systems, and strengthening the fundamental structure of private and public organisations. However, as technology has evolved, more opportunities have become available for virus writers to express their imagination in malicious code. Computer viruses are a major problem in modern day computing, threatening the structure of organisations, their enterprise systems and eliminating user-acceptance of electronic and mobile services provided. Detection tools such as virus scanners have performed poorly, particularly when facing previously unknown virus or novel variants of existing ones. This paper proposes and performs assessment on advanced proactive and reactive cryptographic measures that ensure the robustness and security of enterprises and computer systems.
Extensively used distributed e-government solutions did not succeed to gain Governmental Organisations' (GOs') and end-users' acceptance since they did not fulfil core requirements such as interoperability, scalability/extensibility, security and trust, and high administration. This paper presents an innovative Local Government Access Framework (LGAF), deployed for the Central Union of Municipalities and Communities of Greece, providing insights to critical success design factors for reengineering mission critical legacy systems so that they can operate in and take full advantage of a user-centric e/m-government environment. The LGAF integrates almost 250 government services in many different domains of the public administration such as in health, social care, education, public transportation, cultural, and others, integrating peak XML technologies, worldwide standards and specifications.
Migration policy making and monitoring constitute critical issues for European countries, given the impact of modern phenomena such as illegal employment on economic growth and future prosperity. The dynamic and complex nature of migration problems demands common approaches and collaborative actions among all stakeholders both at National and European level. Policy and decision makers need to systematically collaborate towards sophisticated approaches that facilitate legal immigrants to be effectively integrated in labor markets and public administration processes. Existing research initiatives and migration-oriented automated tools and services fail to provide a complete, robust and widely available framework for the collaborative development of common pan-European migration policies and the harmonization of processes and documents formats. Identifying these weaknesses as well as the need for enabling and supporting legal immigrants to be informed and provide their valuable feedback, this paper focuses on the description of a web-based communication framework for open collaboration on migration issues. The proposed system, ODYSSEUS, aims at enhancing existing Migration Information Systems by providing an advanced, collaborative and trusted framework for the provision of migration services.
Nowadays, the need for more user-centric privacy-aware transactions raises specific challenges that Service Oriented Architectures (SOA) need to address, including the problems of managing users' personal identification information and ensuring privacy and anonymity in the e/m-environment. This paper presents a targeted, user-centric and federated Single-Sign-On Identity Management System (IAM) called SecIdAM, and a mobile implementation framework for building privacy-aware, interoperable and secure mobile applications with respect to the way that the trust relationship among the involved entities, users and SOAs is established. Moreover, it analyses a user-transparent m-process, simulating the registration, negotiation of policies and identification information preferences, and user's authorisation sessions, as integrated in the IST European programme SWEB for the public sector.
The impressing penetration rates of electronic and mobile networks provide the unique opportunity to organizations to provide advanced e/m-services, accelerating their entrance in the digital society, and strengthening their fundamental structure. Service Oriented Architectures (SOAs) is an acknowledged promising technology to overcome the complexity inherent to the communication among multiple e-business actors across organizational domains. Nevertheless, the need for more privacy-aware transactions raises specific challenges that SOAs need to address, including the problems of managing identities and ensuring privacy in the e/m-environment. This article presents a targeted, user-centric scalable and federated Identity Management System (IAM), calledSecIdAM, and a mobile framework for building privacy-aware, interoperable, and secure mobile applications with respect to the way that the trust relationship among the involved entities, users and SOAs, is established. Finally, it analyzes a user-transparent m-process for obtaining an authentication and authorization token, issued from the SecIdAM as integrated in the IST European programme SWEB for the public sector.
The implementation of large-scale enterprise frameworks for providing advanced e/m-government services necessitates the clear specification, the address, and maintenance of core fundamental design principles, strategies and guidelines. These will accelerate and assure the catch of common goals and benefits such as, to increase intrinsic interoperability, federation, vendor diversification options, business and technology domain alignment, organisational agility, and reduce IT burden. This paper proposes a synchronous e/m-government SOA framework, giving constant emphasis on how and where fundamental design principles are applied with the ultimate goal of producing high quality, secure and interoperable governmental, added-value services.
It is acknowledged that the latest stable XML technologies, standards and specifications may build real interoperable and secure enterprise privacy-aware implementations. However, existing implementations do not address the users’ need to easily handle their identifiers and credentials while providing pluggable modules for interconnecting their pre-existing business applications and platforms. This article proposes a constructive, targeted, user-centric, standards-based, open federated Identity and Access Management (IAM) system, the OpenIdAM, with which trust relationship among the involved entities is established in a secure and interoperable way, enabling end-users to easily e/m-access advanced business services, and Service Providers (SPs) to effectively enhance their infrastructures by easily plug-in existing modules, to secure and manage their enterprise systems without having to implement complex and multiple IAM mechanisms for each one of them.
The growth of high speed e/m-services imposes requirements, including: security, which fosters user trust in mobile services, interoperability, which enables cross-domain mobile service communication and wireless application integration; high administration on the services, organising embedded logic of applications into separate and easily changed 'state machines' to allow new level of processes within governmental services and scalability and extensibility, which ensure that existing services and modules are not degraded and can be easily extended in new, more advance ones. This paper proposes a secure and interoperable e/m-governmental framework and presents an innovative platform architecture for complex e/m services, which integrate peak XML-based technologies.