dimanche 18 juillet 2010

Universal Business Language


Universal Business Language (UBL) is a library of standard electronic XML business documents such as purchase orders and invoices. UBL was developed by an OASIS Technical Committee with participation from a variety of industry data standards organizations. UBL is designed to plug directly into existing business, legal, auditing, and records management practices[1]. It is designed to eliminate the re-keying of data in existing fax- and paper-based business correspondence and provide an entry point into electronic commerce for small and medium-sized businesses.[2]
UBL version 2.0 was approved as an OASIS Committee Specification in October 2006 and has been publicly released. UBL is owned by OASIS and is currently available to all, with no royalty fees. The UBL library of business documents is a well-developed markup language with validators, authoring software, parsers and generators.[3]
UBL 2.0 traces its origins back to the EDI standards and other derived XML standards. In total there are 31 documents covering business needs in the phases of presale, ordering, delivery, invoicing and payment. [4]
As part of the Northern European cooperation on e-commerce and e-procurement, representatives from DenmarkSwedenNorwayFinlandUK and Iceland have set up a working group for developing a Northern European subset of UBL 2.0 documents (NESUBL). The main focus of NES is to define the semantic use of UBL 2.0 as applied to specific business processes. To achieve this the UBL 2.0 standard is restricted on additional levels by using "profiles" that apply to defined business situations. The use of individual elements is specifically described to avoid conflicting interpretation. Additionally each country has developed guidelines that describe the application of the NESUBL subset to domestic business practices. The goal is to enable companies and institutions to implement e-commerce by agreeing to a specific profile and thus eliminate the need for bilateral implementation. Additional countries have shown interest in joining the work. The NESUBL subset was published in March 2007.[5]
Since its publication, NESUBL subset has influenced government eProcurement initiatives across Europe, for example in Denmark, Sweden, Norway, Iceland, Holland, Turkey. It is also the basis for a eProcurement initiative, ePrior, by the European Commission, Directorate General's of the European Commission, starting with the Directorate General for Information Technology (DIGIT).[6]
An excellent analysis of Business Requirements for eInvoicing in a Public Procurement Context is available at [7]
Further development of NES has progressed over to CEN/BII workshop and will be the basis for the PEPPOL project, Pan European Public Procurement project.[8] [9]
The goal of PEPPOL is to run public procurement pilots across borders within the EU, based on harmonised procurement documents developed by CEN / BII workshop.[10]



mercredi 30 juin 2010

What is PCI DSS?

The PCI DSS, a set of comprehensive requirements for enhancing payment account data security, was developed by the founding payment brands of the PCI Security Standards Council, including American Express, Discover Financial Services, JCB International, MasterCard Worldwide and Visa Inc. Inc. International, to help facilitate the broad adoption of consistent data security measures on a global basis.
The PCI DSS is a multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design and other critical protective measures. This comprehensive standard is intended to help organizations proactively protect customer account data.
The PCI Security Standards Council will enhance the PCI DSS as needed to ensure that the standard includes any new or modified requirements necessary to mitigate emerging payment security risks, while continuing to foster wide-scale adoption.
Ongoing development of the standard will provide for feedback from the Advisory Board and other participating organizations. All key stakeholders are encouraged to provide input, during the creation and review of proposed additions or modifications to the PCI DSS.
The core of the PCI DSS is a group of principles and accompanying requirements, around which the specific elements of the DSS are organized:
Build and Maintain a Secure Network
Requirement 1: Install and maintain a firewall configuration to protect cardholder data
Requirement 2: Do not use vendor-supplied defaults for system passwords and other security parameters
Protect Cardholder Data
Requirement 3: Protect stored cardholder data
Requirement 4: Encrypt transmission of cardholder data across open, public networks
Maintain a Vulnerability Management Program
Requirement 5: Use and regularly update anti-virus software
Requirement 6: Develop and maintain secure systems and applications
Implement Strong Access Control Measures
Requirement 7: Restrict access to cardholder data by business need-to-know
Requirement 8: Assign a unique ID to each person with computer access
Requirement 9: Restrict physical access to cardholder data
Regularly Monitor and Test Networks
Requirement 10: Track and monitor all access to network resources and cardholder data
Requirement 11: Regularly test security systems and processes
Maintain an Information Security Policy
Requirement 12: Maintain a policy that addresses information security
To further the adoption of the PCI DSS, the PCI Security Standards Council defines credentials and qualifications for QSAs and ASVs. The PCI Security Standards Council also manages a global training and certification program for QSAs and ASVs, and will publish a directory of certified providers on this Web site.

mardi 29 juin 2010

RIF Standard Supports Data Integration, Enterprise Agility

 Today W3C published a new standard for building rule systems on
  the Web. Declarative rules allow integration and transformation
  of data from multiple sources in a distributed, transparent and
  scalable manner. The new standard, called Rule Interchange
  Format (RIF), was developed with participation from the
  Business Rules, Logic Programming, and Semantic Web communities
  to provide interoperability and portability between many
  different systems using declarative technologies. For more
  information, see the RIF FAQ.

  http://www.w3.org/2005/rules/wiki/RIF_FAQ

  The six new standards are:

    * RIF Core Dialect, which provides a standard, base level of
      functionality for interchange
    * RIF Basic Logic Dialect and RIF Production Rule Dialect
      provided extended functionality matching two common classes
      of rule engines
    * RIF Framework for Logic Dialects describes how to extend
      RIF for use with a large class of systems
    * RIF Datatypes and Built-Ins 1.0 borrows heavily from XQuery
      and XPath for a set of basic operations
    * and RIF RDF and OWL Compatibility specifies how RIF works
      with RDF data and OWL ontologies.

  Along with these standards, W3C today published five related
  documents: "RIF Overview," "RIF Test Cases," "OWL 2 RL in
  RIF," "RIF Combination with XML data," and "RIF In RDF." The
  RIF Working Group is also preparing a primer and a revision of
  its outdated "Use Cases and Requirements." Learn more about
  the Semantic Web Activity.

  http://www.w3.org/TR/2010/NOTE-rif-overview-20100622/
  http://www.w3.org/TR/2010/WD-rif-test-20100622/
  http://www.w3.org/TR/2010/NOTE-rif-owl-rl-20100622/
  http://www.w3.org/TR/2010/WD-rif-xml-data-20100622/
  http://www.w3.org/TR/2010/WD-rif-in-rdf-20100622/
  http://www.w3.org/2005/rules/wiki/RIF_Working_Group
  http://www.w3.org/TR/2008/WD-rif-ucr-20081218/
  http://www.w3.org/2001/sw

Source : http://www.w3.org/News/2010#entry-8839

dimanche 20 juin 2010

La DAJ met à jour les formulaires de marchés publics (DC, OUV et NOTI)

La Direction des affaires juridiques (DAJ) du MINEFE à Bercy vient de publier sur son site internet de nouveaux modèles de formulaires DC (déclaration des candidats), OUV (ouverture des candidatures et des offres) et NOTI (notification). Les modifications apportées ont pour objectif d'adapter les imprimés standards aux récentes évolutions réglementaires et à les simplifier. Cependant, la DAJ engage les praticiens à lui faire part de leurs remarques et propositions sur ces nouevaux formulaires avant le 14 juillet 2010 à l'adresse suivante : mp-formulaires.daj@finances.gouv.fr. A l'issue de cette consultation, les formulaires définitifs seront publiés.

Dans les documents proposés à consultation, les termes utilisés ont été unifiés, "en harmonie avec les termes figurant dans le Code des marchés publics" et "des commentaires sur l'usage des imprimés ont été intégrés en préambule des documents". Le nombre de signatures et de documents exigés des candidats a également été réduit. Ainsi, les membres d'un groupement candidat à l'attribution d'un marché doivent actuellement porter leur signature dans trois rubriques du DC4 (constituant la lettre de candidature et portant habilitation du mandataire par ses co-traitants) et une du DC5 (fixant la liste des renseignements ou documents demandés aux candidats). Si les projets de formulaire sont adoptés, les candidats n'auront plus qu'à signer le DC4 qui comportera désormais la déclaration sur l'honneur des candidats et attestera des renseignements produits au titre du DC5.
La DAJ rappelle également que les modèles de formulaires peuvent être ajustés par les pouvoirs adjudicateurs en fonction des informations qu'ils souhaitent demander (ajout de mentions, de lignes supplémentaires). Toutefois, les éventuelles adaptations "ne doivent pas aller au-delà de ce qui est exigé par la réglementation" et le logo et l'identification du ministère de l'Economie, de l'Industrie et de l'Emploi doivent être retirés.
 
Source : Apasp et http://www.localtis.info/

Référence : fiche de la Direction des affaires juridiques du ministère de l'Economie, de l'Industrie et de l'Emploi.

lundi 31 mai 2010

Android-Powered Sensors Monitors Vital Signs

In science fiction films from Aliens to Avatar, commanders back at the base station always know when soldiers of the future get taken out by hostiles--because their vital signs are being monitored in real time. Doing that with present-day technology is a challenge, not least because collecting and transmitting all of the data that can be gathered by even a handful of motion and vital-signs sensors would be a huge drain on battery power and wireless bandwidth.
By equipping the clothing and bodies of users with a mesh of multiple sensors - known as "smart dust" - that report to an Android-powered phone, researchers are pioneering an open-source route to realizing the dream of always-on medical monitoring. Their work has already allowed them to measure how much test subjects exercise, how well their hearts are doing and how much air pollution they're being exposed to.
The resulting data have a number of applications:
  • Incorporation of historical and real-time data on vital signs into permanent medical records
  • Automatically inform a patient when to adjust their heart medication
  • Turn exercise and daily activity levels into a Foursquare-style competition
  • Allow users to avoid locations and times of day when air pollution is worst
The technology (pdf) is described in a paper to be delivered in late June at the 2010 International conference on Pervasive technologies for assistive environment in Samos, Greece. It outlines a hierarchy of processing steps that make 24/7 monitoring of vital signs (such as breathing and heart rate) realistic given the battery life issues and bandwidth constraints of mobile phones
Three-layer architecture of the DexterNet system with example hardware, communication and software implementation.
This hierarchy, known as DexterNet, includes sequential processing at each level of the hardware involved: the sensors, known as the body sensor layer, the smartphone orpersonal network layer, and finally in the "cloud" or global network layer that backs up and does final processing of all of the user's data. The purpose of in-device processing in each layer is the reduction of the amount of information transmitted wirelessly between each device.
The lowest level of this hierarchy, individual sensors on the user's limbs and torso, can gather data on a number of parameters: motion in 3 axes (realized with a three-axis accelerometer and a two-axis gyroscope), heart ECG, levels of airborne particulate matter, and, for breathing movements, "electrical impedance pneumography."
To reduce the frequency with which these sensors must communicate with the user's smartphone (and the volume of information they have to transmit) these sensors are capable of basic signal-processing algorithms across a programmer-definable time period, including minimum, maximum, average and mean values for any particular parameter.
Two types of sensors were used, one, known as the TelosB, is about the size of a USB thumb drive, and sports a Texas Instruments processor often found in embedded applications and 10k of integrated RAM. The other, Intel's SHIMMER sensor, runs theTinyOS operating system designed specifically for remote sensors, weighs only 15 grams and is not much bigger than a quarter.
Led by Edmund Seto of the School of Public Health at UC Berkeley, the researchers involved were able to further integrate data gathered from the wireless sensors with data gathered by the phones themselves. By combining location, time of day and air-quality data, for example, the researchers were able to create maps of user's days that highlight the places and times when they were exposed to greatest levels of air pollution.
Because phones and sensors can communicate with each other wirelessly via Bluetooth, the number of sensors that can be embedded both on a user and in his or her environment is practically limitless. In one application, the researchers put a sensor into the digital bathroom scale of users and their blood pressure monitors to quantify daily changes related to too much fluid retention in patients. The resulting data allowed their algorithms, processed in by the server to which the smartphone sends its data, to suggest possible modification of dosage of blood pressure medication.
Seto et al. cited the Android platform as a unique enabler of their work, not only because Android phones, like all smart phones, are fairly capable wearable computers in their own right. Because Android is open-source, the researchers were able to develop on top of it using the SPINE platform for remote sensing, and to add to it their own API, known as WAVE (not to be confused with Google's Wave). In combination, these research platforms allow them free reign to experiment.
So far the only drawback to using the Android platform in this work, note the researchers, is that it can't locate users indoors. The researchers spend a portion of their paper trying to re-invent the wheel by speculating about ways to accomplish this via the use of Wifi nodes and even visual recognition of interior spaces using the phone's camera, without ever realizing, apparently, that Skyhook Wireless already has an API and an international database of wifi networks that can accomplish this.

mardi 18 mai 2010

The XML Security Working Group has published three Last Call Working Drafts

  The XML Security Working Group has published three Last Call
  Working Drafts: "XML Encryption Syntax and Processing Version 1.1," "XML Signature Syntax and Processing Version 1.1," and "XML Security Generic Hybrid Ciphers." The group also published a Working Draft of "XML Security Algorithm Cross-Reference." XML Encryption specifies a process for encrypting data and representing the result in XML. XML Signatures provide integrity, message authentication, and/or signer authentication services for data of any type, whether located within the XML that includes the signature or elsewhere. The third document augments XML Encryption by defining algorithms, XML types and elements necessary to enable use of generic hybrid ciphers in XML Security applications. The final document summarizes XML Security algorithm URI identifiers and the specifications associated with them. Last Call comments are welcome through 10 June. Learn more about the Security Activity.

  http://www.w3.org/2008/xmlsec/
  http://www.w3.org/TR/2010/WD-xmlenc-core1-20100513/
  http://www.w3.org/TR/2010/WD-xmldsig-core1-20100513/
  http://www.w3.org/TR/2010/WD-xmlsec-generic-hybrid-20100513/
  http://www.w3.org/TR/2010/WD-xmlsec-algorithms-20100513/
  http://www.w3.org/Security/



Source :  http://www.w3.org/News/2010#entry-8801

XProc Standard Defines Way to Organize and Share XML Workflows

  Today W3C announced a powerful tool for managing XML-rich processes such as business processes used in enterprise environments. The W3C Recommendation " "XProc: An XML Pipeline Language,"" provides a standard framework for composing XML processes. XProc streamlines the automation, sequencing and management of complex computations involving XML by leveraging existing technologies widely adopted in the enterprise setting.
  "XML is tremendously versatile," said Norman Walsh, MarkLogic, and one of the co-editors of the specification. "Just off the top of my head, I can name standard ways to store, validate, query, transform, include, label, and link XML. What we haven't had is any standard way to describe how to combine them to accomplish any particular task. That's what XProc provides."
  Read more in the press release and learn more about XML.

  http://www.w3.org/TR/2010/REC-xproc-20100511/
  http://www.w3.org/2010/05/xproc-pr
  http://www.w3.org/standards/xml/

Source :   http://www.w3.org/News/2010#entry-8793

jeudi 13 mai 2010

European Commission Releases New Version of Open e-PRIOR To Push eProcurement Across EU

The Directorate-General for Informatics (DIGIT) has recently announced that a new version of Open e-PRIOR, the open-source version of the e-PRIOR (electronic PRocurement, Invoicing and Ordering) platform has been published on the Open Source Observatory and Repository for European public administrations (OSOR.eu). 



Based on the success and the positive response received on the technical sneak preview published in November 2009, the Open e-PRIOR team has been working on adding the functionality foreseen under the IDABC (Interoperable Delivery of European eGovernment Services to public Administrations, Business and Citizens) programme, as well as taking on feedback received by different parties. 
The new version of Open e-PRIOR delivers an embedded PEPPOL (Pan-European Public Procurement Online) Access Point, which provides a great opportunity for Customers wishing to participate in the PEPPOL pilot that will commence in May 2010.  Through the use of this Access Point, Customers will be able to connect to their Suppliers by exchanging Invoices over the PEPPOL network.  For this purpose a PEPPOL test client is also being provided in the package together with a detailed Software Architecture Document. 
Open e-PRIOR is the first eProcurement implementation which enables the exchange of electronic business documents using the data models of CEN/ISSS WS/BII.
Those willing to know more about Open e-PRIOR can:
download the new version of Open e-PRIOR from OSOR.eu at http://forge.osor.eu/frs/?group_id=188 
join the Open e-PRIOR community in order to learn more about the project, contribute with their feedback and participate in the making of this platform throughhttp://www.osor.eu/projects/openeprior 
read documentation about Open e-PRIOR, including a guide on how to get Open e-PRIOR running and to understand the Software Architecture through http://forge.osor.eu/docman/?group_id=188 
Interested parties can contact the dedicated team who is ready to share knowledge, experiences and to provide support, by e-mail DIGIT-EPRIOR-SUPPORT@ec.europa.eu or through OSOR athttps://forge.osor.eu/forum/forum.php?forum_id=508.

XML Linking Language (XLink) 1.1 is a W3C Recommendation

  The XML Core Working Group has published a W3C Recommendation of "XML Linking Language (XLink) Version 1.1." This
  specification defines the XML Linking Language (XLink) Version 1.1, which allows elements to be inserted into XML documents in order to create and describe links between resources. It uses XML syntax to create structures that can describe links similar to the simple unidirectional hyperlinks of today's HTML, as well as more sophisticated links. "Changes from XLink 1.0" include: xlink:type is no longer required for simple links, IRIs are used instead of URIs, and the specification includes
  non-normative sample XML Schema and RELAX NG grammars. 


Learn more about the Extensible Markup Language (XML) Activity.

  http://www.w3.org/XML/Core
  http://www.w3.org/TR/2010/REC-xlink11-20100506/
  http://www.w3.org/TR/2010/REC-xlink11-20100506/#changes
  http://www.w3.org/XML/


Source :  http://www.w3.org/News/2010#entry-8791

samedi 10 avril 2010

M2M and RFID

This report evaluates the working aspects of M2M along with the details of RFID, provides deep insights into telecommunication technologies, reviews the latest developments within M2M, and provides further analysis through in-depth case study examples.


Machine-to-Machine (M2M) communications and Radio Frequency ID (RFID) together represent a means of direct communication between connection hardware and the object that needs monitoring: the information about its status of performance is directly sent to a computer system without the need for human intervention. This makes automation of processes or consumer action possible. 

The technology that utilized originates largely in the manufacturing and industrial processes industry, where physical assets networking have been done for decades. The goal of M2M-RFID is exactly as of a plant-floor automation systems or remote-monitoring solutions: it evolves getting information from sensors in a device and transmitting it to an IT network.


More here : http://www.pr-inside.com/machine-to-machine-m2m-and-rfid-r1788263.htm