Die Präsentation wird geladen. Bitte warten

Die Präsentation wird geladen. Bitte warten

Leslie Romeo Head of De-Mail DE-MAIL MESSAGEBOX - MADE IN GERMANY.

Ähnliche Präsentationen


Präsentation zum Thema: "Leslie Romeo Head of De-Mail DE-MAIL MESSAGEBOX - MADE IN GERMANY."—  Präsentation transkript:

1 Leslie Romeo Head of De-Mail DE-MAIL MESSAGEBOX - MADE IN GERMANY

2 1&1 - Member of United Internet AG History of De-Mail De-Mail Infrastructure Comparison of Standards: De-Mail = eIDAS?! 1&1 De-Mail GmbH Agenda June 2016 2

3 Strong Team 8 200 employees (2 700 in product management, development and system administration) Sales Power about 3.2 million contracts annually 50 000 sign-ups for free services daily Operational Excellence 49 million accounts in 11 countries 7 Certified Data Centers 70 000 servers in Europe and the US Powerful Network Infrastructure 41 000 km optical fibre network 1&1: Internet-Services of United Internet AG Access Applications Network Devices Content Software 1&1 De-Mail GmbHJune 2016 3

4 Locations 70 000 servers 16.24 million paying customers 33.49 million free accounts Hosting of over 19 million domains 70 000 servers 16.24 million paying customers 33.49 million free accounts Hosting of over 19 million domains 1&1 De-Mail GmbHJune 2016 4

5 Snail Mail Communication (Letter) Digital Communication (E-Mail) - non-binding - not suitable for commercial use + widely spread + fast and convenient Snail Mail Communication (Letter) + legally binding + (legally) recognized - declining - slow and inconvenient Signed Digital Communication + (only) partially (legally) binding - not widely spread - complicated and inconvenient - not mass suitable Communications Environment in Germany 1&1 De-Mail GmbHJune 2016 5 Digital Communication (E-Mail)

6  De-Mail should not make „E-Mail secure“ but instead adequately replace letters.  It‘s not enough just to „transfer the letter to the internet“. „De-Mail should especially include all values of the current paper-based communication in combination with the advantages of the established digital communication.“ ►Reliable, legally binding, and traceable as well as simple, fast, flexible, transparent, and convenient. 6 De-Mail Vision 1&1 De-Mail GmbHJune 2016 6

7 De-Mail History 2006 De-Mail Act and first DMDA De-Mail Act and first DMDA Start Economic and political conversations 4 DMDA (Public admin., Enterprise, SME, priv. cust.) Over 1 million priv. and 40 000 business cust. eGovernment Act 2011 2013 2015 2016 Operation Execution: Economy Governance: Regulatory Bodies Operation Execution: Economy Governance: Regulatory Bodies Development Execution: Economy Governance: Regulatory Bodies Development Execution: Economy Governance: Regulatory Bodies Project Government and Economy Project Government and Economy Organisational Governmental Initiative Organisational Governmental Initiative 1&1 De-Mail GmbHJune 2016 7 Timeline Governance

8 Open Standard in open network within a closed user group Communication between individuals, companies and public administration No crossing of E-Mail and De-Mail Services Solution 1&1 De-Mail GmbHJune 2016 8 Legally binding digital communication Authenticity Confidentiality Integrity Protection Traceability

9 Scope of Functions Attributes 1&1 De-Mail GmbHJune 2016 9  Explicit Addressing: FName.LName [.Num]@provider.de-mail.de. Business@Company-Sample.de-mail.de. John_John-Doe@provider.de-mail.de.  Mailbox and Delivery Service  Reliable, legally binding, and traceable delivery (delivery and send receipt)  Explicit Addressing: FName.LName [.Num]@provider.de-mail.de. Business@Company-Sample.de-mail.de. John_John-Doe@provider.de-mail.de.  Mailbox and Delivery Service  Reliable, legally binding, and traceable delivery (delivery and send receipt) Optional:  Secure Document Store Encrypted Storage and Archive of digital documents.  Identification Service Third Party Authentication, e.g. name, age, billing address and/or delivery address. Optional:  Secure Document Store Encrypted Storage and Archive of digital documents.  Identification Service Third Party Authentication, e.g. name, age, billing address and/or delivery address.  Integrity Protection Integrity protection as standard (hashing of meta data and message content) Optional: Use of digital signatures.  Traceability Qualified signed delivery and delivery receipt from the sender/recipient provider.  Integrity Protection Integrity protection as standard (hashing of meta data and message content) Optional: Use of digital signatures.  Traceability Qualified signed delivery and delivery receipt from the sender/recipient provider.  Authenticity Safe intial registration and authentication as trusted source beyond a reasonable doubt. Different authentication levels - [Normal] Username/ Password - [High] Two-factor authentication (e.g. text, TAN)  Secure Transmission  Standard: Encrypted transmission between all communication participants  Optional: End-to-End Encryption/ (qualified) digital signatures  Authenticity Safe intial registration and authentication as trusted source beyond a reasonable doubt. Different authentication levels - [Normal] Username/ Password - [High] Two-factor authentication (e.g. text, TAN)  Secure Transmission  Standard: Encrypted transmission between all communication participants  Optional: End-to-End Encryption/ (qualified) digital signatures

10 Service Provider Sender Service Provider Recipient Recipient Overview of Functions Interoperational protocol between service providers Protocol depending on sender client Web browser E-Mail-Client Plugin Solutions OSCI-Client Gateway Verification/ adding of meta data Integritiy protection on message level Encryption on message level Delivery receipt Requirements of the transmission protocol between service providers Delivery receipt Encryption Verification of meta data and Integrity Protocol depending on recipient client Sender Optional: End-to-end encryption 1&1 De-Mail GmbHJune 2016 10 Web browser E-Mail-Client Plugin-Solution OSCI-Client Gateway

11 Involvement of the economy at an early stage Overall cooperation between government and economy Very good cooperation within the economy during the implementation General Interest / Acceptance of Users, especially private customers What went well? *Study of internet users communication behavior [Convios Consulting] „Over 60% of users could imagine using De-Mail already today; 5% would even pay for the service“ 1&1 De-Mail GmbHJune 2016 11 Yes, even if it cost 2 Euro monthly Yes, as long as it is free unlikely No

12 Use cases are urgently required What should be improved? 1&1 De-Mail GmbHJune 2016 12 De-Mail als Erfolgsmodell De-Mail, der ungenutzte Dienst Hope towards Government Administration not fulfilled Around 60% * of indiviudals do not use De-mail because public offices can‘t be reached and 40%* of the companies do not use De-Mail because it is not viewed as a standard. The Resulting Inactivity Around 70% * of the consumers did not use their De-Mail mailbox (incl. free flat rate). With companies the inactvity is over 90%*  Risk: The perception of participants and press of De-Mail as a failed governmental IT project is steadily rising! Opportunities: Government Administration – the desired partner Over 80%* of individuals, as well as 58%* of the companies, want to use De-Mail for communication with their government administration. For almost 90%* this was the main reason of registration. * Result of an online survey of 20 000 customers (individuals and companies) of 1&1, WEB.DE and GMX customers (details on backup slides)

13  Promote rapid dissemination across all target groups □ Visible offer by public sector □ Commitment of economy □ Mandatory usecases (if needed, free of cost) □ Visibility for end user (adresses on electronic ID card, registry of residents) □ Involvement of entities that will disseminate information  Improve usage possibilities and create more incentives □ Reduce entry barriers (e.g. possibilities of identification) □ Subsidise usage Supportive activities to maximise the offer of use cases 1&1 De-Mail GmbHJune 2016 13

14 Target: Digital Transformation of paper mail. Facts De-Mail (§§ 1ff. De-Mail G)  Accredited De-Mail service provider  Identification beyond a reasonable doubt of all Users as foundation of a De-Mail account (LOA 4)  Continuous Integrity Protection  Qualified signed received receipt, delivery receipt, and read receipt including time stamp. Requirements for qualified electronic registered delivery services (Art. 44 (1) eIDAS  (…) qualified trust service provider(s)  (…) a high level of confidence the identification of the sender;  (…) the identification of the addressee before the delivery of the data;  (…) preclude the possibility of the data being changed undetectably;  the date and time of sending, receiving and any change of data are indicated by a qualified electronic time stamp. De-Mail =* eIDAS *Confirmed by BSI, BNetzA and BfDI De-Mail =* eIDAS *Confirmed by BSI, BNetzA and BfDI Target: Trusted Services have the same legally binding status as the paper process. De-Mail does not equal eIDAS? The facts: 1&1 De-Mail GmbHJune 2016 14

15  1&1 IT infrastructure is certified according to the De-Mail standard (BSI and BfDI) and intents to be recognized as a qualified eIDAS trust service (process pending) by July, 1st.  The infrastructure is based on widely used and recognized international standards in the E- Mail environment (SMTP, S/MIME, SSL, etc.) and it is globally adaptable.  Technical specifications of the De-Mail standard have already been introduced in international standardisation bodies.  possible next steps to offer and implement eIDAS compliant qualified trustservices: InteroperabilityScope Expansion / Scalability Certified Infrastructure in EU 1&1 De-Mail GmbHJune 2016 15 The 1&1 infrastructure can thus be implemented as already certified cost-saving white label solution („SAAS“/„managed“/“on premise“). Operating for EU memberstates as nationwide or distributed system.. Highly scalable (from 1-10 million users upwards). The 1&1 infrastructure can thus be implemented as already certified cost-saving white label solution („SAAS“/„managed“/“on premise“). Operating for EU memberstates as nationwide or distributed system.. Highly scalable (from 1-10 million users upwards).  The SPOCS project, sponsored by the EU commission, has drawn up procedures for the interoperability of systems operating according to the De-Mail standard with systems of other member states.  De-Mail based systems are an integrated part of the eSense project in regards to the cross- border legally binding communication with France, Austria, Slovenia and Greece.  The SPOCS project, sponsored by the EU commission, has drawn up procedures for the interoperability of systems operating according to the De-Mail standard with systems of other member states.  De-Mail based systems are an integrated part of the eSense project in regards to the cross- border legally binding communication with France, Austria, Slovenia and Greece.

16 ???????????????????????????? Questions? 1&1 De-Mail GmbHJune 2016 16

17 1&1 De-Mail GmbH Leslie RomeoErnst-Frey-Straße 10 Head of De-Mail 76135 Karlsruhe Germany Phone+49 721 91374-3973 leslie.romeo@1und1.de leslie.romeo@1und1.de-mail.de www.1und1.de Thank you for your attention! 1&1 De-Mail GmbHJune 2016 17

18 Back Up Slides 1&1 De-Mail GmbHJune 2016 18

19 De-Mail erstellen Kurze, automatisierte und entschlüsselte Prüfung (Spam / Viren) im flüchtigen Speicher Übermittlung über verschlüsseltem Kanal Anzeige der De-Mail De-Mail Dienste- anbieter Sender De-Mail Dienste- anbieter Empfänger Empfänger Sender Zweistufige Anmeldung Zwei-Faktor- Authentifikation (Besitz/Wissen) Vertrauliche Transportkanäle Integritätsschutz durch DKIM-Signatur Pentests Striktes Rollen-Berechtigungskonzept durchgänginges 4-Augen-Prinzip Redudante Systeme DMDA-DMDA-Kommunikation über SSL-Tunnel Dokumentenverschlüsselung Schutz vor SPAM, VIren und Maleware Vertrauliche Transportkanäle Integritätsschutz durch DKIM-Signatur Zweistufige Anmeldung Zwei-Faktor- Authentifikation (Besitz/Wissen) Qualifizierte elektronische Signaturen Qualifiziert signierte Abhol-, Versand- und Eingangsbestätigung Algorithmen gemäß Vorgaben des BSI Kurze, automatisierte und entschlüsselte Prüfung (Spam / Viren) im flüchtigen Speicher Verschlüsselte Ablage im Postfach Umgebung vom BSI nach ISO 27001 auf Basis IT-Grundschutz und durch BfDI nach Datenschutz Kriterienkatalog zertifiziert und unter ständiger Kontrolle Absicherungsübersicht 1&1 De-Mail GmbHJune 2016 19

20 MassenversenderUse CasesPostE-Mail Banken Versicherungen Vereine Telekommunikationsunternehm en Öffentliche Verwaltung Versorger [...] RechnungenXX* MahnungenX- KontoauszügeX- VerträgeX- AGB- Änderungen X- BescheideX- InformationenXX Sensible DatenXX Klassisch versendete Dokumente sind: Status Quo Versandweg 1&1 De-Mail GmbHJune 2016 20

21 Anzahl der Briefsendungen (< 50g) in Deutschland*ca. 19,6 Milliarden Stück - Versendet von privaten Unternehmen (~ 92 %)ca. 18,03 Milliarden Stück - Versendet von Privatpersonen (~ 8 %)ca. 1,57 Milliarden Stück Grds. für den elektronischen Versand geeignet (~ 75 %)ca. 14,7 Milliarden Stück Erzielter Umsatz für Briefsendungen*ca. 10,6 Milliarden € Anteiliger Umsatz bei substituierbarem Versand (~ 75 %)ca. 7,95 Milliarden € Basis eines Einsparungspotenzial sind, außer dem hier berücksichtigten Porto, auch die günstigeren, medienbruchfreien Prozess- und Bearbeitungskosten, ohne Medienbruch. * im Jahr 2007Quelle: Studie der WIK-Consult GmbH im Auftrag der BNetzA (2009): Nachfrage von Postdienstleistungen von Geschäftskunden Status Quo - Kosten 1&1 De-Mail GmbHJune 2016 21

22 Auszug aus der MaFo von Juli 2014 an De-Mail Bestandskunden (GK: 483 Teilnehmer): Was glauben Sie woran es liegt, dass De-Mail noch nicht flächendeckend genutzt wird? Wie oder für was würden Sie De-Mail zukünftig einsetzen (Mehrfachnennung möglich)? Wie häufig haben Sie seit Vertragsabschluss den De-Mail Dienst nutzen können? 90,5% Gar nicht 4,6% weniger als einmal im Monat 2,3% einmal im Monat De-Mail MaFo Geschäftskunden 1&1 De-Mail GmbHJune 2016 22

23 Auszug aus der MaFo von Juli 2014 an De-Mail Bestandskunden (PK 20.269 Teilnehmer): Was glauben Sie woran es liegt, dass De-Mail noch nicht flächendeckend genutzt wird? Wie oder für was würden Sie De-Mail zukünftig einsetzen? (Mehrfachauswahl möglich) Wie häufig haben Sie seit Vertragsabschluss den De-Mail Dienst nutzen können? Mit welcher Ambition haben Sie sich ursprünglich für De-Mail entschieden? (Mehrfachauswahl möglich) weniger als einmal im Monat einmal im Monat Gar nicht De-Mail MaFo Privatkunden 1&1 De-Mail GmbHJune 2016 23

24 ca. 80% des Markts national verteilt ca. 70% De-Mail Potential auf „einem Klick“ (akkr. DMDAs) Situation De-Mail (07/2014): 70% aller privaten Mailnutzer werden durch akkreditierte DMDAs direkt erreicht und haben De-Mail „auf einen Klick“ verfügbar. ca. 1 Mio. Endnutzer verbindlich unter Vertrag (50% identifiziert) ca. 50.000 Unternehmen mit De-Mail Domain unter Vertrag Erleichterung der Ende-zu-Ende Verschlüsselung durch die Integration von PGP in De-Mail per Ende 2014 Nationale Anbieter mit rechtssicherer Lösung: Nationale Anbieter: US-Provider : De-Mail gut gestartet, aber noch kein Durchbruch 1&1 De-Mail GmbHJune 2016 24

25

26

27

28

29

30


Herunterladen ppt "Leslie Romeo Head of De-Mail DE-MAIL MESSAGEBOX - MADE IN GERMANY."

Ähnliche Präsentationen


Google-Anzeigen