Virtual Face to Face Meetings for ID-check

Slides:



Advertisements
Similar presentations
An Alternative to Short Lived Certificates By Vipul Goyal Department of Computer Science & Engineering Institute of Technology Banaras Hindu University.
Advertisements

Robots Jens Jensen, STFC RAL GridNet2/ UK e-Science CA /NGS/GridPP/
Report on Attribute Certificates By Ganesh Godavari.
Alexander Potapov.  Authentication definition  Protocol architectures  Cryptographic properties  Freshness  Types of attack on protocols  Two-way.
Tweaking the Certificate Lifecycle for the UK eScience CA John Kewley NGS Support Centre Manager & Service Manager for the UK e-Science CA
Lecture 18 Page 1 CS 111 Online Access Control Security could be easy – If we didn’t want anyone to get access to anything The trick is giving access to.
Architectural Considerations for GEOPRIV/ECRIT Presentation given by Hannes Tschofenig.
Time with Office of Sponsored Programs April 4, 2011 Topic: Cost Share.
NECTEC-GOC CA Self Audit 7 th APGrid PMA Face-to-Face meeting March 8 th, 2010 Large-Scale Simulation Research Laboratory Sornthep Vannarat Large-Scale.
Revocation in MICS §4.4 May 11-13, 2009 Zürich, Switzerland.
HEPSYSMAN UCL, 26 Nov 2002Jens G Jensen, CLRC/RAL UK e-Science Certification Authority Status and Deployment.
PKI Services for CYPRUS STOCK EXCHANGE Kostas Nousias.
18 th EUGridPMA, Dublin / SRCE CA Self Audit SRCE CA Self Audit Emir Imamagić SRCE Croatia.
Academia Sinica Grid Computing Certification Authority F2F interview (Malaysia )
Jens' obligatory soap box Can't be a PMA without a SoapBox A random collection of Soapy things Nicosia, Jan 2009.
UGRID CA Self-audit report Sergii Stirenko 21 st EUGRIDPMA Meeting Utrecht 24 January 2011.
Soapbox (S-Series) Certificate Validation Jens Jensen, STFC.
Applying For A VA Loan Is it Difficult?. The home mortgage loans guaranteed by the U.S. Department of Veterans Affairs have been a popular way for veterans.
IRAN-GRID CA Self Audit IRAN-GRID CA Self Audit Report Shahin Rouhani IRAN-GRID Tehran Iran Shahin Rouhani Grid Computation Group IPM, Tehran, Iran May.
EU GridPMA meeting Dublin, January 2010
Introduction to Industry
TAG Presentation 18th May 2004 Paul Butler
OPT Optional Practical Training
Screening for Patients’ Health Insurance and Confidentiality Needs
Applicant Profile® G.A.T.E.® Test Administration Training UPS MAPP.
Training for Supervisors and Designees
Preparing for your visa application
Applying for a visa to study in the UK
Immigration – Common Errors and How To Conduct An Internal I-9 Audit
CANADA’S ANTI-SPAM LEGISLATION (CASL)
I-9 Instructions and FAQs
Jens Jensen EU Grid PMA, Berlin Jan 2015
Information Governance Support Information Governance Services
Public Key Infrastructure (PKI)
Tender Evaluation and Award Process
IEEE 802 Rules Update November 2012 meeting
Transitional Exit Capacity Proposals -Update
AEGIS Certification Authority
IT443 – Network Security Administration Instructor: Bo Sheng
What’s Changing in Research Administration?
TAG Presentation 18th May 2004 Paul Butler
CS480 Cryptography and Information Security
Points-based immigration system
Certificates An increasingly popular form of authentication
Network Services Interface
Tweaking the Certificate Lifecycle for the UK eScience CA
Helpful Information to Support Your Secondary School Appeal
Tracker I-9 Upgrade November 2017.
Program Management Portal (PgMP): Catalog and the Client
Domain Matching for BID Association Requests
Applying for a visa to study in the UK
Alignment of Part 4B with ISAE 3000
The IGTF Charter Name uniqueness throughout the IGTF is anchored in the Charter Current Charter assigns a namespace to an Authority, implying that the.
© 2017 Universal Service Administrative Co.
Grid Security M. Jouvin / C. Loomis (LAL-Orsay)
Analysing Information Collection Methods
Investigator of Record – Definition
Digital Certificates and X.509
UK e-Science CA and JCS Migration Status
Internal controls 01-Nov-2017.
Special Class Status.
Alignment of Part 4B with ISAE 3000
ServiceLink Training Video Managing Job Orders Pending Completion
Resource Certificate Profile SIDR WG Meeting IETF 66, July 2006
Optional Practical Training (OPT)
Certificates An increasingly popular form of authentication
Dr Linda Cornwall STFC/RAL EGI OMB 27th September 2013
Alignment of Part 4B with ISAE 3000
WORKING ON FUNDING YEAR (FY) 2019
Hazelwood Schools Wednesday 2nd October 2019.
Presentation transcript:

Virtual Face to Face Meetings for ID-check John Kewley Jens Jensen UK eScience CA

Virtual F2Fs Why are virtual F2Fs desirable? Virtual F2Fs for Re-Applications Virtual F2Fs for New requests Conclusions Proposal

Why Virtual F2Fs? The requirement to visit your local RA Operator is one which can be a hurdle for new personal certificate requests for users at large (especially distributed) sites. Maintaining a large RA Operator network can be problematic. Being able to meet over a video link would be a major improvement

Video ID checks In the following circumstances being able to do a Video ID check would be preferable from the usability point of view (we’ll worry about LoA/security later): Bootstrapping a New RA There are no longer any RA Operators at a site User doesn’t work at the same site and rarely visits the site the RA Op is based at. For very small sites it would reduce the requirement for having a separate RA, and training the RA Operators.

When Virtual F2Fs? There are 2 cases for which a virtual meeting can be considered for a personal certificate: PhotoID check for a Re-Application PhotoID check for a New certificate

What is a Re-Application? A Re-Application is the process of obtaining a personal certificate when you have previously held one with the same DN, but are not able to do a renew/rekey: Previous certificate has expired sufficiently long ago that it is outside any “grace” period [30 days for UK eScience CA] Previous certificate was revoked So, basically the same as a New request except the RA Op already has a photocopy of the original PhotoID and MUST NOT issue a certificate with the same DN unless (s)he can guarantee that the requestor is the same person as in the original.

Re-Application by Video For a Video meeting, the following would seem to give a similar LoA to that obtained by a physical face to face meeting: The meeting is over a high quality video (at least sufficient to easily see/read the PhotoID The PhotoID should be the SAME one as used originally, and hence should match the photocopy in the RA records. Applicant informs RA Op of the request ID, and the PIN of the CSR. Additional “evidence” needs recording: e.g. a screenshot of the PhotoID on which the RA Op writes the request number. Therefore the RA Op can see the face of the person in the video meeting; it is the same face as on the photocopy in the records; the matching PhotoID is clearly in the hands of the applicant; and there is evidence that the CSR about to be approved was requested by this person.

So how about NEW requests? Most of the above written about Re-Application applies, but for a NEW request you need to identify more security features on the PhotoID. Such security features may vary from ID to ID so suitable training in what is appropriate needs to be taught. Also, using Staff IDs is unlikely to be sufficient. It also implies that the video link must be of a very high quality.

Asserted copy The main difference between the requirements for a re-application F2F video meeting and that of a new application is proving that the PhotoID is genuine. One way to assert this would be for the requestor to take their PhotoID to an appropriate person (for instance a notary public) to copy, sign and stamp and then post direct to the CA. This could then be used in parallel with the video meeting.

Conclusions The provision of an appropriate Virtual F2F meeting for PhotoID checking would be a major improvement to the processes of many CAs. While we believe it is possible to ensure an appropriate level of assurance for a re-application, it would be considerably harder to do that for an initial application, at least without something else such as an asserted copy of that PhotoID.

Proposal We should encourage CAs to accept Re-applications over video link now and feed back any issues they find. We should allow video F2F meetings for new requests if accompanied by a trusted asserted copy of the PhotoID. At the next PMA meeting we should have a demo of how good an ID check you can do over HQ video-link is in the absence of an asserted copy of the PhotoID.