NS/EP Service Provider Credential for SIP RPH Signing

Slides:



Advertisements
Similar presentations
Grid Security Infrastructure Tutorial Von Welch Distributed Systems Laboratory U. Of Chicago and Argonne National Laboratory.
Advertisements

Identity and Access Management
Proxy Authentication of the Emergency Status of SIP Calls draft-barnes-ecrit-auth-00 Richard Barnes IETF 69, Chicago, IL, USA.
Module 10: Designing an AD RMS Infrastructure in Windows Server 2008.
Active Directory ® Certificate Services Infrastructure Planning and Design Published: June 2010 Updated: November 2011.
DOCUMENT #:GSC15-PLEN-26 FOR:Presentation SOURCE: ATIS AGENDA ITEM: PLEN 6.4 CONTACT(S): James McEachern ATIS Identity Management.
Certificate Credentials STIR WG IETF 91 (Honolulu) Sean Jon.
DOCUMENT #: GSC15-GTSC8-06 FOR: Presentation SOURCE: ATIS AGENDA ITEM: GTSC8; 4.2 CONTACT(S): Art Reilly ATIS Cybersecurity.
DHS/NCS Priority Services By An Nguyen. Introduction: National Security/Emergency Preparedness (NS/EP) users rely heavily on public telecommunications.
Jackie Voss Manager, Global Standards Development ATIS All-IP Transition Initiatives December 1, 2015.
July 24, Web Services Distributed Management (WSDM) TC Submission: Web Services Manageability Heather Kreger IBM Title slide Igor.
ATIS Identity Management Standards Development DOCUMENT #:GSC13-PLEN-37 FOR:Presentation SOURCE:ATIS AGENDA ITEM:Plenary; IdM and Identification Systems;
November 2004 Dorothy Stanley (Agere Systems) IEEE IETF Liaison Report November 2004 Dorothy Stanley – Agere Systems IEEE Liaison – IETF.
親愛的吉姆舅舅: 今天吃完晚餐後,奶奶說,在家 裡情況變好以前,您要我搬到城裡跟 您住。奶奶有沒有跟您說,爸爸已經 好久沒有工作,也好久沒有人請媽媽 做衣服了? 我們聽完都哭了,連爸爸也哭了, 但是媽媽說了一個故事讓我們又笑了。 她說:您們小的時候,她曾經被您追 得爬到樹上去,真的嗎? 雖然我個子小,但是我很強壯,
Richard EAP-WAI Authentication Protocol Stockholm, IETF 75th draft-richard-emu-wai-00.
Jim McEachern Senior Technology Consultant ATIS July 8, 2015.
Timeline – Standards & Requirements
Status Update -- ATIS Robocalling and Caller ID Initiatives
STI Interworking with SIP-PBXs
draft-ietf-lisp-sec-12
IP-NNI Joint Task Force Status Update
SHAKEN Governance Authority Next Steps
Timeline - ATIS Involvement
Status Update -- ATIS Robocalling and Caller ID Initiatives
Improving Security of Real-time Communications
Global Standards Collaboration (GSC) 14
SHAKEN Governance Authority Criteria
ATIS Cybersecurity DOCUMENT #: GSC13-GTSC6-12 FOR: Presentation
Global Standards Collaboration (GSC) GSC-15
Chris Wendt, David Hancock (Comcast)
Timeline - ATIS Involvement
IP-NNI Joint Task Force Status Update
SG-13 / SSG Information Sharing Session Geneva - 05 November 2002
Proposed ATIS Standard for Signing of SIP RPH
GeoMesh Blockchain Networking - Slide Presentation
Reference Architecture and Call Flow Example for SIP RPH Signing
Analysis of Use of Separate Identity Header for SIP RPH Signing
RFC PASSporT Construction 6.2 Verifier Behavior
SHAKEN Jim McEachern Senior Technology Consultant ATIS December 2017.
Proposal for Change/Improvements in STIR/SHAKEN Technical Report on SHAKEN APIs for a Centralized Signing and Signature Validation Server.
RFC PASSporT Construction 6.2 Verifier Behavior
RFC PASSporT Construction 6.2 Verifier Behavior
Doug Bellows – Inteliquent 10/4/2018
Enterprise Scenarios August 2018.
SIP RPH and TN Signing Cross Relationship
TITLE: Baseline Display Guidelines SOURCE*: Hala Mowafy (Ericsson)
STIR WG IETF-100 PASSPorT Extension for Resource-Priority Authorization (draft-ietf-stir-rph-01) November, 2017 Ray P. Singh, Martin Dolly, Subir Das,
TN-PoP Scenarios Jim McEachern Principal Technologist ATIS August 2018.
STIR WG IETF-99 PASSPorT Extension for Resource-Priority Authorization (draft-ietf-stir-rph-00) July, 2017 Ray P. Singh, Martin Dolly, Subir Das, and An.
Change Proposals for SHAKEN Documents
SIP RPH Signing Use Cases
STIR WG IETF-102 PASSPorT Extension for Resource-Priority Authorization (draft-ietf-stir-rph-06) July 18, 2018 Ray P. Singh, Martin Dolly, Subir Das, and.
RFC Verifier Behavior Step 4: Check the Freshness of Date
I-81 Corridor Improvement Plan
SHAKEN Jim McEachern Senior Technology Consultant ATIS December 2017.
Proposal for Change/Improvements in STIR/SHAKEN Technical Report on SHAKEN APIs for a Centralized Signing and Signature Validation Server.
IPNNI SHAKEN Enterprise Models: LEMON TWIST
Enterprise Structure For Use Case Application of Various Token/Cert Proposals Presented by: Rebekah Johnson.
STIR Certificate delegation
SHAKEN for Presented to: Ericsson Contact:
Calling Party Identity
Enterprise Use Cases and A-Level Attestation
Enterprise Certificates DRAFT
Enterprise Use Cases and A-Level Attestation
Proposed Changes to STI-VS "iat" freshness check
STIR / SHAKEN for 911 use of SHAKEN 8/7/2019
Calling Party Identity
Enterprise Certificates
Rich Call Data Integrity Mechanism
draft-ietf-stir-oob-02 Out of Band
Presentation transcript:

NS/EP Service Provider Credential for SIP RPH Signing Ray P. Singh November 6, 2017 NS/EP Service Provider Credential for SIP RPH Signing PTSC and IPNNI Task Force Meetings McLean, Virginia November 6, 2017

Overview Background Next Step Objective IETF last call was initiated for draft-ietf-stir-rph-01 providing PASSPorT extension for SIP RPH Signing Next Step Objective Define Solution for Authority/Delegation and NS/EP Service Provider (SP) Credential (i.e., Certificate) for SIP RPH Signing

Authority/Delegation and SP Credential Solution considerations Authority and Delegation OEC is the authority for claims associated with “ets” and “wps” namespaces in the SIP RPH NS/EP Service Providers are delegated by OEC as authority for signing SIP RPH with “ets” and “wps” namespaces

Options Option 1: Authority issues certificates for authorized NS/EP Service Providers Option 2: NS/EP Service Providers use their own certificate to identify themselves (e.g., TN certificate used for SHAKEN) Dedicated infrastructure for NS/EP Service Provider certificate issuance and maintenance Leverages SHAKEN infrastructure by using the carrier certificate to sign both TN and SIP RPH Certificate identifies authorized NS/EP Provider Manual distribution of list of authorized NS/EP Service Providers Different certificates required for SHAKEN and RPH signing Carriers benefit of using same credentials for SHAKEN and RPH signing - Avoids complexity of having to use a different certificate for RPH signing from the one used for TN signing Recommendation: NS/EP NGN-PS Service Provider use SHAKEN Credential (i.e., Certificate) for both TN and RPH Signing.

Conclusion/Next Step Need to identify the enhancements needed to allow a NS/EP NGN-PS Service Provider to use its SHAKEN certificate to sign SIP RPHs