Don Wright Director of Standards Lexmark International don@lexmark.com P2600 Hardcopy Device and System Security April 2006 Working Group Meeting Don Wright Director of Standards Lexmark International don@lexmark.com 11/20/2018
Agenda Items Monday/Tuesday, April 3 - 4 Welcome & Introductions Update and Approve Agenda Review and approve March Minutes IEEE Patent Policy Review 2006 Meeting Schedule Update on TCG Update on INCITS CS1 Working Group Review of Action Items from March Meeting Topics from e-mail 11/20/2018
Agenda Items Monday/Tuesday, April 3 - 4 Document Review: Clauses 1-9, especially Clause 5 Document Review of PPs B (Enterprise) PP D (SoHo) PP C (Public) PP A (High) PP Other items Schedule Next meeting details Summarize and record action items 11/20/2018
Minutes from March Meeting Minutes were published shortly after the meeting. They are available at: http://grouper.ieee.org/groups/2600/minutes/P2600-minutes-Mar2006.pdf Any corrections or changes? 11/20/2018
Instructions for the WG Chair At Each Meeting, the Working Group Chair shall: Show slides #1 and #2 of this presentation Advise the WG membership that: The IEEE’s patent policy is consistent with the ANSI patent policy and is described in Clause 6 of the IEEE-SA Standards Board Bylaws; Early disclosure of patents which may be essential for the use of standards under development is encouraged; Disclosures made of such patents may not be exhaustive of all patents that may be essential for the use of standards under development, and that neither the IEEE, the WG, nor the WG Chairman ensure the accuracy or completeness of any disclosure or whether any disclosure is of a patent that, in fact, may be essential for the use of standards under development. Instruct the WG Secretary to record in the minutes of the relevant WG meeting: That the foregoing advice was provided and the two slides were shown; That an opportunity was provided for WG members to identify or disclose patents that the WG member believes may be essential for the use of that standard; Any responses that were given, specifically the patents and patent applications that were identified (if any) and by whom. 11/20/2018 (Not necessary to be shown) Approved by IEEE-SA Standards Board – March 2003 (Revised March 2005)
IEEE-SA Standards Board Bylaws on Patents in Standards IEEE standards may include the known use of essential patents and patent applications provided the IEEE receives assurance from the patent holder or applicant with respect to patents whose infringement is, or in the case of patent applications, potential future infringement the applicant asserts will be, unavoidable in a compliant implementation of either mandatory or optional portions of the standard [essential patents]. This assurance shall be provided without coercion. The patent holder or applicant should provide this assurance as soon as reasonably feasible in the standards development process. This assurance shall be provided no later than the approval of the standard (or reaffirmation when a patent or patent application becomes known after initial approval of the standard). This assurance shall be either: a) A general disclaimer to the effect that the patentee will not enforce any of its present or future patent(s) whose use would be required to implement either mandatory or optional portions of the proposed IEEE standard against any person or entity complying with the standard; or b) A statement that a license for such implementation will be made available without compensation or under reasonable rates, with reasonable terms and conditions that are demonstrably free of any unfair discrimination. This assurance is irrevocable once submitted and accepted and shall apply, at a minimum, from the date of the standard's approval to the date of the standard's withdrawal. New text in red! Even newer text in blue! 11/20/2018 Slide #1 Approved by IEEE-SA Standards Board – March 2003 (Revised February 2006)
Inappropriate Topics for IEEE WG Meetings Don’t discuss the validity/essentiality of patents/patent claims Don’t discuss the cost of specific patent use Don’t discuss licensing terms or conditions Don’t discuss product pricing, territorial restrictions, or market share Don’t discuss ongoing litigation or threatened litigation Don’t be silent if inappropriate topics are discussed… do formally object. If you have questions, contact the IEEE-SA Standards Board Patent Committee Administrator at patcom@ieee.org or visit http://standards.ieee.org/board/pat/index.html This slide set is available at http://standards.ieee.org/board/pat/pat-slideset.ppt 11/20/2018 Slide #2 Approved by IEEE-SA Standards Board – March 2003 (Revised March 2005)
Officers No Change Chair: Don Wright, Lexmark Vice Chair: Lee Farrell, Canon Secretary/Lead Editor: Brian Smithson, Ricoh 11/20/2018
2006 Meeting Schedule May 23-24 Paris, @ HÔTEL ATALA June 19-20, Camas WA @ Sharp July 26-27 Rochester, NY @ Xerox September 6-7 Boulder, CO @ IBM October 23-24, Lexington KY @ Lexmark December 11-12, Orange County @ Canon 11/20/2018
Trusted Computing Group Update 11/20/2018
INCITS CS1 : Cyber-Security Update 11/20/2018
Group General Action Items from March Update web site with May meeting details – done Convert all sections to new Operational Environment names – done except clause 8, clause 9 & PP-C, Convert all sections to new PP names – done except PP-C Convert HVA to CIM Medium @ EAL 3 – no Convert PP-D (SoHo) to EAL 1/Low Assurance – done For PP-D: User authentication for printing – protecting the user document data – no Take out the UD threats Don’t include user authentication for print Add back in threats to HCD’s integrity (“proxy”, “sw.update”) Harmonize Subject/Object implementation – no Sharp: Details of meeting in Camas WA – same as last time 11/20/2018
Action Items from Previous Meetings Review entries in P2600-action-items excel spreadsheet ? 11/20/2018
Issues raised on e-mail Smithson - Glossary Smithson - PP Environment Name Change Smithson - T.TSF.CRED.DISK Chen - Plain English PPs Smithson e-mail of 3/24 (Subject: Some comments on PPs) 11/20/2018
Document Section Status Editors Assigned: Clause 1 & 4 – Don W. Clause 2 & Informative References – Don W. Clause 3 (definitions) -- Alan Sukert Clause 5 (environments) – Peter C. Clause 6 (assets) – Brian V. Clause 7 (threats) – Jerry T. Clause 8 (Mitigation) – Tom H. Clause 9 (Best Practices) – Don W. PP-A -- Ron Nevo PP-B -- Brian Smithson PP-C -- Nancy Chen PP-D -- Carmen Aubry Other Annexes – Smithson/Sukert 11/20/2018
Document Review Drafts needing most review Others clauses 5 – Cybuck (Done) 3 – Sukert (Done) 9 – Wright (Done) PP-A (done) PP-B (done) PP-C (done) PP-D (partially done… need full review of 4.1 & 4.2) Others clauses PP Annexes – Smithson (Done) 11/20/2018
Document Review: PP-A Review Draft number 18a Now Protection Profile A, EAL 3 11/20/2018
Document Review: PP-B Review Draft number 18a Now Protection Profile B, EAL 2 11/20/2018
Document Review: PP-C Review Draft number 18a Now Protection Profile C, EAL 2 11/20/2018
Document Review: PP-D Review Draft number 17b Now Protection Profile D, EAL1 11/20/2018
Next Meeting Details May 23 - 24 Where: HÔTEL ATALA Hotels: HOTEL ATALA (****) 10 rue CHATEAUBRIAND 75008 PARIS tel : 33.(0)1.45.62.01.62 fax : 33.(0)1.42.25.66.38 www.hotelatala.com single : 183 euros double : 195 euros HÔTEL GOLDEN TULIP SAINT HONORE (****) 218 - 220 rue du Faubourg Saint Honoré 75008 PARIS tel : 33.(0)1.49.53.03.03 fax : 33.(0)1.40.75.02.00 www.royalgardenparis.com single : 209 euros double : 229 euros HÔTEL SOFITEL (****) 14 rue Beaujon 75008 PARIS tel : 33.(0)1.53.89.50.50 fax : 33.(0)1.53.89.50.51 www.sofitel.com / www.accorhotels.com rate : 245 euros 11/20/2018
Next Meeting Details 11/20/2018
Other Business Schedule Clauses 1-9, Informative Annex Ready for merging May & June meeting reviews Protection Profiles Waiting for April decision on extent of change to CCV3 draft Simple changes: July draft of CCV3 into the PPs by Sept? PPs reviewed and iterate 1 or 2 times Complex changes: who knows? Complete draft out of December meeting 11/20/2018
Other Business Schedule January February March Form IEEE ballot body Engage with CC Eval Labs February Start Balloting Start Evaluation of PPs March April -- (Will need group meeting) Reconcile comments from IEEE and Eval Labs May – June - July Recirculations September RevCom / Standards Board Approval 11/20/2018
Action Items for May Each person should explore with their company funding the CC Evaluation Lab. Exactly how much depends on number of participants Some money perhaps as early as December, more in Jan/Feb 2007. 11/20/2018
Backup Slides 11/20/2018
Mailing List and Web Site Listserv run by the IEEE An archive is available on the web site Subscribe via a note to: listserv@listserv.ieee.org containing the line: subscribe stds-2600 Only subscribers may send e-mail to the mailing list. No Change 11/20/2018
Project Schedule from Sept Meeting The PAR included estimates of the end-points of the schedule: Initial ballot through IEEE (Lab get this as well) Do needed recircs to get close Run through the lab Recirc the lab’s final changes if any Turn around the clause 1-8 changes before Dec. Meeting Merge section together for December meeting Get all PPs in CCv3 by December meeting Form IEEE Ballot Body in 1Q06 11/20/2018