© Southampton City Council Sean Dawtry – Southampton City Council Implementing a PKI The Southampton Pathfinder for Smart Cards in public services.

Slides:



Advertisements
Similar presentations
Public Key Infrastructure and Applications
Advertisements

Digital Certificate Operation in a Complex Environment Matthew J. Dovey Oxford University Computing Services.
Digital Certificate Installation & User Guide For Class-2 Certificates.
Agenda 2 factor authentication Smart cards Virtual smart cards FIM CM
MIA requirements analyis, 13/10/99 1 Introduction to the MODELS Information Architecture (MIA) and the requirements analysis study Rosemary Russell, UKOLN.
Modeling Hybrid Information Environments: The Librarian and the Super Model Kerry Blinco Consultant Macquarie University Project Manager LIDDAS Project.
- 1 - Defense Security Service Background: During the Fall of 2012 Defense Security Service will be integrating ISFD with the Identity Management (IdM)
Digital Certificate Installation & User Guide For Class-2 Certificates.
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
© Southampton City Council Sean Dawtry – Southampton City Council The Southampton Pathfinder for Smart Cards in public services.
FIPS 201 Personal Identity Verification For Federal Employees and Contractors National Institute of Standards and Technology Information Technology Laboratory.
Copyright © 1999, Financial Services Technology Consortium. All rights reserved. FSML and Echeck Milton M. Anderson Financial Services Technology Consortium.
1st Expert Group Meeting (EGM) on Electronic Trade-ECO Cooperation on Trade Facilitation May 2012, Kish Island, I.R.IRAN.
Cross Platform Single Sign On using client certificates Emmanuel Ormancey, Alberto Pace Internet Services group CERN, Information Technology department.
Password? CLASP Project Update C5 Meeting, 16 June 2000 Denise Heagerty, IT/IS.
2009 Architecture Plan Overview 2009 Architecture Plan Overview.
Holding slide prior to starting show. Supporting Collaborative Working of Construction Industry Consortia via the Grid - P. Burnap, L. Joita, J.S. Pahwa,
1/13/05NCASSR PNNL Visit1 Security Tools Area Overview, Credential Management Services, and the PKI Testbed Jim Basney Senior Research Scientist
DESIGNING A PUBLIC KEY INFRASTRUCTURE
Southampton SmartCities scheme Peter Verrept
U.S. Environmental Protection Agency Central Data Exchange EPA E-Authentication Pilot NOLA Network Node Workshop February 28, 2005.
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
Chapter 11: Active Directory Certificate Services
About PKI Key Stores Dartmouth College PKI Lab. Key Store Defined Protected “vault” to hold user’s private key with their copy of their x.509 certificate.
AJAC Systems Hotel Reservation System
Speaker name Title Project Kick-Off Requirements and Process Review.
Certificate and Key Storage Tokens and Software
Inside the PKI Framework: * Activating the Puzzle Pieces PKI Summit Snowmass August
Public Key Infrastructure from the Most Trusted Name in e-Security.
NASA Personal Identity Verification (PIV) NASA Personal Identity Verification (PIV) High Level System Overview Tice F. DeYoung, PhD 14th Fed/Ed Workshop.
Release & Deployment ITIL Version 3
May 30 th – 31 st, 2006 Sheraton Ottawa. Microsoft Certificate Lifecycle Manager Saleem Kanji Technology Solutions Professional - Windows Server Microsoft.
Access and Identity Management System (AIMS) Federal Student Aid PESC Fall 2009 Data Summit October 20, 2009 Balu Balasubramanyam.
Best Practices in Deploying a PKI Solution BIEN Nguyen Thanh Product Consultant – M.Tech Vietnam
F. Guilleux, O. Salaün - CRU Middleware activities in French Higher Education.
OCLC Online Computer Library Center CONTENTdm ® Digital Collection Management Software Ron Gardner, OCLC Digital Services Consultant ICOLC Meeting April.
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
Trade Software Developer Technical Seminar Document Imaging System March 7, 2012.
Team Members David Haas Yun Tang Robert Njoroge Tom Kerwin Clients Facilities Management Don Anderson Rick Klein.
 T-Box is a solution which promotes and potentiates the creative, responsible, and safe use of technology within education. 
An Intuitive Collaboration Tool for Teachers and Students By Cassie Dove T - BOX PLANET.
UNCLASSIFIED NGA NIPRNET Presentation to FLIP Coordinating Committee, Digital Working Group Larry Glick, (314) , Aeronautical.
MINISTRY OF SOCIAL AFFAIRS AND HEALTH 1 The Finnish National Electronic Patient Record Archive
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
Maintaining Network Health. Active Directory Certificate Services Public Key Infrastructure (PKI) Provides assurance that you are communicating with the.
Windows 2000 Certificate Authority By Saunders Roesser.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
By Umair Ali. Dec 2004Version 1 -PKI - a security architecture – over the internet. -Provides an increased level of confidence for exchanging information.
9 Systems Analysis and Design in a Changing World, Fourth Edition.
Single Sign-On across Web Services Ernest Artiaga CERN - OpenLab Security Workshop – April 2004.
Integrating Charity into Everyday Life Share Jar.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Flexible Registration for Community Education Dottie Marron Delivery Center Manager Student Administrative Services Consulting Center.
Query Health Technical WG Update 1/12/2011. Agenda TopicTime Slot Administrative stuff and reminders2:00 – 2:05 pm Specification Updates QRDA HQMF Query.
Introducing… Conferencing Manager. Agenda Citrix MetaFrame Conferencing Manager Solving business challenges Value to our channel Citrix MetaFrame Conferencing.
25 April Unified Cryptologic Architecture: A Framework for a Service Based Architecture Unified Cryptologic Architecture: A Framework for a Service.
Eurostat Sharing data validation services Item 5.1 of the agenda.
PKI Services for CYPRUS STOCK EXCHANGE Kostas Nousias.
Certificate Security For Users Obtaining and Using Your Personal Certificate using the OSG PKI Kyle Gross – OSG Operations Support Lead Elizabeth Prout.
ArcGIS for Server Security: Advanced
Giuseppe LA ROCCA INFN - Catania, Italy
DIGITAL SIGNATURE SERVICE
Alternative Solutions
National Occupational Standards
Public Key Infrastructure from the Most Trusted Name in e-Security
WEB SERVICES DAVIDE ZERBINO.
PLANNING A SECURE BASELINE INSTALLATION
EDAMIS - current status / further development
Presentation transcript:

© Southampton City Council Sean Dawtry – Southampton City Council Implementing a PKI The Southampton Pathfinder for Smart Cards in public services

© Southampton City Council Sean Dawtry – Southampton City Council Agenda Overview of SmartPath Principles Project Scope The Process How Does it Work Progress Major Issues The Future

© Southampton City Council Sean Dawtry – Southampton City Council Overview Develop Robust/Resilient Security Infrastructure for Electronic Service Delivery. Though Development of PKI Build Around Existing SmartCities Scheme Available from Kiosks, PCs in Libraries 6000 Citizens

© Southampton City Council Sean Dawtry – Southampton City Council Principles Bridge Digital Divide Through SmartCard Public Access Points Needed Real World Application –Housing Repairs Portability and Interoperability –Java 2 Enterprise Edition –XML

© Southampton City Council Sean Dawtry – Southampton City Council Scope Business Process Development –SmartCities –Housing –PKI/Certificate Management Infrastructure Development System Design Integration –With Back Office –SmartCities Secure Portal Intuitive User Interface

© Southampton City Council Sean Dawtry – Southampton City Council Process Select Systems Integrator –S-CAT Phase One –Logical Architecture –Supplier Selection –High Level Physical Architecture Phase Two –Define Physical Infrastructure –Integration Definition –Public Consultation

© Southampton City Council Sean Dawtry – Southampton City Council Process Phase 2 –Design of Processes Housing repairs SmartCities Registration Certificate Management Phase 3 –Software Development –Infrastructure Installation –Integration –Testing –Implementation

© Southampton City Council Sean Dawtry – Southampton City Council How Does It Work Registration –Certificate Request Posted from SmartCities to FTP Server –Certificate Server Regularly Polls for Requests –FTP Request to Certificate Server –Check in CRM to Confirm Housing Tenant –Certificate and User Account Created –FTP Back to SmartCities –Card Encoded with Certificate Ready for Use

© Southampton City Council Sean Dawtry – Southampton City Council How Does It Work Login Process –Card Inserted Inserted Reader –PIN Unlocks Necessary Keys –Certificate Copied From the Card to Cryptographic Store in Microsoft IE 5 –Java Applet Synchronises Certificate with User Account –Confirmation of Account Entry in Security/Policy Server –Access to Specified Resources via Proxy Server through Firewall Housing Repairs –Upon Completion Cryptographic Store is Flushed –Ready For Next User

© Southampton City Council Sean Dawtry – Southampton City Council How Does It Work Lost/Stolen/Blacklisted Cards –Card Loss Report –SmartCities Creates a ‘Hotlist’ –‘Hotlist’ Sent to SmartPath –Checked – Certificate and Account Revoked –New Card Created if Necessary –Registration Process Begins

© Southampton City Council Sean Dawtry – Southampton City Council Progress Currently in Final Phase of Testing Due to Complete 29 th April Delays Due to Need to Replace Security Infrastructure Supplier Issues Relating to Card/Browser Synchronisation Key Member of Staff on Jury Service for 2 Weeks

© Southampton City Council Sean Dawtry – Southampton City Council Major Issues Coordinating Multiple Partners Level of Work Required on Certificate Policies –Certificate Policy –Certificate Practice Statement Integration Between Smart cards and Web Browser ‘Don’t Believe the Hype’

© Southampton City Council Sean Dawtry – Southampton City Council The Future Develop Key Components as a Product that Could Implemented Elsewhere Share Documents –Certificate Practice Statement –Certificate Policy –Design Documents Develop as a National model Integrate With UK-Online Obtain T-Scheme Approval

© Southampton City Council Sean Dawtry – Southampton City Council