ellen_messmer
Senior Editor, Network World

Illinois puts pizazz back in PKI

News
Jul 11, 20075 mins

Program once hailed as leading-edge back on track after stumbles

State of Illinois had placed a big bet on public-key infrastructure (PKI) for e-commerce, but that was becoming a losing bet three years ago as state agencies floundered with issuing digital certificates. But a drastic change to centralize certificate issuance through the Illinois IT department saved the project, among the most ambitious for PKI in the country.

In 1999 Illinois placed a big security bet on public-key infrastructure for e-commerce, but three years ago its PKI project faltered as state agencies foundered badly when issuing the digital certificates to citizens.

It wasn’t supposed to turn out that way. The state’s landmark Electronic Commerce Security Act had given digitally signed documents an equal legal status to wet-signature paper ones in 1999, putting Illinois on the cusp of the PKI revolution. “Over the next 18 months we hope to distribute over a million digital IDs to citizens and businesses to enable them to do business with the state of Illinois as an integrated secure Web-driven government,” proclaimed then-Governor George Ryan.

The idea was to decrease paper-based exchange in favor of electronic documents in every sphere of government on every level by having citizens submit digitally signed forms instead of written signatures.

In early 2001, that still sounded possible, as Illinois had the technology contracts in place — primarily one with Entrust — making digital-certificate registration, issuance and management software available to state agencies. But the agencies were flummoxed by the intricacies of PKI, in which sender and recipient can exchange encrypted and signed documents through a public-private key pair also used to verify contents haven’t been altered.

“By 2003, we had less than 6,000 certificates issued,” acknowledges Doug Kasamis, acting deputy director of the state’s IT department, the Central Management Services (CMS) Bureau of Communication and Computer Services.

More wheels were coming off the wagon as Gov. Ryan, once praised for setting up a cabinet-level chief technology office, left office under a cloud of scandal that year, later being convicted of racketeering and fraud charges. By 2004, it was clear that something had to be done to save the PKI effort, whicht was failing despite the fact that Illinois was distributing certificates for free.

“We called this our ‘IT rationalization,’” says Mark Anderson, head of the PKI project. Basically, the state agencies and the IT department settled on a last-ditch plan to centralize the administration of PKI at the CMS level, having CMS do the technical work on behalf of the state agencies.

“We centralized the infrastructure, consolidating the servers and LANS,” Anderson says. “We run the master directory, the public-key and revocation list.”

CMS basically took over technical responsibility for issuing digital certificates, delivering them upon request to agencies over the state’s private-line network.

“Today, we’re the certificate authority,” says Kasamis about the CMS role. Illinois, which submits to an annual “eValidate” audit by Deloitte & Touche required by the state’s e-commerce PKI law, keeps the root keys on a server locked in an isolated room in the Springfield, Ill., data center. Illinois also stores what it calls the signature blob of all digitally signed content, which provides proof, if that’s ever needed, of what user certificate signed what content.

That process has worked to salvage the PKI project from failure. While Illinois is far from reaching that million-certificate milestone once envisioned by Ryan, today the state has issued more than 107,000 digital certificates on behalf of state agencies, universities and law enforcement to distribute to individuals doing business with them.

Most of these are regular certificates in which an individual only has to present an Illinois driver’s license to obtain one. But in the first-level system of certificates that’s been set up, some are high-assurance, requiring fingerprinting and a background check.

“The first-level certificates would be used with our Web-based interface to validate a driver’s license, for example,” says Kasamis. Other applications include Medicaid providers locating client benefit information online, and water-treatment facilities that submit wastewater-discharge monitoring reports with the Illinois Environmental Protection Agency using PKI.

“Protection of information is very important so the encryption and signing is important to us,” says Illinois EPA Director Doug Scott about digital certificates.

The EPA’s Web-based application for filing forms and signing them with a digital certificate offers an alternative to filling out paper ones and faxing or mailing them in, says Scott. Slightly less than half of the EPA’s documents are submitted electronically with digital signatures now, he says.

To encourage more electronic filing, the EPA recently gave out $500 to 100 people randomly selected from among those who do business with the EPA to get them to use computer resources to file electronically. “We’re trying to help some of the smaller businesses with this,” says Scott.

Digitally signed files have proven a boon to the EPA because the information on wastewater, such as estimated flow, tends to be more accurate when submitted over the Web than that mailed into the EPA in paper form.

“In terms of the accuracy of the information, the computer has estimated flows, and if the flow is listed much higher than anticipated, the computer will flag it there online,” says Scott. Because the Illinois EPA shares its data with the federal EPA, Illinois checked to make sure there was no problem with digital-certificate-based filing. “The federal EPA said it was fine.”