{"id":636,"date":"2007-10-15T22:19:00","date_gmt":"2007-10-16T07:19:00","guid":{"rendered":"http:\/\/www.cloudidentity.com\/blog\/2007\/10\/15\/windows-cardspace-silverlight-help-singapore-to-get-easier-and-safer-access-to-health-data\/"},"modified":"2007-10-15T22:19:00","modified_gmt":"2007-10-16T07:19:00","slug":"windows-cardspace-silverlight-help-singapore-to-get-easier-and-safer-access-to-health-data","status":"publish","type":"post","link":"https:\/\/www.cloudidentity.com\/blog\/2007\/10\/15\/windows-cardspace-silverlight-help-singapore-to-get-easier-and-safer-access-to-health-data\/","title":{"rendered":"Windows CardSpace &amp; Silverlight help Singapore to get easier and safer access to health data"},"content":{"rendered":"<p><P><IMG height=\"375\" alt=\"image\" src=\"http:\/\/cloudidentity.com\/blog\/wp-content\/uploads\/2007\/10\/image_4a83fe80-9ebb-41b7-87fe-a715891d805a.png\" width=\"500\" border=\"0\"> <\/P><br \/>\n<P>In short: few hours ago there was the&nbsp;launch of the a pilot for the web portal <A href=\"https:\/\/myhealth.sg\/\"><EM>my<\/EM>health.sg<\/A>, a platform for allowing individuals to manage information about health, fitness, nutrition and so on. For the time being, the pilot will be limited to a restricted number of users. <A href=\"http:\/\/blogs.msdn.com\/lchong\/default.aspx\">Linda<\/A> was there and sent me the nice picture above. The project is the result of a partnership between the <A href=\"http:\/\/www.cgh.com.sg\/\">Changi General Hospital<\/A> (CGH), Microsoft, <A href=\"http:\/\/www.ncs.com.sg\/\">NCS Group<\/A>&nbsp;and <A class=\"\" href=\"http:\/\/www.radiantrust.com\/\">RadianTrust<\/A>. This is a fantastic app with great features, and yet another proof of the power of Siverlight. From where I stand, however, the coolest thing about this project is that the users authenticate with the application using a managed information card, backed by a hard token (<A href=\"http:\/\/blogs.msdn.com\/lchong\/archive\/2007\/03\/21\/microsoft-enterprise-application-development-platform-post-event-update.aspx\">Singapore&#8217;s DORIS token<\/A>). Ah, and that&#8217;s also the fact that it accounts for a good percentage of the Singapore immigration stamps I got on my passport in the last year an a half\/2 years (besides <A href=\"http:\/\/download.microsoft.com\/download\/8\/b\/6\/8b6a6bbf-9d25-455e-be2d-2d6857bc545a\/STEE%20case%20study.doc\">this<\/A> and others I can&#8217;t talk about yet ;-)).&nbsp;The Singapore team that made this happen (among which: my dear friend <A href=\"http:\/\/blogs.msdn.com\/lchong\/default.aspx\">Linda Chong<\/A> &amp; the excellent Lee Theng Chia from Microsoft Singapore, the superstar <A href=\"http:\/\/www.businessmobileasia.com\/blogs\/themfiles\/\">Lee Lup Yuen<\/A> from NCS) is absolutely outstanding.<\/P><br \/>\n<P>As for <A href=\"http:\/\/blogs.msdn.com\/vbertocci\/archive\/2007\/02\/03\/otto-store-walking-through-the-cardspace-experience.aspx\">the post I&#8217;ve made at the conclusion of the Otto project<\/A>, I can&#8217;t go in any details of the architecture here (beyond the obvious facts that you can figure out on your own). I will just walk you through the user experience, obfuscating the personal identifiable details. Also, take into account that you can&#8217;t perform the walkthrough yourself unless you are proper user of the application (with all the authentication factors).<\/P><br \/>\n<P>&nbsp;<\/P><br \/>\n<P>The first step is, of course, landing on the main page.<\/P><br \/>\n<P><IMG height=\"363\" alt=\"image\" src=\"http:\/\/cloudidentity.com\/blog\/wp-content\/uploads\/2007\/10\/image_1.png\" width=\"500\" border=\"0\"> <\/P><br \/>\n<P>Clicking on Login brings to this screen, where the user is prompted to insert his\/her hard token.<\/P><br \/>\n<P><IMG height=\"201\" alt=\"image\" src=\"http:\/\/cloudidentity.com\/blog\/wp-content\/uploads\/2007\/10\/image_3.png\" width=\"400\" border=\"0\"> <\/P><br \/>\n<P>Pressing OK leads to the familiar Identity Selector:<\/P><br \/>\n<P><IMG height=\"360\" alt=\"image\" src=\"http:\/\/cloudidentity.com\/blog\/wp-content\/uploads\/2007\/10\/image_caf295ef-0b41-41ba-ac2a-4efa8b7b97db.png\" width=\"500\" border=\"0\"> <\/P><br \/>\n<P>Selecting the card and clicking on retrieve starts the STS invocation; the user is prompted for the passphrase associated to the hard token.<\/P><br \/>\n<P><IMG height=\"371\" alt=\"image\" src=\"http:\/\/cloudidentity.com\/blog\/wp-content\/uploads\/2007\/10\/image_d462691a-a18e-4bc0-9603-41970b7be5e5.png\" width=\"500\" border=\"0\"> <\/P><br \/>\n<P>..and we are in! After the strong authentication phase, the user can now access a number of high value services.<\/P><br \/>\n<P><IMG height=\"381\" alt=\"image\" src=\"http:\/\/cloudidentity.com\/blog\/wp-content\/uploads\/2007\/10\/image_604d94df-961c-4c3c-a09c-61aed0c20437.png\" width=\"500\" border=\"0\"> <\/P><br \/>\n<P>&nbsp;<\/P><br \/>\n<P>That&#8217;s it! The use of the application in itself after the authentication is out of scope for my blog so I won&#8217;t go further, however rest assured that it is really beautiful &amp; functional at the same time.<\/P><br \/>\n<P>I would like to&nbsp;stress even further&nbsp;the great value that CardSpace brings to this project. <\/P><br \/>\n<P>Health care data are, perhaps even more than finance, among the most private data we own. Add to this that Singapore is one of the most security conscious countries I&#8217;ve ever visited: the level of knowledge of computer security matters among citizens, from the cab driver to the executive, never ceases to amaze me. For a security geek like me it&#8217;s paradise :-). it&#8217;s no surprise that in such an environment highly sophisticated initiatives like the N-factors DORIS hard token arise; it&#8217;s also no surprise that one would want to leverage that level of authentication for&nbsp;accessing&nbsp;high value data such as health care records.<BR>CardSpace is the&nbsp;perfect mean of seamlessly blending the usage of DORIS, an already existing hard token, in the user experience of the application. The card provides a very handy metaphor for users of all levels of computer literacy; the software necessary for taking advantage of the cryptographic capabilities of the hard token is already in CardSpace itself (apart from the CSP); and the adherence to the identity metasystem roles ensures correct flow of the information and opens the door for future participation to the wider ecosystem.<\/P><br \/>\n<P><BR>For the time being I won&#8217;t go further, but there still a lot to be said on this project. Again congratulations to CGH, to Microsoft Singapore, to&nbsp;NCS and to RT!<\/P><br \/>\n<P>Let me close with the same sentence I used in a similar post, some months ago:<\/P><br \/>\n<P><EM>Kim, here&#8217;s some energy for fueling the Identity Big Bang. How about that? \ud83d\ude42<\/EM><br \/>\n<P><EM>&nbsp;V.<\/EM><\/P><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In short: few hours ago there was the&nbsp;launch of the a pilot for the web portal myhealth.sg, a platform for allowing individuals to manage information about health, fitness, nutrition and so on. For the time being, the pilot will be limited to a restricted number of users. Linda was there and sent me&#8230;<\/p>\n","protected":false},"author":1,"featured_media":1486,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_kad_post_transparent":"","_kad_post_title":"","_kad_post_layout":"","_kad_post_sidebar_id":"","_kad_post_content_style":"","_kad_post_vertical_padding":"","_kad_post_feature":"","_kad_post_feature_position":"","_kad_post_header":false,"_kad_post_footer":false,"footnotes":""},"categories":[61,39,9,86,93,46,55],"tags":[],"class_list":["post-636","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-architecture-ws","category-cardspace","category-identity","category-infocard","category-ria","category-silverlight","category-windows-cardspace"],"_links":{"self":[{"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/posts\/636","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/comments?post=636"}],"version-history":[{"count":0,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/posts\/636\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/media\/1486"}],"wp:attachment":[{"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/media?parent=636"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/categories?post=636"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudidentity.com\/blog\/wp-json\/wp\/v2\/tags?post=636"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}