Organization for the Advancement of Structured Information Standards Presented by Chuck White & Jerry StUEve © 2018 Fornetix · All Rights Reserved
What Is OASIS? OASIS is a nonprofit consortium that drives the development, convergence, and adoption of open standards for the global information society. OASIS works because different teams come to OASIS from different background and different goals. © 2018 Fornetix · All Rights Reserved
In Standards We Trust KMIP PKCS#11 OpenC2 Fornetix & OASIS © 2018 Fornetix · All Rights Reserved
What does KMIP do? Security Applications or Appliances Key Material & Metadata Transport KMIP Key Management Server Create, Register, Locate and Retrieve Encryption Keys Many extended services: Encrypt, Decrypt, Signing, Split- Keys etc. Supports Symmetric Keys, Asymmetric Keys, Certificates, Signing etc. Rich metadata for essential cryptographic management Much more than just add, modify & delete The KMIP specification includes an incredibly broad range of capabilities for full lifecycle management of security objects, with almost unlimited extensibility through a flexible, yet interoperable attribute model. 46 Operations (much more than just add, modify & delete) enables Security Appliances/Applications to perform tasks including: Encryption, Decryption, Authentication, Certification, Signing, Verification and Split-Key operations. 9 Object types catering for many more security objects include: Certificate, Certificate Request, Opaque Object, PGP Key, Private Key, Public Key, Secret Data, Split Key, Symmetric Key 54 Attributes to represent information (meta-data) about each Object under management
KMIP Deployed in Solutions KMIP solutions are deployed across in all industry sectors, delivering management of security objects for: Cloud Storage Identity Management Financial systems Automotive Healthcare Email Provisioning and supply chain PKI Communications Authentication Defense
KMIP Specification Development Enterprise Requirements Specification Development Product Deployment Specification Testing Being part of the OASIS KMIP TC enables vendors to more quickly bring their customers’ requirements to the standards development process. The enterprise requirements drive the Specification development which Drives the Product Testing which is fed back into the enterprise
KMIP 2018 RSA Interop Demonstration Over the last month implementations from these vendors have undergone a rigorous Interoperability testing process to prove the latest additions to the KMIP Specification and deliver true multi vendor interoperability. It is this rigor that ensures conformant implementations meet the aims of the KMIP Technical Committee and the expectations of the market If you have not already seen a demonstration from at least one of these members, please ask for a demonstration at the conclusion of this presentation.
KMIP RSA 2018 Test Results 9 KMIP TC members 17 implementations 8 Client Implementations 9 Server Implementations Over 33,000 successful test runs 72 Test combinations 4 encodings 9 KMIP Technical Committee members testing 17 implementations 8 Client Implementations 9 Server Implementations Over 33,000 successful test runs 72 Test combinations across 4 encodings
KMIP Deployed by Organizations Many organizations are relying on KMIP to ensure management and visibility of their security object It remains the default standard for full lifecycle security object management
Technologies Consistent Data Storage HSM Integration Cyber Defense Data in Motion Hypervisor Storage Cloud Storage Database Storage Hardened Boundary for Cryptographic Functions Supports Top Algorithms Threat Mitigation Machine Identity IoT Security PKI Management Security Cryptographic Velocity Mutual Authentication © 2018 Fornetix · All Rights Reserved
What Does This Mean? Benefits Speed & Savings Shared Enhancements With consistent interfaces, we can integrate our product with others in a much shorter timeframe with a lower integration cost and additional security. Shared Enhancements Focus on making other enhancements to our product and rolling those enhancements back into the technical committee for consideration. Mutual Growth The end result of this collaborative process is making everyone’s products better. © 2018 Fornetix · All Rights Reserved
Across Verticals Practicality of Standards Energy Healthcare Financial Cross-Vertical Concerns Smart Meters Smart Grid Power Generation Electronic Health Records Medical Implants Connected Medical Diagnostic Systems Medical Record Integrity Financial Transaction Enablement Customer Confidentiality Record Integrity GDPR Secure Supply Chain Crypto Agility © 2018 Fornetix · All Rights Reserved